Verified Tech Jobs & Hiring Companies, Updated Every 24 Hours
Direct career links to high-growth tech startups and Fortune 500 engineering teams across the United States, Europe, and Worldwide. We audit careers daily to ensure zero ghost listings and zero expired apply links.
All Verified Employers (618)
Filtered and verified against live career portals
The Verified Direct-Apply Tech Job Board
Landing a high-compensation software engineering, data, AI, or product role should not require fighting through zombie job posts, recruiter agency reposts, or expired links. KodeSword indexes verified tech career openings by connecting directly with corporate Applicant Tracking Systems (ATS) including Greenhouse, Lever, Ashby, and Workday. Every single role featured on this platform is active and routes straight to the hiring company’s career page.
Popular Tech Roles
Top Tech Hubs
Why Tech Candidates Use KodeSword vs. Traditional Aggregators
- 100% Direct Corporate Links: Zero middleman recruiter reposts.
- Continuous 24h Pruning: Expired and filled listings removed daily.
- Comprehensive Salary Data: Compensation extracted from verified JDs.
- Zero Paywalls or Registration: Browse and apply completely free.
Frequently Asked Questions
- How often are tech job openings updated on KodeSword?
- Our crawlers sync with official company Applicant Tracking Systems (ATS) including Greenhouse, Lever, Workday, and Ashby every 24 hours. Expired or filled roles are pruned daily to prevent ghost job listings.
- Are these direct job applications or recruiter agency reposts?
- Every role links directly to the official corporate careers portal. There are zero intermediary recruiters, no paywalls, and no sponsored spam.
- What kinds of tech roles are listed on KodeSword?
- We index white-collar software engineering, AI/Machine Learning, DevOps, SRE, Cloud Infrastructure, Data Engineering, Cyber Security, and Technical Product Management roles across US hubs and remote companies.

Xai
Actively Hiring79 open positions matching criteria
AI Tutor - Software Engineering
Software Engineering
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: Contribute to AI model training initiatives by curating code examples, offering precise solutions, and providing meticulous corrections in specialized programming languages. Evaluate and refine AI-generated code, ensuring it adheres to industry standards for efficiency, scalability, and reliability. Collaborate with cross-functional teams to enhance AI-driven coding solutions, ensuring they meet enterprise-level quality and performance benchmarks. BASIC QUALIFICATIONS: Professional software engineering experience building scalable, high-performance applications. Deep expertise in one or more programming languages. Strong proficiency in relevant frameworks and libraries. Solid understanding of software design principles, performance optimization, and best practices. Experience implementing quality standards, including accessibility, security, and reliability where applicable. Strong debugging and profiling skills using development tools and performance monitoring. Hands-on experience with testing frameworks and tools relevant to your domain. PREFERRED SKILLS AND EXPERIENCE: The ideal candidate for this role is adaptable, possesses strong logical reasoning skills, is detail-oriented, and thrives in a fast-paced work environment. Experience integrating analytics, monitoring, and security best practices relevant to your technical domain. Experience with containerization technologies (e.g., Docker). Knowledge of complementary technologies (e.g., backend systems, APIs, databases, authentication) to enable effective cross-functional collaboration. LOCATION AND OTHER EXPECTATIONS: Tutor roles may be offered as full-time, part-time, or contractor positions, depending on role needs and candidate fit. For contractor positions, hours will vary widely based on project scope and contractor availability, with no fixed commitments required. On average most projects may involve at least 10 hours per week to achieve deliverables effectively though this is not a fixed commitment and depends on the scope of work. Contractors have full flexibility to set their own hours and determine the exact amount of time needed to complete deliverables. Tutor roles may be performed remotely from any location worldwide, subject to legal eligibility, time-zone compatibility, and role specific needs. For US based candidates, please note we are unable to hire in the states of Wyoming and Illinois at this time. We are unable to provide visa sponsorship. For those who will be working from a personal device, your computer must be a Chromebook, Mac with MacOS 11.0 or later, or Windows 10 or later. COMPENSATION AND BENEFITS: US based candidates: $40/hour - $100/hour depending on factors including relevant experience, skills, education, geographic location, and qualifications. International candidates: Information will be provided to you during the recruitment process. Benefits vary based on employment type, location and jurisdiction. Benefits for eligible U.S. based positions include health insurance, 401(k) plan, and paid sick leave. Specific details and role specific information will be provided to you during the interview process. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...Sr. Security Engineer - GRC Fintech & Financial Services
Information Security
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development. Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk. Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface. Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments. Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations. Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures. Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy. Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable. Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred. Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...Sr. Security Engineer - GRC Fintech & Financial Services
Information Security
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development. Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk. Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface. Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments. Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations. Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures. Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy. Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable. Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred. Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...Sr. Security Engineer - GRC Fintech & Financial Services
Information Security
