About this Compliance and Regulatory Manager - Digital Health (SaMD) role at Isla
🕙 Role details: This is a full time role for 40 contracted hours per week
💷 Salary: £52,000 - £68,000
🌍 Location: We are a hybrid team, based throughout the UK. We offer the flexibility to work outside of the UK up to 90 days per year, however you must be able to work and live permanently within the UK, and travel to London at least 4 times a year for team meeting sessions and additionally as needed.
Who we are
Isla Health is a venture-backed health-tech startup, supporting our partners across the UK, EU and internationally. We’ve built a new category of healthcare technology which we refer to as the Digital Pathway Platform (DPP). Founded in 2019, we now support 25% of NHS Trusts and see 2 million submissions on the platform every year.
As a company, we’re all laser focused on enabling a scalable model of care which empowers healthcare staff and improves patient outcomes. The DPP supports this by setting up digital pathways which are remote-first and asynchronous. As pathways harness sophisticated automation, clinical algorithms and intelligent cohorting, patients always take the optimised route through their pathway, thereby delivering a step change in clinical productivity.
The role
We're looking for a Compliance Manager to take ownership of quality, regulatory and business compliance across Isla Health.
As our platform scales, we expand internationally and our technology supports increasingly sophisticated clinical pathways, our regulatory and compliance obligations are becoming more complex. We need someone who can ensure we're meeting those obligations, managing risks proactively and embedding the right standards across the business.
You'll oversee our Quality Management System (QMS), drive our medical device regulatory readiness, and manage a broad range of compliance activities spanning information governance, data protection, IT security and wider business operations.
A big part of this role is ensuring that our processes and controls aren't just documented, but are consistently understood and followed. You'll work closely with teams across Isla to identify gaps, improve how we operate and make sure everyone understands their responsibilities when it comes to quality, security and compliance.
This is a highly hands-on role with significant ownership. You'll work alongside our Engineering, Product, Delivery and Operations teams, as well as external regulatory and clinical specialists, to translate complex requirements into practical, scalable processes.
We're looking for someone who is highly organised, detail-oriented and proactive. Someone who enjoys getting into the detail, but can also step back, challenge how things are done and drive improvements across the business. You'll play an important role in ensuring Isla can continue to grow quickly while maintaining the high standards of quality, safety and security our customers rely on.
What you’ll do
- Own our Quality Management System: Act as our Quality Management Officer (QMO), ensuring our QMS is effective, up to date and embedded across Isla. Lead internal audits, CAPAs, non-conformances, change control, supplier monitoring and management reviews, ensuring issues are resolved, actions are completed and improvements are sustained.
- Drive medical device regulatory compliance: Take ownership of our medical device regulatory roadmap, working with external specialists and internal teams to progress our Class IIa ambitions, including classification, registration, ISO 13485 readiness, technical documentation and post-market surveillance. Ensure requirements are understood, work is prioritised and progress is driven through to completion.
- Coordinate clinical safety compliance: Work closely with our Clinical Safety Officer, Product and Engineering teams to ensure clinical safety requirements are reflected in our processes, documentation and product development. Coordinate the follow-through of clinical risk assessments, safety actions and relevant incident reporting, ensuring clear ownership and appropriate evidence.
- Embed compliance across Isla: Make sure teams understand and follow the standards relevant to their work, from software development and product releases to information security and day-to-day operations. Identify gaps, train colleagues and challenge practices that don't meet our standards.
- Own IT and information security compliance: Drive Cyber Essentials and Cyber Essentials Plus certifications, penetration testing and security assurance. Work with Engineering and other teams to make sure vulnerabilities are addressed and staff consistently follow security best practices.
- Lead information governance and data protection: Own the day-to-day implementation of our data protection obligations across the UK and international markets, including GDPR, data retention, subject access requests, data protection impact assessments, incident management and NHS information governance requirements. Work closely with our designated Data Protection Officer (DPO) to ensure risks are identified, obligations are met and appropriate controls are in place.
- Manage wider business compliance: Keep on top of our business policies, insurance, supplier obligations and contractual compliance requirements, ensuring they remain appropriate as Isla grows.
- Navigate international regulatory requirements: Understand how medical device, healthcare, data protection and security requirements differ across the UK, EU and other markets. Identify what Isla needs to do to enter new markets and remain compliant as we expand.
- Manage external assurance and regulatory relationships: Be the main point of coordination for regulatory advisers, auditors and certification bodies. Know when to bring in specialist expertise and ensure recommendations turn into actions.
Requirements
We're looking for someone with hands-on experience in quality, regulatory and compliance management within healthtech or medical devices.
You'll understand medical device regulation, quality management systems and GDPR, including how compliance requirements differ across international markets. More importantly, you'll know how to put those requirements into practice, bringing teams together, improving processes and making sure things get done.
You'll be successful in this role if you have experience in:
Medical device regulation: Practical experience with medical device classification, registration and ongoing regulatory compliance, ideally involving Software as a Medical Device (SaMD) and Class IIa requirements.
- Quality management: Experience implementing, maintaining and improving a Quality Management System, including ISO 9001 and ideally ISO 13485.
- Data protection and international privacy regulation: Strong working knowledge of UK and EU GDPR, with practical experience managing data protection compliance across multiple jurisdictions.
- Information governance and security: A good understanding of information security and governance requirements, with experience coordinating compliance activities, assurance or certifications such as NHS DSPT, Cyber Essentials or ISO 27001.
- Quality assurance: Experience managing internal audits, corrective and preventive actions (CAPAs), document control, change management, risk assessments and continuous improvement.
- Process implementation: Experience developing clear policies, procedures and controls, and ensuring they are consistently adopted and followed across an organisation.
- Stakeholder management: Experience working with cross-functional teams, technical specialists, external advisers and senior stakeholders to drive accountability and improvements.
Nice to have:
- Experience navigating international healthcare and medical device regulations, including UK MHRA requirements, EU MDR or equivalent frameworks in markets such as Australia.
- Experience acting as a Quality Management Officer (QMO) or holding responsibility for a QMS in a regulated organisation.
- Experience acting as a designated Data Protection Officer (DPO), ideally within healthcare technology or an organisation handling sensitive personal data.
- Experience with regulatory submissions, technical documentation, post-market surveillance or medical device certification.
- Experience coordinating penetration testing, security assessments or remediation programmes.
- Experience working in a healthtech startup or scale-up where you've helped establish or significantly improved compliance processes.
We appreciate you may not meet every requirement listed above. If you're excited by the role and believe you could make a meaningful contribution at Isla, we'd love to hear from you.
Benefits
You'll join a small, ambitious team where you'll have real ownership from day one. This is a role for someone who enjoys variety, loves solving problems and wants to play an important part in scaling a company that's transforming healthcare. As Isla grows, you'll have the opportunity to grow with us, taking on increasingly strategic responsibilities and helping shape how the business operates.
You’ll also benefit from all of our perks:
🏡 Work where you do your best work either from home or at our office in 131 Finsbury Pavement (Moorgate) 🏢
📈 Share in our success with EMI share options
🕜 Flexible working times
🌍 Work abroad for up to 90 days per year
🏖️ 25 days annual leave on top of bank holidays. Plus, take your birthday off and another significant day off of your choice 🎂
🍜 Quarterly meal on us enjoy up to £75 to treat friends or family
🧘♀️ Wellbeing allowance (£50 per month for gym membership/wellbeing activities) or private medical insurance
💡 Salary sacrifice pension plus access to Mintago for retail discounts, financial coaching, childcare vouchers, virtual GP and more
🎉 Enhanced parental leave to support your family when it matters most
🎳 Quarterly team socials
📚 An annual learning budget to support your growth
💗 Work with purpose - you'll be delivering social impact through improved patient healthcare
🚀 Join at an exciting stage - we're a well-funded, rapidly growing health tech company tackling a global challenge
🌱 Help shape the future of Isla - your ideas won't disappear into layers of management. You'll have real ownership, real impact, and help define how we grow the business
What is the hiring process for this role at Isla?
Interviewing with us for the role will be split into 3 stages:
- A screening interview with someone from our Operations team- 15 minutes
- An interview with our Senior Operations Manager - 1 hour
- A final interview with our Co-founder CTO and MDR Consultant - 30 minutes
Isla is an equal opportunity employer and is committed to building an inclusive and diverse team. We encourage all qualified candidates to apply. Isla does not discriminate against anyone on the basis of their race, gender, disability, religion, national origin, age, or any other protected category. We choose to celebrate our team’s differences and see them as one of our most valuable assets.Recruitment is not one-size-fits-all and we're happy to tailor our hiring process to better meet the needs of individual applicants. Please email [email protected] with any requests for support.