Overview
As Global Risk & Compliance Manager, you will architect and scale the Group’s risk and compliance framework across jurisdictions and acquisitions. You’ll partner with Legal, IT, Operations and senior leaders to ensure governance is robust, audit-ready and scalable. You’ll drive cybersecurity governance, policy lifecycle, vendor oversight and data protection programs in a fast-growth, listed environment. This is a chance to build a global function that supports entrepreneurial growth while maintaining regulatory obligation and transparency.
Responsibilities
- Manage and enhance the enterprise risk framework, risk register and full lifecycle (identify, mitigate, test, remediate, report)
- Maintain a consolidated view of strategic, operational, financial, regulatory and cyber risks across the group
- Strengthen cybersecurity governance with the CISO, aligning to ISO 27001 and SOC 2
- Lead the risk and compliance programme ensuring controls are well-designed, operational and scalable (SOC 2 Type 2, ISO 27001)
- Maintain a centralised, audit-ready evidence repository and coordinate internal/external audits and due diligence
- Develop playbooks for vendor intake, audit readiness and control testing across operating companies
- Oversee global policy lifecycle and regulatory alignment, including data protection compliance (GDPR, CCPA) as a data processor
- Own vendor and third-party risk management with proportionate due diligence
- Deliver executive risk reporting and act as bridge between IT/Security, Legal, HR, Finance, M&A and Operations leadership
Key requirements
- 5+ years’ experience in risk, compliance, audit or governance within professional services, technology or listed environments
- Strong experience managing risk registers, control frameworks, remediation plans and executive reporting
- Experience with SOC 2, ISO 27001/27002, NIST CSF or similar certifications
- Understanding of global data protection and supplier risk requirements
- Ability to translate technical controls and regulatory requirements into operational practice with technical teams
- Intellectually curious
- Strategically minded
- Commercially pragmatic
- SOC 2
- ISO 27001/27002
- NIST CSF
…
