Rodeo
Get started

Waystone

Enterprise Resilience Governance and Compliance Lead

Ireland
Posted about 15 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About Waystone

Waystone is a leading asset-servicing solutions provider of institutional governance, administration, risk, and compliance services to financial institutions. With over 25 years’ experience and a comprehensive range of specialist services to its name, Waystone helps our clients structure, operate, and grow through our expertise, innovation, and digitisation, backed by the operational scale to support global expansion.

Job Description

The Enterprise Resilience Governance and Compliance Lead is responsible for establishing, embedding, and continuously enhancing Waystone’s enterprise-wide operational and digital resilience governance and compliance capability. The role spans four integrated disciplines:

  • IT and regulatory compliance — maintaining a globally consistent control framework across DORA, and other applicable regulatory obligations.
  • Operational resilience compliance — ensuring Waystone has sufficient controls in place to prevent, withstand, respond to, and recover from disruptions to important business services across all jurisdictions.
  • AI governance — supporting the Group Head of Enterprise Resilience in the governance of the AI Management System (AIMS) aligned to ISO 42001:2023 and the EU AI Act, and supporting the AI Working Group (AIWG).
  • Policy governance — owning the enterprise policy framework for IT and Operational Resilience, including the development, review, version control, and retirement of policies, standards, and procedures across the Enterprise Resilience and IT functions.

Reporting to the Group Head of Enterprise Resilience, the role provides oversight and subject-matter leadership for operational resilience, AI governance, ICT risk, business continuity, technology continuity, third-party resilience, and emerging technology risk, ensuring compliance with global regulatory frameworks including (but not limited to):

  • EU Digital Operational Resilience Act (DORA)
  • UK FCA / PRA Operational Resilience
  • Central Bank of Ireland operational resilience expectations
  • Global standards such as ISO 22301, ISO 27001, ISO 42001:2023, NIST, and IOSCO FR/02/2026

The role operates across Technology and Operations acting as a key interface with business, regulators, auditors, and clients, and ensuring resilience is demonstrable, testable, and embedded into day-to-day operations.

Key Responsibilities

  • Design, implement, and maintain a globally consistent Enterprise Resilience Governance and Compliance framework, encompassing DORA, FCA/PRA Operational Resilience, Central Bank of Ireland expectations, GDPR, EU AI Act, and ISO 42001:2023, and other applicable global regulations; including ownership of the enterprise policy framework across resilience, AI governance, and IT compliance domains.
  • Implement and operate a Jurisdictional IT, Operational Resilience, and AI Compliance Management Programme, including the development and maintenance of jurisdictional regulatory gap analyses across all relevant regions, encompassing AI Act obligations, operational resilience requirements, and ICT risk controls.
  • Maintain a global compliance calendar, ensuring all resilience, ICT, and regulatory obligations, reviews, and reporting deadlines are identified, tracked, and met.
  • Own the policy governance framework across the Enterprise Resilience and IT functions, including the development, periodic review, version control, approval routing, and retirement of policies, standards, and procedures; maintain a policy register; ensure all governance documents are aligned to applicable regulatory requirements and ISO standards; and oversee policy attestation and awareness activities across the functions.
  • Provide oversight of IT and operational resilience controls, including the regular review and update of the control frameworks to reflect regulatory change, emerging risk, and internal policy updates.
  • Support the Chief Information Officer in performing the Financial Conduct Authority (UK) SMF24 (Chief Operations Function) role.
  • Support the Cloud Officer and Autonomous Systems Officer, ensuring regulatory compliance for AI governance, cloud governance, outsourcing, resilience, exit planning, and shared responsibility models.
  • Support the AI Management System (AIMS) programme, aligned to ISO 42001:2023, including the AI system inventory and Statement of Applicability; act as the designated subject-matter lead, supporting the Group Head of Enterprise Resilience as accountable officer, for EU AI Act compliance, DIFC DPR 10, and other emerging AI regulations; and support operational dependency and resilience risks identification arising from AI adoption across the enterprise.
  • Conduct IT and resilience compliance risk assessments, with a focus on cloud environments, AI systems, third-party dependencies, and emerging technologies.
  • Support the development and maintain the full suite of AIMS governance documentation including AI policies, standards, procedures, and lifecycle controls; and lead the introduction and ongoing enhancement of AI-driven compliance automation for monitoring, evidence collection, and reporting.
  • Consolidate all IT and resilience regulatory controls into Waystone’s Vanta, ensuring documentation is accurate, current, and audit-
  • Lead quarterly Enterprise Resilience Governance and Compliance reporting across all entities, including entity-level operational resilience reports, AIMS performance metrics, policy governance metrics, and DORA compliance reporting; ensure data is collected, validated, and reported accurately, and transition all reporting into Business as Usual (BAU) operations.
  • Report quarterly into the Enterprise Resilience Committee on IT and operational resilience compliance and governance matters including key compliance and governance KPIs, items for escalation and horizon scanning.
  • Identify opportunities to automate compliance and resilience processes, including policy reviews, reporting, and control monitoring, and provide recommendations to enhance compliance tools and workflows.
  • Provide oversight and challenge of ICT and operational third-party resilience, supporting due diligence, ongoing monitoring, concentration risk assessment, and exit planning.
  • Support regulatory inspections, internal audits, and independent assurance activities, ensuring clear, consistent, and evidence-based responses.
  • Lead the identification and retrospective governance of Shadow AI, including the implementation of a Shadow AI identification procedure; maintain the enterprise AI system inventory; ensure all in-scope AI systems are assessed, classified, and registered under the AIMS prior to deployment or continued use.
  • Support the Group Head of Enterprise Resilience by attending entity board, client, and fund meetings to address operational resilience, AI governance, IT compliance, technology risk queries; prepare AI governance updates and compliance attestations for board and regulatory audiences, supporting client due diligence and regulatory disclosures.
  • Promote a strong organisational culture of resilience, accountability, and regulatory awareness, embedding resilience considerations into change and transformation initiatives.
  • Provide guidance, coaching, and training within the job area to junior team members and colleagues across the Enterprise Resilience function on AI governance, IT compliance, and resilience matters; manage major or complex governance projects involving the delegation and review of others' work.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Preferred Skills and Experience

