Security GRC Lead Sokin is scaling its security function, and as such this is a hands-on delivery role, not a policy-writing or oversight seat. You'll own governance, risk, and compliance end to end, from framework and p…
Skills: Governance, Risk Management, Compliance, SOC 2, ISO 27001
Marketing Automation Officer Application Deadline: 16 August 2026 Department: Digital Employment Type: Permanent - Full Time Location: London Compensation: £35,721 per year + benefits Description Are you a marketing prof…
We are seeking a Data Engineer to work within our growing Data team to help shape and enhance our data capabilities. The role is to provide data engineering expertise to support delivery of our programme of work. This wi…
Skills: Azure Data Factory, Databricks, T-SQL, Python, Data warehousing
Hi 👋 We’re Legl. Legl is building the operating system for modern legal services. We help law firms and regulated businesses replace manual, fragmented workflows with intelligent software from client onboarding and comp…
Skills: Data strategy, Data roadmap, Snowflake, Dbt, Fivetran
About Us : Our client is an established technology firm delivering high-performance B2B and B2C solutions. Their platform is a sophisticated ecosystem involving complex integrations with KYC/KYB providers, credit scoring…
Principal Product Manager - iGaming & Gambling Ecosystem
City of London, England, United Kingdom · Hybrid
Senior+$2.0B raised
Principal Product Manager - iGaming & Gambling Ecosystem Paysafe is a global payments platform powering the experience economy, with a strong focus on the iGaming, video gaming, e-commerce, online trading, retail, travel…
Paysafe is a global payments platform powering the experience economy, with a strong focus on the iGaming, video gaming, e-commerce, online trading, retail, travel and hospitality sectors. With 30 years of expertise in p…
Skills: Product Strategy, Payment Systems, Video Gaming Ecosystems, Fintech, API Strategy
Software Engineer Webex Real-time Media Engineering Group Meet the Team Cisco's Webex Real-time Media Engineering Group is redefining the future of collaboration. We're building a world where people connect effortlessly …
Ready for a challenge? Then Just Eat Takeaway.com might be the place for you. We’re a leading global online delivery platform, and our vision is to empower everyday convenience. Whether it’s a Friday-night feast, a post-…
Skills: Data Engineering, Python, SQL, BigQuery, dbt Core
Senior Software Engineer Webex Real-time Media Engineering Group Meet the Team Cisco's Webex Real-time Media Engineering Group is redefining the future of collaboration. We're building a world where people connect effort…
Job Description What is the opportunity? We are looking for a Senior Murex Business Analyst to join our team in London, where you'll play a pivotal role in optimizing our Murex platforms. You will be part of a distribute…
Skills: Murex, Business Analysis, FX Derivatives, Interest Rate Derivatives, SQL
CIO CCO Frameworks - Lead Risk and Control Self Assessment Specialist (6-month contract)
City of London, England, United Kingdom · Hybrid
Senior
Job title: CIO CCO Frameworks – Lead Risk and Control Self Assessment Specialist Role type: Contractor (6 months) Corporate level: Associate equivalent Division: Chief Control Office Department: Risk and Control Manageme…
Skills: Risk and Control Self Assessment (RCSA), Risk Management, Stakeholder Management, Operational Risk Management, Governance Reporting
Job title: CIO CCO Frameworks – Senior Principal Risk Management Specialist Role type: Contractor (6 months) Corporate level: Vice President equivalent Division: Chief Control Office Department: Risk and Control Manageme…
Meet the Team Cisco ThousandEyes is a Digital Experience Assurance platform that empowers organizations to deliver flawless digital experiences across every network - even the ones they don’t own. Powered by AI and an un…
The Role We are seeking a capable Consulting Data Architect to join our Insurance Technology Consulting practice and play a pivotal role in shaping, selling, and delivering data-led consulting engagements for insurance c…
Skills: Data Architecture, Insurance Domain Knowledge, Cloud-native Data Platforms, Data Governance, Enterprise Data Modelling
City of London, England, United Kingdom · Remote Solely
Senior
Main responsibilities Design, build, and support corporate networks, servers, storage, telephony, and systemsImplement secure, fault-tolerant infrastructure solutionsProvide technical leadership and architectural directi…
Skills: Network engineering, Systems engineering, VMware, AWS, Azure
The Head of Security Architecture with deep expertise in AI systems to design, implement, and maintain secure architectures for enterprise security, artificial intelligence and machine learning initiatives across the org…
This role will directly support the Global Information and Cyber Security (ICS) Group within WTW. You will use your skills and experience to support ICS team, delivering technology and cyber regulatory engagements. Worki…
Skills: Information security, Cybersecurity, Regulatory compliance, Risk management, Project management
Own the messages that turn a curious enterprise buyer into a conversation, and a new customer into a lasting one. The Ardoq story Ardoq is one of Norway's most exciting scale-ups, a truly global company built out of Oslo…
City of London, England, United Kingdom · Remote Solely
Senior
Job Title: REVIT/CAD/BIM Engineer Location: London Contract type: Contract Working pattern: Remote Company Our client is an industry leading technology solutions provider delivering innovative workplace experience, immer…
Skills: Revit, AutoCAD, BIM, AV Infrastructure, System Design
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Full-time
professional certificate
Posted 9d ago
~40 hrs/week
Responsibilities
You will own the end-to-end governance, risk, and compliance program, including framework implementation, audit delivery, and automated evidence collection. The role requires hands-on technical engagement with cloud infrastructure, engineering practices, and vendor risk assessments.
Requirements
Candidates must have at least 4 years of experience in GRC or information security with direct experience managing SOC 2 or ISO 27001 audits. Strong technical literacy in cloud environments, CI/CD pipelines, and GRC automation tools like Vanta is essential.
