Overview
As Birdie’s Risk & Compliance Manager, you will define and embed the company’s compliance programs across data protection, information security, and health-system governance. You’ll own NHS DSPT/DSCR compliance and ensure NHS data integrations (GP Connect, PDS) meet standards. You’ll collaborate with engineering, product, legal, and operations, supported by the GC and external DPO, to maintain a proactive risk posture. This role combines legal/regulatory translation with practical guidance for tech teams, driving trust and resilience in a fast-moving SaaS environment. You’ll contribute to a mission-driven scale-up that improves care for older adults and shapes how technology enables safer, D
Pay / Benefits
- Competitive base salary
- Generous stock options
- Learning & growth budget
- Hybrid working (London HQ)
- Private health insurance
- Employer pension contribution (UK)
Responsibilities
- Own data protection compliance across product and operations, coordinating with external DPO on DPIAs, RoPA, and information rights processes
- Lead the annual NHS DSPT submission and maintain DSCR and clinical risk alignment
- Assure NHS interoperability connections (GP Connect, PDS) meet compliance and data flow standards
- Maintain risk register and control frameworks, conduct third-party risk assessments and internal audits
- Lead incident response for data protection and compliance breaches, from root cause to remediation
- Develop KRIs/KPIs for leadership and promote a risk-aware culture across tech, product and GTM teams
Key requirements
- Familiarity with NHS DSPT, DSCR, and NHS API assurance frameworks (GP Connect, PDS)
- Strong knowledge of UK GDPR and Data Protection Act 2018; able to apply practically in a SaaS context
- Experience leading risk assessments, control design, and managing a risk register (preferably with external DPO or legal counsel)
- Ability to translate complex legal/health-system regulations into actionable engineering/product requirements
- Clear written and verbal communication; ability to train and report to executives
- Relevant certification (CIPP/E, CIPM, CISM, CISA) or familiarity with ISO 27001/Cyber Essentials/SOC 2 is a plus
- Clear written and spoken communication
- Judgment and diplomacy to challenge while maintaining relationships
- Ability to translate regulation into practical requirements for engineers
- NHS DSPT and DSCR familiarity
- GP Connect and PDS interoperability knowledge
- UK GDPR and Data Protection Act 2018 application in SaaS
…
