Sida 1 av 1
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security controls across our Azure Gov Cloud environment (including hybrid and multi-cloud scenarios). In this hands-on role, you will build, strengthen, and maintain our cloud security posture, protect critical workloads, and collaborate with engineering, DevOps, and compliance teams to embed security throughout the development lifecycle. You will develop, implement, and leverage Microsoft’s native security tools to detect threats, respond to incidents, and ensure alignment with industry standards and regulations. Lastly, you will be required to both achieve and maintain compliance with government regulations such as FedRAMP and CMMC. RESPONSIBILITIES: * Implement, design, and manage security architecture for Azure Government and Commercial deployments (with considerations for DoD IL5\IL6 and FedRAMP High controls) * Configure and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response * Design and enforce identity & access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access * Secure network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints * Protect data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls * Develop and maintain security policies, initiatives, and blueprints using Azure Policy and Microsoft Purview for compliance (NIST, FedRAMP, CMMC, STIGs, etc.) * Perform threat hunting, incident response, and forensics using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of Infrastructure as Code (IaC), containers, Kubernetes (AKS), and serverless workloads * Collaborate with developers and architects to implement DevSecOps practices, including secure CI/CD pipelines, code scanning, and secure defaults * Monitor and remediate security findings, reduce attack surface, and improve overall security posture per the Microsoft Cloud Security Benchmark (MCSB) * Deploy configurations and compliance policies to Azure AVD endpoints using Intune and other Azure native services. BASIC QUALIFICATIONS: * Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one. * 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus) * Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview * Strong understanding of DLP implementation both in cloud and on endpoints utilizing Purview and other Microsoft native controls * Experience implementing security in hybrid/multi-cloud environments * Proficiency in scripting/automation (PowerShell, Azure CLI, Bicep/ARM templates, Terraform) * Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management * Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements * Excellent problem-solving, analytical, and communication skills * Strong verbal and written communication skills and the ability to stay composed under pressure. PREFERRED SKILLS AND EXPERIENCE: * Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100) * Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD) * Deep experience with detection and response engineering and SOC operations * Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection * Prior experience in government regulations frameworks such as FedRAMP and CMMC. COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: * To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
Location: THG Labs, Meridian Business Park, Trowbridge, BA14 0BP About THG Labs THG acquired Acheson & Acheson in 2018 to bring full service, product development & manufacturing in-house to supply innovative branded and THG Beauty Brand products to the industry. In 2022 Acheson & Acheson became THG Labs. Capabilities include: * In-house market knowledge & trends * End-to-end service from idea generation through to manufacturing and launch * Technical, commercial and production expertise * Outstanding customer service About The Regulatory Compliance Team Based within the Beauty division of the business, The Regulatory Compliance Team is responsible for reviewing and assessing current and new cosmetic regulations globally including horizon scanning to make sure our clients have the latest information. The team are responsible for checking and tracking the compliance to these regulations of all the ingredients, materials and formulations sourced and manufactured by THG Labs. As well as managing and monitoring various certifications including audits, as well as processing and managing complaints and testing of products. Why be a Technical Information Officer at THG Labs? Reporting to Snr Compliance Officer, the Technical Information Officer is responsible for assisting the team in accurate data collection, reporting, maintenance and researching compliance of raw materials and finished cosmetic products. They will provide support to all members of the Regulatory Compliance Team to facilitate the delivery of projects assigned, ensuring products are safe, legal and sustainable. As a Technical Information Officer you will: * Collection of data relating to raw materials and finished goods to support the Regulatory Compliance team in the requirements for full compliance to all countries and regions as well as certifications as needed by the business and clients. * Ensuring accurate management of data in systems required for development and maintenance of cosmetic regulatory documentation. In accordance with company service level agreements and customer briefs. * Maintenance and collation of data relating to external certification of products including COSMOS, RSPO, VEGAN SOCIETY, Halal and Cruelty Free International. * Reporting and maintaining data relating to sustainability of raw materials and finished products. * Developing knowledge of regulations relating to the development, manufacture, and sale of Cosmetic and toiletry products * Communicating with suppliers, requesting up to date and accurate information is received and processed in accordance with service level agreements. * Follow company work