Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Full-Time 75600 - 92400 £ / year (est.) Home office (partial)
X

At a Glance

  • Tasks: Lead GRC initiatives for EU/UK regulations and enhance information security compliance.
  • Company: Join SpaceXAI, a pioneering tech firm on a mission to advance AI for humanity.
  • Benefits: Competitive salary, flexible work options, and opportunities for professional growth.
  • Other info: Collaborative culture with a flat structure, perfect for those who thrive on initiative.
  • Why this job: Make a real impact in a dynamic environment while shaping the future of AI and compliance.
  • Qualifications: 5+ years in GRC or information security with hands-on experience in EU/UK regulations.

The predicted salary is between 75600 - 92400 £ per year.

  • Sr. Security Engineer - GRC EU/UK Regulation & Data Protection
  • London, England, United Kingdom

Space XAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.

Our team is small, highly motivated, and focused on engineering excellence.

This organization is for individuals who appreciate challenging themselves and thrive on curiosity.

We operate with a flat organizational structure.

All employees are expected to be hands‑on and to contribute directly to the company’s mission.

Leadership is given to those who show initiative and consistently deliver excellence.

Work ethic and strong prioritization skills are important.

All employees are expected to have strong communication skills.

They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE

We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for Space XAI and x Money.

As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical.

You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high‑growth company.

The ideal candidate brings hands‑on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact.

This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel.

RESPONSIBILITIES

  • Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third‑party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting x Money.
  • Build and maintain Compliance-as-Code capabilities — policy‑as‑code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point‑in‑time checks.
  • Operate and extend GRC platforms (e. g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor‑or‑supervisor‑ready narratives without slowing development.
  • Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third‑party oversight, and secure SDLC) — not just document them.
  • Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations.
  • Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third‑party / critical provider diligence aligned to DORA.
  • Liaise with the Data Privacy team on security‑relevant intersections (e. g., security measures supporting confidentiality and integrity.
  • Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on information security topics; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e. g., ISO 27001, SOC 2) where they overlap.
  • Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.

BASIC QUALIFICATIONS

  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 5+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure.
  • Hands‑on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations — not only reading the requirements.
  • Familiar with data privacy regulations applicable to the EU/UK region (e. g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts.
  • Experience with Compliance-as-Code practices and GRC automation tooling (e. g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
  • Technical fluency sufficient to speak the language of engineering, On‑premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance.

PREFERRED SKILLS AND EXPERIENCE

  • 7+ years of information security compliance, GRC engineering, or technology audit‑related experience in fintech or financial services with a primary EU/UK focus.
  • Hands‑on experience implementing technical controls (e. g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
  • Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.
  • Familiar with GDPR concepts that commonly intersect with information security (e. g., security of processing, breach notification timelines, encryption/pseudonymization as security measures) when collaborating with DPO/Legal/Privacy functions.
  • Familiarity with DORA ICT third‑party risk, register of information, threat‑led penetration testing (TLPT) concepts, and major ICT‑related incident reporting expectations.
  • Experience with AI governance under the EU AI Act or related national guidance, especially security controls for AI features in regulated financial products.
  • Familiar with related regional regimes that may touch information security scope (e. g., e Privacy, Digital Services Act touchpoints, Mi CA where relevant to product scope, or FCA Consumer Duty technology implications).
  • Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers.
  • Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics.
  • Exceptional analytical, problem‑solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment‑ready launch.
  • Excellent communication and stakeholder management skills — able to explain information security and regulatory requirements to engineers, legal, privacy, sales, and executives in plain language.
  • Certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar preferred; are a plus for liaison fluency, not a substitute for security depth.
  • Prior experience working with or within EU/UK‑regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus.
  • #J-18808-Ljbffr

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection employer: x

England Sports Group is an exceptional employer that prioritises the growth and development of its staff while making a meaningful impact on the lives of vulnerable young people. With a supportive work culture, comprehensive training opportunities, and a commitment to blending sport with mental wellbeing, employees can thrive in a rewarding environment that values innovation and inclusivity. Located in East Molesey, this forward-thinking organisation offers a unique chance to inspire and empower the next generation through sports education.

X

Contact Details:

x Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

Get Involved in the Cybersecurity Community

Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!

Show Off Your Skills with Capture the Flag Competitions

Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including x, love seeing candidates who actively engage in these challenges.

Tailor Your Online Presence

Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!

Apply Directly Through x

Don’t forget to head straight to our website and check out any openings for cybersecurity roles at x. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.

We think you need these skills to ace Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

SQL
Python
Problem-Solving Skills
Communication Skills
Data Engineering
Data Pipeline Development
API Integration

Some tips for your application 🫡

Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!

Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!

Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at x insight into your practical problem-solving abilities and makes your application memorable.

Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to x that you’re committed to staying ahead in the game.

How to prepare for a job interview at x

Sharpen Your Technical Skills

For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.

Prepare for Scenario-Based Questions

Expect the interviewers at x to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.

Highlight Your Certifications

Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at x.

Show Your Passion for Cybersecurity

Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.