Zartis Logo

Zartis

Head of Risk and Compilance

Posted 2 Hours Ago
Be an Early Applicant
Remote or Hybrid
Hiring Remotely in European Union
Senior level
Remote or Hybrid
Hiring Remotely in European Union
Senior level
Lead and evolve the company's Risk & Compliance function: own the company-wide risk register, run annual risk assessments, manage IT security risk, lead incident response, maintain ISO 27001/Cyber Essentials and GDPR compliance across multiple EU entities, monitor emerging EU regulation (NIS2, AI frameworks), manage external relationships, and build a proactive compliance culture while directly advising the COO and C-suite.
The summary above was generated by AI
The company and our mission: 

Zartis is a global AI transformation and technology consulting partner where talented engineers and technologists work on cutting edge innovation. We partner with ambitious organizations to design, build, and scale technology solutions that deliver real impact.

Our teams bring deep expertise in AI driven platforms, secure API architectures, and cloud native engineering. You will work on meaningful projects that accelerate the adoption of advanced technologies, from strategy and discovery through to full product delivery, helping turn complex challenges into measurable outcomes.

With engineering hubs across EMEA and LATAM, and long term partnerships in financial services, healthcare and life sciences, and energy and climate, we offer opportunities to work on projects that truly matter. Here, you will not just build technology, you will drive business impact and grow your career alongside industry leaders.

We are looking for a Head of Risk and Compliance to work on a project in the Tech Company industry.

The project:

We are looking for a Head of Risk & Compliance to lead and evolve our Risk & Compliance function. This is a senior leadership role designed for someone who can own the strategic risk agenda, drive a proactive compliance culture, and provide direct decision-making support to the COO. You will manage an internal R&C team, act as the primary accountable owner across all compliance domains, and bring the technical depth in information security and IT infrastructure that bridges the gap between governance frameworks and real-world implementation. 

What you will do:
  • Own the company-wide risk register: maintain, prioritise, and drive resolution across all risk domains (legal, operational, data, information security).

  • Develop and lead the annual risk assessment cycle; translate outputs into concrete mitigation plans with owners and deadlines.

  • Act as the accountable owner for IT security risk, working with internal technical stakeholders and external providers to ensure vulnerabilities, access controls, and infrastructure risks are identified, assigned, and addressed.

  • Act as the primary escalation point for risk and compliance matters.

  • Design and maintain the governance framework across 8 EU jurisdictions, ensuring policies are current, proportionate, and consistently applied.

  • Lead incident response: own the end-to-end process from detection to resolution, including client notification, root cause analysis, and lessons learned.

  • Own ongoing ISO 27001 and Cyber Essentials certifications and lead future certifications (SOC 2 or equivalent) as the business requires.

  • Lead GDPR compliance across all entities: DPIAs, records of processing, data subject requests, breach management, and DPA relationships.

  • Monitor and interpret emerging EU regulation, including NIS2 and upcoming frameworks, and translate requirements into operational action plans before deadlines.

  • Manage relationships with external legal counsel, auditors, and regulatory bodies.

  • Directly manage the Risk & Compliance Manager and any future hires within the function.

  • Set clear performance expectations; develop the team's capability to operate with minimal escalation.

  • Act as an internal advisor to other business functions such as Business, Operations and Finance.


What you will bring:
  • 7+ years in risk, compliance, or information security roles, with at least 3 in a leadership capacity.

  • Direct ownership of ISO 27001; hands-on experience with GDPR compliance operations across multiple jurisdictions.

  • Track record of building or significantly maturing a compliance function, not just maintaining one.

  • Experience working in a tech, consulting, or professional services environment.

  • Demonstrated ability to engage C-suite and clients on risk topics with clarity and commercial awareness.

 
Nice to have:
  • Exposure to AI governance frameworks or emerging EU regulation in the AI space.

  • Familiarity with multi-entity structures across EU jurisdictions (Spain, Ireland, Portugal, Germany, UK).

 
What we offer: 
  • 100% Remote Work

  • WFH allowance: Monthly payment as financial support for remote working.

  • Career Growth: We have established a career development program accessible for all employees with a 360º feedback that will help us to guide you in your career progression.

  • Training: For Tech training at Zartis, you have time allocated during the week at your disposal. You can request from a variety of options, such as online courses (from Pluralsight and Educative.io, for example), English classes, books, conferences, and events.

  • Mentoring Program: You can become a mentor in Zartis or you can receive mentorship, or both.

  • Zartis Wellbeing Hub (Kara Connect): A platform that provides sessions with a range of specialists, including mental health professionals, nutritionists, physiotherapists, fitness coaches, and webinars with such professionals as well.

  • Multicultural working environment: We organize tech events, webinars, parties, and activities to do online team-building games and contests.

Similar Jobs

12 Hours Ago
Remote
Senior level
Senior level
Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
The Pre-Sales Solutions Engineer leads technical discovery, designs and executes POCs, advises on architectural needs, triages issues, and collaborates with teams to ensure customer success and continuous engagement throughout the project lifecycle.
Top Skills: DockerHTTPJavaScriptKubernetesPythonSipTypescriptWebrtc
12 Hours Ago
Remote
Senior level
Senior level
Artificial Intelligence • Machine Learning • Natural Language Processing • Software • Conversational AI
The Solutions Architect will lead enterprise deployments, ensure technical success for customers, and contribute to product improvements. Responsibilities include architecture design, post-sales support, technical problem-solving, and customer engagement.
Top Skills: DockerJavaScriptKubernetesPythonRust
2 Hours Ago
Remote
Senior level
Senior level
Artificial Intelligence • Machine Learning • Music • Generative AI
Integrate a partner client application with internal services, migrate users and data to cloud infrastructure, update frontend UI/UX for migration workflows, modify Node.js/TypeScript backend for correct data mapping, and rapidly troubleshoot integration issues during testing and rollout.
Top Skills: Cloud InfrastructureExpressJwtNestjsNode.jsOauthReactRest ApisTypescriptVueWebsockets

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account