Responsibilities
- Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.
- Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks.
- Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
- Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development.
- Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them.
- Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk.
- Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface.
- Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
- Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap.
- Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.
Basic Qualifications
- Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
- 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
- Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements.
- Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
- Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance.
Preferred Skills and Experience
- 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services.
- Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
- Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations.
- Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures.
- Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy.
- Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable.
- Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.
- Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics.
- Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch.
- Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language.
- Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred.
- Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus.
Compensation and Benefits
$152,000 - $228,000 USD base salary (total rewards package also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks).