Security Architect

Capital.com
Warsaw, Sofia
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Analytical thinking","Stakeholder management","Communication","Risk-focused decision-making"]

Own the enterprise security GRC framework, defining the policy hierarchy, risk register methodology, control ownership, and audit evidence structure. Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and drive remediation priorities. Serve as the final authority on regulatory interpretation and manage compliance/obligation management across FCA, CySEC, ASIC, SCB, and SCA jurisdictions. Shape security awareness architecture and advise C-suite stakeholders on security risk trade-offs.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Capital.com
Capital.com
4 days ago

Security Architect

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 20 hours agoStatus: Live

Job Summary

Own the enterprise security GRC framework, defining the policy hierarchy, risk register methodology, control ownership, and audit evidence structure. Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and drive remediation priorities. Serve as the final authority on regulatory interpretation and manage compliance/obligation management across FCA, CySEC, ASIC, SCB, and SCA jurisdictions. Shape security awareness architecture and advise C-suite stakeholders on security risk trade-offs.
Location: Warsaw, Sofia
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Own the enterprise security GRC framework, including policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • •Map controls to DORA, NIS2, ISO 27001, and PCI-DSS; identify gaps and set remediation priorities.
  • •Provide authoritative regulatory interpretation for audits and regulatory submissions.
  • •Own the compliance and obligation management framework across regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA).
  • •Define security awareness architecture (segmentation, interventions, and measurement) and advise CISO/CHRO/Risk/Compliance on security risk and investment trade-offs.

Pay and Benefits

Perks:Health InsurancePensionPaid LeaveRemote Work

Key Requirements

  • •8+ years in security with a significant focus on GRC, regulatory compliance, and risk, owning these programs at enterprise level.
  • •Deep working knowledge of ISO 27001 and PCI-DSS (with DORA and NIS2 preferred), translating regulatory text into specific controls.
  • •Multi-jurisdiction compliance experience with direct exposure to FCA or CySEC as a strong advantage.
  • •Proven ability to advise and influence C-suite stakeholders on complex security and regulatory matters.
  • •Relevant professional certifications (CISSP, CISM, CRISC, or equivalent).
Experience:FintechGRCRegulatory complianceEnterprise securityFinancial services
Skills:Analytical thinkingStakeholder managementCommunicationRisk-focused decision-making
Certifications:CISSPCISMCRISC
Languages:English
Tech Stack:ISO 27001PCI-DSSDORANIS2GRCRisk register methodologyAudit evidence

Company Brief

Capital.com
Operates an online trading platform offering CFDs, forex, commodities, indices and cryptocurrencies to retail investors and traders, combining market access with educational content, analytics, and AI-driven insights for informed trading decisions.
Industry: Trading Platforms
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: London, United Kingdom
Founded: 2016
WebsiteLinkedIn