instructions and procedures. * Communicating effectively and positively with all teams, colleagues, and managers. * Take reasonable care for the health and safety for yourself and other persons who may be affected by your work * To cooperate with regards to all company health & safety measures, following H&S training when using equipment * Report to a person in authority any work situation which may represent a serious or imminent danger to health & safety or any shortcomings in the protection arrangements to health & safety. In respect of any hazards remember ‘see it, report it’ * Helping to promote a positive working atmosphere within the company. * Any other duties that may be required from time to time. What skills and experience do I need for this role? * Experience within the cosmetics, personal care, chemical, pharmaceutical, food, or regulatory compliance sectors. * Knowledge of cosmetic regulations, ingredient compliance, or product certification requirements. * Familiarity with certification schemes such as COSMOS, RSPO, Vegan Society, Halal, and Cruelty Free International. * Understanding of sustainability reporting and environmental data management. * Experience liaising with suppliers to obtain technical, regulatory, or compliance documentation. What’s in it for me? Career Development * Access bespoke development programmes that have been designed and developed by our in-house L&D team. * Continued development through our upskilling programme that is delivered in partnership with an industry-leading training provider. Enhanced Leave * 25 days annual leave plus bank holidays. * Don’t want to work on your birthday? We don’t either! Enjoy your day off on us! * Enhanced maternity and paternity pay, depending on length of service. * Up to 10 days compassionate leave. * Buy back up to 3 days each year. * Unlock 2 days volunteer leave after 12-months. Wellbeing Support * Access face-to-face and virtual appointments with our in-house GP (Manchester Head Office). * Access our 247 Employee Assistance Programme (EAP) which is provided by Bupa. Other Perks * Save up to 12% on the cost of personal tech through our salary sacrifice scheme. * Up to 50% staff discount on THG brands. * Know someone who would be perfect for THG? Refer them and get up to £1000 when they pass their probation. * Anniversary gifts when you hit 5 and 10 years of service.
Role: Head of Lawyer Support Location: Poole/Hybrid - 4 days per week in our office. ABOUT WOODSTOCK LEGAL SERVICES: Woodstock Legal Services isn’t your typical law firm. We’re breaking the mold – ditching the jargon, delivering expert advice, and doing things differently in the legal world. We've gathered our wisdom from years of legal experience and paired it with a willingness to break the mold. At Woodstock, you’ll be part of a people-first culture where ideas are welcomed, collaboration is second nature, and your contribution really matters. We invest in our internal teams because we know they’re the engine that keeps everything running and we’re proud of the culture we’ve built together. About Woodstock Legal Services & Lawhive Partnership The Woodstock vision was to create a law firm that felt different, one where lawyers had true freedom and flexibility within a community of grade A lawyers and the best operational and regulatory support on offer - all while ensuring our clients remain our constant focus. Since 2014, Woodstock has grown into a thriving community of lawyers, built on the principle that legal practice can be both professional and personal. We set out to create a place where lawyers have the freedom to shape fulfilling careers, and where clients benefit from clear, expert advice delivered with genuine care. That vision remains at the heart of everything we do. By joining the Lawhive Group, we are strengthening this vision - combining the trusted relationships and values that define Woodstock, with innovative tools that ease the pressures of legal work. This means our lawyers can dedicate more time to what matters most: guiding and supporting our clients. THE ROLE We're looking for the senior operator who will own Lawyer Support end-to-end and make Woodstock the easiest place in the UK to practice law. You’ll own the Lawyer Support function end-to-end. The team, the systems, the SLAs, and the standards. Making sure our lawyers have a setup that lets them focus on practising law and serving clients. This is a department-level leadership role. You’ll be responsible for a function of 30+ people, managing through experienced team leads and managers rather than directly supervising the front line. You will be accountable for the performance, capacity, culture, and continuous improvement of the function, and you’ll work closely with the wider Lawhive Group to integrate tools, data, and operating practices that move us forward as one business. We’re looking for someone who is comfortable leading at scale, has done it before, and is energised by the chance to modernise how a legal support function runs, not just keep it ticking. The right person is a builder: confident with change, fluent with data and tooling, and able to bring a large team with them. WHAT YOU’LL OWN * Lead the Lawyer Support function at Woodstock: a team of 30+ working across our digital inbound channels (Intercom) and overseeing the document centre, which handles printing, posting, and storage. * Run the Printing and Post operation. Inbound and outbound mail, document production, scanning, distribution, and the physical workflow that keeps casework moving. * Manage through managers. Develop, coach, and hold accountable a team of team leads and managers; build a leadership bench that scales as we grow. * Set the operating model: structure, capacity planning, shift patterns, SLAs, and the metrics that prove we’re delivering for consultants and clients. * Own the quality