Security Governance, Risk, Compliance Lead at Sokin | AE | Rezi

Security Governance, Risk, Compliance Lead at Sokin

Security Governance, Risk, Compliance Lead

Sokin · AE

1 months ago

Security Governance, Risk, Compliance Lead

Sokin · AE

2 months ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Security Governance, Risk, Compliance Lead role.

Rezi rewrites your resume against Sokin's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Security Governance, Risk, Compliance Lead posting at Sokin — free, in seconds.

About the Role

This is a hands-on delivery role focused on owning governance, risk, and compliance end-to-end, including framework and policy work, control implementation, evidence automation, and audit delivery with a small team of SMEs. You will be actively involved in technical environments like Vanta, AWS/GCP/Azure consoles, Jira, and GitHub to ensure controls are effectively implemented and documented.

Responsibilities

  • Own and mature the compliance program across SOC 2, ISO 27001, PCI DSS, and GDPR, with active awareness of DORA and FCA/PRA operational resilience.
  • Run Vanta day-to-day, including control mapping, automated evidence review, remediation tracking, and integration health.
  • Build and maintain the risk register as a living system, owning the scoring methodology and driving remediation.
  • Maintain the policy and procedure library in Confluence, ensuring documentation reflects actual technical implementation.
  • Design and run vendor/third-party risk assessments with appropriate risk tiering.
  • Lead external audits and pen test coordination end-to-end.
  • Work directly in GitHub on control-relevant engineering practices.
  • Investigate control failures and monitoring alerts directly to understand root cause in cloud infrastructure.
  • Own security questionnaire responses for customer and partner due diligence.
  • Perform regulatory horizon scanning and translate changes into control and policy updates.
  • Report risk posture, audit status, and control health to the CISO and the board.
  • Use tooling to automate control mapping, draft policy updates, and summarize vendor risk documentation.

Requirements

  • 4+ years in GRC, information security, or compliance, with at least one year hands-on in a security engineering or IT operations role.
  • Direct experience running SOC 2 and/or ISO 27001 audits from the compliance side, including evidence collection and auditor management.
  • Working technical literacy: comfortable reading IAM policies, understanding a SIEM alert, following a CI/CD pipeline, and assessing technical explanations.
  • Hands-on experience with Vanta or an equivalent GRC automation platform (Drata, Secureframe).
  • Comfortable working daily in Jira and Confluence.
  • Understanding of payments-specific risk, including PCI DSS scoping, third-party processor risk, and financial services regulatory expectations.
  • Strong written communication skills for policies, board summaries, and customer-facing security answers.

Skills

  • GRC
  • Information Security
  • Compliance
  • Security Engineering
  • IT Operations
  • SOC 2
  • ISO 27001
  • PCI DSS
  • GDPR
  • DORA
  • FCA/PRA operational resilience
  • MAS TRM
  • CBUAE
  • VARA
  • DFSA
  • Vanta
  • Drata
  • Secureframe
  • Jira
  • Confluence
  • GitHub
  • AWS
  • GCP
  • Azure
  • IAM policies
  • SIEM alerts
  • CI/CD pipelines
  • Payments risk
  • Third-party risk assessment
  • Vendor risk management
  • Audit management
  • Risk register management
  • Policy and procedure development
  • Regulatory horizon scanning
  • Reporting
  • Scripting (Python or similar) - Nice to have
  • Fintech
  • Payments

Location

  • EMEA
  • APAC
  • North America

Work Type

  • Agile
  • Flexible working culture

Experience Level

  • 4+ years in GRC, information security, or compliance
  • At least one year hands-on in a security engineering or IT operations role

Education Level

  • CISA certification - Nice to have
  • CISSP certification - Nice to have
  • ISO 27001 Lead Auditor/Implementer certification - Nice to have

About the Company

  • Sokin is a next-generation B2B financial services provider enabling businesses to make and receive global payments with greater speed, lower cost, and total transparency.
  • Our mission is to simplify global business so businesses thrive wherever they choose to grow.
  • We deliver services across global payments and receivables, Foreign Exchange (FX), treasury management, and finance reconciliations.
  • We are rapidly expanding with a presence in EMEA, APAC, and North America, backed by a strong global infrastructure and industry-leading partners.
  • We are redefining how businesses move money worldwide.
  • Our clients span industries from sports and entertainment to logistics and travel.
  • We are building a team of exceptional people who share our ambition to transform the future of global payments.

Equal Opportunity

  • Sokin is an equal opportunities employer and committed to maintaining an inclusive work environment.
  • Please reach out to discuss any accommodations you may require during the recruitment process.