# Senior Security Engineer - GRC EU/UK Regulation & Data Protection

**Company:** [xAI](https://hotfix.jobs/companies/xai)
**Location:** London, United Kingdom
**Role:** Security Engineering
**Experience:** 7+ years
**Skills:** Dora, Eu Ai Act, Nis2, Psd2, Uk Gdpr, Compliance-As-Code, Vanta, AWS, GCP, Azure, CI/CD, IAM, Encryption, ISO 27001, SOC 2
**Posted:** 2026-08-13

> The Senior Security Engineer will build and operate EU/UK security GRC programs for regulated fintech products, automating controls and evidence collection while partnering with engineering, privacy, auditors, and regulators. Requires substantial regulated-environment experience and hands-on knowledge of DORA, EU/UK regulations, cloud security, and compliance automation.

## Job Description

## Responsibilities

- Own and evolve EU/UK financial-services and digital operational-resilience posture across DORA, including ICT risk management, incident reporting, resilience testing, and third-party ICT-provider oversight, alongside relevant EBA, ESMA, EIOPA, PSD2/PSR, PRA, and FCA expectations.
- Build and maintain Compliance-as-Code capabilities, including policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD.
- Operate and extend GRC platforms such as Vanta for control mapping, evidence management, and continuous compliance; integrate them with cloud, identity, logging, and engineering systems.
- Partner with architects and engineering leads to incorporate EU/UK information-security and regulatory requirements into system design.
- Design, implement, and validate technical controls for access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC.
- Operate the cybersecurity and compliance risk register, quantify risks, and track remediation based on meaningful business and regulatory impact.
- Lead information-security risk assessments and compliance reviews for products, features, vendors, and architectural changes affecting the EU/UK regulated attack surface.
- Conduct ICT third-party and critical-provider diligence aligned to DORA.
- Liaise with Data Privacy on security-relevant intersections, including confidentiality and integrity measures.
- Manage relationships with external auditors, assessors, and applicable supervisory contacts.
- Develop and improve information-security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2, ISO 27001, and SOC 2.
- Champion pragmatic governance that prioritizes real security and business risk.

## Requirements

- Bachelor's degree in computer science, information security, cybersecurity, or an engineering/STEM field.
- At least 5 years of experience in GRC, information-security compliance, or technology audit in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure.
- Hands-on experience implementing or operating controls against several of DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational-resilience expectations.
- Familiarity with EU/UK data-privacy regulations, including EU GDPR, UK GDPR, and the UK Data Protection Act 2018.
- Experience with Compliance-as-Code and GRC automation tooling such as Vanta or similar platforms.
- Technical fluency across on-premises, hybrid, or cloud environments and security architecture.

## Preferred Qualifications

- At least 7 years of information-security compliance, GRC engineering, or technology-audit experience in fintech or financial services, primarily focused on the EU/UK.
- Hands-on implementation of IAM, logging and monitoring, encryption, network segmentation, and infrastructure-hardening controls.
- Experience integrating compliance checks into CI/CD pipelines.
- Experience supporting ISO 27001 and/or SOC 2 programs.
- Familiarity with GDPR security concepts, DORA ICT third-party risk, registers of information, TLPT, major ICT-related incident reporting, and AI governance under the EU AI Act.
- Familiarity with ePrivacy, Digital Services Act, MiCA, or FCA Consumer Duty technology implications.
- Experience supporting trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers.
- Ability to operate risk registers and exercise judgment in ambiguous situations.
- Strong analytical, problem-solving, organizational, project-management, communication, and stakeholder-management skills.
- Certifications such as CISSP, CISA, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are preferred.
- Experience with EU/UK-regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus.

## Similar jobs

- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr
- [Security Engineer, Detection and Response](https://hotfix.jobs/jobs/02ff0cde-e8e1-4f38-9c48-d8149d22a95b) - Writer - London, United Kingdom
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Senior Security Engineer, Research & Engineering](https://hotfix.jobs/jobs/f9156020-d99c-45aa-8dba-fcd0035e45b4) - Trail of Bits - Remote
- [Senior Security Engineer, Security Incident Response Team - EMEA](https://hotfix.jobs/jobs/33cbe57c-bb91-44ff-8901-3cde1ac976a7) - GitLab - Remote

**Apply:** https://hotfix.jobs/jobs/d9a627a2-1682-45f7-b291-0f75a05b37c2
**Canonical:** https://hotfix.jobs/jobs/d9a627a2-1682-45f7-b291-0f75a05b37c2