- Company Name
- Allwyn UK
- Job Title
- Risk and Compliance Officer (12 Months FTC)
- Job Description
-
**Job Title**
Risk and Compliance Officer (12‑Month Fixed Term Contract)
**Role Summary**
Drive the risk management and compliance agenda for a large, multi‑national lottery operator, ensuring alignment with enterprise frameworks, regulatory standards, and internal policies. The role covers risk assessment, third‑party risk, identity and access management, audit facilitation, governance support, and security culture initiatives.
**Expectations**
- Deliver risk assessments, maintain risk registers, and ensure timely remediation of identified risks.
- Mature and enforce third‑party risk management policies.
- Support identity & access management processes and remediate findings promptly.
- Maintain compliance with UK legislation and industry standards (DPA 2018, PCI‑DSS, ISO27001, Licence 4, WLA:SCS).
- Lead or participate in internal and external security & privacy audits, providing evidence and implementing corrective actions.
- Act as secretariat for governance committees, preparing metrics, reports, and governance documentation.
- Promote a security‑aware culture through training, awareness, and threat education.
**Key Responsibilities**
- Conduct comprehensive risk assessments and keep local and functional risk registers current.
- Manage and enhance the Third‑Party Risk Management policy and framework.
- Oversee Identity & Access Management findings, ensuring remediation within agreed timelines.
- Ensure compliance with regulatory frameworks (Licence 4, ISO27001, PCI‑DSS, DPA 2018).
- Coordinate security and privacy audits, gather evidence, and close audit findings.
- Serve as governance committee secretariat: collate information, track metrics, draft governance papers.
- Deliver training and awareness sessions on security threats and best practices.
- Monitor regulatory updates and adjust policies and controls accordingly.
**Required Skills**
- In‑depth knowledge of information security concepts, standards, and frameworks.
- Strong understanding of UK Data Protection legislation and privacy principles.
- Experience with security governance and compliance (DPA, PCI‑DSS, ISO27001).
- Ability to work independently and collaboratively on complex projects.
- Excellent communication skills for presenting technical risks to diverse audiences.
- High attention to detail, ownership, and rapid learning capability.
- Proficiency in documenting risk and compliance activities; familiarity with risk registers.
- Comfortable using tools for risk tracking, audit evidence collection, and governance documentation.
**Required Education & Certifications**
- Bachelor’s or Master’s degree in Information Security, Computer Science, or related field.
- Professional certifications such as CISM, CISSP, or equivalent highly desirable.
- Knowledge of Python programming is a plus.