LogoKode$word
Xai logo
Verified Tech Organization

Careers at Xai

Browse and filter through all verified positions currently open at Xai.

Total Company Roles79
Matching Filter79
x.aiHQ: New York, New York, United States

Founded in 2014, x.ai makes an artificial intelligence personal assistant who schedules meetings for you. There's no sign-in, no password, no download; all you do is CC amy@x.ai into your email thread, just like you would a human personal assistant. Amy then takes over the tedious email ping pong that comes along with scheduling a meeting. We're a hardcore technology company, developing invisible software. We build our business sustainably through passionate and loyal customers-and every single team member, scientist or not, has a mission of delivering exceptional customer service at all times. Backed by blue chip investors, including IA Ventures, Firstmark, Two Sigma Ventures, SoftBank Capital, DCM and Pritzker Group, the team is located in New York City.

Sector:aiartificial intelligenceb2bchatbots softwareenterprise software

All Openings (79)

Ordered by most recently published

Sr. Security Engineer - GRC Fintech & Financial Services

On-sitefull timeLead / StaffNew York, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development. Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk. Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface. Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments. Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations. Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures. Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy. Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable. Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred. Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

Sr. Security Engineer - GRC Fintech & Financial Services

On-sitefull timeLead / StaffWashington, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development. Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk. Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface. Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments. Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations. Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures. Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy. Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable. Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred. Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel. RESPONSIBILITIES: Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development. Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations. Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third-party / critical provider diligence aligned to DORA. Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity. Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on information security topics; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure. Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations — not only reading the requirements. Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of information security compliance, GRC engineering, or technology audit-related experience in fintech or financial services with a primary EU/UK focus. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations. Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines, encryption/pseudonymization as security measures) when collaborating with DPO/Legal/Privacy functions. Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing (TLPT) concepts, and major ICT-related incident reporting expectations. Experience with AI governance under the EU AI Act or related national guidance, especially security controls for AI features in regulated financial products. Familiar with related regional regimes that may touch information security scope (e.g., ePrivacy, Digital Services Act touchpoints, MiCA where relevant to product scope, or FCA Consumer Duty technology implications). Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain information security and regulatory requirements to engineers, legal, privacy, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar preferred; are a plus for liaison fluency, not a substitute for security depth. Prior experience working with or within EU/UK-regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

Sr. Security Engineer - GRC Fintech & Financial Services EU/UK

On-sitefull timeLead / StaffLondon, United Kingdom
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel. RESPONSIBILITIES: Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development. Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations. Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third-party / critical provider diligence aligned to DORA. Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity. Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on information security topics; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure. Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations — not only reading the requirements. Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of information security compliance, GRC engineering, or technology audit-related experience in fintech or financial services with a primary EU/UK focus. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations. Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines, encryption/pseudonymization as security measures) when collaborating with DPO/Legal/Privacy functions. Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing (TLPT) concepts, and major ICT-related incident reporting expectations. Experience with AI governance under the EU AI Act or related national guidance, especially security controls for AI features in regulated financial products. Familiar with related regional regimes that may touch information security scope (e.g., ePrivacy, Digital Services Act touchpoints, MiCA where relevant to product scope, or FCA Consumer Duty technology implications). Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain information security and regulatory requirements to engineers, legal, privacy, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar preferred; are a plus for liaison fluency, not a substitute for security depth. Prior experience working with or within EU/UK-regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

Sr. Security Engineer - GRC Frameworks & AI Governance

On-sitefull timeLead / StaffPalo Alto, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

Sr. Security Engineer - GRC Frameworks & AI Governance

On-sitefull timeLead / StaffNew York, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

Sr. Security Engineer - GRC Frameworks & AI Governance

On-sitefull timeLead / StaffWashington, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

Sr. IT Data Engineer

On-sitefull timeSeniorPalo Alto, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: At SpaceXAI, the IT Data Engineering team implements and supports applications to help internal customers meet their operational needs. We establish processes for continual improvement, guide administration, and partner with multiple stakeholders on a project-to-project basis. Our mission is to keep the business running effectively while maintaining a healthy application environment. RESPONSIBILITIES: Help lead SpaceXAI's data strategy by implementing established ETL patterns, creating and supporting dependable infrastructure, and reusable components. Partner with business and engineering teams to prioritize requests and consistently deliver excellent results against time-sensitive priorities. Collaborate effectively in a fast-paced environment using strong interpersonal communication skills. BASIC QUALIFICATIONS: BA/BS in a related field (Computer Science degree preferred) Minimum 5 years of relevant experience, preferably in an enterprise environment Strong experience with databases (Vertica, MySQL, or similar) and advanced SQL Java development experience (Spring, JEE/JSE) and proficiency in Python or other modern languages Hands-on experience with integrations, APIs, and message queuing technologies (e.g., Kafka, RabbitMQ) Experience working with 3rd party APIs (Salesforce, Workday, etc.) Background working in an Agile environment PREFERRED SKILLS AND EXPERIENCE: Experience with API Gateways (e.g., Kong), RAML, and REST-based APIs Designing and deploying scalable, reliable, high-volume data integrations and real-time pipelines Big data technologies (Hadoop, MongoDB, HBase, Cassandra) On-prem and cloud enterprise solutions (Oracle, Salesforce, Workday) Scala / Scalding Deep knowledge of access control and data security Leading Data/BI/Analytics projects with a customer-first approach Custom ETL design, implementation, and maintenance Performance monitoring, error logging, and troubleshooting Java applications COMPENSATION AND BENEFITS $172,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Data Engineering & BI
Verified2 days ago

