At a Glance
- Tasks: Lead data governance and privacy initiatives for a cutting-edge financial services platform.
- Company: Join EC Markets, a globally recognised financial brokerage with a dynamic team.
- Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
- Other info: Work in a collaborative atmosphere with excellent career advancement potential.
- Why this job: Make a real impact on data governance in a fast-paced fintech environment.
- Qualifications: Experience in data governance, UK GDPR, and regulatory compliance is essential.
The predicted salary is between 60000 - 80000 £ per year.
Company Overview
EC Markets is a globally recognised financial brokerage, providing advanced FX and CFD trading services.
As part of its growing finance team, EC Markets is seeking an Accounts Assistant to support daily financial operations and reporting, ensuring compliance, accuracy, and efficiency across the department.
Role Purpose
Support the business in achieving launch readiness by assessing, documenting and implementing the data governance, privacy and information security controls required for an FCA-regulated financial services platform.
The consultant will work across Product, Technology, Operations, Risk and Compliance to ensure customer data is appropriately governed, protected and processed in accordance with UK GDPR and FCA expectations.
This is a delivery-focused engagement with the primary objective of identifying launch blockers, closing critical gaps, and leaving behind sustainable governance processes.
Key Responsibilities
- Data Discovery & Governance
- Lead an end-to-end review of customer data across the organisation, including:
- What data is collected
- Why it is collected
- Where it is stored
- Who has access
- How it moves through systems
- Who external processors are
Deliverables: data inventory, data classification framework, Information Asset Register, data flow diagrams.
- GDPR & Privacy
- Review compliance with UK GDPR and Data Protection Act requirements, including:
- Lawful basis
- Consent
- Retention
- Deletion
- Subject access requests
- International transfers
- Processor agreements
Deliverables: gap assessment, risk register, required remediation plan.
Data Security Review
Assess current controls covering
- RBAC (role-based access control)
- MFA (multi-factor authentication)
- Encryption
- Secrets management
- Audit logging
- Backup strategy
- Disaster recovery
- Production access
Identify launch-critical risks.
- AI & Data Usage Governance
- Review the use of Claude, Snowflake, other LLMs, and internal reporting tools. Define:
- Acceptable use
- Access model
- PII handling
- Prompt handling
- Data retention
- User permissions
Produce governance recommendations.
Third Party Risk
Review all vendors processing customer data, including cloud providers, AI providers, communications platforms, and payment providers.
Ensure processor agreements, data residency, contractual protections, and security posture are appropriate.
Policies & Documentation
Produce or review
- Privacy Notice
- Data Retention Policy
- Information Security Policy
- Data Classification Policy
- Access Control Policy
- Incident Response Plan
- Data Governance Policy
- Launch Readiness Assessment
Produce a quick-turnaround executive report identifying
- Green — ready for launch
- Amber — acceptable with known risks
- Red — must be resolved before launch
With clear, prioritised, actionable tasks to achieve launch readiness.
- Success Criteria
- By the end of the engagement, the business should be able to confidently answer:
• What customer data do we hold, and why do we hold it?
• Where is it stored, and who has access?
• Is that access appropriate?
• Where does data leave our environment?
• Which suppliers process customer data?
• What data is considered sensitive?
- Are we compliant with GDPR and FCA expectations — and can we evidence this?
Essential Requirements
- Regulatory & Compliance Background
- Demonstrable experience leading data governance and privacy programmes for FCA-regulated or financial services businesses
- Prior experience supporting an FCA authorisation process or a regulated product launch, ideally in fintech or payments
- Strong working knowledge of UK GDPR and the Data Protection Act 2018 — lawful basis, consent, retention, deletion, subject access requests, and international transfers
- Practical understanding of FCA expectations around data handling and customer outcomes, not just theoretical GDPR knowledge
- Experience producing gap assessments, risk registers, and remediation plans that stand up to regulatory scrutiny
- Data Discovery & Documentation
- Hands-on experience running end-to-end data discovery and mapping exercises across an organisation, not just reviewing existing documentation
- Track record of producing data inventories and data classification frameworks from scratch
- Experience building Information Asset Registers and data flow diagrams
- Ability to identify data processors and third parties handling customer data as part of a discovery exercise
- Technical Security Assessment
- Ability to assess technical security controls directly with engineering teams, rather than relying solely on policy-level documentation
- Working knowledge of RBAC (role-based access control) and MFA (multi-factor authentication) implementation
- Familiarity with encryption standards and secrets management practices
- Experience reviewing audit logging, backup strategy, disaster recovery, and production access controls
- Ability to translate technical findings into launch-critical risk ratings for non-technical stakeholders
- AI, Data & Vendor Governance
- Practical experience governing the use of AI/LLM tools (e. g. Claude, other LLMs) in a regulated environment, including acceptable use and access models
- Understanding of PII handling and prompt-handling risk in AI-assisted workflows
- Experience with data platform governance (e. g. Snowflake) — data retention and user permissions
- Experience conducting third-party and vendor risk assessments, including cloud providers, AI providers, communications platforms, and payment providers
- Working knowledge of data residency requirements and contractual/processor agreement protections
- Delivery, Communication & Working Style
- Track record of producing clear, regulator-ready policy documentation (privacy, retention, information security, access control, incident response) at speed
- Comfortable operating as an autonomous, hands-on contractor in a lean startup environment — able to self-direct and work with minimal oversight
- Ability to prioritise launch-critical risk over process, making pragmatic calls where a startup may lack mature governance infrastructure
- Strong stakeholder management skills across Product, Technology, Operations, Risk and Compliance
- Ability to translate technical and regulatory detail into a clear, executive-level Red/Amber/Green narrative
- Proven ability to deliver a full assessment and documentation set against a tight, fixed deadline ahead of a live launch date
- Location
- 30 City Road, London
Data Governance Consultant in London employer: EC Markets
EC Markets is an exceptional employer, offering a dynamic work environment in the heart of London where innovation meets collaboration. As a Social Media Coordinator, you will thrive in a performance-driven culture that prioritises professional development and career progression, all while contributing to a leading global financial services provider. With a focus on technology and client experience, you'll have the opportunity to make a meaningful impact in a rapidly evolving industry.
StudySmarter Expert Advice🤫
We think this is how you could land Data Governance Consultant in London
✨Join Compliance Communities
Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!
✨Attend Industry Conferences
Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.
✨Leverage Your University Career Services
If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.
✨Showcase Your Knowledge Online
Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like EC Markets looking for candidates who are engaged and informed.
We think you need these skills to ace Data Governance Consultant in London
Some tips for your application 🫡
Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!
Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.
Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!
Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at EC Markets. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!
How to prepare for a job interview at EC Markets
✨Master the Regulations
Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!
✨Show Your Analytical Skills
Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!
✨Know Your Tools
Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!
✨Align with Company Culture
Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with EC Markets’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!