SpaceXAI11 days ago
Старший инженер по информационной безопасности - GRC EU/UK Regulation & Data Protection
Salary not specified
Dublin
Responsibilities
- 01Own and evolve EU/UK financial services and digital operational resilience posture across DORA
- 02Build and maintain Compliance-as-Code capabilities
- 03Operate and extend GRC platforms
- 04Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early
- 05Design, implement, and validate technical information security controls relevant to regulated EU/UK environments
- 06Operate the cybersecurity and compliance risk register
- 07Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes
- 08Liaise with the Data Privacy team on security-relevant intersections
- 09Own and cultivate relationships with external auditors, assessors, and supervisory contacts on information security topics
- 10Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2, and complementary frameworks
- 11Champion pragmatic governance
Requirements
- 01Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
- 025+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure
- 03Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations
- 04Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts
- 05Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection
- 06Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance
What we offer
- 01Occasional travel may be required
- 02Flat organizational structure
- 03Hands-on and direct contribution to the company’s mission
- 04Leadership given to those who show initiative and consistently deliver excellence
- 05Strong communication skills