(Legal) Senior Compliance Manager
Senior Compliance Manager IT GRC & AI Governance
The job in short
As an IT Governance, Risk and Compliance (GRC) Manager, you enable Backbase in conducting its business in full compliance with all relevant national and international laws and regulations. This also includes knowledge and experience of professional standards, accepted business practices, internal policy standards and IT Security frameworks such as SOC2, ISO27001 and PCI-DSS etc. requirements. You will focus strategically on setting up and driving our AI Governance frameworks.
A key part of the role is to embed Compliance into the way Backbase builds and sells its products, working closely with Product, Engineering and Sales to translate regulatory requirements into pragmatic product guardrails, design principles and customer-facing positions. The role is expected to balance regulatory rigor with commercial and product realities, enabling innovation rather than operating primarily as a control or approval function.
In addition, you will help shape an AI-native Compliance function, identifying where AI and automation can materially improve the speed, quality and scalability of compliance activities. This includes redesigning workflows, introducing AI-supported controls and monitoring, and reducing manual effort while maintaining appropriate human oversight and accountability.
There is both an ethical component and a pragmatic approach to compliance that this role requires to help the organization manage risk and build trust with our Customers. The Senior IT GRC Manager must possess a strong understanding of the fast-paced FinTech environment, paired with the professional presence to lead customer-facing trust and security conversations. This is an exciting role that allows for growth and development in the area of IT GRC Compliance. You will play a pivotal part in developing this role and influencing a culture of AI Compliance across Backbase. You will report directly to the VP Legal & Compliance Together with your team of two dedicated compliance managers, andyou will assume day-to-day management of a wide range of Compliance activities and implementation initiatives. You will report directly to the VP Legal & Compliance.
Meet the job
Functional/ Technical Skills
- Support design, implementation and strategic management of IT Controls & Compliance Frameworks for an international organization, taking ownership of AI Governance frameworks (e.g. NIST AI RMF, EU AI Act, ISO 42001).
- Act as a strategic compliance partner to Sales and as a senior client-facing compliance representative, engaging directly with clients and prospects on regulatory, AI governance, security and compliance matters and helping navigate these topics throughout complex enterprise sales cycles.
- Ensure compliance with industry best security practices within SaaS environments.
- Manage and coordinate customer and independent third-party attestations as part of the contractual obligations and certification requirements.
- Support Third-Party Risk assessments and regular assurance program
- Prior experience working with GRC tools and platforms
- Ability to analyse and translate laws, regulations and technical requirements into commercially focused business processes
- Ability to execute and report status on Risk Assessment and Risk Mitigation Program metrics.
- Proficient at maintaining policies and procedures as part of the Policy Governance Framework and coordinating that with other departments.
- Drive the development of an AI-native Compliance operating model, proactively identifying opportunities to use AI, agents and automation across activities such as regulatory monitoring, control testing, evidence gathering, policy management, risk assessments, customer questionnaires and compliance reporting.
Business, product and industry knowledge
- Ability to integrate in an Agile/Scrum working environment to drive teams.
- Knowledge of multiple security and privacy frameworks, Third-party risk, outsourcing and banking regulations, etc.
- Knowledge of Secure-SDLC tooling and design
- Knowledge of modern cloud technologies (AWS, Azure) and risks associated with Software-as-a-Service model.
- Knowledge of Open Banking / PSD2 is an added advantage
- Knowledge of the requirements of ethics & compliance programs in international business
- Strong understanding of how enterprise software products are designed, developed, released and commercialised, with the ability to integrate compliance considerations into product roadmaps and development processes without unnecessarily slowing innovation.
- Ability to understand the commercial context of customer requirements and distinguish between genuine regulatory requirements, customer risk preferences and contractual asks, allowing Backbase to take informed and proportionate positions.
Complexity & Problem Solving
- Proven ability to lead tactical compliance setup and operations
- SME with the ability to give concise and to-the-point compliance advice
- Proactive & analytical program management approach.
- Able to distinguish between areas requiring strict controls and areas where a more proportionate, principles-based approach is appropriate.
- A builder mindset: capable not only of operating existing compliance processes, but of challenging and redesigning them through technology, automation and AI.
Collaborations and Interactions
- Establish strong working relationships with Product, Engineering, Security, Legal and Sales, acting as an embedded business partner rather than a downstream compliance reviewer.
- Build credibility with senior internal stakeholders and customers by combining regulatory expertise with an understanding of Backbase's products, technology and commercial model.
How about you?
- Minimum of 8 years of relevant working experience in the practical implementation of Compliance programs in an international environment, with proven practical experience in IT security, governance, risk management and compliance roles.
- Strong working knowledge in AI Governance frameworks.
- Experience supporting enterprise Sales or customer-facing compliance discussions, ideally with regulated financial institutions.
- Evidence of an AI-first / automation mindset: you actively look for ways to simplify, automate or redesign compliance processes rather than scaling through additional manual effort.
- Commercially minded and comfortable making risk-based judgments rather than defaulting to a purely restrictive interpretation of compliance requirements.
- Bachelor’s degree required; - Academic degree desired in the area of IT Security, Risk Management, Cyber Security, Information Security.
- Fluent English - written and spoken required (mandatory)
- Senior professional certifications desired (e.g. CISM, CRISC, CISSP, or AI certifications like IAPP AIGP) or willingness to obtain them.
- Experience with managing the IT GRC team with 2 direct reports.
- Ability to work with the latest tech stack (Latest Azure Services, Grafana, Elastic Cloud, Open Source tooling, Dependency Track, Trivy etc. - Security Tools)
Apply for this job
*
indicates a required field