AI Hiring Index

xAI · Engineering · Senior · Posted 2026-07-28

Sr. Security Engineer - GRC Fintech & Financial Services

xAI · Palo Alto, CA; New York, NY; Washington, DC · $152k–258k base

This range's midpoint is above 34% of posted engineering ranges at AI companies right now. Compare it with every posted range at xAI by level, and at 281 other AI companies, in the AI Salary Report, US$29 once, or see the free salary index.

Apply on xAI's site Watch xAI for new roles

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.  Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.

ABOUT THE ROLE:

We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on fintech and financial services regulation to help scale compliance for SpaceXAI and xMoney. As we operate deeper in regulated financial environments, maintaining a robust, transparent, and technically sound GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on fintech compliance experience (PCI DSS, NYDFS, FFIEC), fluency in data privacy frameworks (GDPR, CCPA), and GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact.

This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities.

RESPONSIBILITIES:

Own and evolve financial services and payments compliance posture across PCI DSS, NYDFS (including 23 NYCRR 500), FFIEC guidance, and related banking/fintech regulatory expectations supporting xMoney across relevant jurisdictions.

Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit readiness scales with the business rather than depending on manual, point-in-time checks.

Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks.

Partner with Architects and Engineering Leads to bake compliance and privacy requirements; translate complex regulatory obligations into concrete technical implementations and auditor-ready narratives without slowing development.

Design, implement, and validate technical controls relevant to fintech environments (cardholder data environment scoping and segmentation, access control, logging, encryption, change management, vulnerability management) — not just document them.

Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk.

Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the regulated attack surface.

Own and cultivate relationships with external auditors, assessors (e.g., QSAs where applicable), and regulators; serve as the bridge between auditors and internal teams so requests are reasonable, clear, and relevant to our stack.

Develop, maintain, and continuously improve policies, standards, and procedures aligned to PCI, NYDFS, FFIEC, privacy laws, and complementary frameworks (e.g., SOC 2, ISO 27001) where they overlap.

Champion pragmatic governance — prioritize issues that represent real security or business risk over checkbox compliance.

BASIC QUALIFICATIONS:

Bachelor's degree in computer science, Information S …

New engineering roles at AI companies, every Monday. The week's openings in this function across 277 companies, plus the weekly index. Free.

More engineering roles at xAI

See also: Security Engineer jobs · AI jobs in San Francisco Bay Area · xAI salaries · AWS jobs · GCP jobs · Azure jobs.

This listing is reproduced from xAI's public careers feed and links to the original. AI Hiring Index is not the employer and does not accept applications. All xAI roles · AI salaries.