At a Glance
- Tasks: Lead UK privacy compliance and regulatory oversight while collaborating with cross-functional teams.
- Company: Join Affirm, a forward-thinking company transforming credit into a friendly experience.
- Benefits: Enjoy competitive pay, comprehensive health coverage, flexible spending, and generous time off.
- Other info: Remote-first culture with opportunities for career growth and professional development.
- Why this job: Make a real impact on consumer protection and privacy in a dynamic fintech environment.
- Qualifications: 6+ years in regulatory compliance, strong understanding of UK GDPR, and excellent partnership skills.
The predicted salary is between 101000 - 149000 £ per year.
Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.
About the Legal, Compliance, and Public Affairs team: The Legal, Compliance, and Public Affairs team is a group of dedicated professionals committed to helping Affirm scale, innovate, and provide outstanding products for consumers, merchants, and key partners. We combine legal, compliance, and policy expertise to guide growth, shape products, and build trust across our ecosystem. Our work spans multiple professional disciplines and provides the foundation for Affirm’s mission to deliver honest financial products.
About the role: The Manager, Regulatory Compliance & Privacy (DPO) will support the UK Compliance function by leading and coordinating key second-line regulatory compliance and privacy oversight activities for the UK entity. This role will serve as the operational lead for UK privacy compliance and Data Protection Officer (DPO) responsibilities, while also supporting broader UK regulatory compliance priorities, including vulnerable customers and other key regulatory expectations and programs. The role will partner closely with Legal, Product, Engineering, Operations, Risk, Financial Crimes, and other Compliance stakeholders to ensure a well-governed, scalable, and effective UK compliance framework.
What you’ll do:
- Serve as the primary operational lead for UK privacy compliance matters and act as the designated Data Protection Officer (DPO) for the UK entity, subject to any final organisational and regulatory approvals.
- Lead and oversee existing key UK privacy governance activities, including Data Protection Impact assessments (DPIA’s), oversight, privacy risk assessments, incident and breach governance, data subject rights processes, retention and deletion governance, and regulatory documentation, where required suggest improvements.
- Lead the regulatory input of the firm's Management Information (MI) dashboard for Privacy, to include data relating to consumer outcomes and the firm's meeting of Privacy requirements.
- Ensure ongoing consideration of the metrics and make recommendations for improvement or updates.
- Lead the development of the firm's Privacy Compliance Monitoring Programme (CMP) ensuring its suitability is aligned to the risk appetite of the firm, the regulatory landscape and the market within which the firm operates.
- Support in completion of the firm's Enterprise wide compliance risk assessment and control inventory, including collecting and documenting results, establishing where opportunities exist and work with internal and external partners to deliver.
- Translate legal and regulatory requirements into compliance standards, governance routines, oversight expectations, and program requirements for first-line stakeholders.
- Support the design, implementation, and continuous improvement of the UK regulatory compliance framework across key privacy, conduct and consumer protection areas, including vulnerable customers and other core UK regulatory programs.
- Provide second-line challenge and oversight of first-line control environments, including review of control design, identification of gaps, escalation of issues, and remediation tracking.
- Maintain and enhance governance processes for UK compliance issues management, risk assessments, control oversight, and reporting.
- Support internal audit, external audit, regulatory enquiries, and external partner review activity, including coordination of materials, tracking of actions, and remediation governance.
- Prepare recurring management reporting, governance materials, and issue summaries for senior leadership and relevant governance forums.
- Partner with Legal to ensure clear delineation between legal advisory responsibilities and Compliance operational / oversight responsibilities, particularly in the privacy space.
- Partner with Product, Engineering, Operations, and other cross-functional stakeholders to ensure UK privacy and regulatory requirements are operationalised effectively.
- Coordinate with regional and global Compliance partners to support consistency in governance standards, documentation, and reporting across jurisdictions.
- Help identify and implement improvements to compliance processes, governance routines, documentation standards, and oversight tools.
