Sobre este puesto de Senior Cyber Risk & Compliance Role en Oodle Finance
Senior Cyber Risk and Compliance Lead
🌏 Manchester
💷 Competitive salary + Discretionary Company Bonus Scheme
⏰ Monday – Friday (37.5 hours per week - hybrid)
💖 Our perks
- 🌏 25 days holiday (rising to 28 after 3 years’ service) plus bank holidays
• 🤒 Private Medical – via Vitality (incl. family cover & rewards)
• 🤒 Health cash plan – via Health Shield
• 👍 Pension – Oodle contributes 5%
• 🥝 Free breakfast, drinks and fruit in the office
• 🤟 Employee discounts
• 👌 1 day volunteer day per year
• ⭐ Mental health care – 6 free counselling sessions (EAP)
• 🤧 Enhanced company sick pay
• 👨 Enhanced family leave
🚗 Oodle – who are we?
Our mission is to be the UK’s simplest way to find and finance a great value used car. We want to put car buyers back in control and make the car buying experience as simple, straightforward, and joyful as possible. We’re a team of 450 people across Manchester, Oxford and London, and 2026 is shaping up to be another exciting year!
🙌 The Role
We are looking for a Senior Cyber Risk and Compliance Lead to strengthen and scale our cyber risk and governance capability across Oodle.
This is a senior individual contributor role with accountability for driving maturity, consistency and effectiveness across cyber risk and compliance activities. You will act as the primary day-to-day subject matter expert for cyber risk and governance, ensuring our frameworks and practices keep pace with business growth, regulatory expectations, and emerging risks including AI.
Working within the InfoSec team, and in close partnership with the Head of InfoSec, you will take hands-on responsibility for delivering our risk and compliance programme, collaborating with senior stakeholders across Technology, Product, Legal, and Operations to proactively identify, assess, and provide expert guidance on managing risk.
What you’ll be getting up to:
- Take day-to-day responsibility for the Cyber Risk Register, keeping it current, prioritised, and reflective of the evolving threat landscape
- Drive cyber risk assessments and threat modelling, providing SME-level input on AI and emerging technology risks and delivering pragmatic, proportionate guidance to colleagues and business stakeholders
- Deliver third-party security risk assessments and lifecycle monitoring, ensuring supplier risk is understood and managed consistently
- Maintain and evolve the security policy and control framework, leading the day-to-day delivery of compliance activities across key frameworks, including audit preparation and remediation tracking
- Drive consistent standards and quality across all cyber risk activities, including managing the risk exception process end-to-end
- Support cyber awareness and culture initiatives to help embed secure behaviours across the organisation
- Develop and maintain the cyber risk metrics and reporting framework, translating risk posture into clear KPIs/KRIs and preparing input into governance forums and senior leadership packs
- Monitor the emerging threat, regulatory landscape and relevant sector obligations, providing horizon scanning and timely guidance to keep the organisation ahead of compliance obligations
You’ll be a great fit if you have:
- 4+ years' experience in cyber risk, information security or GRC roles, with demonstrated experience leading risk and compliance activities
- Strong knowledge of frameworks such as ISO 27001, NIST CSF, and Cyber Essentials
- Proven experience owning and delivering risk registers and risk assessment programmes
- Experience leading supplier and third-party risk management activities
- Strong understanding of compliance expectations including PCI-DSS and UK GDPR / data protection obligations
- A demonstrated ability to influence and challenge at senior levels, acting as a trusted SME and translating complex cyber risks into clear, business-relevant insight
- A proactive, structured and outcome-focused approach