Full job description
Security GRC Lead
Sokin is scaling its security function, and as such this is a hands-on delivery role, not a policy-writing or oversight seat. You'll own governance, risk, and compliance end to end, from framework and policy work through to control implementation, evidence automation, and audit delivery with a small team of SMEs.
This isn't a role where you write documentation and hand off the real work. You'll be in Vanta, in the AWS/GCP/Azure consoles, in Jira and GitHub, and in engineering conversations regularly enough to know whether a control is actually true, not just documented.
About Us Sokin is a next-generation B2B financial services provider, enabling businesses to make and receive global payments with greater speed, lower cost, and total transparency. Our mission is simple: we’re simplifying global business - so businesses thrive wherever they choose to grow. We deliver services across:
Global payments and receivables
Foreign Exchange (FX)
Treasury management
Finance reconciliations
We are rapidly expanding, with established presence in EMEA, APAC, and North America, backed by a strong global infrastructure and industry-leading partners, we are redefining how businesses move money worldwide.
Our clients span industries from sports and entertainment to logistics and travel, and our community is growing rapidly. As we continue to expand, we’re building a team of exceptional people who share our ambition to transform the future of global payments.
What you'll do
Own and mature our compliance program across SOC 2, ISO 27001, PCIDSS, and GDPR, with active awareness of DORA (ICT risk management, third-party ICT oversight, incident classification) and FCA/PRA operational resilience (SYSC 8, SYSC 13) given our regulatory footprint, plus MAS TRM and UAE regulatory (CBUAE, VARA, DFSA) obligations where applicable
Run Vanta day to day: control mapping, automated evidence review, remediation tracking, integration health, and building custom automations/API connections where native integrations don't cover a control
Build and maintain the risk register as a living system, own the scoring methodology, and drive remediation with named owners and deadlines tracked in Jira
Maintain the policy and procedure library in Confluence as structured, version-controlled documentation that reflects actual technical implementation, not templated language pulled from a framework doc
Design and run vendor/third-party risk assessments, with risk tiering appropriate to a payments business (processors, banking partners, cloud providers, sub-processors)
Lead external audits and pen test coordination end to end: scoping, evidence, auditor liaison, QSA engagement (PCIDSS), and findings remediation
Work directly in GitHub on control-relevant engineering practices (branch protection, CI/CD evidence, code review requirements) rather than requesting screenshots secondhand
Investigate control failures and monitoring alerts directly, enough to understand root cause in cloud infrastructure (AWS/GCP/Azure), IAM, CI/CD, and logging before looping in engineering
Own security questionnaire responses for customer and partner due diligence, using an answer-library approach (Vanta's answer library) rather than starting from scratch each time
Perform regulatory horizon scanning across our active jurisdictions and translate changes directly into control and policy updates you implement
Report risk posture, audit status, and control health to the CISO and, periodically, the board
Use tooling to automate control mapping across overlapping frameworks, draft policy updates, and summarize vendor risk documentation, freeing time for judgment calls over paperwork
What We're Looking for:
Essential:
4+ years in GRC, information security, or compliance, ideally with at least one year hands-on in a security engineering or IT operations role
Direct experience running SOC 2 and/or ISO 27001 audits from the compliance side, including evidence collection and auditor management
Working technical literacy: comfortable reading IAM policies, understanding a SIEM alert, following a CI/CD pipeline in GitHub, and telling when an engineer's explanation of a control doesn't hold up
Hands-on experience with Vanta or an equivalent GRC automation platform (Drata, Secureframe) - beyond just uploading evidence
Comfortable working daily in Jira and Confluence as the system of record, not via a delegate
Strong written communication - policies, board summaries, and customer-facing security answers in the same week
Nice to have:
CISA, CISSP, or ISO 27001 Lead Auditor/Implementer certification
Experience in a regulated fintech or payments environment specifically
DORA, MAS TRM, or UAE (CBUAE/VARA/DFSA) regulatory experience specifically
Scripting ability (Python or similar) for control automation or evidence pipeline work
Prior experience building or significantly maturing a GRC function
Why this role
Real scope to run the function the right way, with direct CISO access, modern tooling already in place, and a stack spanning AWS, GCP, and Azure, without legacy process debt to unwind.
Please note, candidates will need to have the right to work in the jurisdiction that they are looking to work in.
Sokin is an equal opportunities employer and committed to maintaining an inclusive work environment. As a growing global startup with bases across multiple countries, we were established on and continue to promote an agile, flexible working culture. Please reach out to discuss any accommodations you may require during the recruitment process.
We remove the borders, barriers and burdens of international payments.
We exist to support businesses succeed on the global stage, by removing friction to international trade. We’ve brought exciting financial and technical talent from across the globe together to produce products that empower our clients at home and abroad. We strive to build what’s next in global payments and banking.
Offices: London, England WC1R 4BZ, GB
Global Money TransfersFXFintechand PaymentsFinancePaymentsFinTechFinancial Services
How many Technology jobs are open in City of London, United Kingdom right now?
There are currently 698 open technology positions in City of London, United Kingdom listed on Clera. New openings are added daily as companies post roles.
Which companies are hiring for Technology roles in City of London, United Kingdom?
Companies currently hiring include JPMorganChase, Deloitte, Sainsbury's, Legal & General, Just Eat Takeaway.com, among others. Browse the listings above to see every active employer.
Are there remote or hybrid Technology jobs in City of London, United Kingdom?
Yes — 472 of the 698 open technology positions offer remote or hybrid work (43 remote, 429 hybrid).
How do I apply for Technology jobs in City of London, United Kingdom?
Each listing links directly to the employer's application page. Apply early — fresh listings get the most recruiter attention in the first two weeks.