Security Architect

Posted 3 Days Ago
Be an Early Applicant
3 Locations
Remote or Hybrid
Senior level
Software
The Role
Own the enterprise security governance, risk, and compliance framework for a global regulated fintech. Responsibilities include mapping controls to international regulations, managing multi-jurisdiction obligations, interpreting regulatory requirements, advising executive stakeholders, defining security architecture standards, and supporting third-party risk and operational resilience programs.
Summary Generated by Built In

Capital.com is a global fintech company with over 1,000,000 clients worldwide. Our platform offers CFD trading across 5,000+ markets, powered by proprietary AI technology that helps traders make better decisions. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.

As part of our continued investment in security and regulatory resilience, we are seeking a Security Architect to own the design of our enterprise security governance, risk, and compliance (GRC) framework. This is a senior, high-visibility role that sits at the intersection of security architecture, multi-jurisdiction regulatory compliance, and organizational risk — shaping how a global fintech company regulated across five jurisdictions thinks about, measures, and reduces security risk.

Responsibilities:

  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority.
  • Act as the final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions.
  • Own the compliance and obligation management framework across all five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA), including regulatory horizon scanning.
  • Represent the company in regulatory discussions alongside the CISO and General Counsel where required.
  • Define the company's human-risk philosophy and shape the security awareness architecture — segmentation, interventions, and measurement.
  • Advise the CISO, CHRO, Risk, and Compliance teams on security risk, regulatory obligations, and investment trade-offs.
  • Set the architectural standards the Corporate Security team executes against, and sign off on significant framework changes.
  • Support Third-Party Risk Management and Business Continuity & Crisis Management from a security and technical perspective.

Requirements:

  • 8+ years in security with a significant focus on GRC, regulatory compliance, riskmanagement, or a combination — with a track record of owning these programs at enterpriselevel, not just familiarity with them.
  • Proven experience designing enterprise-level security architectures or frameworks;experience in a regulated financial services environment (brokerage, payments, banking, orequivalent) is preferred but not required.
  • Deep command of ISO 27001 and PCI-DSS (working knowledge of DORA and NIS2preferred), with the ability to translate regulatory text into specific controls, identify gaps, anddetermine what is mandatory versus discretionary.
  • Multi-jurisdiction compliance experience; direct exposure to FCA or CySEC is a strongadvantage.
  • Demonstrated ability to advise and influence C-suite stakeholders on complex security andregulatory matters.
  • A structured, analytical thinking style — able to hold multiple regulatory regimessimultaneously without losing precision on any of them.
  • Fluent English, written and spoken.

Nice to have:

  • Direct experience managing regulatory submissions or engaging with supervisory authorities(FCA, CySEC, ASIC, SCB, or SCA).
  • TPRM program design experience, including DORA ICT third-party risk requirements andsupply chain risk.
  • Business Continuity Management background, with experience meeting operational resilienceobligations and presenting at Board level.
  • Security awareness program design with measurable behaviour-change outcomes.
  • Experience building or scaling a Corporate Security function from an early stage.
  • Relevant professional certifications (CISSP, CISM, CRISC, or equivalent).

Skills Required

  • 8+ years of experience in security, with significant focus on GRC, regulatory compliance, risk management, or a combination
  • Experience owning enterprise-level security programs
  • Experience designing enterprise-level security architectures or frameworks
  • Deep command of ISO 27001 and PCI-DSS
  • Working knowledge of DORA and NIS2
  • Ability to translate regulatory text into controls, identify gaps, and determine mandatory versus discretionary requirements
  • Multi-jurisdiction compliance experience
  • Ability to advise and influence C-suite stakeholders on complex security and regulatory matters
  • Structured and analytical thinking skills
  • Fluent written and spoken English
  • Experience in a regulated financial services environment
  • Direct exposure to FCA or CySEC
  • Experience managing regulatory submissions or engaging with supervisory authorities
  • Third-party risk management program design experience, including DORA ICT third-party risk requirements and supply chain risk
  • Business continuity management experience involving operational resilience obligations and Board-level presentations
  • Security awareness program design experience with measurable behavior-change outcomes
  • Experience building or scaling a Corporate Security function
  • CISSP, CISM, CRISC, or equivalent certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Hartford, CT
18 Employees

What We Do

Capital provides software that enables founders to raise, hold, spend, and send funds all in one place. Capital has evolved its flagship fundraising tool (formerly known as Party Round) to provide founders with banking solutions that streamline their startups.

Similar Jobs

Kraken Digital Asset Exchange Logo Kraken Digital Asset Exchange

Architect

Blockchain • Financial Services • Cryptocurrency • Web3
Remote
22 Locations
2900 Employees

Pfizer Logo Pfizer

Quality Assurance Manager

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
Remote or Hybrid
28 Locations
121990 Employees

Capco Logo Capco

Business Consulting Opportunities - Middle East

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Capco Logo Capco

Cloud & Cyber Security Opportunities - Qatar

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
10 Locations
6000 Employees

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account