bar. Make sure file opening, consultant support, and print and post are accurate, fast, and audit-ready at all times. * Drive change. Lead the adoption of new tooling, automation, and AI-enabled workflows across the function, in partnership with Lawhive’s product and operations teams. * Partner cross-functionally with Lawhive’s Operations, Talent, and Product teams. * Represent Lawyer Support in senior forums. * Be the senior point of escalation for complex consultant issues and operational risk. * Own the budget and headcount plan for the function, working with Finance and the Director of Operations. WHAT SUCCESS LOOKS LIKE IN THE FIRST 12 MONTHS * A stable, well-led function with clear team structures, defined manager roles, and a credible succession plan underneath you. * A published operating model with documented SLAs, capacity model, and a live performance dashboard the leadership team trusts. * Measurable improvements in turnaround times, accuracy, and consultant satisfaction across file opening, consultant support, and print and post. * At least one significant tooling or automation change shipped end-to-end, reducing manual effort and freeing capacity. * Lawyer Support recognised across the Lawhive Group as a high-performing, well-run function. WHAT YOU’LL BRING * Proven experience leading departments of 50+ people in a support, operations, or service environment. Ideally including a regulated industry such as legal, financial services, or healthcare. * A track record of managing managers, not just individual contributors. You’ve built and coached a layer of leadership underneath you. * Strong, modern operations instincts: capacity planning, SLA management, workforce planning, performance management, and quality assurance. * Tech-forward and change-confident. You’ve led teams through meaningful change (new tools, new processes, automation, AI) and you can show what changed and what it delivered. * Comfortable owning a physical operation as well as a digital one. Print, post, scanning, and document workflows are part of this role. * Calm, credible communicator. Comfortable in front of senior stakeholders, lawyers, and your own team. * Data-literate. You make decisions from numbers, not vibes, and you can build the dashboards and rituals to keep a department honest. * People-first leadership style. You set a high bar and build the kind of team people want to stay in. * Comfortable being in the Poole office three days a week, working alongside the team you lead. NICE TO HAVE * Prior experience in a law firm, legal services, or another regulated professional services environment. * Exposure to LEAP or similar legal practice management tooling. * Experience operating in a high-growth, PE- or VC-backed environment. LOCATION AND WORKING PATTERN This role is based in our Poole office four days per week. The remaining one day can be worked remotely. We expect the Head of Lawyer Support to be physically present with the team they lead, particularly during periods of change and growth, and to be on-site for the days the print and post operation is running. INTERVIEW PROCESS * Introductory call with our Talent team * Operational leadership interview. A working session on how you’d approach a real Woodstock scenario. * Values interview with Leadership * We offer! UK Benefits ✈️ 33 days’ annual leave (25 + bank holidays) plus your birthday off 🎄 Extended Christmas holiday 💰 Pension contribution ☮️ Give back - support a good cause with a charity day each year
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. * Department: Data & Technology Solutions (DTS) * Reports To: SVP Security and Compliance * Location: [London/Hybrid 2 days a week in office] * Position Type: Full-Time ROLE OVERVIEW The Product, Application and Offensive Security Lead is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective. The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required. ---------------------------------------------------------------------------------------------------------------------------------- KEY RESPONSIBILITIES 1. HANDS-ON PRODUCT AND APPLICATION SECURITY Provide hands-on security support across DTS products and engineering teams. This includes: * Reviewing product designs, technical designs, APIs, services, and integrations. * Identifying security weaknesses in applications, workflows, and data flows. * Advising engineering teams on secure implementation. * Supporting secure design decisions during product discovery and delivery. * Helping teams resolve security issues pragmatically without creating unnecessary delivery friction. 2. SECURE SOFTWARE DEVELOPMENT LIFECYCLE (SDLC) Embed security into the software development lifecycle across DTS. This includes: * Defining and applying secure engineering standards. * Supporting secure coding practices. * Reviewing CI/CD security controls. * Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning. * Helping teams triage, prioritise, and remediate security findings. * Working with engineering teams to make security checks practical and repeatable. 3. THREAT MODELLING AND SECURITY DESIGN REVIEWS Run threat modelling and security design reviews for new and changed capabilities. This includes: * Facilitating threat modelling sessions with engineering and product teams. * Reviewing authentication and authorization designs. * Assessing API exposure, data flows, trust boundaries, and abuse cases. * Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse. * Documenting key findings, recommendations, and residual risks. 4. OFFENSIVE SECURITY AND ADVERSARIAL TESTING Carry out and coordinate offensive security testing across DTS products and platforms. This includes: * Performing hands-on security testing of products, APIs, and workflows. * Coordinating external penetration tests. * Supporting red team and purple team exercises where required. * Testing abuse cases and attacker paths. * Testing access control, authentication, authorization, and data leakage risks. * Validating remediation of security findings. * Feeding material risks into the ISMS and Risk Officer for tracking. 5. API, INTEGRATION AND DATA PRODUCT SECURITY Provide security assurance for APIs, integrations, and data products. This includes: * Reviewing externally exposed APIs and partner integrations. * Assessing rate limiting, authorization, tenant isolation, logging, abuse prevention, and data leakage controls. * Supporting secure integration between InfoSum, Open Intelligence, Resolve, WPP Open, and third-party platforms. * Reviewing data product workflows for misuse, excessive access, or unintended exposure. * Working with Privacy Engineering on privacy-sensitive APIs, algorithms, and outputs. 6. AI AND AGENTIC SECURITY TESTING Provide hands-on security review and adversarial testing for AI-enabled and agentic capabilities. This includes: * Testing prompt injection, tool misuse, data leakage, and excessive agency. * Reviewing how agents access APIs, data, tools, and workflows. * Testing whether agent permissions can be bypassed or escalated. * Assessing action boundaries and human approval points. * Working with Identity, AI, and Data Access Governance to validate agent access models. * Documenting AI and agentic security risks and remediation actions. 7. VULNERABILITY TRIAGE AND REMEDIATION SUPPORT Help teams understand, prioritise, and fix security vulnerabilities. This includes: * Reviewing vulnerability findings from scans, penetration tests, code reviews, cloud tools, and external reports. * Prioritising findings based on exploitability, exposure, data sensitivity, and business impact. * Working directly with engineers to define remediation options. * Validating that fixes are effective. * Supporting exception and risk acceptance decisions where remediation is delayed. * Ensuring significant issues are visible through the DTS risk process. 8. ENGINEERING ENABLEMENT AND SECURITY COACHING Act as a practical security partner to engineering teams. This includes: * Providing secure implementation guidance. * Creating lightweight security patterns and examples. * Coaching engineers on common application, API, and AI security risks. * Helping teams understand the “why” behind security requirements. * Supporting a culture where security is part of product quality, not a separate approval gate. ---------------------------------------------------------------------------------------------------------------------------------- KEY ACCOUNTABILITIES The Product, Application and Offensive Security Lead will be accountable for: * Hands-on application and product security support across DTS. * Secure SDLC guidance and practical adoption. * Threat modelling and security design reviews. * API, integration, and data product security reviews. * Offensive security and adversarial testing activity. * AI and agentic security testing. * Vulnerability triage, remediation guidance, and fix validation. * Coordination with ISMS/Risk to ensure material risks and exceptions are tracked. * Helping engineering teams build secure systems without unnecessary delivery drag. ---------------------------------------------------------------------------------------------------------------------------------- SKILLS AND EXPERIENCE The successful candidate will have: * Strong hands-on experience in application security, product security, offensive security, security engineering, or penetration testing. * Good understanding of modern software engineering, APIs, SaaS platforms, distributed systems, and cloud-native applications. * Experience with threat modelling and secure design reviews. * Practical knowledge of common application and API security risks, including authentication, authorization, tenant isolation, injection, data leakage, privilege escalation, and supply chain risk. * Experience using security testing tools and techniques across web applications, APIs, cloud services, and CI/CD pipelines. * Familiarity with SAST, DAST, SCA, secrets scanning, dependency scanning, and vulnerability management workflows. * Experience working directly with engineers to remediate findings. * Understanding of AI and agentic security risks would be highly valuable. * Ability to communicate clearly with engineering, product, architecture, security, and leadership stakeholders. * A pragmatic, delivery-aware approach to security. ---------------------------------------------------------------------------------------------------------------------------------- LEADERSHIP EXPECTATIONS The Product, Application and Offensive Security Lead is expected to: * Be hands-on and technically credible with engineering teams. * Act as a trusted security partner, not just a reviewer or approver. * Challenge insecure designs constructively. * Help teams find practical ways to reduce risk. * Prioritise issues based on real-world exploitability and business impact. * Work across multiple DTS product areas without becoming a delivery bottleneck. * Escalate material risks clearly through the appropriate governance routes. * Promote secure engineering habits through practical guidance and example. ---------------------------------------------------------------------------------------------------------------------------------- SUCCESS MEASURES Success in the role will be measured by: * Security being embedded earlier in product and engineering delivery. * Reduction in high-risk application, API, and product vulnerabilities. * Regular threat modelling and security reviews for critical DTS capabilities. * Effective offensive and adversarial testing of products, APIs, and workflows. * Faster remediation of penetration test and security testing findings. * Improved security assurance for AI and agentic workflows. * Engineering teams receiving practical, actionable security guidance. * Material security risks being surfaced and tracked through the DTS risk process. * Security being viewed by engineering teams as an enabler of trusted delivery rather than a blocker. You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
