Security Architect
Capital.com · Warsaw, Mazowieckie, Poland
Job description
Responsibilities: Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure. Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority. Act as the final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions. Own the compliance and obligation management framework across all five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA), including regulatory horizon scanning. Represent the company in regulatory discussions alongside the CISO and General Counsel where required. Define the company's human-risk philosophy and shape the security awareness architecture — segmentation, interventions, and measurement. Advise the CISO, CHRO, Risk, and Compliance teams on security risk, regulatory obligations, and investment trade-offs. Set the architectural standards the Corporate Security team executes against, and sign off on significant framework changes. Support Third-Party Risk Management and Business Continuity & Crisis Management from a security and technical perspective. Requirements: 8+ years in security with a significant focus on GRC, regulatory compliance, riskmanagement, or a combination — with a track record of owning these programs at enterpriselevel, not just familiarity with them. Proven experience designing enterprise-level security architectures or frameworks;experience in a regulated financial services environment (brokerage, payments, banking, orequivalent) is preferred but not required. Deep command of ISO 27001 and PCI-DSS (working knowledge of DORA and NIS2preferred), with the ability to translate regulatory text into specific controls, identify gaps, anddetermine what is mandatory versus discretionary. Multi-jurisdiction compliance experience; direct exposure to FCA or CySEC is a strongadvantage. Demonstrated ability to advise and influence C-suite stakeholders on complex security andregulatory matters. A structured, analytical thinking style — able to hold multiple regulatory regimessimultaneously without losing precision on any of them. Fluent English, written and spoken. Nice to have: Direct experience managing regulatory submissions or engaging with supervisory authorities(FCA, CySEC, ASIC, SCB, or SCA). TPRM program design experience, including DORA ICT third-party risk requirements andsupply chain risk. Business Continuity Management background, with experience meeting operational resilienceobligations and presenting at Board level. Security awareness program design with measurable behaviour-change outcomes. Experience building or scaling a Corporate Security function from an early stage. Relevant professional certifications (CISSP, CISM, CRISC, or equivalent).
- Department
- Security - CorpSec
- Role group
- DevOps
- Employment
- Hybrid
- Countries
- Cyprus, UK, Bulgaria, Australia, Remote