Chief Information Security Officer (CISO) - London in City of London

Chief Information Security Officer (CISO) - London in City of London

City of London Full-Time 72000 - 108000 £ / year (est.) No working from home possible
Sokin

At a Glance

  • Tasks: Lead and innovate in information security for a next-gen fintech.
  • Company: Join Sokin, a rapidly expanding B2B financial services provider.
  • Benefits: Enjoy competitive salary, equity, hybrid work, and professional development.
  • Other info: Dynamic role with opportunities to build and lead a security team.
  • Why this job: Shape the future of global payments while protecting vital data.
  • Qualifications: 10+ years in info security with leadership experience in regulated environments.

The predicted salary is between 72000 - 108000 £ per year.

We are seeking an experienced Chief Information Security Officer to lead our information security programme. Reporting directly to the CTO, you will be accountable for protecting Sokin's systems, data, and reputation across our global operations. This is a hands‑on leadership role requiring someone who can operate strategically whilst remaining technically engaged. You will build and lead the security function, establish security governance, and ensure compliance with regulatory requirements across FCA, PCI-DSS, and international data protection frameworks.

Sokin is a next‑generation B2B financial services provider, enabling businesses to make and receive global payments with greater speed, lower cost, and total transparency. Our mission is simple: we’re simplifying global business - so businesses thrive wherever they choose to grow.

Key Responsibilities:

  • Security Strategy & Governance
    • Define and execute the enterprise information security strategy aligned with business objectives
    • Establish and maintain the Information Security Management System (ISMS) to support constant certification readiness with PCI DSS, ISO 27001 and SOC2
    • Own security policies, standards, and procedures across the organisation
    • Report to the Board and senior leadership on security posture, risk exposure and programme maturity
    • Manage security budget and resource allocation
  • Risk & Compliance
    • Lead enterprise security risk assessments and maintain the infosec item on the risk register
    • Ensure compliance with FCA operational resilience requirements and SYSC guidelines
    • Maintain PCI-DSS Level 1 compliance across payment processing infrastructure
    • Oversee GDPR, UK Data Protection Act, and international privacy compliance
    • Manage relationships with external auditors, penetration testers, and regulatory bodies
    • Lead third‑party vendor security assessments and due diligence
  • Security Operations
    • Build and lead the Security Operations Centre (SOC) function
    • Establish incident response capabilities and lead major security incident management
    • Implement and manage SIEM, EDR, vulnerability management, and threat intelligence platforms
    • Oversee identity and access management (IAM) strategy and privileged access management (PAM)
    • Drive security monitoring and alerting across cloud and on‑premise infrastructure
  • Application & Cloud Security
    • Embed security into the SDLC through secure development practices and DevSecOps
    • Lead application security programme including SAST, DAST, SCA, and code review processes
    • Secure AWS cloud infrastructure using native and third‑party security tooling
    • Ensure secure API design and implementation for payment integrations
    • Manage secrets management, encryption standards, and key management practices
  • Business Continuity & Resilience
    • Own business continuity and disaster recovery planning from a security perspective
    • Lead security aspects of operational resilience testing and scenario planning
    • Ensure adequate backup, recovery, and failover capabilities for critical systems
  • Culture & Awareness
    • Build security awareness programme including phishing simulations and training
    • Foster a security‑conscious culture across engineering, product, and business teams
    • Recruit, develop, and retain security talent

Requirements:

  • Experience
    • 10+ years in information security with 5+ years in senior security leadership roles
    • Experience in regulated financial services (payments, banking, or fintech)
    • Track record of building and leading security teams in scale‑up environments
    • Experience with FCA regulation, PCI‑DSS compliance, and financial services audits
    • Hands‑on experience with security incident response and crisis management
  • Technical Expertise
    • Deep knowledge of AWS security services (GuardDuty, Security Hub, WAF, KMS, CloudTrail, Config)
    • Experience with containerised environments (EKS/Kubernetes) and serverless security
    • Strong understanding of network security, zero‑trust architecture, and micro‑segmentation
    • Proficiency with SIEM platforms (Splunk, Datadog Security, or equivalent)
    • Knowledge of application security tools: Wiz, SonarQube, Burp Suite, OWASP ZAP
    • Experience with IAM solutions (Auth0, Azure AD) and PAM tools (CyberArk, ConductorOne, Hashicorp)
    • Understanding of cryptographic standards, HSMs, and payment security (tokenisation, encryption)
    • Familiarity with infrastructure‑as‑code security (Terraform, CloudFormation)
  • Leadership & Communication
    • Ability to translate technical risk into business terms for Board and executive audiences
    • Experience presenting to regulators and managing regulatory relationships
    • Strong written communication for policies, procedures, and risk reporting
    • Ability to influence without authority across engineering and business functions

