Rodeo
ResourcesPartnersSign in

EC Markets LTD

Data Governance Consultant

London Borough of Islington
Posted 1 day ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Company Overview

EC Markets is a globally recognised financial brokerage, providing advanced FX and CFD trading services. As part of its growing finance team, EC Markets is seeking an Accounts Assistant to support daily financial operations and reporting, ensuring compliance, accuracy, and efficiency across the department.

Role Purpose

Support the business in achieving launch readiness by assessing, documenting, and implementing the data governance, privacy, and information security controls required for an FCA-regulated financial services platform. The consultant will work across Product, Technology, Operations, Risk, and Compliance to ensure customer data is appropriately governed, protected, and processed in accordance with UK GDPR and FCA expectations. This is a delivery-focused engagement with the primary objective of identifying launch blockers, closing critical gaps, and leaving behind sustainable governance processes.

Key Responsibilities

Data Discovery & Governance

  • Lead an end-to-end review of customer data across the organisation, including:
    • What data is collected
    • Why it is collected
    • Where it is stored
    • Who has access
    • How it moves through systems
    • Who external processors are
  • Deliverables: data inventory, data classification framework, Information Asset Register, data flow diagrams.

GDPR & Privacy

  • Review compliance with UK GDPR and Data Protection Act requirements, including:
    • Lawful basis
    • Consent
    • Retention
    • Deletion
    • Subject access requests
    • International transfers
    • Processor agreements
  • Deliverables: gap assessment, risk register, required remediation plan.

Data Security Review

  • Assess current controls covering:
    • RBAC (role-based access control)
    • MFA (multi-factor authentication)
    • Encryption
    • Secrets management
    • Audit logging
    • Backup strategy
    • Disaster recovery
    • Production access
  • Identify launch-critical risks.

AI & Data Usage Governance

  • Review the use of AI/LLM tools (e.g. Claude, other LLMs) and internal reporting tools. Define:
    • Acceptable use
    • Access model
    • PII handling
    • Prompt handling
    • Data retention
    • User permissions
  • Produce governance recommendations.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Third Party Risk

  • Review all vendors processing customer data, including cloud providers, AI providers, communications platforms, and payment providers. Ensure processor agreements, data residency, contractual protections, and security posture are appropriate.

Policies & Documentation

  • Produce or review:
    • Privacy Notice
    • Data Retention Policy
    • Information Security Policy
    • Data Classification Policy
    • Access Control Policy
    • Incident Response Plan
    • Data Governance Policy

Launch Readiness Assessment

  • Produce a quick-turnaround executive report identifying:
    • Green — ready for launch
    • Amber — acceptable with known risks
    • Red — must be resolved before launch
  • With clear, prioritised, actionable tasks to achieve launch readiness.

Success Criteria

By the end of the engagement, the business should be able to confidently answer:

  • What customer data do we hold, and why do we hold it?
  • Where is it stored, and who has access?
  • Is that access appropriate?
  • Where does data leave our environment?
  • Which suppliers process customer data?
  • What data is considered sensitive?
  • Are we compliant with GDPR and FCA expectations — and can we evidence this?

Essential Requirements

Regulatory & Compliance Background

  • Demonstrable experience leading data governance and privacy programmes for FCA-regulated or financial services businesses.
  • Prior experience supporting an FCA authorisation process or a regulated product launch, ideally in fintech or payments.
  • Strong working knowledge of UK GDPR and the Data Protection Act 2018 — lawful basis, consent, retention, deletion, subject access requests, and international transfers.
  • Practical understanding of FCA expectations around data handling and customer outcomes, not just theoretical GDPR knowledge.
  • Experience producing gap assessments, risk registers, and remediation plans that stand up to regulatory scrutiny.

Data Discovery & Documentation

  • Hands-on experience running end-to-end data discovery and mapping exercises across an organisation, not just reviewing existing documentation.
  • Track record of producing data inventories and data classification frameworks from scratch.
  • Experience building Information Asset Registers and data flow diagrams.
  • Ability to identify data processors and third parties handling customer data as part of a discovery exercise.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Technical Security Assessment

  • Ability to assess technical security controls directly with engineering teams, rather than relying solely on policy-level documentation.
  • Working knowledge of RBAC (role-based access control) and MFA (multi-factor authentication) implementation.
  • Familiarity with encryption standards and secrets management practices.
  • Experience reviewing audit logging, backup strategy, disaster recovery, and production access controls.
  • Ability to translate technical findings into launch-critical risk ratings for non-technical stakeholders.

AI, Data & Vendor Governance

  • Practical experience governing the use of AI/LLM tools (e.g. Claude, other LLMs) in a regulated environment, including acceptable use and access models.
  • Understanding of PII handling and prompt-handling risk in AI-assisted workflows.
  • Experience with data platform governance (e.g. Snowflake) — data retention and user permissions.
  • Experience conducting third-party and vendor risk assessments, including cloud providers, AI providers, communications platforms, and payment providers.
  • Working knowledge of data residency requirements and contractual/processor agreement protections.

Delivery, Communication & Working Style

  • Track record of producing clear, regulator-ready policy documentation (privacy, retention, information security, access control, incident response) at speed.
  • Comfortable operating as an autonomous, hands-on contractor in a lean startup environment — able to self-direct and work with minimal oversight.
  • Ability to prioritise launch-critical risk over process, making pragmatic calls where a startup may lack mature governance infrastructure.
  • Strong stakeholder management skills across Product, Technology, Operations, Risk, and Compliance.
  • Ability to translate technical and regulatory detail into a clear, executive-level Red/Amber/Green narrative.
  • Proven ability to deliver a full assessment and documentation set against a tight, fixed deadline ahead of a live launch date.

Location

30 City Road, London

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Data Governance
UK GDPR
FCA Compliance
Data Mapping
Privacy Impact Assessment
Information Security
Third Party Risk Management
AI Governance
Risk Register
Data Classification
RBAC
MFA
Stakeholder Management
Policy Writing
Data Inventory
Regulatory Reporting

Location

London Borough of Islington, England, United Kingdom

Sign up to applySee more jobs like this