Rodeo
Get started

Shufti

Head of Legal, Compliance & Privacy

London
Posted about 16 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Purpose

To lead Shufti’s Legal, Compliance & Privacy department for a global identity-verification and AML business (KYC, KYB, AML screening). The role owns commercial and corporate legal, compliance and regulatory affairs, and data protection, holds Shufti demonstrably compliant with its own obligations while providing assurance over the screening product Shufti sells, keeps the business audit-ready at all times, and builds the function and the team to do so.

The role is expected to design and run the function end-to-end: set the operating model, stand up the registers and controls, represent the function to the executive, customers and regulators, and grow and lead a multi-disciplinary team across the three pillars.

Scope — three pillars

Pillar Coverage

Commercial & Corporate Legal

MSAs, DPAs, NDAs, contract governance, signing authority, renewals; corporate governance & company-secretarial; employment & ER; disputes; US gaming licences; product-related legal.

Compliance & Regulatory Affairs

Obligations & controls registers, control design & testing, audit readiness & remediation, regulatory change, training; AML / screening (sanctions, PEP, CDD/EDD); product compliance; certification portfolio incl. UK DVS/DIATF; enterprise DDQ / RFI / RFP & security questionnaires.

Privacy & Data Protection

ROPA, DPIA, DSAR, ICO engagement, international transfers (SCC / IDTA), vendor DPAs, privacy-by-design.

Legal Operations (cross-cutting)

Intake, registers/repositories and the KPI dashboard across all three pillars.

Incident & breach response is owned by the Security department and is outside this role’s remit.

Key responsibilities

Leadership & function-building

  • Own the department’s operating model, structure and ways of working; build and lead the team across all three pillars.
  • Represent Legal, Compliance & Privacy to the executive and Board, and to customers, partners, auditors and regulators.
  • Set the governance cadence (weekly RAG, monthly memo, quarterly QBR) and report on function performance.
  • Recruit and develop the team to a consistent bar (ghSMART A-Method); set scorecards, manage performance and succession.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Commercial & corporate legal

  • Own the contract lifecycle — repository, turnaround SLAs, signing-authority matrix, renewals and self-serve playbooks (NDA, customer, vendor, DPA).
  • Run corporate governance and company-secretarial matters; support fundraising, M&A and other strategic transactions with clean documentation and external-counsel coordination.
  • Oversee employment/ER matters and manage disputes and the US gaming-licence portfolio.

Compliance & regulatory affairs

  • Build and maintain the obligations register, controls inventory and testing schedule, and the audit-readiness evidence pack.
  • Own AML / screening controls (sanctions, PEP, adverse-media, CDD/EDD) covering both Shufti’s own obligations and assurance over the screening product.
  • Track regulatory change and emerging regimes (DORA, NIS2, EU AI Act); drive the certification portfolio, including UK DVS/DIATF, and enterprise DDQ / security-questionnaire responses.

Privacy & data protection

  • Oversee the privacy programme — ROPA, DPIA, DSAR, international transfers (SCC/IDTA), vendor DPAs and privacy-by-design — and manage ICO engagement and remediation.

How the role is measured

Performance is measured against the department KPI framework, once each underlying register or system is live (development goal until then):

  • Legal — contract turnaround, review quality/rework, renewal capture, contract governance & control, legal risk/disputes/cost.
  • Compliance — sanctions & anti-bribery, screening-service integrity, audit readiness & records, controls effectiveness, obligations & regulatory change, training, DDQ/query timeliness.
  • Privacy — regulator remediation, DSAR timeliness, records maturity (ROPA/DPIA), data lifecycle & vendor compliance, privacy incidents/risk/training.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Person specification

Essential

  • Qualified lawyer with substantial in-house experience leading legal and/or compliance in a regulated, multi-jurisdiction environment.
  • Strong commercial and corporate contracting, and corporate governance / company-secretarial capability.
  • Genuine cross-border experience and the ability to coordinate external counsel across jurisdictions.
  • Compliance / AML depth — obligations and controls, audit readiness, and screening (sanctions/PEP/CDD-EDD).
  • Data-protection literacy (GDPR/ICO) and the judgement to partner privacy effectively.
  • Evidence of building or materially improving a function, and of leading and developing a team.
  • Clear, pragmatic stakeholder management — an enabler to the business, not a blocker.

Desirable

  • RegTech / fintech / identity-verification domain exposure.
  • Fundraising and/or M&A transaction leadership.
  • Experience with certifications/assurance (e.g. UK DVS/DIATF, ISO/IEC 27001, SOC 2) and AI-regulatory change (EU AI Act).
  • Additional qualification/jurisdiction (e.g. dual-qualified).

What success looks like

Horizon

Indicative outcomes

First 90 days

  • Function operating model and team structure agreed; core registers designed; contract engine and screening SOPs taking shape; hiring underway; a clear DVS/DIATF plan.

6 months

  • Registers live and KPIs being RAG-scored; audit-readiness evidence pack maintained; certifications progressing; team on cadence.

12 months

  • A demonstrably audit-ready, well-run function across all three pillars; commercial legal protecting revenue; compliance and privacy operating to plan; a capable, developing team.

This role description is indicative and may be refined as the department structure is finalised. It is a candidate-neutral job description; no appointment has been made.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Commercial Law
Corporate Governance
Compliance Management
Data Protection
AML Screening
Contract Lifecycle Management
Regulatory Affairs
Privacy-by-Design
Stakeholder Management
Team Leadership
Risk Management
Company Secretarial
GDPR
Audit Readiness
Legal Operations
Cross-border Legal Coordination

Location

London, England, United Kingdom

Sign up to applySee more jobs like this