At a Glance
- Tasks: Lead security governance, risk, and compliance initiatives in a hands-on role.
- Company: Join Sokin, a next-gen B2B financial services provider revolutionising global payments.
- Benefits: Enjoy a hybrid work model, competitive salary, and a dynamic team environment.
- Other info: Be part of a rapidly expanding startup with a commitment to inclusivity.
- Why this job: Make a real impact on global business by enhancing security and compliance.
- Qualifications: 4+ years in GRC or information security with hands-on experience in tech.
Sokin is scaling its security function, and as such this is a hands-on delivery role, not a policy-writing or oversight seat. You'll own governance, risk, and compliance end to end, from framework and policy work through to control implementation, evidence automation, and audit delivery with a small team of SMEs.
This isn't a role where you write documentation and hand off the real work. You'll be in Vanta, in the AWS/GCP/Azure consoles, in Jira and GitHub, and in engineering conversations regularly enough to know whether a control is actually true, not just documented.
About Us
Sokin is a next-generation B2B financial services provider, enabling businesses to make and receive global payments with greater speed, lower cost, and total transparency. Our mission is simple: we're simplifying global business - so businesses thrive wherever they choose to grow. We deliver services across:
- Global payments and receivables
- Foreign Exchange (FX)
- Treasury management
- Finance reconciliations
We are rapidly expanding, with established presence in EMEA, APAC, and North America, backed by a strong global infrastructure and industry-leading partners, we are redefining how businesses move money worldwide. Our clients span industries from sports and entertainment to logistics and travel, and our community is growing rapidly. As we continue to expand, we’re building a team of exceptional people who share our ambition to transform the future of global payments.
What you'd do
- Own and mature our compliance program across SOC 2, ISO 27001, PCI, DSS, and GDPR, with active awareness of DORA (ICT risk management, third-party ICT oversight, incident classification) and FCA/PRA operational resilience (SYSC 8, SYSC 13) given our regulatory footprint, plus MAS TRM and UAE regulatory (CBUAE, VARA, DFSA) obligations where applicable.
- Run Vanta day to day: control mapping, automated evidence review, remediation tracking, integration health, and building custom automations/API connections where native integrations don't cover a control.
- Build and maintain the risk register as a living system, own the scoring methodology, and drive remediation with named owners and deadlines tracked in Jira.
- Maintain the policy and procedure library in Confluence as structured, version-controlled documentation that reflects actual technical implementation, not templated language pulled from a framework doc.
- Design and run vendor/third-party risk assessments, with risk tiering appropriate to a payments business (processors, banking partners, cloud providers, sub-processors).
- Lead external audits and pen test coordination end to end: scoping, evidence, auditor liaison, QSA engagement (PCI DSS), and findings remediation.
- Work directly in GitHub on control-relevant engineering practices (branch protection, CI/CD evidence, code review requirements) rather than requesting screenshots secondhand.
- Investigate control failures and monitoring alerts directly, enough to understand root cause in cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD, and logging before looping in engineering.
- Own security questionnaire responses for customer and partner due diligence, using an answer-library approach (Vanta's answer library) rather than starting from scratch each time.
- Perform regulatory horizon scanning across our active jurisdictions and translate changes directly into control and policy updates you implement.
- Report risk posture, audit status, and control health to the CISO and, periodically, the board.
- Use tooling to automate control mapping across overlapping frameworks, draft policy updates, and summarize vendor risk documentation, freeing time for judgment calls over paperwork.
What We're Looking for:
Essential:
- 4+ years in GRC, information security, or compliance, ideally with at least one year hands-on in a security engineering or IT operations role.
- Direct experience running SOC 2 and/or ISO 27001 audits from the compliance side, including evidence collection and auditor management.
- Working technical literacy: comfortable reading IAM policies, understanding a SIEM alert, following a CI/CD pipeline in GitHub, and telling when an engineer's explanation of a control doesn't hold up.
- Hands-on experience with Vanta or an equivalent GRC automation platform (Drata, Secureframe) - beyond just uploading evidence.
- Comfortable working daily in Jira and Confluence as the system of record.
- Understanding of payments-specific risk: PCI DSS scoping, third-party processor risk, financial services regulatory expectations.
- Strong written communication - policies, board summaries, and customer-facing security answers in the same week.
Nice to have:
- CISA, CISSP, or ISO 27001 Lead Auditor/Implementer certification.
- Experience in a regulated fintech or payments environment specifically.
- DORA, MAS TRM, or UAE (CBUAE/VARA/DFSA) regulatory experience specifically.
- Scripting ability (Python or similar) for control automation or evidence pipeline work.
- Prior experience building or significantly maturing a GRC function.
Why this role
Real scope to run the function the right way, with direct CISO access, modern tooling already in place, and a stack spanning AWS, GCP, and Azure, without legacy process debt to unwind.
Please note, candidates will need to have the right to work in the jurisdiction that they are looking to work in. Sokin is an equal opportunities employer and committed to maintaining an inclusive work environment. As a growing global startup with bases across multiple countries, we were established on and continue to promote an agile, flexible working culture. Please reach out to discuss any accommodations you may require during the recruitment process.
Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid employer: Sokin
Sokin is an exceptional employer that fosters a dynamic and innovative work culture, perfect for those passionate about fintech and global payments. Located in the vibrant city of London, employees benefit from a collaborative environment that encourages professional growth and development, alongside competitive compensation and unique opportunities to shape the future of FX products. Join us to be part of a rapidly expanding team where your contributions truly matter.
StudySmarter Expert Advice🤫
We think this is how you could land Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Sokin, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Sokin
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Sokin. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Security Governance, Risk, Compliance Lead Technology · London, Dubai · Hybrid
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Sokin insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Sokin that you’re committed to staying ahead in the game.
How to prepare for a job interview at Sokin
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Sokin to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Sokin.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.