15 часов назад
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr. Security Engineer - GRC EU/UK Regulation & Data Protection (DORA/EU AI Act): Building and operating automated information security GRC capabilities for regulated EU/UK financial services and AI products with an accent on Compliance-as-Code, continuous evidence collection, and operational resilience. Focus on implementing technical controls, assessing regulatory and third-party risk, and translating DORA, GDPR, NIS2, and EU AI Act obligations into secure engineering practices.
Location: London, England, United Kingdom
Company
Develops AI systems and regulated financial products, including xMoney, with a focus on engineering excellence and practical governance.
What you will do
- Own and evolve EU/UK financial services and digital operational resilience compliance across DORA and UK PRA/FCA requirements.
- Build Compliance-as-Code capabilities, including policy-as-code, automated control validation, continuous evidence collection, and CI/CD monitoring.
- Operate and extend GRC platforms such as Vanta, integrating them with cloud, identity, logging, and engineering systems.
- Design and validate technical security controls covering access management, logging, encryption, change management, vulnerability management, third-party ICT risk, and secure SDLC.
- Partner with architects and engineering leads to embed regulatory and security requirements into product and platform design.
- Lead risk assessments, compliance reviews, audit and supervisory relationships, policies, risk registers, and assessment-ready compliance programs.
Requirements
- Bachelor’s degree in computer science, information security, cybersecurity, engineering, or another STEM field.
- At least 5 years of GRC, information security compliance, or technology audit experience in fintech, banking, payments, or other heavily regulated environments with EU/UK exposure.
- Hands-on experience with several of DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience requirements.
- Experience with Compliance-as-Code, GRC automation, continuous monitoring, and reducing manual evidence collection.
- Technical fluency across security architecture and on-premises, hybrid, or cloud environments such as AWS, GCP, or Azure.
- Working knowledge of EU/UK privacy requirements, including EU GDPR, UK GDPR, and the UK Data Protection Act 2018.
Nice to have
- 7+ years of information security compliance, GRC engineering, or technology audit experience with a primary EU/UK focus.
- Experience with IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening, and compliance checks in CI/CD.
- ISO 27001 and/or SOC 2 program experience, plus DORA ICT third-party risk, register of information, TLPT, and major incident reporting knowledge.
- Experience with AI governance, trust centers, vendor questionnaires, customer security reviews, or regulated financial institutions.
- CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar certification.
Culture & Benefits
- Small, highly motivated team with a flat organizational structure.
- Hands-on environment focused on engineering excellence, curiosity, initiative, and direct contribution.
- Strong emphasis on concise, accurate communication and pragmatic governance over checkbox compliance.
- Occasional travel may be required.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →