Security GRC Lead: Hands-On Compliance & Audit

Sokin

Harrow

On-site

GBP 70,000 - 120,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Sokin is scaling its security function and the Security GRC Lead will own governance, risk and compliance end to end, from framework work to control implementation and audit delivery with a small team of SMEs.

You'll work hands-on in Vanta and cloud consoles (AWS/GCP/Azure), in Jira and GitHub, and collaborate closely with engineering to ensure controls are genuinely implemented, not merely documented.

Qualifications

  • 4+ years in GRC, information security, or compliance, with hands-on experience in security engineering or IT operations.
  • Direct experience running SOC 2 and/or ISO 27001 audits with evidence collection and auditor management.
  • Technical literacy: read IAM policies, interpret SIEM alerts, follow CI/CD in GitHub, and verify control claims.
  • Hands-on experience with a GRC automation platform (Vanta, Drata or Secureframe).
  • Comfortable using Jira and Confluence as the system of record.
  • Understanding payments-specific risk: PCI DSS scoping, third-party processor risk.

Responsibilities

  • Own and mature our compliance program across SOC 2, ISO 27001, PCI DSS, and GDPR, with awareness of DORA and FCA/PRA obligations.
  • Run day-to-day Vanta: control mapping, automated evidence review, remediation tracking, integrations.
  • Build and maintain the risk register with scoring and deadlines in Jira.
  • Maintain policy library in Confluence reflecting actual implementation, not templated language.
  • Design and run vendor/third-party risk assessments with appropriate risk tiering.
  • Lead external audits and pen test coordination end to end: scoping, evidence, auditor liaison, findings remediation.
  • Work in GitHub on control-relevant engineering practices rather than screenshots.
  • Investigate control failures and monitoring alerts to understand root cause in cloud infra.
  • Own security questionnaire responses for customer/partner due diligence using an answer library.
  • Perform regulatory horizon scanning and translate changes into control and policy updates.
  • Report risk posture, audit status, and control health to CISO and board.
  • Automate control mapping and summarize vendor risk documentation to free time for judgement calls.

Skills

GRC
SOC 2
ISO 27001
Audits
Cloud security
Vanta
Jira
Confluence
GitHub
CI/CD
Python scripting

Tools

Vanta
Drata
Secureframe
GitHub
Jira
Confluence
AWS
GCP
Azure

Job description

Sokin is scaling its security function and the Security GRC Lead will own governance, risk and compliance end to end, from framework work to control implementation and audit delivery with a small team of SMEs.

You'll work hands-on in Vanta and cloud consoles (AWS/GCP/Azure), in Jira and GitHub, and collaborate closely with engineering to ensure controls are genuinely implemented, not merely documented.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hands-On GRC Lead: Security, Risk & Compliance
Hands-On GRC Lead: Security, Risk & Compliance

Sokin • Greater London

Hybrid
GBP 90,000 - 130,000
Hands-On Security GRC Lead: Cloud, Audits & Automation
Hands-On Security GRC Lead: Cloud, Audits & Automation

Sokin • Greater London

Hybrid
GBP 90,000 - 150,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • Harrow

On-site
GBP 70,000 - 120,000
Security & GRC Lead: Cyber Risk, Audit & Compliance
Security & GRC Lead: Cyber Risk, Audit & Compliance

Amiqus • United Kingdom

On-site
GBP 60,000 - 85,000
Security Governance, Risk, Compliance Lead
Security Governance, Risk, Compliance Lead

Sokin • Greater London

Hybrid
GBP 90,000 - 150,000
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid

Sokin • Greater London

Hybrid
GBP 90,000 - 130,000
GRC Automation Lead: Vendor Risk & Compliance
GRC Automation Lead: Vendor Risk & Compliance

Samsara • City Of London

Hybrid
GBP 70,000 - 110,000
Professional development stipend
Flexible remote model
Security GRC Specialist — Governance, Risk & Compliance
Security GRC Specialist — Governance, Risk & Compliance

Rowden • Bristol

Hybrid
GBP 50,000 - 60,000
GRC & Security Assurance Consultant
GRC & Security Assurance Consultant

NTT Limited • Greater London

On-site
GBP 70,000 - 110,000
Junior GRC Analyst: ISO/SOC Audits & Risk (Hybrid)
Junior GRC Analyst: ISO/SOC Audits & Risk (Hybrid)

Starling • Cardiff

Hybrid
GBP 42,000 - 65,000
Private Medical Insurance
Company pension scheme
Life insurance
+1