Senior Security Engineer
$152k - $258kSpaceXAI
Sr. Security Engineer - GRC Fintech & Financial Services New York, New York, United States; Palo Alto, California, United States; Washington, District of Columbia, United States SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands‑on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high‑growth company. The ideal candidate brings hands‑on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance‑as‑Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. RESPONSIBILITIES: Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions. Build and maintain Compliance‑as‑Code capabilities — policy‑as‑code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point‑in‑time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor‑ready narratives without slowing development. Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk. Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface. Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments. Hands‑on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements. Experience with Compliance‑as‑Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit‑related experience in fintech or financial services. Hands‑on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations. Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI‑scoped architectures. Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy. Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money‑transmitter expectations, or international banking rules in the EU, UK, or other markets, e DORA) is valuable. Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem‑solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment‑ready launch. Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred. Experience with emerging AI‑related financial services expectations or securing AI features in a regulated fintech product is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long‑term disability insurance, life insurance, and various other discounts and perks. To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . #J-18808-Ljbffr
- ...Lakera, a Check Point Company, is seeking a Solutions Engineer to accelerate sales velocity, increase customer success and shape the product experience as we scale. You’ll be the primary technical point of contact through the sales process and a resource for customer...Senior
$40 - $60 per hour
...A security technology firm is seeking a Senior Loss Prevention IT Security Engineer. This role requires expertise in installing and programming systems like Genetec and network troubleshooting with a focus on access control and CCTV systems. Candidates should have 8+ years...SeniorHourly payContract work$165k - $215k
...metropolis.io is seeking a Senior Security Engineer to establish a dedicated infrastructure and network security function. This role focuses on managing AWS and Oracle Cloud environments while ensuring enterprise security initiatives are met, including zero-trust architectures...Senior$155k - $175k
...Business System which makes everything possible. The Senior SIEM Engineer will be responsible for engineering, sustaining, and continuously... ...enterprise-wide threat detection, investigations, and security operations. This position is within the Danaher Corporate...SeniorRemote workWork from homeFlexible hours$149k - $235k
...spanning AWS, GCP, and self-managed Kubernetes, backed by self-managed data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security...SeniorWork at officeLocal areaFlexible hours$154k - $231k
...currently considering candidates for this role in California, Seattle, or NYC. Join Our Team... We are seeking a highly skilled Senior Security Engineer to join our advanced Security Operations team. This role is focused on leading complex incident response and forensic...SeniorFull timeTemporary workSecond jobWork at officeLocal areaRemote workWork from homeFlexible hours- ...PNC Financial Services Group, Inc. is seeking a Software Security Specialist Sr focused on AI Security. This role involves leading secure design and developing policies for GenAI across the organization. The ideal candidate will have over 5 years of experience in application...Senior
- ...Intelligent Technical Solutions seeks a Project Engineer II to plan, implement, and deliver technology solutions for clients. The role focuses on Microsoft cloud, endpoint management, and security projects, collaborating with teams and clients to ensure quality project...Senior
$320k - $405k
...a whole. Our team is a quickly growing group of committed researchers, engineers, policy experts, and business leaders working together to build beneficial AI systems. About the Team The Security Engineering team protects Anthropic's AI systems and maintains the trust...SeniorWork at officeVisa sponsorshipFlexible hours- ...Cloud Hybrid Technologies, LLC is seeking a Senior Cyber Security Engineer IV to join the team in Basking Ridge, NJ. The role requires extensive experience in security analyses and implementing services in AWS. Successful candidates will hold a Bachelor's degree in Computer...SeniorHourly pay
- ...Lauder Companies in New York seeks an experienced Application Security professional to lead secure SDLC initiatives, DevSecOps integration... ...and partners. This role emphasizes collaboration with IT, engineering, and security stakeholders to implement threat modeling, #J-1...Senior
- The Estée Lauder Companies Inc. is seeking an experienced Application Security professional to evangelize our security strategy under the Global Head of Application Security. You will work on SDLC security, DevSecOps, and multi-cloud initiatives to deliver trusted software...Senior
$150k - $200k
Truebill is seeking a Cloud Security Engineer in Washington, D.C. to manage and enhance AWS security strategies while collaborating with the InfoSec team. You will be responsible for evolving our cloud infrastructure, ensuring secure deployments, and treating detection...SeniorWork at office$140k - $155k
