Company
Healthcare
ComplianceandRegulatoryAssociate
Neural analysis suggests this role is
optimal for Mid+ candidates.
“Compliance and Regulatory Associate. Skills: Information security, Data protection, Regulatory affairs, Quality management. Update policies, procedures, and control evidence. Prepare for internal and external audits”
Industry & Context.
What They're Looking For.
Must Have
1-2 years experience in information security, compliance, or data protection role, Working knowledge of ISO 27001 and/or GDPR / UK GDPR, Organisational skills to manage multiple workstreams, Methodical and documentation-oriented, Clear communicator able to chase colleagues
Nice to Have
Familiarity with ISO 13485 or quality management systems, Experience with medical device software regulation, Exposure to supplier risk management, Experience working with US and UK regulatory frameworks simultaneously, Experience with compliance tooling or workflow automation
What You'll Do.
Prepare for internal and external audits
Maintain records of processing activities
Support data subject access requests
Track compliance obligations under UK GDPR and US
Coordinate security testing activity
and track penetration testing
Follow up on remediation actions
Process third-party security assessments
Maintain vendor risk register
Chase outstanding vendor responses
Manage security onboarding and offboarding processes
Review access controls
Maintain security incident register
Support incident triage and documentation
Track CAPAs to closure
Prepare responses to customer security questionnaires
Prepare assurance requests for external partners
Track outstanding sign-offs
Maintain and update SOPs and work instructions
Assist with audit evidence preparation
Log complaints and adverse events
Monitor closure timelines for complaints and CAPAs
Support change control administration
Track change request documentation
Assist with regulatory filing
Maintain technical files for UK and US medical
Provide documentation support for new product introductions
Support QMS supplier qualification processes
Coordinate and track evidence for audits
Liaise with Engineering
Communicate new processes
Embed controls across functions
Identify opportunities to reduce manual overhead
How You'll Work.
Team & Collaboration
Work with Information Security Lead/DPO; Work with Regulatory Affairs Specialist; Liaise with Engineering, Product, and Operations
Communication Scope
Chase colleagues professionally
Full Job Description
This is a newly created role, driven by business growth and the expanding scope of our compliance programme. You will work directly alongside our Information Security Lead/DPO and our Regulatory Affairs Specialist, providing hands-on support across both information security and quality/regulatory functions. Your primary focus will be information security and data protection, supporting ISMS operations, supplier assessments, and infosec-related processes, and supporting quality management and regulatory affairs. You will own a real workload from day one, with clear mentorship and room to grow into a specialist role. We welcome applications from people with a variety of backgrounds and experiences. Compliance expertise can be built in many different ways, and we're more interested in how you think, how you work, and what you bring to the team than in whether your CV matches every bullet point. If this role interests you, please apply. KEY RESPONSIBILITIES Information Security & Data Protection - Support the maintenance of our ISO 27001 ISMS by updating policies, procedures, and control evidence, and helping prepare for internal and external audits. - Assist with data protection administration: maintaining records of processing activities, supporting data subject access requests, and tracking compliance obligations under UK GDPR and relevant US frameworks including HIPAA. - Coordinate security testing activity, working with the InfoSec Lead to scope, schedule, and track penetration testing and vulnerability assessments, and following up on remediation actions. - Support supplier and vendor management: processing third-party security assessments, maintaining the vendor risk register, and chasing outstanding responses. - Manage security-related onboarding and offboarding processes, including access control reviews and checklist completion. - Maintain the security incident register, support initial triage and documentation of incidents, and track CAPAs through to closure.
Applying for this Compliance and Regulatory Associate role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.