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development. Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk. Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface. Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated financial environments. Hands-on experience with PCI DSS and at least one of NYDFS (23 NYCRR 500) or FFIEC cybersecurity/IT examination guidance — including implementing or operating controls, not only reading the requirements. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience in fintech or financial services. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting SOC 2 and/or ISO 27001 programs alongside fintech-specific obligations. Experience with payment ecosystems, cardholder data environments, tokenization, or similar PCI-scoped architectures. Working knowledge of data privacy frameworks including GDPR and CCPA/CPRA, and experience partnering with Legal or Privacy. Familiarity with additional financial regulatory regimes (e.g., GLBA, BSA/AML technology controls, state money-transmitter expectations, or international banking rules in the EU, UK, or other markets, e.g DORA) is valuable. Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain regulatory and privacy requirements to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, PCIP, CIPP/US, CIPP/E, or similar preferred. Experience with emerging AI-related financial services expectations or securing AI features in a regulated fintech product is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
Information Security
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel. RESPONSIBILITIES: Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development. Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations. Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third-party / critical provider diligence aligned to DORA. Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity. Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on information security topics; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure. Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations — not only reading the requirements. Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of information security compliance, GRC engineering, or technology audit-related experience in fintech or financial services with a primary EU/UK focus. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations. Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines, encryption/pseudonymization as security measures) when collaborating with DPO/Legal/Privacy functions. Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing (TLPT) concepts, and major ICT-related incident reporting expectations. Experience with AI governance under the EU AI Act or related national guidance, especially security controls for AI features in regulated financial products. Familiar with related regional regimes that may touch information security scope (e.g., ePrivacy, Digital Services Act touchpoints, MiCA where relevant to product scope, or FCA Consumer Duty technology implications). Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain information security and regulatory requirements to engineers, legal, privacy, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar preferred; are a plus for liaison fluency, not a substitute for security depth. Prior experience working with or within EU/UK-regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...Sr. Security Engineer - GRC Fintech & Financial Services EU/UK
Information Security
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on European Union and United Kingdom information security and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we expand deeper into regulated EU/UK markets, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with frameworks such as DORA, the EU AI Act, NIS2, and related EU/UK information security and operational resilience obligations, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel. RESPONSIBILITIES: Own and evolve EU/UK financial services and digital operational resilience posture across DORA (including ICT risk management, incident reporting, resilience testing, and third-party ICT provider oversight), and complementary expectations from EBA/ESMA/EIOPA guidance, PSD2/PSR where applicable, and UK PRA/FCA operational resilience requirements supporting xMoney. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake EU/UK information security and regulatory requirements into design early; translate complex obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development. Design, implement, and validate technical information security controls relevant to regulated EU/UK environments (access control, logging and monitoring, encryption, change management, vulnerability management, ICT third-party oversight, and secure SDLC) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under EU/UK supervisory expectations. Lead information security risk assessments and compliance reviews for new products, features, vendors, and architectural changes that affect the EU/UK regulated attack surface, including ICT third-party / critical provider diligence aligned to DORA. Liaise with the Data Privacy team on security-relevant intersections (e.g., security measures supporting confidentiality and integrity. Own and cultivate relationships with external auditors, assessors, and (where applicable) supervisory contacts on information security topics; serve as the bridge between external parties and internal teams so requests are reasonable, clear, and relevant to our stack. Develop, maintain, and continuously improve information security policies, standards, and procedures aligned to DORA, the EU AI Act, NIS2 where in scope, and complementary frameworks (e.g., ISO 27001, SOC 2) where they overlap. Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, information security compliance, or technology audit roles in fintech, banking, payments, or other heavily regulated environments with EU and/or UK exposure. Hands-on experience implementing or operating controls against several of the following: DORA, the EU AI Act, NIS2, PSD2/PSR, or UK PRA/FCA operational resilience expectations — not only reading the requirements. Familiar with data privacy regulations applicable to the EU/UK region (e.g., EU GDPR, UK GDPR, UK Data Protection Act 2018) sufficient to liaise with Privacy counterparts. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, or similar), with a bias toward continuous monitoring and reducing manual evidence collection. Technical fluency sufficient to speak the language of engineering, On-premises, hybrid, or cloud (AWS/GCP/Azure), and security architecture, and to anticipate how design decisions impact information security risk and compliance. PREFERRED SKILLS AND EXPERIENCE: 10+ years of information security compliance, GRC engineering, or technology audit-related experience in fintech or financial services with a primary EU/UK focus. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, network segmentation, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience supporting ISO 27001 and/or SOC 2 programs alongside EU/UK regulatory obligations. Familiar with GDPR concepts that commonly intersect with information security (e.g., security of processing, breach notification timelines, encryption/pseudonymization as security measures) when collaborating with DPO/Legal/Privacy functions. Familiarity with DORA ICT third-party risk, register of information, threat-led penetration testing (TLPT) concepts, and major ICT-related incident reporting expectations. Experience with AI governance under the EU AI Act or related national guidance, especially security controls for AI features in regulated financial products. Familiar with related regional regimes that may touch information security scope (e.g., ePrivacy, Digital Services Act touchpoints, MiCA where relevant to product scope, or FCA Consumer Duty technology implications). Experience enabling enterprise sales through trust centers, vendor questionnaires, and customer security reviews for EU/UK buyers. Proven ability to operate a risk register and apply judgment in gray areas — focusing on outcomes over optics. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to assessment-ready launch. Excellent communication and stakeholder management skills — able to explain information security and regulatory requirements to engineers, legal, privacy, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or similar preferred; are a plus for liaison fluency, not a substitute for security depth. Prior experience working with or within EU/UK-regulated financial institutions, EMI/PI environments, or supervised fintechs is a plus. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...Sr. Security Engineer - GRC Frameworks & AI Governance
Information Security
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...Sr. Security Engineer - GRC Frameworks & AI Governance
Information Security
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer to own and scale our security and AI governance compliance posture as SpaceXAI grows. You will set the standards the organization builds to, design and implement controls, and automate the unglamorous parts of compliance so a fast-moving team can ship safely. The ideal candidate combines deep fluency across modern security and AI frameworks with GRC engineering skills: you translate control requirements into technical implementations, partner with engineers to bake compliance into architecture and CI/CD, and replace point-in-time checklist work with continuous, engineered assurance. You will collaborate across engineering, legal, product, and leadership to keep our AI systems audit-ready across enterprise, commercial, and public-sector environments. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. RESPONSIBILITIES: Own and execute security compliance implementation and audits across core frameworks including SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, ISO 42001, and the EU AI Act, including control design, mapping, gap assessment, evidence collection, and remediation tracking. Build and maintain Compliance-as-Code and continuous compliance capabilities — policy-as-code, automated control validation, continuous evidence pipelines, and monitoring integrated into development and deployment workflows — so the company can move fast without cutting corners. Operate and extend GRC platforms (e.g., Vanta) as the system of record for controls, evidence, and audit readiness; integrate them with cloud, identity, and engineering tooling to reduce manual toil. Partner with engineering and architecture to embed compliance requirements early in design reviews; translate framework obligations into clear technical control narratives that satisfy auditors without slowing delivery. Develop, maintain, and continuously improve corporate policies, standards, and procedures that support the company's governance and AI management system posture. Identify, assess, and prioritize risks related to AI/ML operations, cybersecurity, regulatory compliance, data privacy, intellectual property, and cloud deployments; distinguish meaningful business risk from compliance theater. Lead risk assessments and compliance reviews for new products, model deployments, features, and architectural changes, with particular attention to AI system risks (data handling, model governance, agentic and conversational surfaces). Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack. Champion a culture of security and compliance across the company — educating teams on why controls exist, not only enforcing them. BASIC QUALIFICATIONS: Bachelor's degree in computer science, Information Security, Cybersecurity, or in an engineering/STEM field. 8+ years of experience in GRC, security compliance, or technology audit roles with hands-on GRC engineering responsibilities. Demonstrated experience implementing and maintaining security compliance frameworks in cloud environments (AWS, GCP, or Azure). Expert-level working knowledge of several of the following: SOC 2, NIST CSF, NIST SP 800-53, ISO 27001, and ISO 42001 — including building and running controls, not only reading the frameworks. Experience with Compliance-as-Code practices and GRC automation tooling (e.g., Vanta, Drata, or similar), with a bias toward continuous monitoring. Ability to evaluate control objectives against real IT and cloud configurations and to work alongside engineers on remediation. PREFERRED SKILLS AND EXPERIENCE: 10+ years of security compliance, GRC engineering, or technology audit-related experience. Hands-on experience implementing technical controls (e.g., IAM, logging and monitoring, encryption, infrastructure hardening) and integrating compliance checks into CI/CD pipelines. Experience in the tech or AI/ML industry, particularly with startups or high-growth product organizations. Working knowledge of HIPAA privacy and security rules (bonus), ideally mapped into a SOC 2 or ISO-certified control environment. Experience supporting SOX / ITGC design, documentation, testing, or auditor coordination, especially in a publicly traded or IPO-bound company. Strong understanding of AI ethics and AI governance frameworks (e.g., NIST AI RMF, ISO 42001, EU AI Act) and associated operational risks. Working knowledge in data privacy frameworks (e.g., GDPR, CCPA) in a technology or cloud environment. Exceptional analytical, problem-solving, organizational, and project management skills, with the ability to take compliance programs from conception to audit-ready launch. Excellent communication and stakeholder management skills — able to explain risk and tradeoffs to engineers, legal, sales, and executives in plain language. Certifications such as CISSP, CISA, CISM, CRISC, CGEIT, ISO 27001 Lead Implementer/Auditor, or similar preferred. Experience with public sector or federal compliance programs (e.g., FedRAMP, NIST 800-171, CMMC) is a plus. COMPENSATION AND BENEFITS: $152,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here . SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice .
View more...