...business by fusing threat intelligence, monitoring, detection engineering, and response into one proactive, intelligence-led defense capability that breaks down silos to reduce risk and strengthen security across the enterprise. The team prioritizes collaboration, continuous...SeniorSecond jobLive inWorldwideFlexible hours- ...Tuteck is seeking a Microsoft Security & Compliance Consultant to design and implement AD security hardening, Purview data protection, and 365 compliance solutions. You will remediate privileged access risks, implement tiering, and harden NTLM/Kerberos, while configuring...Senior
- CyberCube is looking for a quantitative analyst for their Cyber Risk Modeling team in New York City, NY. This role focuses on building analytical models for the insurance industry, working at the intersection of modeling, cyber, and insurance. Ideal candidates will have...SeniorFlexible hours
$150k
...through technology. The successful candidate will serve as a Senior Cloud Security Architect reporting to the Infrastructure Management... ...Interaction with OTI Infrastructure Management leadership, its engineering and architecture teams, operations team, and cloud vendors....SeniorFull timeWork at officeShift workNight shiftWeekend workAfternoon shift- ...Cloud Software Group's Citrix unit seeks a Principal Security Technology Strategist to help customers adopt Citrix security solutions across North America. Work with account teams and the Security BU to drive secure access initiatives and extend security DNA across client...Senior
- ...Job Description Job Description ▶︎ Job Details ・Job Title: Senior Security Engineer / Advanced Security Engineer ・Client: Japanese IT Company ・Working Location: New York, NY 10022 ・Working Style: Onsite / Hybrid ・Employment Type: Full-time ・Salary: 100-1...SeniorFull timeFor subcontractorVisa sponsorshipShift work
- ...Job Description Job Description J ob Title: Sr. Security Engineer Duration: 6 months Contract To Hire Location: L ooking... ...About the Position Client X is seeking an exceptional Senior Security Engineer to join its IT Security Team in our New York...SeniorContract workWork at officeRemote work
$180k - $210k
...Join Gauntlet as a Senior Security Engineer, partnering with the Head of Security to build, operate and scale our security program. You'll work at the intersection of capital, risk and technology: securing the systems that power some of the largest and most sophisticated...SeniorFull timeWork at officeRemote workWork from home$145k - $210k
Senior Cyber Security Engineer Cooley is seeking a Senior Cyber Security Engineer to join the Security team. Position summary: Cooley Technology embraces a culture of customer service excellence and all members of the department are expected to move this agenda forward...SeniorFull timeTemporary workWork at officeFlexible hoursWeekend work$139k - $204k
...build the capabilities to stay left of boom Work alongside security partners who hold a high bar and expect you to raise it Shape... ...see the fire directly Serving as a clear, credible voice to senior leadership during active incidents — translating fast-moving technical...SeniorPermanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$163.94k - $215.18k
...Job Description Job Description Hi, we're Oscar. We're hiring a Senior Security Engineer 1, GRC to join our Security Team. Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members. We...SeniorFull timeWork at officeFlexible hours$163.94k - $215.18k
...Job Description Hi, we're Oscar. We're hiring a Senior Identity and Access Manager to join our Security Team. Oscar is the first health insurance company... ...the family. As an Identity and Access Management Engineer, you will build Oscar's identity and access management...SeniorFull timeWork at officeFlexible hours$130k - $160k
...Columbia University and Yale University, CertiK is a leading Web3 security company focused on securing blockchain protocols, smart... ...management lifecycle & lead cross-functional incident response with engineering/IT/compliance teams Oversee real-time threat detection/...SeniorFull timeContract workLocal areaFlexible hours$163.94k - $215.18k
...Job Description Job Description Hi, we're Oscar. We're hiring a Senior Security AI Engineer 1 to join our Security Engineering team. Oscar is the first health insurance company built around a full stack technology platform and a relentless focus on serving our members...SeniorFull timeWork at officeFlexible hours$172k - $236k
...About the Role You'll be the architect of our endpoint security posture across the full fleet — macOS, Windows, and BYOD mobile... ...to click the right button. You'll partner with IT, SecOps, and engineering teams to sharpen our telemetry and detections, mentor other engineers...SeniorRemote jobFull timeWork at officeHome officeRelocation packageFlexible hours$180k - $240k
...drive lasting change and help more people access the care they deserve, we'd love to meet you. About the Role The Senior Corporate Security Engineer role is responsible for designing, building and operating the technical security systems and controls that protect...SeniorFull timeWork at officeLocal areaRemote work$165k - $215k
...here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information...SeniorTemporary workWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior Security Engineer. Be the first to apply!
- network security engineer New York, NY
- senior application security engineer New York, NY
- sr security engineer New York, NY
- security infrastructure engineer New York, NY
- senior security operations engineer New York, NY
- dlp security engineer New York, NY
- cloud security engineer New York, NY
- physical security engineer New York, NY
- information technology security engineer New York, NY
- endpoint security engineer New York, NY

