Security Governance, Risk, Compliance Lead

Sokin

Harrow

On-site

GBP 70,000 - 120,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Sokin is scaling its security function and the Security GRC Lead will own governance, risk and compliance end to end, from framework work to control implementation and audit delivery with a small team of SMEs.

You'll work hands-on in Vanta and cloud consoles (AWS/GCP/Azure), in Jira and GitHub, and collaborate closely with engineering to ensure controls are genuinely implemented, not merely documented.

Qualifications

  • 4+ years in GRC, information security, or compliance, with hands-on experience in security engineering or IT operations.
  • Direct experience running SOC 2 and/or ISO 27001 audits with evidence collection and auditor management.
  • Technical literacy: read IAM policies, interpret SIEM alerts, follow CI/CD in GitHub, and verify control claims.
  • Hands-on experience with a GRC automation platform (Vanta, Drata or Secureframe).
  • Comfortable using Jira and Confluence as the system of record.
  • Understanding payments-specific risk: PCI DSS scoping, third-party processor risk.

Responsibilities

  • Own and mature our compliance program across SOC 2, ISO 27001, PCI DSS, and GDPR, with awareness of DORA and FCA/PRA obligations.
  • Run day-to-day Vanta: control mapping, automated evidence review, remediation tracking, integrations.
  • Build and maintain the risk register with scoring and deadlines in Jira.
  • Maintain policy library in Confluence reflecting actual implementation, not templated language.
  • Design and run vendor/third-party risk assessments with appropriate risk tiering.
  • Lead external audits and pen test coordination end to end: scoping, evidence, auditor liaison, findings remediation.
  • Work in GitHub on control-relevant engineering practices rather than screenshots.
  • Investigate control failures and monitoring alerts to understand root cause in cloud infra.
  • Own security questionnaire responses for customer/partner due diligence using an answer library.
  • Perform regulatory horizon scanning and translate changes into control and policy updates.
  • Report risk posture, audit status, and control health to CISO and board.
  • Automate control mapping and summarize vendor risk documentation to free time for judgement calls.

Skills

GRC
SOC 2
ISO 27001
Audits
Cloud security
Vanta
Jira
Confluence
GitHub
CI/CD
Python scripting

Tools

Vanta
Drata
Secureframe
GitHub
Jira
Confluence
AWS
GCP
Azure

Job description

Security GRC Lead

Sokin is scaling its security function, and as such this is a hands-on delivery role, not a policy-writing or oversight seat. You'll own governance, risk, and compliance end to end, from framework and policy work through to control implementation, evidence automation, and audit delivery with a small team of SMEs.

This isn't a role where you write documentation and hand off the real work. You'll be in Vanta, in the AWS/GCP/Azure consoles, in Jira and GitHub, and in engineering conversations regularly enough to know whether a control is actually true, not just documented.

About Us

Sokin is a next-generation B2B financial services provider, enabling businesses to make and receive global payments with greater speed, lower cost, and total transparency.

Our mission is simple: we’re simplifying global business - so businesses thrive wherever they choose to grow. We deliver services across:

  • Global payments and receivables
  • Foreign Exchange (FX)
  • Treasury management
  • Finance reconciliations

We are rapidly expanding, with established presence in EMEA, APAC, and North America, backed by a strong global infrastructure and industry-leading partners, we are redefining how businesses move money worldwide.

Our clients span industries from sports and entertainment to logistics and travel, and our community is growing rapidly. As we continue to expand, we’re building a team of exceptional people who share our ambition to transform the future of global payments.

