SpaceXAI11 days ago

Старший инженер по информационной безопасности - GRC EU/UK Regulation & Data Protection

Salary not specified
Dublin

Responsibilities

  • 01Own and evolve EU/UK financial services and digital operational resilience posture across DORA
  • 02Build and maintain Compliance-as-Code capabilities
  • 03Operate and extend GRC platforms
  • 04Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early
  • 05Design, implement, and validate technical information security controls relevant to regulated EU/UK environments
  • 06Operate the cybersecurity and compliance risk register
  • 07Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes
  • 08Liaise with the Data Privacy team on security-relevant intersections
  • 09Own and cultivate relationships with external auditors, assessors, and supervisory contacts on information security topics
  • 10Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2, and complementary frameworks
  • 11Champion pragmatic governance

Requirements

  • 01Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field
  • 025+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure
  • 03Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations
  • 04Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts
  • 05Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection
  • 06Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance

What we offer

  • 01Occasional travel may be required
  • 02Flat organizational structure
  • 03Hands-on and direct contribution to the company’s mission
  • 04Leadership given to those who show initiative and consistently deliver excellence
  • 05Strong communication skills