The Boeing Company is seeking a Software Architect to lead the Software Architecture Team for the AvionX Mission Systems Software organization, focusing on embedded systems and software development.
Security Architect
📜 Description
- Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.
- Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority.
- Act as the final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions.
- Own the compliance and obligation management framework across all five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA), including regulatory horizon scanning.
- Define the company's human-risk philosophy and shape the security awareness architecture — segmentation, interventions, and measurement.
🛠️ Requirements
- 8+ years in security with a significant focus on GRC, regulatory compliance, riskmanagement, or a combination — with a track record of owning these programs at enterpriselevel, not just familiarity with them.
- Proven experience designing enterprise-level security architectures or frameworks;experience in a regulated financial services environment (brokerage, payments, banking, orequivalent) is preferred but not required.
- Deep command of ISO 27001 and PCI-DSS (working knowledge of DORA and NIS2preferred), with the ability to translate regulatory text into specific controls, identify gaps, anddetermine what is mandatory versus discretionary.
- Multi-jurisdiction compliance experience; direct exposure to FCA or CySEC is a strongadvantage.
- Demonstrated ability to advise and influence C-suite stakeholders on complex security andregulatory matters.
- A structured, analytical thinking style — able to hold multiple regulatory regimessimultaneously without losing precision on any of them.
- Fluent English, written and spoken.
- Direct experience managing regulatory submissions or engaging with supervisory authorities(FCA, CySEC, ASIC, SCB, or SCA).
- TPRM program design experience, including DORA ICT third-party risk requirements andsupply chain risk.
- Business Continuity Management background, with experience meeting operational resilienceobligations and presenting at Board level.
Full job description
Capital.com is a global fintech company with over 1,000,000 clients worldwide. Our platform offers CFD trading across 5,000+ markets, powered by proprietary AI technology that helps traders make better decisions. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.
As part of our continued investment in security and regulatory resilience, we are seeking a Security Architect to own the design of our enterprise security governance, risk, and compliance (GRC) framework. This is a senior, high-visibility role that sits at the intersection of security architecture, multi-jurisdiction regulatory compliance, and organizational risk — shaping how a global fintech company regulated across five jurisdictions thinks about, measures, and reduces security risk.
Responsibilities:
Requirements:
Nice to have:
Similar jobs
Search more Architect jobsArchitectural Plan Reviewer and Code Inspector (Hybrid - Arlington, VA)
As an Architectural Plan Reviewer and Code Inspector, you will conduct code enforcement reviews and inspections, ensuring compliance with construction codes and standards for government projects.
Experienced Architect (Health)
Seeking an experienced Architect with a strong background in healthcare design to lead innovative projects and contribute to the evolution of healthcare environments.
CyberArk Architect
Lead the design and implementation of a large-scale Privileged Access Management migration project, focusing on CyberArk architecture and compliance.
TN14 - Software Architect
As a Senior Software Architect, you will lead architectural decisions, improve cloud infrastructure, and mentor engineers while addressing complex technical challenges in a financial services platform.
