Protection Group International
Risk and Compliance Associate

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
About PGI
PGI is a global consultancy that helps organisations build digital resilience. We deploy our people to implement solutions on behalf of clients or to support them in developing their own capabilities. Our vision is a world resilient to digital threats and online harm. To achieve this, we need to grow our team of talented and passionate people.
Our clients include some of the most well-known global brands, national governments, and innovative growing businesses. We operate in an exciting, fast-growing sector that bears increasing relevance and importance to nation-states, corporates, universities, and NGOs.
Role Overview
This role is focused on providing hands-on support across a broad range of Risk & Compliance activities. You will help maintain certifications, coordinate audits and governance processes, support risk management activities, and work collaboratively with stakeholders across the organisation. You will also provide additional capacity for business-critical initiatives and help ensure Risk & Compliance continues to enable business performance rather than act as a barrier to it.
While primarily a support role, you will be expected to work with a high degree of autonomy and act as deputy to the Head of Risk & Compliance when required, including taking ownership of key activities, supporting senior stakeholder engagement, and representing the function during periods of absence.
What You’ll Be Doing
Working closely with the Head of Risk & Compliance, you will help coordinate and deliver key risk, governance, information security, and compliance activities, ensuring the function continues to operate effectively while supporting the wider business.
Strong communication and relationship-building skills are essential, as you will work with colleagues at all levels of the organisation, external auditors, clients, suppliers, and certification bodies. You will provide appropriate challenge, support sound decision-making, and contribute to the delivery of a pragmatic and commercially focused Risk & Compliance function.
Your responsibilities will include, but are not limited to:
- Support the maintenance and coordination of ISO 27001 certification, acting as lead coordinator when required.
- Coordinate internal audits, business continuity exercises, and related compliance activities.
- Maintain key governance artefacts, including the Corrective Actions Log, Audit Schedule, and Continuous Improvement Plan.
- Support risk assessments, management reviews, supplier security due diligence, and the review and maintenance of security policies, procedures, and plans.
- Coordinate security awareness and training programmes, including new starter inductions, and manage the company's e-learning platform (Usecure).
- Provide guidance and support on day-to-day data protection matters, acting as a key point of contact and escalating complex issues where appropriate.
- Support and, where required, oversee the organisation's ongoing compliance with GDPR and wider data protection requirements.
- Monitor and support compliance with client contractual obligations relating to data protection.
- Support the Head of Risk & Compliance in maintaining corporate and departmental risk registers, taking ownership of activities when required.
- Promote a positive, proportionate, and risk-aware culture across the organisation.
- Support business growth and delivery by providing Risk & Compliance input throughout the sales process, including bid submissions and customer due diligence questionnaires.
- Support the maintenance and review of corporate governance policies, including Anti-Bribery and Code of Conduct policies.
- Coordinate activities supporting the maintenance of ISO 9001 certification across the organisation.
- Maintain corporate certifications and registrations, including certification records and renewal schedules.
- Support environmental management, sustainability initiatives, and related reporting requirements.
- Assist with the administration and reporting obligations of the Business Ethics Framework, including the UN Global Compact (UNGC).
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
On Day One You Will Bring
- Experience in corporate governance, risk, and compliance roles within a similarly sized organisation, including maintaining and managing risk registers.
- Experience managing ISO certifications and working with external auditors.
- A strong understanding of information security best practices.
- Excellent communication skills, with the ability to build effective relationships with senior stakeholders, managers, employees, clients, auditors, and compliance bodies.
- Strong attention to detail, commercial awareness, and organisational skills, alongside excellent time management and prioritisation abilities.
- The ability to balance robust risk management with the practical needs of business operations and commercial objectives.
- A continuous improvement mindset with a focus on efficiency and effectiveness.
- Strong relationship-building skills and the ability to influence and challenge constructively.
- A proactive and pragmatic approach to improving processes and implementing best practice.
- The confidence to operate independently and make decisions within agreed parameters, including deputising for the Head of Risk & Compliance when required.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Ideally, You Will Also Have
- Previous experience acting as a DPO or supporting a Data Protection Officer.
- Security management qualifications such as ISO27001 Lead Auditor, CISSP, or CISM.
- Experience providing deputy or stand-in support for a senior Risk, Compliance, Information Security, or Governance leader.
Diversity, Equity and Inclusion at PGI
As a British company which operates internationally, we draw strength from the diversity of our people. Without our diverse team, we couldn’t do the work we do. We are involved in projects across 80+ geographies, our people speak 25+ languages and come from a variety of backgrounds. By hiring and cultivating a diverse, equitable and inclusive workforce, we can uphold values that enable every member of the team to thrive, while delivering novel solutions to novel problems.
Accessibility at PGI
Every individual has different requirements, so we are committed to implementing reasonable adjustments to mitigate physical and non-physical barriers in the workplace. We strive to make the recruitment process as accessible as possible, but if you have any questions or concerns, please get in touch.
Please note: We are not accepting applications or speculative profiles from any recruitment agencies. If we require additional resource, we will reach out to you.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills