About the Role
Support the business in achieving launch readiness by assessing, documenting, and implementing data governance, privacy, and information security controls for an FCA-regulated financial services platform. This role involves working across departments to ensure customer data is governed, protected, and processed in accordance with UK GDPR and FCA expectations, with a focus on identifying and resolving launch blockers.
Responsibilities
- Lead an end-to-end review of customer data, including collection, purpose, storage, access, movement, and external processors.
- Deliverables include: data inventory, data classification framework, Information Asset Register, and data flow diagrams.
- Review compliance with UK GDPR and Data Protection Act requirements, covering lawful basis, consent, retention, deletion, subject access requests, and international transfers.
- Deliverables include: gap assessment, risk register, and required remediation plan.
- Assess current controls for RBAC, MFA, encryption, secrets management, audit logging, backup strategy, disaster recovery, and production access.
- Identify launch-critical risks.
- Review the use of AI/LLM tools (e.g., Claude, Snowflake) and internal reporting tools, defining acceptable use, access models, PII handling, prompt handling, data retention, and user permissions.
- Produce governance recommendations for AI and data usage.
- Review all vendors processing customer data, including cloud, AI, communications, and payment providers, ensuring appropriate processor agreements, data residency, contractual protections, and security posture.
- Produce or review Privacy Notice, Data Retention Policy, Information Security Policy, Data Classification Policy, Access Control Policy, Incident Response Plan, and Data Governance Policy.
- Produce a quick-turnaround executive report identifying launch readiness (Red/Amber/Green) with prioritized, actionable tasks.
Requirements
- Demonstrable experience leading data governance and privacy programs for FCA-regulated or financial services businesses.
- Prior experience supporting an FCA authorisation process or a regulated product launch, ideally in fintech or payments.
- Strong working knowledge of UK GDPR and the Data Protection Act 2018, including lawful basis, consent, retention, deletion, subject access requests, and international transfers.
- Practical understanding of FCA expectations around data handling and customer outcomes.
- Experience producing gap assessments, risk registers, and remediation plans that withstand regulatory scrutiny.
- Hands-on experience running end-to-end data discovery and mapping exercises across an organisation.
- Track record of producing data inventories and data classification frameworks from scratch.
- Experience building Information Asset Registers and data flow diagrams.
- Ability to identify data processors and third parties handling customer data during discovery.
- Ability to assess technical security controls directly with engineering teams.
- Working knowledge of RBAC and MFA implementation.
- Familiarity with encryption standards and secrets management practices.
- Experience reviewing audit logging, backup strategy, disaster recovery, and production access controls.
- Ability to translate technical findings into launch-critical risk ratings for non-technical stakeholders.
- Practical experience governing the use of AI/LLM tools in a regulated environment, including acceptable use and access models.
- Understanding of PII handling and prompt-handling risk in AI-assisted workflows.
- Experience with data platform governance (e.g., Snowflake) including data retention and user permissions.
- Experience conducting third-party and vendor risk assessments.
- Working knowledge of data residency requirements and contractual/processor agreement protections.
- Track record of producing clear, regulator-ready policy documentation at speed.
- Comfortable operating as an autonomous, hands-on contractor in a lean startup environment.
- Ability to prioritize launch-critical risk over process and make pragmatic calls.
- Strong stakeholder management skills across Product, Technology, Operations, Risk, and Compliance.
- Ability to translate technical and regulatory detail into a clear, executive-level Red/Amber/Green narrative.
- Proven ability to deliver a full assessment and documentation set against a tight, fixed deadline ahead of a live launch date.
Skills
- Data Governance
- Data Privacy
- Information Security
- UK GDPR
- Data Protection Act 2018
- FCA Regulations
- Financial Services
- Fintech
- RBAC
- MFA
- Encryption
- Secrets Management
- Audit Logging
- Backup Strategy
- Disaster Recovery
- AI Governance
- LLM Governance
- Vendor Risk Assessment
- Data Discovery
- Data Mapping
- Data Classification
- Information Asset Register
- Data Flow Diagrams
- Gap Assessment
- Risk Register
- Remediation Planning
- Stakeholder Management
- Policy Development
- Incident Response Planning
Location
- 30 City Road, London
Work Type
- Contract
Experience Level
- Senior
- Consultant
About the Company
- EC Markets is a globally recognised financial brokerage, providing advanced FX and CFD trading services.
- EC Markets is seeking an Accounts Assistant to support daily financial operations and reporting, ensuring compliance, accuracy, and efficiency across the department.
