Hiring.Camp

Information Security, Compliance & Data Protection Manager

Blue Matter

·

Jun 29, 2026

Location
London
Type
Full-time
Department
Legal
Seniority
Manager
Education
Master
Closing date
5 days ago
Source
ApplyToJob

Description

Blue Matter is a rapidly growing strategic consulting firm serving clients in the life sciences industry. We partner with our clients to help them achieve commercial success across the lifecycle of their products, portfolios and organisations. Our project types include new product planning, launch strategy & planning, brand & life cycle planning and corporate & portfolio strategy, across a variety of specialty therapeutic areas. 

We have a unique entrepreneurial culture and invest in building Blue Matter to be one of the best places to work. We have a strong global presence with offices in the US (San Francisco, New York, Boston), Europe (London, Zurich, Netherlands), and India (Mumbai, Gurgaon, Pune).

Why this role exists

Our clients are among the most security- and privacy-conscious organisations in the world, and they trust us with highly sensitive commercial and scientific information. As we scale our European operations and navigate increasingly complex data protection requirements, we need a dedicated owner for information security, compliance, and EU-focused data protection.

This role sits in our Technology & Operations team and is based in the UK, giving us strong coverage of GDPR and UK GDPR obligations, alignment with European clients and subsidiaries, and time-zone support for our global team. You’ll also serve as a key point of contact for our EU Operations team, providing hands-on IT support and helping ensure our European presence runs smoothly from a technology and compliance standpoint.

This is a hands-on, high-ownership role — not a tick-box function. You’ll build and run the firm’s security and compliance programme, act as our designated Data Protection Officer (DPO) for the EU, and be the trusted point of contact when clients ask how we protect their data. It’s ideal for someone who wants to shape a programme in a fast-moving, AI-forward consultancy rather than maintain one that already exists.

What you’ll do

Security governance and strategy

  • Own and run Blue Matter’s information security programme end-to-end.
  • Conduct a comprehensive audit of the firm’s global security posture and translate findings into a prioritised remediation roadmap.
  • Define, maintain, and operationalise security policies, standards, and procedures, and keep them current as the firm scales.
  • Maintain the risk register, run regular risk assessments, and drive remediation to closure.
  • Report on security and compliance posture to leadership in clear, business-oriented terms.

Compliance and certifications

  • Audit the firm’s compliance posture, with a focus on GDPR readiness across all operations — identify blind spots and build a path to audit-readiness.
  • Support the SOC 2 Type 2 and HIPAA certification process for Twine, our analytics platform, building on the existing Type 1 attestation. (Note: this is product-scoped, not a company-wide certification.)
  • Build a sustainable, “always-audit-ready” approach rather than a once-a-year scramble.
  • Track relevant regulatory and framework developments and translate them into practical action.

Data protection and privacy (DPO)

  • Serve as the firm’s designated Data Protection Officer (DPO) for the EU.
  • Lead data protection under GDPR and UK GDPR, with particular focus on cross-border data transfers between the EU, UK, and US — including evaluating options such as establishing an EU-based Microsoft tenant to keep EU data within European data centres.
  • Audit how client information flows across jurisdictions: identify data that may fall under GDPR but is not currently categorised as such, and close those gaps.
  • Maintain records of processing (RoPA), conduct Data Protection Impact Assessments (DPIAs), and own data-handling, retention, and minimisation policies.
  • Manage data subject requests and any personal-data incidents, including regulator and individual notifications where required.
  • Identify and address data protection risks across business functions, ensuring personal data is handled within approved systems and contractual frameworks. 

Client security assurance

  • Own the response to client security due-diligence: complete security questionnaires and assessments from biopharma and medtech clients accurately and on time.
  • Support commercial and contractual discussions on security, privacy, and data processing terms (e.g., DPAs).
  • Maintain a library of reusable security documentation, certifications, and answers to accelerate client reviews.

