Hands-On Security GRC Lead: Cloud, Audits & Automation

Sokin

Greater London

Hybrid

GBP 90,000 - 150,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Sokin is scaling its security function and seeking a hands-on Security GRC Lead to own governance, risk, and compliance end-to-end. You will work across SOC 2, ISO 27001, PCI DSS, GDPR with exposure to DORA and regulatory regimes in multiple regions.

You will operate in AWS/GCP/Azure consoles, Jira, GitHub, and Confluence, collaborating with engineering to ensure controls are true, not just documented, and driving remediation with owners and deadlines.

Qualifications

  • 4+ years in GRC, information security, or compliance, with hands-on in security engineering or IT operations
  • Direct experience running SOC 2 and/or ISO 27001 audits, including evidence collection and auditor management
  • Working technical literacy: reading IAM policies, SIEM alerts, CI/CD pipelines in GitHub, and evaluating control explanations
  • Hands-on experience with GRC automation platforms (Vanta, Drata, Secureframe) beyond uploading evidence
  • Comfortable using Jira and Confluence daily as the system of record
  • Understanding payments-specific risk: PCI DSS scoping, third-party processor risk, financial services regulatory expectations
  • Strong written communication for policies, board summaries, and customer-facing security answers

Responsibilities

  • Own and mature our compliance program across SOC 2, ISO 27001, PCI DSS, GDPR, with awareness of DORA and FCA/PRA operational resilience
  • Run Vanta day-to-day: mapping controls, automated evidence review, remediation tracking, integration health
  • Maintain risk register with scoring methodology and track remediation in Jira
  • Design and run vendor/third-party risk assessments with appropriate risk tiering
  • Lead external audits and pen test coordination: scoping, evidence, auditor liaison, findings remediation
  • Work in GitHub on control-relevant engineering practices rather than submitting screenshots
  • Investigate control failures and monitoring alerts to understand root cause in cloud infra
  • Own security questionnaire responses using a library approach for customers/partners

Skills

GRC management
Audits & compliance
Cloud security literacy
Cross-functional collaboration
Regulatory understanding
Technical writi ng ability
Vendor risk assessments

Tools

Vanta
Jira
Confluence
GitHub
CI/CD

Job description

Sokin is scaling its security function and seeking a hands-on Security GRC Lead to own governance, risk, and compliance end-to-end. You will work across SOC 2, ISO 27001, PCI DSS, GDPR with exposure to DORA and regulatory regimes in multiple regions.

You will operate in AWS/GCP/Azure consoles, Jira, GitHub, and Confluence, collaborating with engineering to ensure controls are true, not just documented, and driving remediation with owners and deadlines.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hands-On GRC Lead: Security, Risk & Compliance
Hands-On GRC Lead: Security, Risk & Compliance

Sokin • Greater London

Hybrid
GBP 90,000 - 130,000
Security GRC Lead: Hands-On Compliance & Audit
Security GRC Lead: Hands-On Compliance & Audit

Sokin • Harrow

On-site
GBP 70,000 - 120,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • Harrow

On-site
GBP 70,000 - 120,000
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 90,000 - 130,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • Greater London

Hybrid
GBP 90,000 - 150,000
Head of Security Operations & Detection Strategy
Head of Security Operations & Detection Strategy

Sokin • Harrow

On-site
GBP 120,000 - 170,000
Head of Security Operations & Detection
Head of Security Operations & Detection

Sokin • Greater London

Hybrid
GBP 120,000 - 180,000
Security & GRC Lead: Cyber Risk, Audit & Compliance
Security & GRC Lead: Cyber Risk, Audit & Compliance

Amiqus • United Kingdom

On-site
GBP 60,000 - 85,000
Lead Security Engineer: Own Cloud & Incident Response
Lead Security Engineer: Own Cloud & Incident Response

Understanding Recruitment • Greater London

Hybrid
GBP 110,000 - 150,000
Hybrid working
London office access
Autonomy and ownership
+2
Information Security Manager: GRC, Audits & SecureOps
Information Security Manager: GRC, Audits & SecureOps

EngineersOfAI • Greater London

On-site
GBP 70,000 - 110,000