Nice to Have:

  • CISSP, CISM, or CISA certification
  • Experience with cross‑border payments, FX, or correspondent banking security
  • Knowledge of SWIFT security controls and messaging standards
  • Familiarity with Open Banking and PSD2 security requirements
  • Experience with fraud detection and prevention systems
  • Bug bounty programme management experience
  • Blockchain or digital asset security knowledge
  • Experience managing security across distributed teams (London, Belgrade)

Technology Environment:

You will be securing an environment that includes: AWS (K8S, Lambda, RDS, S3, API Gateway), PostgreSQL, Redis, monolith‑to‑microservices architecture, CI/CD pipelines (GitHub Actions), Terraform, Grafana, and integrations with banking partners, card networks, and payment rails. Our engineering teams operate across the globe in London, Belgrade, Toronto, Latam, Dubai and India.

What We Offer:

  • Competitive salary and equity participation
  • Hybrid working with flexibility
  • Private healthcare
  • Pension contribution
  • Professional development budget
  • Opportunity to shape security strategy at a high‑growth fintech

How to Apply:

Submit your CV and a brief covering letter explaining your relevant experience in regulated financial services security. We are particularly interested in hearing about security programmes you have built or transformed. Please note, candidates will need to have the right to work in the jurisdiction that they are looking to work in.

The main responsibilities of this role are outlined above; however, this description is not exhaustive, and the job holder may be required to undertake additional duties from time to time to ensure the smooth running of the department. The role may require some working outside our normal working hours.

Chief Information Security Officer (CISO) - London in City of London employer: Sokin

Sokin is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets financial services. With a strong commitment to employee growth, we provide competitive salaries, equity participation, and a professional development budget, all while fostering a culture of collaboration and security awareness. Join us to shape the future of global payments and thrive in a rapidly expanding company that values your contributions and offers flexibility through hybrid working arrangements.

Sokin

Contact Details:

Sokin Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Chief Information Security Officer (CISO) - London in City of London

Tip Number 1

Network like a pro! Attend industry events, webinars, and meetups to connect with other professionals in the security field. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your expertise! Create a personal blog or LinkedIn posts sharing insights on information security trends, compliance, or risk management. This not only showcases your knowledge but also helps you stand out to potential employers.

Tip Number 3

Prepare for interviews by brushing up on both technical skills and leadership qualities. Be ready to discuss how you've built security teams or managed incidents in the past. We want to see your hands-on experience shine!

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you're genuinely interested in joining our mission to simplify global business.

We think you need these skills to ace Chief Information Security Officer (CISO) - London in City of London

Information Security Management System (ISMS)
PCI DSS compliance
ISO 27001
SOC2
Security Governance
Risk Assessment
FCA regulation

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the CISO role. Highlight your experience in information security, especially in regulated financial services. We want to see how your skills align with our mission at Sokin!

Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of security programmes you've built or transformed. This is your chance to shine and show us your passion for security!

Showcase Your Technical Expertise:Don’t forget to highlight your technical skills! Mention your experience with AWS security services, compliance frameworks, and any relevant tools you’ve used. We’re looking for someone who can dive deep into the tech side while leading strategically.

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you don’t miss out on any important updates from us. Let’s get started on this journey together!

How to prepare for a job interview at Sokin

Know Your Stuff

Make sure you brush up on the latest trends and regulations in information security, especially those relevant to financial services like FCA and PCI-DSS. Being able to discuss these topics confidently will show that you're not just a leader but also technically engaged.

Showcase Your Leadership Skills

Prepare examples of how you've built and led security teams in previous roles. Highlight your experience in scaling up security functions and how you've fostered a security-conscious culture within organisations. This is crucial for a hands-on leadership role.

Be Ready for Scenario Questions

Expect to face scenario-based questions that assess your incident response capabilities and crisis management skills. Think about past incidents you've managed and be ready to discuss your approach to handling them effectively.

Communicate Clearly

Practice translating complex technical risks into business terms. You’ll need to present to the Board and senior leadership, so being able to communicate clearly and persuasively is key. Prepare some concise points on how you would report on security posture and risk exposure.