SECTION I · THE BRIEF
Brief #76086Updated 01 SEP 2026WARSAW, MAZOWIECKIELeverFINANCIAL TECHNOLOGY COMPANIES
Employbl Company Profile

Security Architect

We are on a mission to make the world of finance more accessible, engaging and useful.

Location
Warsaw, Mazowieckie
Company size
50–2,000
Posted
2d ago
Via
Lever
Section II · Full ProfileFree with an account
  • 01Comp band & equity packageLocked
  • 02Seniority & experience requirementsLocked
  • 03Interview process & rubricLocked
  • 04Hiring manager & team contextLocked
  • 05Growth trajectory in this roleLocked
  • 06Offer & decision timelineLocked

Free account · no card · 2 minutes

Capital logo

Security Architect · Capital

View company profile
Job title
Security Architect
Job location
Warsaw, Mazowieckie, Poland
Job description

Capital.com is a global fintech company with over 1,000,000 clients worldwide. Our platform offers CFD trading across 5,000+ markets, powered by proprietary AI technology that helps traders make better decisions. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.

As part of our continued investment in security and regulatory resilience, we are seeking a Security Architect to own the design of our enterprise security governance, risk, and compliance (GRC) framework. This is a senior, high-visibility role that sits at the intersection of security architecture, multi-jurisdiction regulatory compliance, and organizational risk — shaping how a global fintech company regulated across five jurisdictions thinks about, measures, and reduces security risk.

Responsibilities:
  • Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
  • Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority.
  • Act as the final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions.
  • Own the compliance and obligation management framework across all five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA), including regulatory horizon scanning.
  • Represent the company in regulatory discussions alongside the CISO and General Counsel where required.
  • Define the company's human-risk philosophy and shape the security awareness architecture — segmentation, interventions, and measurement.
  • Advise the CISO, CHRO, Risk, and Compliance teams on security risk, regulatory obligations, and investment trade-offs.
  • Set the architectural standards the Corporate Security team executes against, and sign off on significant framework changes.
  • Support Third-Party Risk Management and Business Continuity & Crisis Management from a security and technical perspective.
  • Requirements:
  • 8+ years in security with a significant focus on GRC, regulatory compliance, riskmanagement, or a combination — with a track record of owning these programs at enterpriselevel, not just familiarity with them.
  • Proven experience designing enterprise-level security architectures or frameworks;experience in a regulated financial services environment (brokerage, payments, banking, orequivalent) is preferred but not required.
  • Deep command of ISO 27001 and PCI-DSS (working knowledge of DORA and NIS2preferred), with the ability to translate regulatory text into specific controls, identify gaps, anddetermine what is mandatory versus discretionary.
  • Multi-jurisdiction compliance experience; direct exposure to FCA or CySEC is a strongadvantage.
  • Demonstrated ability to advise and influence C-suite stakeholders on complex security andregulatory matters.
  • A structured, analytical thinking style — able to hold multiple regulatory regimessimultaneously without losing precision on any of them.
  • Fluent English, written and spoken.
  • Nice to have:
  • Direct experience managing regulatory submissions or engaging with supervisory authorities(FCA, CySEC, ASIC, SCB, or SCA).
  • TPRM program design experience, including DORA ICT third-party risk requirements andsupply chain risk.
  • Business Continuity Management background, with experience meeting operational resilienceobligations and presenting at Board level.
  • Security awareness program design with measurable behaviour-change outcomes.
  • Experience building or scaling a Corporate Security function from an early stage.
  • Relevant professional certifications (CISSP, CISM, CRISC, or equivalent).
  • View job listing ↗
    The Saturday Briefing

    Get the Saturday tech briefing

    New company profiles, funding moves, and who’s hiring across the market — every Saturday morning.

    Capital headquarters

    Company size

    502,000 employees

    Founded

    2016

    Total raised

    $25,000,000

    View company profile ↗

    Funding rounds