Senior Security Engineer - GRC EU/UK Regulation & Data Protection
The Senior Security Engineer will build and operate EU/UK security GRC programs for regulated fintech products, automating controls and evidence collection while partnering with engineering, privacy, auditors, and regulators. Requires substantial regulated-environment experience and hands-on knowledge of DORA, EU/UK regulations, cloud security, and compliance automation.
About the job
Responsibilities
- Own and evolve EU/UK financial-services and digital operational-resilience posture across DORA, including ICT risk management, incident reporting, resilience testing, and third-party ICT-provider oversight, alongside relevant EBA, ESMA, EIOPA, PSD2/PSR, PRA, and FCA expectations.
- Build and maintain Compliance-as-Code capabilities, including policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD.
- Operate and extend GRC platforms such as Vanta for control mapping, evidence management, and continuous compliance; integrate them with cloud, identity, logging, and engineering systems.
- Partner with architects and engineering leads to incorporate EU/UK information-security and regulatory requirements into system design.
- Design, implement, and validate technical controls for access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC.
- Operate the cybersecurity and compliance risk register, quantify risks, and track remediation based on meaningful business and regulatory impact.
- Lead information-security risk assessments and compliance reviews for products, features, vendors, and architectural changes affecting the EU/UK regulated attack surface.
- Conduct ICT third-party and critical-provider diligence aligned to DORA.
- Liaise with Data Privacy on security-relevant intersections, including confidentiality and integrity measures.
- Manage relationships with external auditors, assessors, and applicable supervisory contacts.
- Develop and improve information-security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2, ISO 27001, and SOC 2.
- Champion pragmatic governance that prioritizes real security and business risk.
Requirements
- Bachelor's degree in computer science, information security, cybersecurity, or an engineering/STEM field.
- At least 5 years of experience in GRC, information-security compliance, or technology audit in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure.
- Hands-on experience implementing or operating controls against several of DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational-resilience expectations.
- Familiarity with EU/UK data-privacy regulations, including EU GDPR, UK GDPR, and the UK Data Protection Act 2018.
- Experience with Compliance-as-Code and GRC automation tooling such as Vanta or similar platforms.
- Technical fluency across on-premises, hybrid, or cloud environments and security architecture.
Preferred Qualifications
- At least 7 years of information-security compliance, GRC engineering, or technology-audit experience in fintech or financial services, primarily focused on the EU/UK.
- Hands-on implementation of IAM, logging and monitoring, encryption, network segmentation, and infrastructure-hardening controls.
- Experience integrating compliance checks into CI/CD pipelines.
- Experience supporting ISO 27001 and/or SOC 2 programs.
- Familiarity with GDPR security concepts, DORA ICT third-party risk, registers of information, TLPT, major ICT-related incident reporting, and AI governance under the EU AI Act.
- Familiarity with ePrivacy, Digital Services Act, MiCA, or FCA Consumer Duty technology implications.
- Experience supporting trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers.
- Ability to operate risk registers and exercise judgment in ambiguous situations.
- Strong analytical, problem-solving, organizational, project-management, communication, and stakeholder-management skills.
- Certifications such as CISSP, CISA, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are preferred.
- Experience with EU/UK-regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus.
Skills
Dora, Eu Ai Act, Nis2, Psd2, Uk Gdpr, Compliance-As-Code, Vanta, AWS, GCP, Azure, CI/CD, IAM, Encryption, ISO 27001, SOC 2
Similar jobs
Security Engineering jobsSenior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.
Build AI-focused detection and response capabilities, investigate incidents, and hunt threats across distributed training and inference infrastructure. The role requires staff-level security engineering experience, including 3+ years securing AI/ML or distributed systems and strong automation and detection skills.
Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.
Senior security engineer who red teams formally verified systems, assesses proof and threat-model boundaries, and builds AI-driven vulnerability discovery and exploit-generation tooling. Requires hands-on offensive security, formal methods, systems expertise, software development, and rigorous technical reporting.
Leads high-severity security investigations and end-to-end incident response for GitLab’s cloud and corporate environments. The role focuses on DFIR, detection engineering, automation, AI-assisted workflows, executive communication, and improving operational maturity within a global 24/7 team.