Security and Compliance Manager

Sierra Sierra · AI Frontier · London, United Kingdom · Compliance

This role focuses on customer trust enablement, AI governance, and ensuring AI systems align with regulations like the EU AI Act. The manager will translate regulatory requirements into technical controls for model governance, agent security, and data handling, acting as a liaison between Legal, Engineering, and Product teams. The role also involves managing customer-facing trust materials and representing the company in audits.

What you'd actually do

  1. Act as a primary point of accountability for customer trust enablement, including participation in customer meetings, security reviews and AI governance.
  2. Contribute to AI Governance including building guardrails to align with AI regulations (EU AI Act, ISO 42001, NIST AI RMF and local EU laws).
  3. Partner closely with Legal and Privacy to interpret regulatory requirements and support complex, security-sensitive contractual discussions, escalating risks and tradeoffs appropriately.
  4. Collaborate with Engineering and Product to ensure expectations are reflected in system design and operational effectiveness.
  5. Translate regulatory and privacy expectations into scalable, region-aware technical controls across model governance, agent security and safety, and data handling.

Skills

Required

  • 8+ years of experience in security compliance, privacy, or regulatory roles in SaaS, fintech, or AI companies.
  • Deep experience with EU regulatory frameworks, including GDPR, DORA, EU AI Act and emerging AI regulations, paired with strong awareness of US and APAC regulatory norms.
  • Demonstrated ability to operate globally understanding where requirements must diverge and where alignment is possible.
  • Experience engaging directly with enterprise and regulated customers as a trusted representative of security, privacy, and compliance.
  • Ability to translate abstract or evolving regulatory requirements into defensible, real-world practices.
  • Comfort operating in ambiguity, making reasoned judgment calls, and clearly articulating rationale and tradeoffs.
  • Strong written and verbal communication skills, including close collaboration with Legal and external stakeholders.

Nice to have

  • Direct experience preparing for or operationalizing DORA, EU AI Act or ISO/IEC 42001.
  • Experience working in and/or supporting fintech or AI companies globally
  • Familiarity with AI governance frameworks such as NIST AI RMF or CSA AI controls.
  • Experience navigating cross-border data transfer, residency, and localization consideration in a multi-cloud environment.
  • Prior experience in customer-facing, sales-adjacent, or deal-support contexts.
  • Experience automating global security and compliance workflows.

What the JD emphasized

  • AI regulations
  • EU AI Act
  • AI governance