Microsoft 365 security operations

  • Secure and govern our Microsoft 365 (E5) environment — Entra ID, Microsoft Defender, Microsoft Purview, and Intune.
  • Own identity and access management: conditional access, MFA rollout, privileged access, joiner/mover/leaver processes, and least-privilege enforcement.
  • Implement and tune data loss prevention (DLP), information protection/labelling, and device compliance.
  • Partner with IT on secure configuration, patching, and endpoint hardening.

EU Operations IT support

  • Provide hands-on IT support for the EU Operations team, including on-site technical assistance when needed.
  • Act as the day-to-day technology point of contact for European colleagues, ensuring they have the tools and infrastructure to work effectively.
  • Support the growth of EU operations from a technology and compliance standpoint as the firm continues to expand in Europe.

Third-party and vendor risk

  • Run third-party and vendor risk management across our supply chain, including security review of new tools and AI/SaaS vendors.
  • Maintain an inventory of vendors and their data access, and reassess risk on a regular cadence.

Incident response and investigations

  • Own and update the incident response plan; lead detection, triage, investigation, containment, and post-incident review.
  • Investigate security events (for example, analysing Entra ID sign-in and audit logs), and produce clear, actionable incident reports.
  • Run tabletop exercises so the firm is prepared before an incident happens.

Security awareness and culture

  • Build and deliver security awareness training and phishing simulations.
  • Make security approachable and practical so the whole firm becomes a partner in protecting client data.


What you’ll bring

Required

  • 5+ years of combined IT and information security/GRC experience, ideally in an environment that handles sensitive client data — such as regulated industries, professional services, defence, government, or pharma.
  • Strong, practical knowledge of GDPR and UK GDPR and day-to-day data protection, with experience navigating cross-border data transfer complexities. Bonus if you’ve been through a GDPR audit or worked for a multinational with operations both inside and outside the EU.
  • Hands-on experience with ISO 27001 and/or SOC 2 implementation and audits.
  • Core IT administration abilities — comfortable providing hands-on technical support alongside governance and strategy work.
  • Working familiarity with the Microsoft 365 security stack (Entra ID, Defender, Purview, Intune).
  • Experience responding to client/customer security assessments and questionnaires.
  • AI fluency and day-to-day use of automation tools in your workflow — we’re an AI-forward firm and expect the same mindset from this role.
  • Based in the UK with the right to work, ideally in or near London (the role is hybrid, occasional office presence is required).
  • Excellent written and verbal communication: you can translate security and risk into plain business language for leadership, clients, and colleagues.

Strongly preferred

  • Experience standing up or maturing a security/compliance programme (not only operating an established one).
  • Experience serving as or supporting a Data Protection Officer (DPO) function.
  • Familiarity with EU and UK regulatory developments such as NIS2 and DORA.
  • Experience managing third-party/vendor risk for SaaS and AI tooling.

Nice to have

  • Exposure to life sciences or pharma, and awareness of GxP, GDP, or healthcare data considerations (e.g., HIPAA for US-facing work).
  • Experience establishing data-protection or data-risk practices.
  • Experience supporting M&A or subsidiary integration from a security and compliance perspective.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, ISO 27001 Lead Implementer/Auditor, CIPP/E, or CIPM — valued but not required; we prioritise practical experience.

Who thrives here

  • Builders who want to own a programme and shape it, not just keep the lights on.
  • Self-starters who proactively identify problems and propose solutions — we don’t want someone who waits to be told what to do.
  • Pragmatic risk managers who right-size controls to the business instead of defaulting to maximum friction.
  • Versatile operators comfortable moving between compliance strategy, hands-on security configuration, and IT support for colleagues.
  • Clear communicators who earn trust with clients, leadership, and engineers alike.
  • People genuinely interested in the security and governance challenges of a modern, AI-forward firm.