- Showcase Compliance as an open for business function, accessible and relatable to the goals and objectives of the firm.
What we look for:
- 6+ years of experience in regulatory compliance, privacy compliance, risk management, governance, audit, or a related control function, preferably within financial services, fintech, banking, or another regulated environment, ideally past experience acting as a DPO in a regulated consumer credit firm.
- Strong understanding of UK privacy and regulatory compliance expectations, including UK GDPR, governance, DPIA’s, breach processes, data subject rights, consumer protection, conduct risk, vulnerable customers, and related compliance program requirements.
- Experience operating within a second-line of defence model, including governance, oversight, monitoring, and independent challenge of first-line control environments.
- Demonstrated ability to translate legal and regulatory requirements into policies, standards, procedures, governance routines and control expectations.
- Experience supporting audits, regulatory exams, control reviews, or similar oversight processes in a regulated environment.
- Strong cross-functional partnership skills, with the ability to work effectively with Legal, Marketing, Product, Engineering, Operations, Risk, and Compliance stakeholders.
- Sound judgment, strong organisational discipline, and the ability to manage sensitive regulatory matters with discretion and rigor.
- Experience preparing management reporting, governance materials, and escalation summaries for senior stakeholders.
- Ability to manage multiple workstreams and move between strategic governance design and day-to-day execution.
- Bachelor’s degree or equivalent practical experience; relevant certifications.
Base Pay Grade - L Equity Grade - 5 Employees new to Affirm typically come in at the start of the pay range. Affirm focuses on providing a simple and transparent pay structure which is based on a variety of factors, including location, experience and job-related skills. Base pay is part of a total compensation package that may include monthly stipends for health, wellness and tech spending, and benefits (including 100% subsidised medical coverage, dental and vision for you and your dependents). In addition, the employees may be eligible for equity rewards offered by Affirm Holdings, Inc. (parent company). GBR base pay range per year: £101,000 - £149,000.
Location: Remote UK
Affirm is proud to be a remote-first company! The majority of our roles are remote and you can work almost anywhere within the country of employment. Affirmers in proximal roles have the flexibility to work remotely, but will occasionally be required to work out of their assigned Affirm office. A limited number of roles remain office-based due to the nature of their job responsibilities.
We’re extremely proud to offer competitive benefits that are anchored to our core value of people come first. Some key highlights of our benefits package include:
- Health care coverage - Affirm covers all premiums for all levels of coverage for you and your dependents.
- Flexible Spending Wallets - generous stipends for spending on Technology, Food, various Lifestyle needs, and family forming expenses.
- Time off - competitive vacation and holiday schedules allowing you to take time off to rest and recharge.
- ESPP - An employee stock purchase plan enabling you to buy shares of Affirm at a discount.
We believe It’s On Us to provide an inclusive interview experience for all, including people with disabilities. We are happy to provide reasonable accommodations to candidates in need of individualized support during the hiring process.
Compliance Manager (Data Protection Officer, Regulatory Compliance & Privacy) employer: Affirm
Affirm is an exceptional employer that prioritises a remote-first work culture, allowing employees to thrive from anywhere in the UK. With a strong focus on employee well-being, Affirm offers comprehensive health coverage, generous stipends for technology and lifestyle needs, and competitive time-off policies, all while fostering an environment of growth and collaboration. Joining the International Expansion Unit as a Staff Software Engineer means being at the forefront of innovative solutions that shape the future of credit, with ample opportunities for professional development and influence within a mission-driven team.
StudySmarter Expert Advice🤫
We think this is how you could land Compliance Manager (Data Protection Officer, Regulatory Compliance & Privacy)
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Affirm looking for candidates who are engaged and informed.
We think you need these skills to ace Compliance Manager (Data Protection Officer, Regulatory Compliance & Privacy)
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Affirm. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at Affirm
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Affirm’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!