Senior Risk & Compliance Consultant (Data Privacy)

Posted 3 Days Ago
Be an Early Applicant
7 Locations
In-Office or Remote
Senior level
Professional Services • Financial Services
The Role
Provides privacy and data protection consulting to multiple clients, covering privacy audits, gap analyses, DPIAs, policy development, AI privacy assessments, supplier due diligence, breach response, regulatory communications, data subject requests, training, and risk reporting. Advises business, legal, and information security stakeholders across varied sectors while managing client engagements and a small consulting team.
Summary Generated by Built In

We are seeking an experienced Senior Risk & Compliance Consultant (Data Privacy Consultant / DPO) to work from our Birmingham office (hybrid working with flexibility). Other offices will be considered. This position is permanent and ideally full-time (36.25 hours) however part-time (4 days) will also be considered. 

 

As an experienced Senior Risk & Compliance Consultant / Data Privacy Consultant, you'll support a diverse portfolio of clients across multiple sectors in a fast-paced consulting environment. The role involves both proactive privacy advisory work and reactive support for incidents such as data breaches and data subject rights requests (DSRs). This position suits someone who is calm under pressure, comfortable managing multiple priorities, and able to explain privacy risks and decisions clearly, concisely, and without jargon to business stakeholders at all levels.

 

 

A snapshot of your day

  • Support multiple client engagements simultaneously across a range of sectors in a busy consulting environment
  • Proactively assess and improve clients’ data protection and privacy posture, including Privacy gap analyses and audits; Risk assessments and DPIAs, including for new technologies and data uses; and Policy, procedure, and framework development
  • Assess and advise on the privacy implications of processing personal data using AI and automated decision-making technologies
  • Conduct third-party and supplier privacy assessments, including data processing due diligence and ongoing assurance
  • Produce clear, well-structured audit and assessment reports with practical, prioritised recommendations
  • Provide calm, pragmatic advice during reactive scenarios, including Data breaches and incident response; Regulatory notifications and communications; and Data subject rights requests (access, erasure, rectification, etc.)
  • Deliver privacy education and training, tailored to different audiences and levels of knowledge
  • Act as a trusted advisor, helping clients balance regulatory requirements with business objectives across differing regulatory and operational contexts
  • Communicate effectively with operational teams, senior leaders, and non-technical stakeholders, avoiding unnecessary jargon or alarmism
  • Work collaboratively with legal, information security, and business teams to embed privacy into day-to-day operations
  • Maintain awareness of relevant data protection laws, regulatory guidance, and best practices (e.g. GDPR, UK GDPR)
  • Managing a small team of consultants

 

 

We would love to hear from you if you have:

  • Proven experience working in a busy, multi-client environment supporting organisations across multiple sectors, either in consultancy or an equivalent in-house role; with hands-on experience delivering both proactive privacy advisory services and reactive support
  • Ability to quickly understand different business models, risk profiles, and regulatory environments, and tailor privacy advice accordingly
  • Practical experience handling data breaches and incident response and data subject rights requests
  • Experience assessing AI and automated processing activities involving personal data, including understanding risk, transparency, and accountability considerations
  • Demonstrated ability to conduct third-party privacy risk assessments, including review of suppliers, processors, and data sharing arrangements
  • Capability to produce high-quality, structured written outputs, including audit and assessment reports
  • Experience designing and delivering privacy training and awareness sessions
  • Excellent communication skills, with the ability to translate privacy requirements into clear, concise business decisions and communicate effectively with technical and non-technical audiences
  • Broader business understanding, enabling pragmatic advice that aligns privacy compliance with operational and commercial realities
  • Experience working across regulated and non-regulated sectors (e.g. financial services, healthcare, technology, public sector, retail)

 

Desirable but not essential:

  • Experience working closely with information security or cybersecurity teams (an advantage)
  • Understanding of technical security controls and how they intersect with privacy and AI risk
  • Professional certification such as Certified Data Protection Officer (DPO) or CIPP/M or other IAPP certifications

 

 

 

What's in it for you:

  • Competitive discretionary annual bonus. 
  • Core benefits including life assurance of four times salary, income protection of 75% of salary for up to five years, and single private medical insurance cover. 
  • A generous pension scheme
  • 25 days' annual leave, increasing to 27 days after five years' service. 
  • Access to the Howden flexible benefits programme, offering a wide range of benefits and discounts to support your wellbeing, family life and lifestyle. 
  • The opportunity to be part of a growing global business where career development, collaboration and innovation are encouraged.

 

 

Accessibility 

If you require reasonable adjustments or want more information on accessibility, please let us know

 

Follow Howden on LinkedIn  

 

We kindly ask recruitment agencies to not send speculative CVs. Should we need assistance, we will reach out. All enquiries should be directed to [email protected]   

Skills Required

  • Proven experience in a busy, multi-client environment across multiple sectors, in consultancy or an equivalent in-house role
  • Hands-on experience delivering proactive privacy advisory services and reactive support
  • Ability to understand business models, risk profiles, and regulatory environments and tailor privacy advice
  • Practical experience handling data breaches and incident response
  • Practical experience handling data subject rights requests
  • Experience assessing AI and automated processing involving personal data
  • Experience conducting third-party privacy risk assessments, including suppliers, processors, and data-sharing arrangements
  • Ability to produce high-quality audit and assessment reports
  • Experience designing and delivering privacy training and awareness sessions
  • Excellent communication skills with technical and non-technical audiences
  • Broader business understanding to align privacy compliance with operational and commercial realities
  • Experience working across regulated and non-regulated sectors
  • Experience working with information security or cybersecurity teams
  • Understanding of technical security controls and their relationship to privacy and AI risk
  • Professional certification such as Certified Data Protection Officer, CIPP/M, or another IAPP certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
1,338 Employees
Year Founded: 1989

What We Do

We are proud to be a leading independent UK professional services consultancy at the forefront of risk, pensions, investment and insurance. With a team of more than 1,750 people in nine offices, including 99 partners, we work to deliver on our values and our promise, ensuring the highest levels of trust, integrity and quality. We act as a trusted partner for a wide range of clients in both the private and public sectors – this includes 25% of FTSE 100 and 15% of FTSE 350 companies. We are free from any external stakeholders, allowing us to take a long-term view with all our clients and giving us the freedom to bring fresh ideas to the table, unobstructed.

Similar Jobs

Barnett Waddingham Logo Barnett Waddingham

Consultant

Professional Services • Financial Services
In-Office or Remote
10 Locations
1338 Employees

CrowdStrike Logo CrowdStrike

Machine Learning Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
3 Locations
11000 Employees

CrowdStrike Logo CrowdStrike

Data Analyst

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
4 Locations
11000 Employees

Rubrik Logo Rubrik

Sales Engineer

Artificial Intelligence • Big Data • Cloud • Information Technology • Software • Cybersecurity • Data Privacy
In-Office or Remote
London, Greater London, England, GBR
3000 Employees

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account