Risk and Compliance Manager

Doctor Care Anywhere
London
2 weeks ago
Applications closed

Related Jobs

View all jobs

Risk and Compliance Manager - Leading top 100 law firm

Governance, Risk and Compliance Manager

IT Governance, Risk and Compliance Manager (GRC)

Compliance Manager

Compliance Manager

Cyber Security Consultant - GRC

Thanks for stopping by! We’re Doctor Care Anywhere: a leading digital platform, with a clear vision to be the primary care provider of choice for digital healthcare – and that all starts with our brilliant team.

We are the UK’s largest private provider of telehealth services. We work with insurers, healthcare providers and corporate customers to provide healthcare services to more than 2 million patients every year. From doctors and designers to software developers and marketers – we’re proud of our people, who love working together to enhance patient experiences for the better. It’s why every year, we help over 2 million people speak to a GP or ACP by video or phone, anywhere in the world.

Our story started back in 2013, and as we continue to grow, we’re looking for the very best talent to help us achieve our ambitious goals. If you’re highly motivated and would love to work with us as we continue to grow, then we would love to hear from you

Your new role:The Risk & Compliance Manager is responsible for delivering and maintaining risk and compliance activities across Doctor Care Anywhere (DCA). This includes owning the risk register, ensuring compliance with ISO 27001 and CQC regulations, and overseeing governance processes. The role plays a key part in maintaining robust risk management frameworks, regulatory assurance programs, and aligning DCA with industry standards and best practices. The post holder will lead the development and implementation of effective risk management and CQC compliance frameworks while actively managing governance processes, policies, and patient safety initiatives. 

Salary :£55,000 Per Annum

Application Deadline:Provisional closing date of Midday Thursday 10th April(We may close the advertisement early if we receive a sufficient number of applications)

Requirements

Key Responsibilities 

Compliance  

  • Project manage CQC inspections and other internal/external regulatory reviews, ensuring adherence to compliance requirements before, during, and after inspections. 
  • Embed a strong understanding of CQC regulations across the business, ensuring compliance is integrated into daily operations. 
  • Stay updated on regulatory changes and advise on necessary policy and procedural updates. 
  • Manage and maintain ISO 27001 certification, including project management, documentation, testing, and cross-functional collaboration to ensure ongoing compliance. 
  • Work closely with the Incidents & Complaints Manager to translate system learning and emerging themes into risk mitigation strategies. 
  • Maintain a central repository of compliance evidence to streamline audits and client assurance processes. 

 

Risk 

  • Maintain and manage the corporate risk register, ensuring effective documentation and mitigation of risks. 
  • Work with operational teams to embed a strong understanding of risk management and how to identify, assess, and mitigate risks at the team level. 
  • Educate teams on operational risks that contribute to the overall corporate risk strategy. 
  • Develop and implement risk management strategies, including risk identification, assessment, mitigation, and monitoring. 
  • Oversee third-party risk management, ensuring appropriate security assessments of supply chain partners in collaboration with Finance and Procurement. 
  • Analyse incidents and complaints for risk management and quality assurance, identifying trends and areas for improvement. 
  • Prepare reports, papers, and presentations for internal committees to document risk management activities and appetite. 

 

Governance  

  • Support the governance audit framework by planning and conducting internal audits as a second-line check. 
  • Undertake investigations for incidents and complaints, ensuring a structured and thorough approach. 
  • Own and manage the policy schedule and repository, ensuring compliance with industry regulations and best practices. 
  • Foster a culture of collaboration in defining and maintaining effective policy management at DCA. 
  • Monitor regulatory changes and ensure organizational policies remain current and compliant. 
  • Work with key stakeholders to implement necessary policy and procedural updates. 
  • Ensure audit and governance reports are accurate, complete, and submitted to the appropriate committees. 

 

Stakeholder Engagement 

  • Act as a primary point of contact for governance matters, facilitating governance committees and liaising with external partners. 
  • Engage with the Executive Team and Heads of Departments, maintaining a high level of stakeholder interaction and autonomy in the role. 
  • Support client security and business partner assurance programs, responding to security-related queries and audits. 
  • Prepare for client and partner security reviews, managing outstanding actions through to completion. 
  • Develop and maintain governance, risk, and compliance (GRC) communication channels, including internal reporting tools and team bulletins. 

 

Training & Education 

  • Develop and deliver training programs on compliance, risk management, and governance, working closely with clinical management on best practices. 
  • Collaborate with Learning & Development teams to integrate risk awareness into company-wide training programs. 
  • Promote a strong culture of compliance and risk awareness across all teams. 

