Sokin on cord

Sokin

Head of Security Operations

External position
London, UK
Hiring internally for Sokin?
FinTech · Payments
The multi-currency platform that supercharges your business payments.
Posted
a month ago
Checked
cord regularly checks that external positions are still open
2 days ago

Skills & Experience

Job roles: Security Engineer
Experience level: Lead, Leadership
Core skills considered: Cyber Security, Network Security
Other skills considered: Penetration Testing, Security Testing

Logistics

Base salary: Undisclosed
Some companies on cord are unable to disclose salaries publicly due to internal company policies. Message the company for salary information.
Employment type: Permanent
Remote working: Hybrid
Visa sponsorship: Not available

Job Description

You will own security operations at Sokin: build it, run it, and grow it. That covers detection strategy, incident response and management, vulnerability management, and identity governance, with day-to-day L1/L2 triage and a chunk of Sentinel content maintenance handled by an outsourced SOC/MSSP. The exact MSSP scope is still being finalized as part of a broader investment case, so you'll help shape the split between what the MSSP owns and what stays in-house as the function matures, rather than inheriting a fixed operating model.

This is not a queue-management role, and it's not a role where you sit above an MSSP and relay their output. You direct the detection strategy and hold the MSSP to a quality bar on the content they build and tune, you own L3 investigation and forensics, you run vulnerability management as a program rather than a scanner subscription, and you own identity governance and incident management end to end. Where the MSSP can't cover something - bespoke detections, payments/fraud-specific logic, judgment calls in an active incident - that's you.


What you'll do

Detection strategy & engineering

  • Define and maintain the detection strategy, mapped to MITRE ATT&CK and iterated against real incidents and threat intel, not left as a static framework exercise
  • Set the standards and review bar for Microsoft Sentinel content (detection rules, analytics, workbooks, Logic Apps playbooks) whether authored by the MSSP or in-house, and own detection-as-code practices - version control, peer review, testing - for that content
  • Own the detections the MSSP can't reasonably build: bespoke, payments/fraud-specific, or identity-driven logic
  • Onboard new log sources and systems into the detection pipeline as the platform evolves, and integrate Defender XDR, Wiz, Cloudflare, Zscaler, and other tooling as it's added, including email/data security telemetry (Defender for O365, DLP) once in scope
  • Consume threat intelligence (feeds, ISACs, sector-specific sources) and translate it into detection and hunting priorities rather than treating it as a subscription nobody reads
  • Build and maintain SOAR automation for alert enrichment, triage, and response actions, so the function scales with the estate rather than with headcount

MSSP & outsourced SOC

  • Own the MSSP/outsourced SOC relationship end to end: SLAs, triage quality, playbook tuning, and contract renewal or rescoping as the function's needs change
  • Actively shape the boundary between MSSP and in-house scope as the team and platform mature, rather than treating today's split as permanent

Incident response & management

  • Lead incident response: own L3 investigation and forensic analysis across cloud and endpoint, working from MSSP escalations and your own detections
  • Own incident management end to end alongside the CISO - major incident declaration, exec/board notification, and coordination with legal/comms on regulatory notification clocks (GDPR 72-hour, DORA incident classification and reporting) - not just the technical investigation
  • Develop and maintain incident response playbooks and runbooks, and test them regularly through tabletop exercises rather than leaving them filed and unverified
  • Drive post-incident reviews and RCAs, and feed lessons back into detection and playbook updates

Vulnerability management & identity governance

  • Own vulnerability management as a program: scanning coverage across cloud, endpoint, and applications, risk-based prioritization, remediation SLAs, and exception handling with named owners
  • Own identity governance within security operations: privileged access monitoring, access anomaly detection, joiner/mover/leaver assurance from a security lens, and identity-related detection coverage across Entra ID/Okta and cloud IAM

Metrics, team, and reporting

  • Own MTTD, MTTR, and other operational metrics: baseline them, track them, and drive them down
  • Manage the security operations team, including direct line management of the Security Analyst, and build the hiring/leveling plan as team and MSSP scope evolve
  • Manage SOC systems, tooling, and processes end to end, including budget and licensing conversations with the CISO
  • Support the CISO on incident communication, board/customer reporting, and post-incident reviews

What we're looking for

Essential:

  • Deep Microsoft Sentinel experience: KQL proficient, able to author and critically review detection rules, workbooks, and playbooks, even where day-to-day content maintenance sits with a third party
  • Experience onboarding new data sources into a SIEM and scaling detection coverage as an environment grows
  • Hands-on incident response and digital forensics experience across cloud and endpoint, including running an incident through containment, eradication, and RCA, not just triage
  • Experience sharing ownership of the incident management process: major incident declaration, exec communication, and regulatory notification timelines (GDPR, DORA, or equivalent), typically alongside a CISO or equivalent
  • Applied MITRE ATT&CK knowledge used in detection engineering, not just framework familiarity
  • Experience running or managing vulnerability management as a program: tooling, prioritization, remediation tracking, and reporting
  • Working knowledge of identity governance and access risk (privileged access, JML, IAM/entitlement review) as it applies to security operations
  • Experience managing an MSSP/outsourced SOC relationship, including SLAs, contract or scope negotiation, and holding a third party accountable for quality
  • Experience running tabletop exercises or equivalent IR plan testing
  • Cloud security telemetry: AWS CloudTrail, Azure Monitor, GCP audit logs
  • Strong written communication for incident reports and RCAs aimed at non-technical readers

Nice to have:

  • Prior people management or mentoring experience in a SOC or detection engineering team
  • Experience with Defender XDR (Defender for Endpoint, Identity, Cloud Apps)
  • Wiz or equivalent CSPM integration into detection pipelines
  • Fintech, payments, or regulated environment background
  • Formal threat intelligence platform experience (beyond consuming feeds)
  • Python or PowerShell for automation
  • Certifications (valued, not required): SC-200, AZ-500, GCIA, GCIH, GCFE, GCFA, or equivalent applied experience

Company Benefits

  • 28 days annual leave (not including public holidays)
  • Birthday Leave
  • Private Medical Insurance
  • Hybrid working
Head of Security Operations at Sokin
Position posted a month ago

Talk directly
to who's hiring

cord intros you to the companies worth joining, from seed to enterprise.