What You'll Do
  • Own and mature our compliance program across SOC 2, ISO 27001, PCI DSS, and GDPR, with active awareness of DORA (ICT risk management, third-party ICT oversight, incident classification) and FCA/PRA operational resilience (SYSC 8, SYSC 13) given our regulatory footprint, plus MAS TRM and UAE regulatory (CBUAE, VARA, DFSA) obligations where applicable
  • Run Vanta day to day: control mapping, automated evidence review, remediation tracking, integration health, and building custom automations/API connections where native integrations don't cover a control
  • Build and maintain the risk register as a living system, own the scoring methodology, and drive remediation with named owners and deadlines tracked in Jira
  • Maintain the policy and procedure library in Confluence as structured, version-controlled documentation that reflects actual technical implementation, not templated language pulled from a framework doc
  • Design and run vendor/third-party risk assessments, with risk tiering appropriate to a payments business (processors, banking partners, cloud providers, sub-processors)
  • Lead external audits and pen test coordination end to end: scoping, evidence, auditor liaison, QSA engagement (PCI DSS), and findings remediation
  • Work directly in GitHub on control-relevant engineering practices (branch protection, CI/CD evidence, code review requirements) rather than requesting screenshots secondhand
  • Investigate control failures and monitoring alerts directly, enough to understand root cause in cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD, and logging before looping in engineering
  • Own security questionnaire responses for customer and partner due diligence, using an answer-library approach (Vanta's answer library) rather than starting from scratch each time
  • Perform regulatory horizon scanning across our active jurisdictions and translate changes directly into control and policy updates you implement
  • Report risk posture, audit status, and control health to the CISO and, periodically, the board
  • Use tooling to automate control mapping across overlapping frameworks, draft policy updates, and summarize vendor risk documentation, freeing time for judgment calls over paperwork
Essential
What We're Looking For
  • 4+ years in GRC, information security, or compliance, ideally with at least one year hands-on in a security engineering or IT operations role
  • Direct experience running SOC 2 and/or ISO 27001 audits from the compliance side, including evidence collection and auditor management
  • Working technical literacy: comfortable reading IAM policies, understanding a SIEM alert, following a CI/CD pipeline in GitHub, and telling when an engineer's explanation of a control doesn't hold up
  • Hands-on experience with Vanta or an equivalent GRC automation platform (Drata, Secureframe) - beyond just uploading evidence
  • Comfortable working daily in Jira and Confluence as the system of record, not via a delegate
  • Understanding of payments-specific risk: PCI DSS scoping, third-party processor risk, financial services regulatory expectations
  • Strong written communication - policies, board summaries, and customer-facing security answers in the same week
Nice To Have
  • CISA, CISSP, or ISO 27001 Lead Auditor/Implementer certification
  • Experience in a regulated fintech or payments environment specifically
  • DORA, MAS TRM, or UAE (CBUAE/VARA/DFSA) regulatory experience specifically
  • Scripting ability (Python or similar) for control automation or evidence pipeline worki>
  • Prior experience building or significantly maturing a GRC function
Why this role

Real scope to run the function the right way, with direct CISO access, modern tooling already in place, and a stack spanning AWS, GCP, and Azure, without legacy process debt to unwind.

Please note, candidates will need to have the right to work in the jurisdiction that they are looking to work in.

Sokin is an equal opportunities employer and committed to maintaining an inclusive work environment. As a growing global startup with bases across multiple countries, we were established on and continue to promote an agile, flexible working culture. Please reach out to discuss any accommodations you may require during the recruitment process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 90,000 - 130,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • Greater London

Hybrid
GBP 90,000 - 150,000
GRC Engineer
GRC Engineer

Apex Fintech Solutions • Belfast City District

Hybrid
GBP 70,000 - 95,000
28 days annual leave + NI holidays
Annual bonus
Pension matched up to 7%
+2
InfoSec Analyst II (GRC) Information security London
InfoSec Analyst II (GRC) Information security London

Checkout Ltd • Greater London

Hybrid
GBP 50,000 - 70,000
Snacks and meals provided
Collaborative work environment
GRC Senior Analyst
GRC Senior Analyst

Recruitment • Greater London

On-site
GBP 75,000 - 110,000
GRC Engineer
GRC Engineer

PEAK6 • Belfast City District

Hybrid
GBP 60,000 - 90,000
Market-leading salary
Pension matched 7%
Training budget
+7
GRC Engineer
GRC Engineer

Peak6 Investments LLC • Belfast City District

Hybrid
GBP 80,000 - 120,000
Annual bonus
28 days annual leave
Pension matched up to 7%
+4
Technical Operations Manager
Technical Operations Manager

Sokin • City Of London

Hybrid
GBP 70,000 - 90,000
Group AML Manager
Group AML Manager

Sokin • Greater London

On-site
GBP 110,000 - 150,000
Head of Security Operations
Head of Security Operations

Sokin • Harrow

On-site
GBP 120,000 - 170,000