---
title: "Security Architect"
company: "capital.com"
company_url: "https://www.remjobs.works/companies/capital-com"
url: "https://www.remjobs.works/job/capital-com-security-architect-6ec20351-776f-4bb4-b7f3-a0056390c6df"
apply_url: "https://jobs.lever.co/capital/119d01b5-0a3c-4109-8ea0-9b231f60d718"
workplace: hybrid
location: "Warsaw, Mazowieckie, Poland"
employment_type: other
seniority: mid
role: devops-infrastructure
region: europe
date_posted: 2026-09-01T08:15:35.571Z
first_seen_by_remjobs: 2026-09-15T19:11:55.761Z
---

# Security Architect

**capital.com** · Warsaw, Mazowieckie, Poland

Apply: https://jobs.lever.co/capital/119d01b5-0a3c-4109-8ea0-9b231f60d718

## About the role

Capital.com is a global fintech company with over 1,000,000 clients worldwide. Our platform offers CFD trading across 5,000+ markets, powered by proprietary AI technology that helps traders make better decisions. Our top-rated products have won prestigious industry awards for their cutting-edge technology and seamless client experience. We deliver only the best, so we are always in search of the best people to join our ever-growing talented team.

As part of our continued investment in security and regulatory resilience, we are seeking a **Security Architect **to own the design of our enterprise security governance, risk, and compliance (GRC) framework. This is a senior, high-visibility role that sits at the intersection of security architecture, multi-jurisdiction regulatory compliance, and organizational risk — shaping how a global fintech company regulated across five jurisdictions thinks about, measures, and reduces security risk.

##### Responsibilities:

- Own the enterprise security GRC framework — policy hierarchy, risk register methodology, control ownership, and audit evidence structure.

- Map controls to DORA, NIS2, ISO 27001, and PCI-DSS, identify gaps, and set remediation priority.

- Act as the final authority on regulatory interpretation affecting security, including written positions for audits and regulatory submissions.

- Own the compliance and obligation management framework across all five regulated jurisdictions (FCA, CySEC, ASIC, SCB, SCA), including regulatory horizon scanning.

- Represent the company in regulatory discussions alongside the CISO and General Counsel where required.

- Define the company's human-risk philosophy and shape the security awareness architecture — segmentation, interventions, and measurement.

- Advise the CISO, CHRO, Risk, and Compliance teams on security risk, regulatory obligations, and investment trade-offs.

- Set the architectural standards the Corporate Security team executes against, and sign off on significant framework changes.

- Support Third-Party Risk Management and Business Continuity & Crisis Management from a security and technical perspective.

##### Requirements:

- 8+ years in security with a significant focus on GRC, regulatory compliance, riskmanagement, or a combination — with a track record of owning these programs at enterpriselevel, not just familiarity with them.

- Proven experience designing enterprise-level security architectures or frameworks;experience in a regulated financial services environment (brokerage, payments, banking, orequivalent) is preferred but not required.

- Deep command of ISO 27001 and PCI-DSS (working knowledge of DORA and NIS2preferred), with the ability to translate regulatory text into specific controls, identify gaps, anddetermine what is mandatory versus discretionary.

- Multi-jurisdiction compliance experience; direct exposure to FCA or CySEC is a strongadvantage.

- Demonstrated ability to advise and influence C-suite stakeholders on complex security andregulatory matters.

- A structured, analytical thinking style — able to hold multiple regulatory regimessimultaneously without losing precision on any of them.

- Fluent English, written and spoken.

##### Nice to have:

- Direct experience managing regulatory submissions or engaging with supervisory authorities(FCA, CySEC, ASIC, SCB, or SCA).

- TPRM program design experience, including DORA ICT third-party risk requirements andsupply chain risk.

- Business Continuity Management background, with experience meeting operational resilienceobligations and presenting at Board level.

- Security awareness program design with measurable behaviour-change outcomes.

- Experience building or scaling a Corporate Security function from an early stage.

- Relevant professional certifications (CISSP, CISM, CRISC, or equivalent).

**What you will get in return:**
 
• **Competitive Salary:** We believe great work deserves great pay! Your skills and talents will be rewarded with a salary that makes you feel valued and motivated.
• **Work-Life Harmony:** Join a company that genuinely cares about you - because your life outside of work matters just as much as your time on the clock. #LI-Hybrid
• **Generous Time Off:** Need a breather? Our annual leave policy lets you recharge and enjoy life outside of work without a worry.
• **Employee Referral Program:** Love working here? Share the love! Bring your talented friends on board and get rewarded for growing our awesome team.
• **Comprehensive Health & Pension Benefits:** From medical insurance to pension plans, we’ve got your back. Plus, location-specific benefits and perks!
• **Workation Wonderland:** Live your digital nomad dreams with 30 extra days to work remotely from anywhere in the world (some restrictions apply). Adventure awaits!
• **Volunteer Days:** Make a difference! Take two additional paid days each year to support causes you care about and give back to the community.
 
 
 
Be a key player at the forefront of the digital assets movement, propelling your career to new heights! Join a dynamic and rapidly expanding company that values and rewards talent, initiative, and creativity. Work alongside one of the most brilliant teams in the industry.

---

Source: capital.com's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/capital-com-security-architect-6ec20351-776f-4bb4-b7f3-a0056390c6df