 

Remit 

  • Organisational wide impact 
  • Deputise for the Head of Risk, Governance and Compliance as required 
  • Provide cross-cover for Incident & Complaints Manager as required 

 

Experience & Qualifications 

  • Proven experience for at least five years previously managing compliance, risk, and governance frameworks, particularly ISO 27001, and third-party risk assessments. (Essential) 
  • Minimum two year experience in healthcare governance background operating in a senior role 
  • Experience in managing Risk Register and policies 
  • Experience conducting audits, assurance reviews, and regulatory monitoring. 
  • Previous managerial experience (desirable) 
  • Knowledge of the UK GDPR and Data Protection Act  (Essential) 
  • Knowledge of CQC framework (Essential) 
  • Strong knowledge of security, risk management, and regulatory compliance methodologies. 
  • Understanding of Risk Management Systems, able to produce detailed reports with analytical narrative 
  • Strong interpersonal skills, with the ability to engage stakeholders at all levels. 
  • Strong analytical and reporting skills to track and trend key risk themes. 
  • Relevant industry certifications (e.g., ISO 27001 Lead Auditor, CISSP, CISM) highly desirable. 

Benefits

Why you want to work here:

We understand the importance of good health and happiness for our patients and our team is just the same. At our Doctor Care Anywhere, you're not just an employee; you're a valued member of our team. We believe in giving you the freedom to supercharge your career with us while feeling completely supported. Here's what you can look forward to when you join us:

 Private Medical Insurance: We've got you covered including Opticians & Dental appointments!

‍⚕️ Doctor Care Anywhere subscription: For you and 5 of your family and friends, Get ready to enjoy health consultations on the go!

️ 25 Days Holiday + Bank Holidays (FTE): You've earned it! Enjoy time off to recharge, explore, and make incredible memories.

 Birthday Day Off: Go and celebrate however you like!

‍♂️ Buy' up to 5 days of additional annual leave (FTE) as part of our focus on health and wellbeing

 Company Pension scheme planting a money tree for your future

 Charity Days: Join us in giving back to the community! We're all about making a difference together.

 Enhanced Maternity and Paternity Pay: Extra support during this special time.

 Bike2Work Scheme: We love an eco-friendly commute!

 UK Hybrid Working: An agile and autonomous hybrid work environment

 Development Opportunities: Get ready to grow, learn, and make strides in your career!

Doctor Care Anywhere is committed to safeguarding and promoting the welfare of its patients and expects all Colleagues to share this commitment. This post is subject to satisfactory DBS and reference checks. 

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

BAE Systems Cybersecurity Jobs in 2025: Your Complete UK Guide to Protecting Governments, Businesses and Critical Infrastructure

From securing the Royal Navy’s new Dreadnought submarines to foiling multimillion‑pound fraud rings, BAE Systems Digital Intelligence (DI)—formerly Detica—sits at the sharp end of global cyber defence. Head‑quartered in Guildford with hubs in Gloucester, Leeds and London, the 5,500‑strong DI business delivers threat‑intelligence platforms, secure‑by‑design software and 24/7 SOC services to government and commercial clients worldwide. With escalating ransomware, AI‑driven disinformation and complex supply‑chain threats, BAE plans to expand its UK cyber workforce by 20 % in 2025. Whether you’re a graduate passionate about reverse engineering, a DevSecOps engineer who loves IaC, or an incident‑response pro comfortable in high‑side environments, this guide explains how to land a BAE Systems cybersecurity job in 2025.

Cyber Security vs. Ethical Hacking vs. Security Analysis Jobs: Which Path Should You Choose?

In an era where data breaches, ransomware attacks, and sophisticated digital threats dominate headlines, the demand for skilled cyber security professionals has never been higher. From global corporations to small businesses, organisations are scrambling to protect their systems, networks, and data from malicious actors. If you’ve been exploring cyber security jobs on www.cybersecurityjobs.tech, you’ve likely encountered various specialised roles—Ethical Hacking (often termed Penetration Testing), Security Analysis, Security Architecture, Incident Response, and more. Yet many job seekers and technology enthusiasts are unsure how these fields overlap or which one is right for them. In this in-depth guide, we’ll demystify three core disciplines—Cyber Security, Ethical Hacking, and Security Analysis—outlining the skills each requires, the responsibilities you can expect, salary ranges in the UK, and typical day-to-day activities. By the end, you’ll have a clearer understanding of these roles, helping you decide which path to pursue in this fast-growing industry. And when you’re ready to take the next step, head over to www.cybersecurityjobs.tech to explore the latest openings and find your perfect match.

Cyber Security Programming Languages for Job Seekers: Which Should You Learn First to Launch Your Security Career?

Cyber security has become a top priority for companies of all sizes, public institutions, and governments. As cyber threats evolve—from sophisticated ransomware attacks to large-scale data breaches—employers are eager to recruit talent with the skills to detect, prevent, and respond to security incidents. If you’re exploring roles on www.cybersecurityjobs.tech, a key question inevitably arises: Which programming language should you learn first for a career in cybersecurity? Cyber security is a multifaceted domain encompassing network security, application security, reverse engineering, digital forensics, ethical hacking (penetration testing), and more. Each niche may have unique language preferences—like Python for scripting tasks, C/C++ for exploit development, or Rust for building secure low-level tools. In this article, we’ll: Highlight the top programming languages used across cyber security. Break down pros, cons, and key use cases for each language. Present a simple beginner’s project for hands-on learning. Share essential resources and tips, so you can stand out in the competitive cybersecurity job market.