SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
xAI is seeking an experienced Senior Security Engineer focused on Governance, Risk, and Compliance (GRC) for EU and UK markets. You will architect and operate the compliance systems and processes that enable the company to scale securely across regulated financial services and AI environments.
Key responsibilities include:
• Own and evolve the EU/UK financial services and digital operational resilience posture, including DORA (Digital Operational Resilience Act) compliance, ICT risk management, incident reporting, resilience testing, and third-party oversight. Support complementary obligations from EBA/ESMA/EIOPA guidance, PSD2/PSR, and UK PRA/FCA requirements.
• Build and maintain Compliance-as-Code capabilities—policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD pipelines—so audit and supervisory readiness scales with business growth.
• Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance. Integrate with cloud, identity, logging, and engineering systems to reduce administrative overhead.
• Partner with architects and engineering leads to embed EU/UK information security and regulatory requirements into design early. Translate complex obligations into concrete technical implementations and auditor-ready narratives without slowing development velocity.
• Design, implement, and validate technical information security controls relevant to regulated EU/UK environments: access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC.
• Operate the cybersecurity and compliance risk register. Identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations.
• Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes affecting the EU/UK regulated attack surface, including ICT third-party and critical provider diligence aligned to DORA.
• Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity).
• Own relationships with external auditors, assessors, and supervisory contacts on information security topics. Serve as the bridge between external parties and internal teams to ensure requests are reasonable, clear, and relevant.
• Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2, and complementary frameworks (ISO 27001, SOC 2).
• Champion pragmatic governance—prioritize issues representing real security or business risk over checkbox compliance.
The role operates within a flat organizational structure where all employees are hands-on contributors. You will work in a small, highly motivated team focused on engineering excellence and curiosity-driven problem-solving.