Compliance and Regulatory Associate

Compliance and Regulatory Associate

Full-Time 30000 - 40000 £ / year (est.) No working from home possible
Limbic

At a Glance

  • Tasks: Support information security and regulatory functions while gaining hands-on experience.
  • Company: Join a growing company focused on compliance and data protection.
  • Benefits: Competitive salary, equity options, 25 days PTO, and mental health support.
  • Other info: Dynamic team environment with opportunities for personal and professional growth.
  • Why this job: Make a real impact in compliance and grow into a specialist role.
  • Qualifications: 1-2 years in info security or compliance; knowledge of ISO 27001 and GDPR preferred.

The predicted salary is between 30000 - 40000 £ per year.

This is a newly created role, driven by business growth and the expanding scope of our compliance programme. You will work directly alongside our Information Security Lead/DPO and our Regulatory Affairs Specialist, providing hands‑on support across both information security and quality/regulatory functions. Your primary focus will be information security and data protection, supporting ISMS operations, supplier assessments, and infosec‑related processes, and supporting quality management and regulatory affairs. You will own a real workload from day one, with clear mentorship and room to grow into a specialist role. We welcome applications from people with a variety of backgrounds and experiences. Compliance expertise can be built in many different ways, and we’re more interested in how you think, how you work, and what you bring to the team than in whether your CV matches every bullet point. If this role interests you, please apply.

Key Responsibilities

  • Information Security & Data Protection
    • Support the maintenance of our ISO 27001 ISMS by updating policies, procedures, and control evidence, and helping prepare for internal and external audits.
    • Assist with data protection administration: maintaining records of processing activities, supporting data subject access requests, and tracking compliance obligations under UK GDPR and relevant US frameworks including HIPAA.
    • Coordinate security testing activity, working with the InfoSec Lead to scope, schedule, and track penetration testing and vulnerability assessments, and following up on remediation actions.
    • Support supplier and vendor management: processing third‑party security assessments, maintaining the vendor risk register, and chasing outstanding responses.
    • Manage security‑related onboarding and offboarding processes, including access control reviews and checklist completion.
    • Maintain the security incident register, support initial triage and documentation of incidents, and track CAPAs through to closure.
    • Prepare responses to customer security questionnaires and assurance requests for external partners.
    • Own the administrative chasing layer: tracking outstanding sign‑offs, forms, training acknowledgements, and evidence requests across the business.
  • Regulatory Affairs & Quality
    • Support QMS documentation under ISO 13485 by maintaining and updating SOPs, work instructions, and quality records, and assisting with audit evidence preparation.
    • Assist with complaint and CAPA tracking: logging complaints and adverse events, monitoring closure timelines, and supporting documentation of corrective and preventive actions.
    • Support change control administration: preparing and tracking change request documentation across product and process changes.
    • Assist with regulatory filing and technical file maintenance for UK and US medical device requirements, including UK MDR 2002 and FDA SaMD guidance.
    • Provide documentation support for new product introductions.
    • Support QMS supplier qualification processes and documentation.
  • Cross-Functional & Operational
    • Help coordinate and track evidence for ISO 27001 and ISO 13485 internal and external audits, including liaising with Engineering, Product, and Operations teams.
    • Support the wider company's transition into compliant operations by helping communicate new processes, coordinate training, and embed controls across functions.
    • Assist with identifying opportunities to reduce manual overhead through process improvement and workflow automation, as capacity allows.

Essential WHAT WE'RE LOOKING FOR

  • 1–2 years of experience in an information security, compliance, or data protection role, ideally within a healthcare, health technology, or other regulated environment.
  • Working knowledge of ISO 27001 and/or GDPR / UK GDPR, gained through practical experience or formal study.
  • Exposure to healthcare data environments, including an understanding of the sensitivity and regulatory obligations around health information (HIPAA familiarity is a plus).
  • Strong organisational skills: able to manage multiple ongoing workstreams, track outstanding actions, and follow up persistently without losing detail.
  • Methodical and documentation-oriented: comfortable producing and maintaining accurate compliance records, evidence packs, and audit trails.
  • Clear communicator, able to chase colleagues for information and sign‑offs professionally and effectively.

Desirable

  • Familiarity with ISO 13485 or quality management systems, either through direct experience or study.
  • Experience with medical device software regulation (UK MDR, FDA SaMD) or willingness to build this knowledge quickly.
  • Exposure to supplier risk management or third‑party security assessments.
  • Experience working with US and UK regulatory frameworks simultaneously.
  • Experience with compliance tooling or workflow automation.

Personal Attributes

  • Proactive and self‑motivated and able to take ownership of tasks and see them through without close supervision.
  • Calm under pressure and comfortable operating in a fast‑paced environment where priorities can shift.
  • Curious and eager to develop: interested in building expertise across both infosec and regulatory domains over time.
  • Collaborative: able to work effectively as part of a small, senior team where everyone’s contribution matters.

What we offer

  • Competitive salary and equity share options.
  • 25 days PTO plus bank holidays.
  • Company pension scheme (UK).
  • Enhanced parental leave packages (UK).
  • Support with purchasing work‑related books and materials.
  • Quarterly Life Days: Enjoy 4 paid days off per year (one each quarter) to use whenever you choose to relax, recharge, or take care of personal matters.
  • Mental Health Support: Access to dedicated mental health support services.

Compliance and Regulatory Associate employer: Limbic

As a Compliance and Regulatory Associate, you will thrive in a dynamic environment that prioritises employee growth and development. Our company fosters a collaborative work culture where your contributions are valued, and you will benefit from competitive salaries, generous leave policies, and dedicated mental health support. With clear mentorship and opportunities to specialise in compliance and information security, this role offers a meaningful career path in a supportive setting.

Limbic

Contact Details:

Limbic Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Compliance and Regulatory Associate

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Limbic looking for candidates who are engaged and informed.

We think you need these skills to ace Compliance and Regulatory Associate

Information Security
Data Protection
ISO 27001
UK GDPR
HIPAA
Regulatory Affairs
Quality Management Systems (QMS)

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Limbic. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Limbic

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Limbic’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!