ActiveJobs
X Ai

Sr. Security Engineer - GRC APAC Fintech & Financial Services

X Ai · Tokyo

Full-timeOn-sitePosted 9 October 2026
Apply on Company Site →

Job description

SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking an experienced Governance, Risk, and Compliance (GRC) Engineer focused on Japanese information security and financial services regulation to help scale compliance for SpaceXAI and X Money. As we expand deeper into the regulated Japanese market, maintaining a robust, transparent, and technically sound information security GRC program is critical. You will architect the systems and processes that automate trust — a pragmatic operator who understands that GRC exists to enable the business, balancing rigorous standards with the velocity of a high-growth company. The ideal candidate brings hands-on experience with JFSA supervisory expectations, APPI, and local Japanese banking and payments technology controls, plus GRC engineering skills: Compliance-as-Code, continuous evidence collection, and deep partnership with engineering so controls are designed into the platform rather than bolted on after the fact. This role may also include additional tasks and responsibilities as needed to support the team and evolving business priorities. This position may require occasional travel. RESPONSIBILITIES: Own and evolve Japan financial services and payments compliance posture across JFSA supervisory expectations (including technology risk management, incident reporting, and third-party technology risk), APPI, and local Japanese banking and payments technology controls supporting X Money. Build and maintain Compliance-as-Code capabilities — policy-as-code, automated control validation, continuous evidence collection, and monitoring integrated into CI/CD — so audit and supervisory readiness scales with the business rather than depending on manual, point-in-time checks. Operate and extend GRC platforms (e.g., Vanta) as the backbone for control mapping, evidence management, and continuous compliance; integrate with cloud, identity, logging, and engineering systems to reduce administrative bottlenecks. Partner with Architects and Engineering Leads to bake JFSA and APPI requirements into design early; translate complex Japanese regulatory obligations into concrete technical implementations and auditor- or supervisor-ready narratives without slowing development. Design, implement, and validate technical controls relevant to Japanese banking and payments environments (access control, logging and monitoring, encryption, change management, vulnerability management, business continuity and disaster recovery, and secure SDLC) — not just document them. Operate the cybersecurity and compliance risk register — identify, quantify, and track risks, distinguishing theoretical gaps from meaningful business and regulatory risk under JFSA supervisory expectations. Lead risk assessments and compliance reviews for new products, payment flows, features, vendors, and architectural changes that affect the Japan regulated attack surface, including third-party technology risk and subcontractor/sub-processor oversight. Liaise with Legal and the Data Privacy team on security-relevant intersections with APPI, including security measures for personal data and breach/incident reporting aligned to applicable JFSA expectations. Own and cultivate relationships with external auditors, assessors, and (where applicable) JFSA supervisory contacts; se

Verified and listed by ActiveJobs. Applications are made directly on X Ai's own career page — we never sit in the middle.