Sr. Security Engineer - GRC EU/UK Regulation & Data Protection
Core
Architect and automate EU/UK information security and financial services compliance (GRC) for a high-growth AI and fintech company, enabling business velocity while meeting rigorous regulatory standards.
Role type
Senior GRC Engineer (EU/UK Regulation & Data Protection)
Builds
Automated compliance systems, Compliance-as-Code capabilities, and integrated GRC platforms for audit readiness.
Domain
Financial Services / Fintech / EU & UK Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
DORA, EU AI Act, NIS2, PSD2/PSR, UK PRA/FCA operational resilience, Compliance-as-Code, GRC automation tooling (e.g., Vanta), technical security controls (IAM, logging, encryption, change management), risk register management, security architecture fluency
Preferred skills
ISO 27001, SOC 2, GDPR security intersections, DORA ICT third-party risk, threat-led penetration testing (TLPT), AI governance under EU AI Act, ePrivacy, Digital Services Act, MiCA, FCA Consumer Duty, enterprise sales trust centers
Technologies
Vanta, AWS, GCP, Azure, CI/CD pipelines
Responsibilities
Own and evolve EU/UK financial services and digital operational resilience posture; Build and maintain Compliance-as-Code capabilities; Operate and extend GRC platforms; Partner with Architects to bake regulatory requirements into design; Design and validate technical information security controls; Operate the cybersecurity and compliance risk register; Lead information security risk assessments; Liaise with the Data Privacy team; Own relationships with external auditors and supervisory contacts; Develop and improve information security policies and standards; Champion pragmatic governance
Seniority
Senior, hands-on IC
