368,910open jobs
9,449companies
47,822added this week
Browse all
Salary
$142k – $322k per year (Estimated)
Location
In office (Dublin)
Seniority
Senior · 7+ years exp
Overview
Company
Impact
Profile match

xAI

xAI is an American artificial intelligence company founded by Elon Musk in 2023 with the stated goal of building models that help humans understand the universe. It develops the Grok family of large language models, distributes them through a consumer assistant, a developer API and deep integration with the X social platform, and adds image and video generation through Grok Imagine. The company runs its own Colossus supercomputer clusters in Memphis, Tennessee, is headquartered in Palo Alto, California, and merged with X Corp in 2025 to combine model development with a large consumer distribution channel.

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust - a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact.

This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel.

RESPONSIBILITIES:

  • Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney.
  • Build and maintain Compliance-as-Code capabilities - policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD - so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks.
  • Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.
  • Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development.
  • Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC) - not just document them.
  • Operate the cybersecurity and compliance risk register - identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations.
  • Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third-party / critical provider diligence aligned to DORA.
  • Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity.
  • Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on information security topics; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack.
  • Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap.
  • Champion pragmatic governance - prioritize issues that represent real security or business risk over checkbox compliance.

BASIC QUALIFICATIONS:

  • Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field.
  • 5+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure.
  • Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations - not only reading the requirements.
  • Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts.
  • Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection.
  • Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance.

PREFERRED SKILLS AND EXPERIENCE:

  • 7+ years of information security compliance, GRC engineering, or technology audit-related experience in fintech or financial services with a primary EU/UK focus.
  • Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines.
  • Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations.
  • Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines, encryption/pseudonymization as security measures) when collaborating with DPO/Legal/Privacy functions.
  • Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing (TLPT) concepts, and major ICT-related incident reporting expectations.
  • Experience with AI governance under the EU AI Act or related national guidance, especially security controls for AI features in regulated financial products.
  • Familiar with related regional regimes that may touch information security scope (e.g., ePrivacy, Digital Services Act touchpoints, MiCA where relevant to product scope, or FCA Consumer Duty technology implications).
  • Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers.
  • Proven ability to operate a risk register and apply judgment in gray areas - focusing on outcomes over optics.
  • Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch.
  • Excellent communication and stakeholder management skills - able to explain information security and regulatory requirements to engineers, legal, privacy, sales, and executives in plain language.
  • Certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar preferred; are a plus for liaison fluency, not a substitute for security depth.
  • Prior experience working with or within EU/UK-regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus.

SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,910 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Dublin
$173k – $314k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco
Apex
JavaScript
Node JS
Python
SQL
TypeScript
Apex
Lightning Web Components
AI/ML
Agentforce
AI Agents
Claude
Claude Code
Copilot
Cursor
LLM
RAG
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Grafana
gRPC
Kubernetes
New Relic
Prometheus
Splunk
Marketing
Salesforce
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Rest-Assured
Selenium
Apply
$158k – $317k per year • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Durham
DevOps
AWS
Azure
GCP
Cybersecurity
Zero Trust
Apply
$54k – $128k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Mexico City
C#
JavaScript
Python
TypeScript
C#
ASP.NET Core
Python
FastAPI
Databases
PostgreSQL
AI/ML
AI Agents
Anthropic
Embeddings
Function Calling
LLM
LLM Guardrails
Model Context Protocol
OpenAI
Semantic Search
Semantic Search
Frontend
Angular
React.js
DevOps
AWS
Azure
CI/CD
GitHub
GitHub Actions
Vector
Vercel
Apply
$90k – $218k per year (Estimated) • In office • Full-Time • 3+ years exp • Quebec • Waterloo
JavaScript
Kotlin
Node JS
Java
Java
Spring Boot
Spring Cloud
Spring Security
Frontend
GraphQL
React.js
Redux
DevOps
Azure
Azure AKS
CI/CD
GitHub Actions
Jenkins
Kubernetes
Terraform
GitHub
Management
Jira
Apply
$256k – $320k per year • Remote/Hybrid • Full-Time • Seattle
Go
Python
AI/ML
AI Agents
CrewAI
LangChain
LangGraph
DevOps
AWS
GCP
Kubernetes
Apply
$209k – $454k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Memphis
Apply
$209k – $454k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Memphis
Apply
$117k – $239k per year (Estimated) • In office • 3+ years exp • Memphis
Apply
$440k per year • In office • Palo Alto
C++
AI/ML
CUDA Toolkit
CUDA
Frontend
Sass
Apply
$167k – $358k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Memphis
Python
SQL
AI/ML
BERT
InfiniBand
DevOps
HPC
Apply
In office • Internship • 1+ year exp • Bachelor's Degree • Dublin
JavaScript
Ruby
Scala
Go
Apply
$49k – $174k per year (Estimated) • In office • Internship • Bachelor's Degree • Dublin
Go
JavaScript
Ruby
Scala
Apply
$59k – $103k per year • Remote/Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Dublin
Apply
$88k – $181k per year (Estimated) • In office • Full-Time • Dublin
Apply
$111k – $201k per year (Estimated) • In office • 10+ years exp • Dublin
Ruby
Apply
See all jobs
This is one of many
368,910 more open roles from verified company boards, updated every day.