Analytics Engineer - X

On-sitefull timeMid-LevelPalo Alto, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a skilled Analytics Engineer to build and maintain robust data systems that enable high-impact quantitative analysis and business decision-making. This role combines strong software engineering practices with expertise in large-scale data processing and advanced analytical methods to deliver reliable, scalable solutions across the organization. This is an opportunity to work on mission-critical systems that power quantitative decision-making at global scale. RESPONSIBILITIES: Design, implement, and optimize end-to-end data pipelines for processing high-volume datasets using tools such as Spark, Kafka, Flink, etc. Develop quantitative models and statistical frameworks to support experimentation, forecasting, and performance measurement. Build and maintain data infrastructure that ensures data quality, consistency, and accessibility for analytical workflows. Collaborate with product engineering, product, and operations teams to translate business requirements into production-grade data systems and insights. Conduct A/B tests, causal analysis, and performance evaluations to drive measurable improvements in key metrics. Implement monitoring, alerting, and automation for data systems to support real-time decision support. Mentor team members on best practices for scalable data engineering and quantitative problem-solving. BASIC QUALIFICATIONS: 4+ years of experience building production data pipelines and infrastructure at scale. Strong proficiency in Python, SQL, and distributed computing frameworks (e.g., Spark, Flink, Hadoop). Demonstrated expertise in statistical methods, predictive modeling, hypothesis testing, and experimental design. Solid understanding of cloud services for data storage, processing, and orchestration. Bachelor's or Master's degree in Computer Science, Statistics, Applied Mathematics, or related quantitative field. Excellent problem-solving skills with a focus on delivering business impact through reliable systems PREFERRED SKILLS AND EXPERIENCE: Prior work in consumer technology, or social media domains. Experience with real-time streaming systems and low-latency data processing. Contributions to open-source data tools or publications on large-scale analytics systems. Track record of reducing operational costs or improving system efficiency through data optimizations. Have the ability to bridge engineering excellence with rigorous analytical approaches. COMPENSATION AND BENEFITS: $180,000 - $440,000 USD Base salary is just one part of our total rewards package at xAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Data Engineering & BI
Verified2 days ago

Application Security Engineer

On-sitefull timeMid-LevelPalo Alto, United States
Apply Now

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a skilled and innovative Application Security Engineer to join our technology-driven company. In this role, you will be responsible for ensuring the security and integrity of our cloud-native applications and systems throughout the software development lifecycle, with a particular focus on code security, CI/CD pipelines, and emerging AI technologies. RESPONSIBILITIES: Conduct in-depth code reviews and static analysis to identify and mitigate security vulnerabilities in our applications Design and implement secure coding guidelines and best practices for development teams Collaborate closely with development teams to integrate security practices throughout the CI/CD pipeline Perform threat modeling and risk assessments for applications, developing mitigation strategies for potential risks Manage vulnerability tracking and remediation efforts, providing guidance to development teams Support incident response activities related to application security Stay current on emerging security threats and trends in cloud-native technologies and AI, continuously enhancing our security measures Evaluate and secure software supply chains, including producing and maintaining Software Bills of Materials (SBOMs) Address security concerns specific to AI and machine learning models, with a focus on the OWASP LLM Top 10 BASIC QUALIFICATIONS: Bachelor's degree in Computer Science, Cybersecurity, or a related field 3-5 years of experience in application security, with a strong focus on code security practices Deep understanding of secure coding practices, application security frameworks, and common vulnerabilities (e.g., OWASP Top 10) Proficiency in Python or Rust programming languages and experience with secure coding practices in these languages Experience securing CI/CD pipelines and implementing DevSecOps practices Familiarity with software supply chain security and SBOM generation tools Experience with security testing tools (e.g., Burp Suite, OWASP ZAP) and static/dynamic code analysis Understanding of AI/ML security implications, particularly those outlined in the OWASP LLM Top 10 Excellent communication skills, able to explain complex security issues to both technical and non-technical audiences PREFERRED SKILLS AND EXPERIENCE: Experience with cloud platforms (e.g., GCP, AWS, Azure) and their security features Relevant security certifications (e.g., CSSLP, OSWE) Background in data privacy and compliance regulations relevant to cloud-native applications and AI systems Experience with GitOps and infrastructure-as-code security Familiarity with federated learning and privacy-preserving machine learning techniques Experience in building custom security tooling to enhance and automate security processes Interest in leveraging AI to automate security tasks and improve efficiency Contributions to open-source security projects or tools Experience in securing AI/ML models and data pipelines COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .

View more...
Cybersecurity
Verified2 days ago

Page 6 of 8