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job
  • Regulatory Expertise: Deep understanding of operational resilience and IT compliance regulatory frameworks (e.g. GDPR, DORA, Operational Resilience, EU AI Act, ISO 42001:2023, UK AI Principles, IOSCO FR/02/2026, DIFC DPR 10).
  • AI Governance & Cloud Compliance: Practical knowledge of AI management systems (ISO 42001), AI Act risk classification, AI system inventory management, agentic AI controls, and cloud compliance frameworks including outsourcing and exit planning obligations.
  • Jurisdictional Compliance Management: Ability to manage and support multi-region compliance requirements and reporting.
  • Policy Governance & Automation: Demonstrated ability to own and operate a policy governance framework, including authoring, reviewing, version-controlling, and retiring policies, standards, and procedures; skilled in policy register management, approval workflow design, attestation programmes, and leveraging automation for compliance monitoring and policy lifecycle management.
  • Training & Communication: Excellent facilitation skills for AI literacy and compliance programmes.
  • Stakeholder Engagement: Ability to collaborate with regulators, clients, and internal teams.
  • Client Engagement: Confident in addressing compliance questions during board, regulator, client and fund meetings.
  • Analytical & Problem-Solving: Strong capability to interpret complex regulations and implement practical solutions.
  • Programme Management: Proven ability to manage complex, multi-workstream programmes spanning operational resilience, AI governance, and IT compliance, including governance documentation build-out, regulatory testing programmes, and entity-level reporting cycles.
  • Ethical Integrity: High professional ethics and attention to detail.

Qualifications

  • Bachelor’s or Master’s degree in IT, Computer Science, Risk Management, or related Compliance field.
  • Excellent business knowledge extending to Waystone’s global compliance footprint.
  • Minimum of 6 years' experience in compliance, risk, or governance roles within financial services.
  • Professional certifications: CISA, CISM, CISSP, CRISC; ISO 42001 Lead Implementer or Auditor are desirable. AI governance credentials (e.g. AIGP, CDPSE) are strongly preferred.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Operational Resilience
AI Governance
IT Compliance
Regulatory Compliance
Policy Governance
Risk Assessment
DORA
ISO 42001
Cloud Compliance
Third-Party Risk Management
Stakeholder Engagement
Programme Management
Audit Support
ICT Risk
Business Continuity
Governance Frameworks

Location

Ireland, England, United Kingdom

Sign up to applySee more jobs like this