About 1st Formations At 1st Formations, we empower entrepreneurs to start, run, and grow their businesses with confidence. Running a business shouldn’t be slowed down by company formation, statutory compliance, accounting, or payroll. From day one, these essentials should be seamless, reliable, and intelligently handled — freeing founders to focus on building and scaling. We’re a leading UK provider of company formation and compliance services, building a modern, fully integrated technology platform that supports founders at every stage of their journey. Our platform brings together formation, compliance, accounting, payroll, and ongoing business support in one cohesive experience. No stitched-together services. No legacy workflows disguised as software. Just a single, scalable platform built for ambitious founders who want to move fast, stay compliant, and grow with confidence. Why Join Us Now? You’ll be joining a business with strong momentum, clear direction, and real opportunity for progression. * £18m annual revenue, including £9m ARR * Over 1 million companies formed * Certified B Corp and Carbon Neutral Business * Forecast to grow 5x–10x over the next three years The Role The MLRO will serve as the registered Money Laundering Reporting Officer, with full accountability for suspicious activity reporting, regulatory engagement, and the consistent application of the highest regulatory and governance standards across the business. This is a senior, operationally hands-on role that combines day-to-day MLRO responsibilities with strategic compliance direction - protecting the business through robust controls, proactive risk management, and continuous regulatory horizon scanning. The postholder will act as a business-enabling partner, working closely with the COO and CEO to translate regulatory requirements into practical action plans, ensuring commercial growth is pursued confidently within a defined risk appetite. We are ideally looking for candidates with experience in the company formations (Trust or Company Service Provider (TCSP)), or accounting sector. Key Responsibilities • Serve as the registered MLRO, with full responsibility for suspicious activity reporting reviews, external SAR submissions, and direct engagement with the NCA and FCA • Own and evolve the group risk framework, including our AML policies and procedures, risk registers and risk appetite statements • Lead AML and financial crime compliance across the group, ensuring ongoing adherence to the Proceeds of Crime Act, Money Laundering Regulations, and UK GDPR • Oversee KYC and CDD controls, sanctions screening, and SAR reporting - continuously optimising processes to handle high volumes of customer onboarding and transactional activity • Drive regulatory horizon scanning, proactively tracking changes to the regulatory landscape and briefing senior leadership with clear, actionable plans • Maintain and improve control effectiveness, overseeing first-line self-assessment and second-line assurance activity, ensuring audit findings are actioned within agreed SLAs • Partner with business leaders and commercial teams to enable growth by embedding compliance into operational and product development processes • Manage relationships with external regulators, auditors, and relevant third parties with professionalism and confidence • Oversee compliance tools and technologies, including AML monitoring systems and case management platforms • Monitor and report on risk posture and compliance KPIs, providing regular updates to the COO, CEO, and senior leadership What We Are Looking For * 10+ years of compliance and risk leadership in a regulated sector, ideally with direct experience in company formations (TCSP) or accountancy services * Proven experience as an MLRO or Deputy MLRO, with direct responsibility for SAR submissions and engagement with the NCA and FCA * Deep expertise in AML and financial crime, with strong working knowledge of the Proceeds of Crime Act, Money Laundering Regulations, GDPR, and FCA guidance * Experience building and managing risk frameworks using the three-lines-of-defence model at scale * A track record of regulatory horizon scanning and delivering compliance change programmes on time * Familiarity with AML monitoring systems and case management platforms * A pragmatic, business-enabling mindset - able to advise on risk-based decisions that support growth rather than obstruct it * Strong stakeholder management skills, with the ability to communicate complex regulatory matters clearly to senior leadership and external partners * Analytical, data-driven approach to assessing risk posture and prioritising remediation * Relevant professional qualification (ICA, CAMS, CISI, or equivalent) strongly advantageous; Bachelor's degree required What We Offer * £80- 120k and comprehensive benefits package * Hybrid working model- Mondays, Wednesdays and Fridays in the Office. * Real opportunities for progression as the business scales * The chance to influence both customer experience and product development * A culture that values ownership, impact, and continuous learning Equal Opportunities 1st Formations is an equal opportunity employer and is committed to creating a diverse and inclusive workplace. We consider all applicants for employment without regard to race, colour, religion, sex, national origin, sexual orientation, age, citizenship, marital status, criminal history, disability, or gender identity. We encourage individuals from all backgrounds to apply. If you have a disability or special need that requires accommodation, please let us know.