Logo-of-Ecmarkets,-Inc.-hiring-for-jobs-in-UK-on-GrabJobs

Data Governance Consultant

Job Description - Data Governance Consultant

Company Overview


EC Markets is a globally recognised financial brokerage, providing advanced FX and CFD trading services. As part of its growing finance team, EC Markets is seeking an Accounts Assistant to support daily financial operations and reporting, ensuring compliance, accuracy, and efficiency across the department.





Role Purpose


Support the business in achieving launch readiness by assessing, documenting and implementing the data governance, privacy and information security controls required for an FCA-regulated financial services platform.


The consultant will work across Product, Technology, Operations, Risk and Compliance to ensure customer data is appropriately governed, protected and processed in accordance with UK GDPR and FCA expectations.


This is a delivery-focused engagement with the primary objective of identifying launch blockers, closing critical gaps, and leaving behind sustainable governance processes.





Key Responsibilities






  1. Data Discovery & Governance


Lead an end-to-end review of customer data across the organisation, including:



  • What data is collected

  • Why it is collected

  • Where it is stored

  • Who has access

  • How it moves through systems

  • Who external processors are


Deliverables: data inventory, data classification framework, Information Asset Register, data flow diagrams.



  1. GDPR & Privacy


Review compliance with UK GDPR and Data Protection Act requirements, including:



  • Lawful basis

  • Consent

  • Retention

  • Deletion

  • Subject access requests

  • International transfers

  • Processor agreements


Deliverables: gap assessment, risk register, required remediation plan.



  1. Data Security Review


Assess current controls covering:



  • RBAC (role-based access control)

  • MFA (multi-factor authentication)

  • Encryption

  • Secrets management

  • Audit logging

  • Backup strategy

  • Disaster recovery

  • Production access


Identify launch-critical risks.



  1. AI & Data Usage Governance


Review the use of Claude, Snowflake, other LLMs, and internal reporting tools. Define:



  • Acceptable use

  • Access model

  • PII handling

  • Prompt handling

  • Data retention

  • User permissions


Produce governance recommendations.



  1. Third Party Risk


Review all vendors processing customer data, including cloud providers, AI providers, communications platforms, and payment providers. Ensure processor agreements, data residency, contractual protections, and security posture are appropriate.



  1. Policies & Documentation


Produce or review:



  • Privacy Notice

  • Data Retention Policy

  • Information Security Policy

  • Data Classification Policy

  • Access Control Policy

  • Incident Response Plan

  • Data Governance Policy



  1. Launch Readiness Assessment


Produce a quick-turnaround executive report identifying:



  • Green — ready for launch

  • Amber — acceptable with known risks

  • Red — must be resolved before launch


With clear, prioritised, actionable tasks to achieve launch readiness.


Success Criteria


By the end of the engagement, the business should be able to confidently answer:



  • What customer data do we hold, and why do we hold it?

  • Where is it stored, and who has access?

  • Is that access appropriate?

  • Where does data leave our environment?

  • Which suppliers process customer data?

  • What data is considered sensitive?

  • Are we compliant with GDPR and FCA expectations — and can we evidence this?


Essential Requirements


Regulatory & Compliance Background



  • Demonstrable experience leading data governance and privacy programmes for FCA-regulated or financial services businesses

  • Prior experience supporting an FCA authorisation process or a regulated product launch, ideally in fintech or payments

  • Strong working knowledge of UK GDPR and the Data Protection Act 2018 — lawful basis, consent, retention, deletion, subject access requests, and international transfers

  • Practical understanding of FCA expectations around data handling and customer outcomes, not just theoretical GDPR knowledge

  • Experience producing gap assessments, risk registers, and remediation plans that stand up to regulatory scrutiny


Data Discovery & Documentation



  • Hands-on experience running end-to-end data discovery and mapping exercises across an organisation, not just reviewing existing documentation

  • Track record of producing data inventories and data classification frameworks from scratch

  • Experience building Information Asset Registers and data flow diagrams

  • Ability to identify data processors and third parties handling customer data as part of a discovery exercise


Technical Security Assessment



  • Ability to assess technical security controls directly with engineering teams, rather than relying solely on policy-level documentation

  • Working knowledge of RBAC (role-based access control) and MFA (multi-factor authentication) implementation

  • Familiarity with encryption standards and secrets management practices

  • Experience reviewing audit logging, backup strategy, disaster recovery, and production access controls

  • Ability to translate technical findings into launch-critical risk ratings for non-technical stakeholders


AI, Data & Vendor Governance



  • Practical experience governing the use of AI/LLM tools (e.g. Claude, other LLMs) in a regulated environment, including acceptable use and access models

  • Understanding of PII handling and prompt-handling risk in AI-assisted workflows

  • Experience with data platform governance (e.g. Snowflake) — data retention and user permissions

  • Experience conducting third-party and vendor risk assessments, including cloud providers, AI providers, communications platforms, and payment providers

  • Working knowledge of data residency requirements and contractual/processor agreement protections


Delivery, Communication & Working Style



  • Track record of producing clear, regulator-ready policy documentation (privacy, retention, information security, access control, incident response) at speed

  • Comfortable operating as an autonomous, hands-on contractor in a lean startup environment — able to self-direct and work with minimal oversight

  • Ability to prioritise launch-critical risk over process, making pragmatic calls where a startup may lack mature governance infrastructure

  • Strong stakeholder management skills across Product, Technology, Operations, Risk and Compliance

  • Ability to translate technical and regulatory detail into a clear, executive-level Red/Amber/Green narrative

  • Proven ability to deliver a full assessment and documentation set against a tight, fixed deadline ahead of a live launch date


Location


30 City Road, London

Original job Data Governance Consultant posted on GrabJobs ©. To flag any issues with this job please use the Report Job button on GrabJobs.
Share Job
Share Job

Similar Data Governance Consultant Jobs in the UK

GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast! Find the best jobs in the UK, apply in 1 click and get a job today!

Mobile Apps

Copyright © 2026 Grabjobs Pte.Ltd. All Rights Reserved.