Compliance Manager

Compliance Manager

Full-Time 50000 - 60000 £ / year (est.) No working from home possible
N

At a Glance

  • Tasks: Lead compliance efforts and ensure security standards across the company.
  • Company: Join Narwhal Labs, a fast-paced AI communications company in Bristol.
  • Benefits: Full-time role with competitive salary and a commitment to diversity.
  • Other info: Dynamic team culture focused on innovation and inclusivity.
  • Why this job: Make a real impact on compliance in a growing tech environment.
  • Qualifications: 3+ years in compliance or information security, with ISO 27001 experience.

The predicted salary is between 50000 - 60000 £ per year.

Location: Bristol, UK (must be able to commute to Bristol)

Employment Type: Full-time

About Us

Narwhal Group (trading as Narwhal Labs) is a Bristol-based agentic AI communications company building DeepBlue OS, a platform that handles voice, SMS, WhatsApp and email interactions for enterprise clients. We're 37 people, ISO 27001 and SOC 2 certified, and mid-Series A with strong investor backing. We move fast, take compliance seriously, and want someone who can do both.

Role Overview

As Compliance Manager you will own and lead Narwhal's ISMS, acting as the primary day‑to‑day custodian of our ISO 27001 and SOC 2 certifications. Reporting directly to the CFO/COO, you'll work across engineering, product, HR, legal, and commercial teams to embed a culture of security and compliance as we scale. This is a hands‑on, high‑ownership role — you'll be writing policy, running audits, managing our external audit relationship with Scrut, and advising leadership on risk.

Key Responsibilities

  • Own and continuously improve the ISMS in line with ISO 27001:2022 and SOC 2 Type II requirements
  • Lead all internal audit activity and manage the relationship with Scrut as external auditor
  • Maintain the risk register, run periodic risk assessments, and present findings to the leadership team
  • Serve as Document Controller, overseeing version control of all policies, procedures, and evidence artefacts

Policy & Controls

  • Draft, review, and update information security policies across the full Annex A control set
  • Ensure controls are operational, evidenced, and audit‑ready at all times
  • Manage supplier and third‑party risk assessments and due diligence processes
  • Support the DPO function on UK GDPR obligations, data subject requests, and breach response

Cross‑functional Compliance

  • Partner with the CTO on technical security controls and vulnerability management
  • Work with the HR team on security, onboarding/offboarding, and access reviews
  • Support commercial and legal teams on security questionnaires, RFP responses, and customer DPAs
  • Advise on compliance implications of new products, integrations, and markets (including international expansion)

Governance & Reporting

  • Prepare compliance reporting for board meetings and investor due diligence
  • Manage the compliance calendar: surveillance audits, recertification cycles, management reviews
  • Run security awareness training across the company
  • Act as a point of escalation for information security incidents alongside the Incident Response Lead

Who We’re Looking For

  • 3+ years in an information security, compliance, or GRC role
  • Demonstrable hands‑on experience with ISO 27001 — ideally having led or co‑led a certification or recertification
  • Working knowledge of SOC 2, UK GDPR and data protection principles
  • Experience writing and maintaining security policies, procedures and risk registers
  • Confident communicator — able to translate technical risk into board‑level language
  • Highly organised with strong attention to detail and the ability to manage multiple workstreams

Desirable Qualifications

  • Experience in a SaaS, AI, or high‑growth tech company
  • Familiarity with compliance automation tooling (Scrut, Vanta, Drata, or similar)
  • Exposure to international compliance requirements (Ireland, UAE, Australia)

Diversity and Inclusion

We're building something global at Narwhal, and we mean that in every sense. The work we do requires different ways of thinking and different ways of thinking come from different people. At Narwhal, we’re committed to building a diverse and inclusive team. We welcome applications from people of all backgrounds, identities, and experiences, and we actively work to ensure our hiring process is fair and accessible for everyone. Reasonable adjustments are available at every stage, just reach out and we’ll make it happen.

Compliance Manager employer: Narwhal Labs

Narwhal Group is an exceptional employer located in the vibrant city of Bristol, offering a dynamic work environment where innovation meets compliance. With a strong focus on employee growth and a commitment to diversity and inclusion, we empower our team members to take ownership of their roles while providing opportunities for professional development. Join us at Narwhal Labs, where you can make a meaningful impact in the fast-paced world of AI communications.

N

Contact Details:

Narwhal Labs Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Compliance Manager

Join Compliance Communities

Get involved in compliance and risk communities — both online and offline. Look for forums, LinkedIn groups, or even local meetups where compliance pros hang out. You never know who might drop a job opportunity your way!

Attend Industry Conferences

Keep an eye out for compliance and risk management conferences and workshops in your area. These events are a goldmine for networking, and they often have job boards or recruiters on-site looking for new talent. Plus, it’s a chance to learn what's trending in the field.

Leverage Your University Career Services

If you’ve recently graduated or are still studying, head over to your university's career services. Many companies, including those in compliance, actively recruit fresh talent through these services, so make sure you tap into that resource.

Showcase Your Knowledge Online

Start writing articles or blog posts about compliance topics that interest you. Share them on platforms like LinkedIn to demonstrate your knowledge and passion. This not only builds your presence in the field but can also catch the attention of companies like Narwhal Labs looking for candidates who are engaged and informed.

We think you need these skills to ace Compliance Manager

ISO 27001
SOC 2
Information Security Management System (ISMS)
Risk Assessment
Policy Writing
Audit Management
Data Protection Principles

Some tips for your application 🫡

Show Your Understanding of Compliance:In the compliance-risk field, it's super important to showcase your understanding of regulations and risk management frameworks. Highlight any relevant coursework, certifications (like ICA or AML), or even projects that demonstrate your knowledge and commitment to this area. We want to see how you can navigate this complex landscape!

Quantify Your Achievements:When detailing your experience, try to quantify your achievements. For example, if you've previously worked on a project that improved compliance metrics or reduced risk exposure, give us the numbers! This data-driven approach really stands out to hiring managers in compliance-risk roles.

Tailor Your CV to Reflect Relevant Skills:Make sure your CV highlights skills that are particularly relevant to compliance, like attention to detail, analytical thinking, and report writing. Ensure these are easy to spot – consider using bullet points to break down your responsibilities and achievements for maximum impact!

Craft a Motivating Cover Letter:In your cover letter, let us know why you’re excited about the compliance-risk role at Narwhal Labs. Share what motivates you about compliance, and how you believe you can contribute to our mission. This is your chance to showcase not only your skills but also your passion for this important field!

How to prepare for a job interview at Narwhal Labs

Master the Regulations

Brush up on key compliance regulations relevant to the industry you're applying to. Familiarising yourself with specific laws and frameworks used in your field will give you an edge during technical questions. Show that you’re not just aware of them but can also apply them—think real-life scenarios!

Show Your Analytical Skills

Compliance roles really focus on analytical skills, so be prepared for case studies or situational questions during the interview. We've got to demonstrate how we approach risk assessments or compliance audits, possibly drawing on examples from past experiences or university projects. Bring some thoughtful case scenarios to discuss!

Know Your Tools

Get comfortable with commonly used compliance software and tools. Familiarity with platforms like RSA or MetricStream can really impress during your interview, as it shows you're ready to hit the ground running. If you’ve had any experience with them, make sure to highlight that!

Align with Company Culture

Since it's a full-time position, show your long-term commitment and interest in the company’s mission and values. Dive into how your ethics and professional philosophy align with Narwhal Labs’s stance on compliance. A shared vision can really resonate with interviewers looking for fit as much as skill!