Security Governance, Risk, Compliance Lead

Security Governance, Risk, Compliance Lead

Full-Time 60750 - 74250 £ / year (est.) Home office (partial)
Sokin

At a Glance

  • Tasks: Lead security governance, risk, and compliance initiatives with hands-on involvement in tech.
  • Company: Join Sokin, a next-gen B2B financial services provider transforming global payments.
  • Benefits: Enjoy a flexible work culture, competitive salary, and opportunities for professional growth.
  • Other info: Work in a dynamic team with direct access to the CISO and modern tools.
  • Why this job: Make a real impact in a fast-paced environment with cutting-edge technology.
  • Qualifications: 4+ years in GRC or compliance, with hands-on experience in security engineering.

The predicted salary is between 60750 - 74250 £ per year.

Sokin is scaling its security function, and as such this is a hands-on delivery role, not a policy-writing or oversight seat. You'll own governance, risk, and compliance end to end, from framework and policy work through to control implementation, evidence automation, and audit delivery with a small team of SMEs.

This isn't a role where you write documentation and hand off the real work. You'll be in Vanta, in the AWS/GCP/Azure consoles, in Jira and GitHub, and in engineering conversations regularly enough to know whether a control is actually true, not just documented.

About Us

Sokin is a next-generation B2B financial services provider, enabling businesses to make and receive global payments with greater speed, lower cost, and total transparency. Our mission is simple: we're simplifying global business - so businesses thrive wherever they choose to grow. We deliver services across:

  • Global payments and receivables
  • Foreign Exchange (FX)
  • Treasury management
  • Finance reconciliations

We are rapidly expanding, with established presence in EMEA, APAC, and North America, backed by a strong global infrastructure and industry-leading partners, we are redefining how businesses move money worldwide. Our clients span industries from sports and entertainment to logistics and travel, and our community is growing rapidly. As we continue to expand, we're building a team of exceptional people who share our ambition to transform the future of global payments.

What you'll do

  • Own and mature our compliance program across SOC 2, ISO 27001, PCI DSS, and GDPR, with active awareness of DORA (ICT risk management, third-party ICT oversight, incident classification) and FCA / PRA operational resilience (SYSC 8, SYSC 13) given our regulatory footprint, plus MAS TRM and UAE regulatory (CBUAE, VARA, DFSA) obligations where applicable.
  • Run Vanta day to day: control mapping, automated evidence review, remediation tracking, integration health, and building custom automations/API connections where native integrations don't cover a control.
  • Build and maintain the risk register as a living system, own the scoring methodology, and drive remediation with named owners and deadlines tracked in Jira.
  • Maintain the policy and procedure library in Confluence as structured, version-controlled documentation that reflects actual technical implementation, not templated language pulled from a framework doc.
  • Design and run vendor/third-party risk assessments, with risk tiering appropriate to a payments business (processors, banking partners, cloud providers, sub-processors).
  • Lead external audits and pen test coordination end to end: scoping, evidence, auditor liaison, QSA engagement (PCI DSS), and findings remediation.
  • Work directly in GitHub on control-relevant engineering practices (branch protection, CI/CD evidence, code review requirements) rather than requesting screenshots secondhand.
  • Investigate control failures and monitoring alerts directly, enough to understand root cause in cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD, and logging before looping in engineering.
  • Own security questionnaire responses for customer and partner due diligence, using an answer-library approach (Vanta's answer library) rather than starting from scratch each time.
  • Perform regulatory horizon scanning across our active jurisdictions and translate changes directly into control and policy updates you implement.
  • Report risk posture, audit status, and control health to the CISO and, periodically, the board.
  • Use tooling to automate control mapping across overlapping frameworks, draft policy updates, and summarise vendor risk documentation, freeing time for judgment calls over paperwork.

What We're Looking for

Essential

  • 4+ years in GRC, information security, or compliance, ideally with at least one year hands-on in a security engineering or IT operations role.
  • Direct experience running SOC 2 and/or ISO 27001 audits from the compliance side, including evidence collection and auditor management.
  • Working technical literacy: comfortable reading IAM policies, understanding a SIEM alert, following a CI/CD pipeline in GitHub, and telling when an engineer's explanation of a control doesn't hold up.
  • Hands-on experience with Vanta or an equivalent GRC automation platform (Drata, Secureframe) - beyond just uploading evidence.
  • Comfortable working daily in Jira and Confluence as the system of record, not via a delegate.
  • Understanding of payments-specific risk: PCI DSS scoping, third-party processor risk, financial services regulatory expectations.
  • Strong written communication - policies, board summaries, and customer-facing security answers in the same week.

Nice to have

  • CISA, CISSP, or ISO 27001 Lead Auditor/Implementer certification.
  • Experience in a regulated fintech or payments environment specifically.
  • DORA, MAS TRM, or UAE (CBUAE/VARA/DFSA) regulatory experience specifically.
  • Scripting ability (Python or similar) for control automation or evidence pipeline work.
  • Prior experience building or significantly maturing a GRC function.

Why this role

Real scope to run the function the right way, with direct CISO access, modern tooling already in place, and a stack spanning AWS, GCP, and Azure, without legacy process debt to unwind.

Please note, candidates will need to have the right to work in the jurisdiction that they are looking to work in. Sokin is an equal opportunities employer and committed to maintaining an inclusive work environment. As a growing global startup with bases across multiple countries, we were established on and continue to promote an agile, flexible working culture. Please reach out to discuss any accommodations you may require during the recruitment process.

Department Technology Locations London, Dubai Remote status Hybrid

Security Governance, Risk, Compliance Lead employer: Sokin

Sokin is an exceptional employer that fosters a dynamic and innovative work culture, perfect for those passionate about fintech and global payments. Located in the vibrant city of London, employees benefit from a collaborative environment that encourages professional growth and development, alongside competitive compensation and unique opportunities to shape the future of FX products. Join us to be part of a rapidly expanding team where your contributions truly matter.

Sokin

Contact Details:

Sokin Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Governance, Risk, Compliance Lead

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Sokin looking for candidates who are engaged and informed.

We think you need these skills to ace Security Governance, Risk, Compliance Lead

Governance, Risk, Compliance (GRC)
SOC 2
ISO 27001
PCI DSS
GDPR
DORA
FCA / PRA operational resilience

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Sokin. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Sokin

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Sokin’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!