How we work

A small, capable Technology & Operations team with real ownership and direct access to leadership. You’ll report to the Director of IT & Security with a dotted line to the EU Operations team. You’ll have the autonomy to build the programme the right way — and the visibility that comes with being the firm’s security and compliance lead. This is a hybrid role based in the UK with on-site presence as needed.
 
Please note: we only email from @bluematterconsulting.com or our JazzHR applicant system. Every open role is listed at bluematterconsulting.applytojob.com, and we never ask for payment, banking details, or equipment purchases.
 

Skills

SOCRisk ManagementComplianceLoss PreventionSOC 2HIPAAGDPRISO 27001CISSP

Similar Jobs

30

Manager (m/f/d) Information Security & Compliance

Hapag-Lloyd·Hamburg, DE·Hybrid

Today

Senior Information Security Compliance Analyst

Motorola Solutions·Ontario, Canada Offsite +2

1w ago

Senior Information Security Compliance Analyst

motorolasolutions·Ontario, Canada Offsite +2

1w ago

Information Security Compliance Specialist

Docebo·Toronto, Ontario·Hybrid

1w ago

Information Security & Compliance Engineer

OfficeRnD·Sofia, Hybrid·Hybrid

1w ago

Information Security Compliance Analyst

Vestwell·New York, NY +1·Hybrid, Onsite

2w ago

IT Networking & Information Security Compliance Administrator

"Eagle Creek Renewable Energy, LLC"·Badin, NC·Remote, Hybrid

3w ago

Director of IT, Information Security & Compliance

Sciens Logistics·Dallas, TX·Onsite

3w ago

Information Security Compliance Analyst

ImageTrend·Eagan, MN·Remote

4w ago

Compliance & Information Security Manager (m/w/d)

Equada·Siegen, Nordrhein-Westfalen

1mo ago

Information Security Compliance Specialist

Securiport·Reston, Virginia

1mo ago

Information Security & Compliance Officer (f/m/d)

SPREAD·Berlin

1mo ago

Director, Information Security & Compliance

ASD Divisional Headquarters - 100·Lewisville, TX

1mo ago

Manager:in Information Security & Compliance (m/w/d)

Steeleurope·Hamborn, Germany·Remote

2mo ago

Sr. Information Security Compliance Analyst

Warnerbros·GA Atlanta 1050 Techwood Drive NW, US·Hybrid

2mo ago

Information Security Compliance Analyst

Holmesmurphy·West Des Moines, US

2mo ago

Information Security & Compliance Associate

Jobs at·Cordoba·Onsite

2mo ago

Information Security Compliance Manager (India)

Tide·India, Delhi NCR

4mo ago

Senior Information Security Compliance Engineer

Crestron·Crestron Electronics Inc. - Plano, TX +1

4mo ago

Information Security & Compliance Leader

RFS Group·New York, San Francisco·Hybrid, Onsite

5mo ago

Information Security Compliance Coordinator

Cgsfederal·Washington, DC·Remote

5mo ago

Information Security, Compliance & IKS Manager (m/w/d) - ISO 27001 - Teilzeit

Cloudiax AG·Deutschland·Remote

6mo ago

Information Security Compliance Analyst - CISSP/CISA

Harborconsulting·Philadelphia, Pennsylvania

1y+ ago

Information Security Compliance Specialist

Tactibit Technologies LLC·Suitland, MD

1y+ ago

Information Security and Compliance Specialist

UPS·NL - SCS-ROERMOND MARIE CURIEWEG 3982, Netherlands +3

2d ago

Senior Director, Information Security and Compliance

Foundant·Canada +1·Remote

1mo ago

Lead, Information Security Regulatory & Compliance

Pru·Wash, NJ·Remote, Hybrid, Onsite

1mo ago

VP, Information Security and Compliance

JOIN THE TEAM·United States of America - Remote·Remote

1mo ago

Information Security and Compliance Analyst Intern

Interac Corp.·Interac Corp. Head Office, Canada

3mo ago

Compliance Manager (Information Security)

Sterling Computers·North Sioux City, SD

5mo ago