Security Governance, Risk, Compliance Lead

Sokin

United Arab Emirates

On-site

AED 350,000 - 550,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Sokin is seeking a Security GRC Lead to own governance, risk, and compliance end to end. This hands-on delivery role covers framework work through to control implementation, evidence automation, and audit delivery with a small team of SMEs.

You will engage in engineering conversations in AWS, GCP, Azure, Jira and GitHub to verify controls are true, not just documented.

Qualifications

  • 4+ years in GRC, information security or compliance.
  • Experience running SOC 2 and/or ISO 27001 audits from the compliance side.
  • Hands-on in security engineering or IT operations.
  • Experience with GRC automation platforms (e.g., Vanta, Drata, Secureframe).
  • Familiarity with Jira/Confluence as system of record.
  • Understanding payments-specific risk (PCI DSS, third-party risk).
  • Strong written communication for policies and board summaries.

Responsibilities

  • Own and mature our compliance program across SOC 2, ISO 27001, PCI DSS and GDPR with regulatory awareness.
  • Run Vanta daily control mapping, evidence review, remediation tracking, and automation.
  • Maintain risk register, scoring methodology, and remediation ownership in Jira.
  • Design and run vendor third-party risk assessments for payments-related partners.
  • Lead external audits and pen-test coordination end to end.
  • Work in GitHub on control-relevant engineering practices and evidence collection.
  • Investigate control failures and monitoring in cloud infrastructure (AWS, GCP, Azure).
  • Prepare security questionnaire responses using an answer library approach.

Skills

GRC
Information security
Compliance
Auditing
Vendor risk management

Tools

Vanta
Jira
Confluence
GitHub

Job description

Security GRC Lead Sokin is scaling its security function and as such this is a hands-on delivery role not a policy-writing or oversight seat. You'll own governance, risk, and compliance end to end from framework and policy work through to control implementation, evidence automation, and audit delivery with a small team of SMEs. This isn't a role where you write documentation and hand off the real work. You'll be in Vanta in the AWS GCP Azure consoles in Jira and GitHub and in engineering conversations regularly enough to know whether a control is actually true, not just documented.

What you'll do
  • Own and mature our compliance program across SOC 2, ISO 27001, PCI DSS and GDPR with active awareness of DORA, ICT risk management, third-party ICT oversight, incident classification and FCA PRA operational resilience SYSC 8, SYSC 13 given our regulatory footprint plus MAS TRM and UAE regulatory CBUAE VARA DFSA obligations where applicable.
  • Run Vanta day to day control mapping, automated evidence review, remediation tracking, integration health, and building custom automations API connections where native integrations don't cover a control.
  • Build and maintain the risk register as a living system, own the scoring methodology, and drive remediation with named owners and deadlines tracked in Jira.
  • Maintain the policy and procedure library in Confluence as structured, version-controlled documentation that reflects actual technical implementation, not templated language pulled from a framework doc.
  • Design and run vendor third-party risk assessments with risk tiering appropriate to a payments business, processors, banking partners, cloud providers, sub-processors.
  • Lead external audits and pen-test coordination end to end: scoping, evidence, auditor liaison, QSA engagement, PCI DSS and findings remediation.
  • Work directly in GitHub on control-relevant engineering practices: branch protection, CI/CD evidence, code review requirements rather than requesting screenshots secondhand.
  • Investigate control failures and monitoring alerts directly enough to understand root cause in cloud infrastructure AWS, GCP, Azure, IAM, CI/CD, and logging before looping in engineering.
  • Own security questionnaire responses for customer and partner due diligence using an answer-library approach, Vanta's answer library, rather than starting from scratch each time.
  • Perform regulatory horizon scanning across our active jurisdictions and translate changes directly into control and policy updates you implement.
  • Report risk posture, audit status, and control health to the CISO and periodically the board.
  • Use tooling to automate control mapping across overlapping frameworks, draft policy updates and summarize vendor risk documentation, freeing time for judgment calls over paperwork.
What we’re looking for
  • Strong Essential: 4 years in GRC, information security or compliance, ideally with at least one year hands-on in a security engineering or IT operations role.
  • Direct experience running SOC 2 and/or ISO 27001 audits from the compliance side, including evidence collection and auditor management.
  • Working technical literacy - comfortable reading IAM policies, understanding a SIEM alert, following a CI/CD pipeline in GitHub and telling when an engineer's explanation of a control doesn't hold up.
  • Hands-on experience with Vanta or an equivalent GRC automation platform (Drata, Secureframe) - beyond just uploading evidence.
  • Comfortable working daily in Jira and Confluence as the system of record, not via a delegate.
  • Understanding of payments-specific risk: PCI DSS scoping, third-party processor risk, financial services regulatory expectations.
  • Strong written communication - policies, board summaries, and customer-facing security answers in the same week.
  • Nice to have: strong CISA, CISSP, or ISO 27001 Lead Auditor Implementer certification.
  • Experience in a regulated fintech or payments environment specifically.
  • DORA, MAS TRM, or UAE CBUAE VARA DFSA regulatory experience specifically.
  • Scripting ability - Python or similar for control automation or evidence pipeline work.
  • Prior experience building or significantly maturing a GRC function.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst (Governance, Risk & Compliance)
GRC Analyst (Governance, Risk & Compliance)

APPIT Software Inc. • Dubai

On-site
AED 150,000 - 200,000
Executive Manager - Squad Cyber Technical Lead
Executive Manager - Squad Cyber Technical Lead

Dicetek LLC • Abu Dhabi

On-site
AED 420,000 - 640,000
EMEA Assurance Lead
EMEA Assurance Lead

Scale AI • United Arab Emirates

On-site
AED 90,000 - 120,000
Head of Compliance Systems & Processes
Head of Compliance Systems & Processes

Leru Partners • Dubai

On-site
AED 210,000 - 270,000
Head of Risk & Compliance
Head of Risk & Compliance

ClearGrid Debt Collection LLC • Dubai

On-site
AED 600,000 - 900,000
Lead SRE / Technology Operations (DevSecOps)
Lead SRE / Technology Operations (DevSecOps)

Client of FinTop Consulting • Dubai

On-site
AED 420,000 - 640,000
Chief Information Security Officer (CISO)
Chief Information Security Officer (CISO)

myZoi • Dubai

On-site
AED 1,000,000 - 1,500,000
Head Of Compliance Systems And Processes
Head Of Compliance Systems And Processes

Leru Partners • Dubai

On-site
AED 600,000 - 900,000
Head of Application Security and Cloud Risk
Head of Application Security and Cloud Risk

amana • Dubai

On-site
AED 350,000 - 520,000
Senior Financial Crime Compliance Governance Manager
Senior Financial Crime Compliance Governance Manager

Revolut • United Arab Emirates

On-site
AED 180,000 - 270,000