Skip to content
xAIxAINew York, NY

Security Engineer

GRC Security Engineer building Compliance-as-Code, automated controls, and continuous compliance for fintech/payments (PCI DSS, NYDFS, FFIEC). Partners with engineering to embed regulatory requirements into systems while enabling business velocity in a regulated AI/fintech environment.

152k – 228k/yr
Hybrid8+ YOESecurity Engineering

About the role

Responsibilities

  • Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.
  • Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks.
  • Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development.
  • Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them.
  • Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk.
  • Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface.
  • Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap.
  • Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.

Basic Qualifications

  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments.
  • Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements.
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
  • Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance.

Preferred Skills and Experience

  • 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services.
  • Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
  • Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations.
  • Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures.
  • Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy.
  • Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable.
  • Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews.
  • Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch.
  • Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language.
  • Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred.
  • Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus.

Compensation and Benefits

$152,000 - $228,000 USD base salary (total rewards package also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks).

Skills

pci dssnydfsffieccompliance-as-codevantaGRCSOC 2ISO 27001GDPRCCPAAWSGCPAzureIAMcissp
Grow Therapy

Senior Engineer, Security

Grow TherapyNew York, NY +2

Senior Security Engineer owning data security infrastructure including classification, masking, encryption, and AI data pipelines. Hands-on builder who defines and executes the data protection roadmap.

152k – 250k/yrRemote5+ YOESecurity Engineering
Rippling

Senior Product Security Engineer

RipplingSan Francisco, CA +3

Hands-on security engineer building product security guardrails, tooling, and SDLC integrations for a multi-product HR/IT/Finance platform. Requires 5+ years in product security, fluency in Python/React/DRF, and experience leading cross-team vulnerability remediation.

151k – 280k/yrHybrid5+ YOESecurity Engineering
1Password

Senior Security Engineer, Vulnerability Management

1PasswordUnited States

Leads product security incident response, coordinated vulnerability disclosure, PSIRT maturity, and customer-facing communications. The role requires 5+ years of security-focused IT or engineering experience, strong cross-functional judgment, coding ability, and experience building incident response tooling, including AI-powered workflows.

153k – 214k/yrRemote5+ YOESecurity Engineering
1Password

Senior Developer, Product Security

1PasswordUnited States

Senior security-focused developer implementing new security features and secure libraries for iOS and hybrid apps at 1Password. Requires 5+ years of security development experience, 3+ years with iOS and Rust.

153k – 214k/yrRemote5+ YOESecurity Engineering
Censys

Senior Security Research Scientist

CensysSan Francisco, CA +3

Conducts internet-wide security research using scan data to identify trends, vulnerabilities, and threats. Analyzes large datasets with tools like BigQuery and Snowflake, partners with engineering teams, and shares insights publicly. Requires deep knowledge of internet protocols.

153k – 212k/yrRemoteSecurity Engineering