This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are seeking an experienced Chief Information Security Officer to lead our information security programme. Reporting directly to the CTO, you will be accountable for protecting Sokin's systems, data, and reputation across our global operations. This is a hands-on leadership role requiring someone who can operate strategically whilst remaining technically engaged. You will build and lead the security function, establish security governance, and ensure compliance with regulatory requirements across FCA, PCI-DSS, and international data protection frameworks.
Job Responsibility:
Define and execute the enterprise information security strategy aligned with business objectives
Establish and maintain the Information Security Management System (ISMS) to support constant certification readiness with PCI DSS, ISO 27001 and SOC2
Own security policies, standards, and procedures across the organisation
Report to the Board and senior leadership on security posture, risk exposure and programme maturity
Manage security budget and resource allocation
Lead enterprise security risk assessments and maintain the infosec item on the risk register
Ensure compliance with FCA operational resilience requirements and SYSC guidelines
Maintain PCI-DSS Level 1 compliance across payment processing infrastructure
Oversee GDPR, UK Data Protection Act, and international privacy compliance
Manage relationships with external auditors, penetration testers, and regulatory bodies
Lead third-party vendor security assessments and due diligence
Build and lead the Security Operations Centre (SOC) function
Establish incident response capabilities and lead major security incident management
Implement and manage SIEM, EDR, vulnerability management, and threat intelligence platforms
Oversee identity and access management (IAM) strategy and privileged access management (PAM)
Drive security monitoring and alerting across cloud and on-premise infrastructure
Embed security into the SDLC through secure development practices and DevSecOps
Lead application security programme including SAST, DAST, SCA, and code review processes
Secure AWS cloud infrastructure using native and third-party security tooling
Ensure secure API design and implementation for payment integrations
Manage secrets management, encryption standards, and key management practices
Own business continuity and disaster recovery planning from a security perspective
Lead security aspects of operational resilience testing and scenario planning
Ensure adequate backup, recovery, and failover capabilities for critical systems
Build security awareness programme including phishing simulations and training
Foster a security-conscious culture across engineering, product, and business teams
Recruit, develop, and retain security talent
Requirements:
10+ years in information security with 5+ years in senior security leadership roles
Experience in regulated financial services (payments, banking, or fintech)
Track record of building and leading security teams in scale-up environments
Experience with FCA regulation, PCI-DSS compliance, and financial services audits
Hands-on experience with security incident response and crisis management
Deep knowledge of AWS security services (GuardDuty, Security Hub, WAF, KMS, CloudTrail, Config)
Experience with containerised environments (EKS/Kubernetes) and serverless security
Strong understanding of network security, zero trust architecture, and micro-segmentation
Proficiency with SIEM platforms (Splunk, Datadog Security, or equivalent)