3 дня назад
Governance, Risk and Compliance Manager (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Governance, Risk and Compliance Manager (AI): Building and running governance, risk, compliance, and security assurance practices for specialty insurance technology with an accent on risk registers, certifications, vendor risk, and client assurance. Focus on preparing for SOC 2 and ISO 27001, coordinating audits, managing AI governance and privacy risks, and translating security issues into clear leadership decisions.
Location: Hybrid role based in the UK, with London office facilities.
Company
develops technology that helps specialty insurance brokers and carriers operate more efficiently through automation and structured digital workflows.
What you will do
- Own the day-to-day risk register, including risk appetite, exceptions, prioritisation, monitoring, and leadership reporting.
- Build and maintain registers of compliance obligations for clients, regulators, and contracts.
- Lead certification and assurance programmes, define scope and targets, and coordinate internal and external audits.
- Manage client security questionnaires and develop a reusable assurance pack.
- Run third-party and vendor risk management, including supplier tiering and due diligence.
- Support data protection, privacy, responsible AI use, security awareness, and company-wide training.
Requirements
- Experience running governance, risk, and compliance programmes in a technology or regulated business.
- Practical knowledge of risk registers, risk appetite, exceptions, and control monitoring.
- Familiarity with assurance frameworks such as SOC 2 and ISO standards.
- Experience with third-party risk, vendor assessments, and client security questionnaires.
- Clear, organised communication skills and the ability to explain risk in plain language.
- Curiosity about AI tools and the ability to support their safe adoption.
Nice to have
- Experience in financial services, InsurTech, or another regulated industry.
- Experience taking a company through SOC 2 or ISO 27001 certification.
- Knowledge of GDPR, data protection, and privacy obligations.
- Interest in AI governance and experience building a GRC function in a scale-up.
Culture & Benefits
- Private medical, income protection, and life insurance.
- 28 days of holiday plus national holidays, enhanced parental pay, and life-events leave.
- Hybrid work support with home-office and equipment allowance, company MacBook, and London office gym facilities.
- Pension and nursery-fee salary exchange, financial wellbeing support, and company stock options.
- Learning allowance and paid leave for conferences or exams.
- Team events, employee assistance resources, and ecological initiatives including tree planting.
Hiring process
- Background checks may include criminal record, credit history, previous employment, and academic qualification verification.
- Accessibility adjustments are available throughout the hiring process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →