Risk & Compliance Lead responsible for designing and implementing risk compliance frameworks for a SaaS company. Collaborating with cross-functional teams to mitigate operational and regulatory risks.
Responsibilities
Own Elliptic’s Risk and Compliance strategy, frameworks, and annual plan
Maintain risk taxonomy, registers, and assessment cadence across business, product, data, third‑party, and operational risks
Facilitate risk identification with domain owners, evaluate inherent/residual risk, and drive treatment plans
Identify applicable obligations and industry standards for a SaaS provider and maintain a single control framework mapped to them
Plan and run a risk‑based assurance programme to test control design and effectiveness
Partner with Platform, SRE, and Security to validate backup, recovery, continuity, and disaster recovery capabilities
Set methodology and thresholds for vendor and product risk, partnering with Procurement, Legal, and Product to embed controls in lifecycle workflows
Coordinate external audits and certifications as needed; ensure our evidence strategy is efficient and reusable
Enable teams through guidance, training, and practical tooling; make compliance easy and transparent
Requirements
Proven ownership of an ERMF or equivalent risk programme in a SaaS or technology business
Designing and operating a unified control framework mapped to multiple obligations or standards
Knowledge of data protection and data governance practices relevant to SaaS
Planning and executing risk‑based assurance and control testing, and managing CAPA to closure
Partnering with engineering and product teams to embed quality and compliance controls into their operations
Clear, concise written communication and executive risk reporting
Strong stakeholder management across technical and non‑technical teams
Nice to have
Experience with ISO 27001, SOC 2, or similar certifications, and familiarity with ISO 9001/22301/14001 as contributing inputs
Exposure to model risk governance or validation practices
Experience with evidence automation or compliance tooling
Benefits
Hybrid working and the option to work from almost anywhere for up to 90 days per year
£500 Remote working budget to set up your home office space
$1,000 Learning & Development budget to use on anything (agreed with your manager) that contributes to your growth and development
Holidays: 25 days of annual leave + bank holidays
An extra day for your birthday
Enhanced parental leave: we provide eligible employees, regardless of gender or whether they become a parent by birth or adoption, 16 weeks fully-paid leave
Telco Regulatory Compliance Assistant supporting global regulatory team at Five9. Managing documentation, reporting, and compliance across various markets in the telecommunications sector.
Data Analyst in the compliance team at Sicredi, gathering and analyzing business data. Responsibilities include monitoring trends and enhancing data processes.
Regulatory Affairs Specialist implementing strategies for pharmaceutical compliance and ensuring adherence to global regulations. Collaborating with cross - functional teams to support product development and licensing.
Director of Governance, Risk & Compliance overseeing technology and AI compliance at MTM Health. Leading regulatory alignment and governance for cloud and software development in a healthcare context.
Spécialiste principal en stratégie réglementaire assurant la conformité réglementaire des produits pharmaceutiques. Collaborant avec des équipes interfonctionnelles pour soutenir le développement de produits.
Senior EHS Manager responsible for compliance audits and initiatives in Watts Industries' manufacturing locations. Monitoring regulatory changes and collaborating with teams to maintain EHS standards.
Director of Compliance and Risk at Voyager Asset responsible for managing risk and compliance policies. Ensuring investment integrity and adherence to regulations in a fast - paced environment.
Compliance Readiness Manager providing expert compliance support and ensuring adherence to regulations in Group Payments. Overseeing compliance readiness and driving initiatives for continuous improvement.
GRC Engineer at security team to strengthen governance, risk, and compliance programs. Collaborating with technical security engineers to protect customer data.
Vice President leading PCI governance, risk, and compliance for Synchrony. Collaborating cross - functionally to ensure PCI compliance and mitigate risks within the organization.