Amoria Group Logo

Amoria Group

Governance Risk and Compliance Manager

Posted 13 Days Ago
Be an Early Applicant
In-Office
Manchester, Greater Manchester, England
Senior level
In-Office
Manchester, Greater Manchester, England
Senior level
Lead and develop the Group Governance, Risk & Compliance framework. Manage the risk register, run assurance and control testing, own operational data protection and data governance, coordinate regulatory horizon scanning, oversee information security governance, deliver training, lead GRC projects and produce risk and compliance reporting for Executive Leadership and the Board.
The summary above was generated by AI

Governance, Risk & Compliance Manager 

Manchester | Hybrid – 3 days per week in the office 
£60,000–£70,000  

We’re looking for a Governance, Risk & Compliance Manager to take ownership of our Group governance, risk and compliance framework and help us continue to strengthen how we manage risk as the business evolves. 

This is a broad role with the opportunity to shape how governance operates across the organisation. You’ll work across operational and commercial risk, compliance, data protection, data governance, regulatory change and assurance, partnering with senior leaders and teams across the Group. 

It’s not a traditional Legal or Cyber GRC role; we’re looking for someone who can take regulatory and governance requirements and turn them into practical frameworks, controls and ways of working that protect the business without creating unnecessary complexity. 

 

What you’ll be doing 

You’ll be responsible for the Group’s Governance, Risk & Compliance framework, with a varied remit including: 

  • Owning and continually developing our Group Governance and Risk Management frameworks.  
  • Managing the Group risk register, working with business leaders to identify, assess and mitigate operational, commercial, regulatory, technology and data risks.  
  • Developing a risk-based assurance programme and carrying out control testing to make sure key controls are working effectively in practice.  
  • Acting as the Group Data Protection and Data Governance Lead, owning the operational privacy framework and working closely with our DPO.  
  • Owning our Data Governance Framework, including master data governance, data ownership, data quality standards and controls.  
  • Coordinating regulatory horizon scanning and producing quarterly impact assessments so upcoming regulatory changes are understood and acted on.  
  • Working with our Security function to provide governance and oversight of information security risk, policies and controls.  
  • Owning the Group governance calendar, ensuring audits, policy reviews, risk reviews, mandatory training and other key governance activities happen when they should.  
  • Working with Business Transformation and L&D to develop annual training across areas such as Data Protection, Information Security, Governance and Risk Management.  
  • Leading governance and compliance projects, including regulatory change, due diligence and implementation of new governance technology.  
  • Leading our Governance & Compliance function and continuing to improve our approach to placement compliance and operational controls.  
  • Developing meaningful risk and compliance dashboards and providing regular reporting and insight to Executive Leadership and the Board.  

The role builds on the assurance, regulatory change, reporting and compliance responsibilities already established within the function.  

 

What we’re looking for 

We’re looking for someone with a strong governance, risk or compliance background who is comfortable working across a broad remit and can apply good governance in a practical commercial environment. 

You’ll ideally bring: 

  • Strong experience within governance, risk, compliance, operational risk or a related discipline.  
  • Experience developing and embedding governance, risk or compliance frameworks.  
  • Good understanding of UK GDPR, data protection and privacy governance.  
  • Experience of assurance, auditing or control testing.  
  • Strong understanding of operational and commercial risk management.  
  • Experience managing risk registers, remediation actions and compliance reporting.  
  • Good understanding of information security governance.  
  • Confidence working with senior stakeholders and providing constructive challenge.  
  • Strong analytical skills and the ability to turn complex requirements into practical business processes and controls.  
  • Experience producing risk and compliance reporting.  
  • Strong communication and stakeholder management skills.  

Experience within recruitment, staffing or professional services would be particularly useful, especially an understanding of the operational, contractual and compliance risks associated with recruitment businesses. 

Experience of data governance, master data management, ISO 27001/ISMS, Cyber Essentials or regulatory change would also be advantageous, but we wouldn’t expect someone to already be an expert across every part of the remit. 

 

Why this role? 

This is an opportunity to take ownership of a developing GRC function rather than inherit a narrow compliance role. 

You’ll have the scope to shape our governance and risk frameworks, develop our approach to assurance and control testing, strengthen data and privacy governance and influence how risk is managed across the Group. 

You’ll work closely with Legal, Technology, Security, Data, Finance and operational teams, with regular exposure to senior leadership and the opportunity to lead cross-functional projects that have a genuine impact on how the business operates. 

Amoria Group is an equal opportunities employer. We celebrate diversity and are committed to creating an inclusive environment for all employees and applicants, regardless of background or protected characteristics.


INDAB

Similar Jobs

Yesterday
Remote or Hybrid
United Kingdom
Senior level
Senior level
Utilities
Leads governance, enterprise risk, compliance, audit, and assurance activities for a growing B2B SaaS business. Maintains scalable GRC frameworks, risk registers, policies, controls, certifications, and digital GRC platforms. Coordinates audits, remediation, regulatory readiness, management reporting, client assurance, and international compliance expansion across the US, APAC, and Europe. The role also delivers training, influences senior stakeholders, and drives continuous improvement.
Top Skills: Cloud-Native ArchitectureGdprGrc Management SystemsIsoSaaSSoc
Senior level
Transportation
Lead development and execution of enterprise GRC frameworks, identify and mitigate cyber and operational risks, manage audits and certifications (ISO27001, PCI DSS, Cyber Essentials), run third-party risk assessments, produce risk/compliance reporting, and advise on security for business and technology change.
Top Skills: Cyber Essentials PlusGdprIso 27001NistPci DssVulnerability Management
An Hour Ago
Remote or Hybrid
United Kingdom
Senior level
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead strategic identity security engagements across EMEA, advising executive stakeholders on risk, regulation, governance, access controls, and operational priorities. Shape complex sales opportunities, define identity roadmaps, facilitate executive workshops, align business and technical teams, and translate identity programs into measurable outcomes. The role requires influencing C-level decisions, working through ambiguity, partnering with sales and delivery teams, and representing SailPoint at industry events.
Top Skills: Cloud SecurityIdentity And Access Management (Iam)Identity Security

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account