Risk & Compliance Manager
Job Description
š¦ About Birdie At Birdie, weāre reimagining care for older adults. Weāre building the technology that powers the future of home healthcare, empowering care teams with tools to deliver better, more dignified care, and enabling older people to thrive in their own homes for longer. Our all-in-one solution powers millions of care visits every month, equipping care providers with the tools they need to deliver exceptional, efficient care. Weāre not here to tinker at the edges. Weāre here to radically transform a broken system. Thatās why weāve built an all-in-one platform that supported over 60 million care visits and enabled care for 116,000 individuals in 2025 , and we continue to grow our impact. Weāre scaling fast, but staying true to our purpose. Thatās why weāre proud to be a B Corp , using business as a force for good. Founded in 2017, Birdie is backed by world-class investors like Index Ventures, Sofina and Omers. In 2023, we ranked #6 in the Deloitte Fast 50 , making us one of the fastest-growing tech companies in the UK. You can check out more about our impact and recognition here . But speed isnāt the point. Impact is. ā”ļø Your mission As Birdie's Risk & Compliance Manager, you will be responsible for defining, embedding, and monitoring Birdieās compliance frameworks across data protection, information security, and health system governance. You will lead our compliance programs for critical health-sector standardsāincluding the NHS Data Security and Protection Toolkit (DSPT) and Digital Social Care Record (DSCR) complianceāand assure all requirements for core NHS service integrations such as GP Connect and the Patient Demographic Service (PDS) . You will work closely with our engineering, product, legal, and operational teams, and will be supported by our General Counsel and external Data Protection Officer (DPO). š¦øāāļø How you will contribute Own data protection compliance across product and operations, working with our external DPO on DPIAs, RoPA and information rights processes Lead the annual NHS DSPT submission and keep us at "Standards Met" year-round, alongside DSCR and clinical risk alignment (DCB0129/0160) where applicable Assure our NHS interoperability connections - GP Connect, PDS, and future health data integrations - meet compliance and data flow standards Maintain Birdie's risk register and control frameworks, running third-party risk assessments and internal audit cycles Lead incident response for data protection and compliance breaches, from root-cause analysis through remediation Build KRIs/KPIs for leadership and the board, and champion a proactive, risk-aware culture across tech, product and go-to-market teams 𤩠Youāll thrive here if... You have strong familiarity with NHS DSPT, DSCR, and NHS API assurance frameworks (GP Connect, PDS) You know UK GDPR and the Data Protection Act 2018 inside out, and can apply it practically in a fast-moving SaaS environment You've led or played a major role in risk assessments, control design, and managing a business risk register - ideally alongside an external DPO or legal counsel You can turn complex legal and health-system regulations into clear, actionable requirements for engineers and product teams You write and speak with clarity, whether it's a policy, an executive report, or team training You have sound judgment and the confidence to challenge while keeping strong working relationships; a relevant certification (CIPP/E, CIPM, CISM, CISA, or similar) or familiarity with ISO 27001/Cyber Essentials/SOC 2 is a plus š§ Imposter syndrome is real ā and we donāt expect you to tick every box. If you're excited about our mission and think you could make a difference here, we want to hear from you. š What youāll get from us We believe people do their best work when theyāre supported, trusted and inspired. Hereās how we build a world-class employee experience: šø Compensation Competitive base salary, reviewed against benchmarks annually Generous stock options - because weā