Everything you need to find work

Surface every relevant position, direct message the people hiring and manage all your applications in one place.

Get started

Every position in one place

We index the web for open positions that might be relevant to you and bring them all in one place.

Positions you might like split into tabs based on their type

Direct messaging

No more CV blackholes. Message people hiring directly and see their activity live on cord.

A sent message to a hiring manager
A board of positions in different stages

Application management

Manage all your applications and interviews in one place.

Advanced insights

Know your worth and see how you compare with other applicants.

Visualisation of a profile match score for a position and score comparison with other applicants

Direct.
Transparent.
Human.

On cord you can message people hiring directly, see when they were last active, how responsive they are and access transparent information that you wouldn't be able to find anywhere else.

Photos people at Starling BankPhotos people at Starling BankPhotos people at Starling BankPhotos people at Starling BankPhotos people at Starling Bank
Starling Bank on cord

Starling Bank

Full Stack Engineer (ML Ops)

London, UK
FinTech · Banking · Finance
A better bank for everyone
Active
over 6 months ago
Responds to
0% of requests
Responds in
1h 55m
Requests
7 pending

Skills & Experience

Job roles: Full Stack
Experience level: Mid, Senior
Core skills considered: Java, React, Redux, AWS, JavaScript

Logistics

Base salary: £70K - £110K
Employment type: Permanent
Remote working: Hybrid (up to 2 remote days p/w)
Visa sponsorship: Not available

Job Description

Starling is the UK’s first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values. All at the tap of a phone, all the time.

Starling is the UK’s first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way.

We’re a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We’re a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 3,000 people across our London, Southampton, Cardiff and Manchester offices.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. We don't like to mandate how much you visit the office and work from home, that's to be agreed upon between you and your manager.

Our Data Environment

Our Data teams are excited about the value of data within the business, powers our product decisions to improve things for our customers and enhance effective and agile decision making, regardless of what their primary tech stack may be. Hear from the team in our latest blogs or our case studies with Women in Tech.

We are looking for talented data professionals at all levels to join the team. We value people being engaged and caring about customers, caring about the code they write and the contribution they make to Starling. People with a broad ability to apply themselves to a multitude of problems and challenges, who can work across teams do great things here at Starling, to continue changing banking for good.

Requirements

We have built our entire banking platform in house and mostly in Java. We are looking for people who want to work on building the tooling that is used by our engineers on a daily basis.

We are looking for people who are truly full stack, and are as comfortable polishing their javascript front end as they are debugging the innards of their java applications database interactions, or standing up infrastructure with terraform. We are looking for people who can:

  • Design REST apis.
  • Code backend services, ideally using Java, or another other server side compiled language.
  • Develop modern front ends, ideally using React and Redux.
  • Get their code into the cloud and support it there, ideally on AWS.
  • Believe in clean coding, simple solutions, automated testing and continuous deployment.
  • Like to take ownership of a feature from the original idea through to live.
  • Think (like us) that a small number of empowered developers is the right way to deliver software.

Company Benefits

  • 33 days holiday (including flexible bank holidays)
  • An extra day’s holiday for your birthday
  • 16 hours paid volunteering time a year
  • Part-time and/or flexible hours available for most roles
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary
  • Hybrid/remote working
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Varied social groups set up and run by our employees
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

Full details are available on our careers site

Interview Process

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Stage 1 - 30 mins with one of the team
  • Stage 2 - Take home challenge
  • Stage 3 - 90 mins technical interview with two team members
  • Stage 3 - 45 min final with an executive and a member of the people team
Alex Yeates on cord
Message Alex Yeates at Starling Bank
Typically responds in an hour

What people are saying

2,000+

users joining every week

Oliver on cord

Oliver

Software Engineering Consultant
It's really easy to use, has a solid selection of jobs, and makes it helpful to direct message companies. The platform seems to offer a good range of opportunities while keeping the process simple and convenient.
November, 2025
David on cord

David

Lead Software Engineer
The platform allows you to create a professional CV, making the setup process simple and polished. The internal chat also provides an easy way to directly contact hiring companies, which makes communication much more efficient.
November, 2025
40,000+

open positions

Nicolae on cord

Nicolae

Senior Full Stack Developer
It is a great platform if you are looking for a job. It makes the search process straight forward and gives you access to solid opportunities.
November, 2025
3 million+

messages exchanged so far

Nicolae on cord

Nicolae

Senior Full Stack Developer
It is a great platform if you are looking for a job. It makes the search process straight forward and gives you access to solid opportunities.
November, 2025
78.43%

response rate from companies

Aarambha on cord

Aarambha

Associate Software Engineer
Absolutely amazing idea, the ability to see which recruiters are active makes finding opportunities very quick. There is a form of transparency built into the website that lacks in any other job searching platform.
August, 2025
Adam on cord

Adam

Senior Engineer
cord was great. Clean UI, easy to browse, and the data feature made it a breeze to quickly check whether my profile would match up well with a particular role. The messaging system made it easy to approach companies but also filter out unwanted requests.
August, 2025
4.6

score on Trustpilot

Talk directly to the people that matter

Join the hundred of thousands of people using cord to find work

Get started
 on cord
 on cord
 on cord
 on cord
 on cord
+414 joined last week
Moved to your Not right positions