Skip to main content
AfterDuty

Risk Analyst

Smart · London, Greater London

Type
Full-time
Posted
13 days ago

Overview

Your experience handling sensitive information and maintaining meticulous records under strict procedures is directly applicable.

About this role

At Smart, our mission is to transform retirement, savings and financial wellbeing, across all generations, around the world.

THE ROLE

We are seeking an organised and proactive Risk Analyst to join our Risk and Privacy team. Reporting to the Senior Risk Manager, this is a hands-on role at the centre of how Smart looks after personal data day to day. Your focus will be the running of our privacy operations — data subject rights requests, privacy incidents, records of processing, retention and privacy assessments — making sure each is handled properly, on time, and with a clear audit trail.

Smart is supported by outsourced privacy consultants who provide the specialist advice and carry out the detailed work. Your role is to keep the operation running around them — coordinating their input, tracking what they produce and making sure their advice is captured and acted on. Alongside this you will provide administrative and coordination support to the wider team, keeping meetings, actions, reporting and documentation running smoothly. You will work closely with legal, compliance, information security, operations and customer services teams, and with the Data Protection Officer.

You do not need to be highly experienced in data protection to apply — we will train you. What matters is an interest in the subject, a methodical approach, and the judgement to handle sensitive information carefully. We will give you the support and training to build the technical knowledge you need.

Key responsibilities

Privacy Operations

  • Manage the day-to-day privacy inbox, triaging incoming queries and either answering them or routing them to the right owner within agreed timescales.
  • Coordinate data subject rights requests end to end, tracking each case against the one-month statutory deadline, gathering material from business owners and preparing the response for review.
  • Log and track privacy incidents and near misses, gathering the facts and following remediation actions through to closure.
  • Maintain the privacy registers and supporting records — including the incident register, the Record of Processing Activities and the DPIA register — so documentation is complete, accurate and audit-ready.
  • Support the DPIA process and other project work, running the initial screening, chasing input from business owners and tracking assessments through to sign-off.
  • Support the periodic review of privacy notices, policies and procedures, and help track retention and the completion of privacy training.
  • Act as a day-to-day point of contact for Smart’s outsourced privacy consultants, coordinating their input, tracking deliverables and making sure their advice is recorded and followed through.
  • Help gather evidence for internal and external audits and client assurance requests relating to data protection.
  • Prepare the underlying data for periodic privacy reporting, such as incident volumes and data subject rights numbers.

Team Administration and Support

  • Coordinate the team’s governance calendar — scheduling meetings and forums, preparing agendas and papers, taking minutes and maintaining action logs.
  • Track actions and deadlines across the team, following up with owners so items are closed on time.
  • Maintain team documentation and records, including version control, document libraries and central registers.
  • Prepare and format reporting packs, papers and presentations for senior management and governance forums.
  • Provide general administrative support to the team, including diary coordination, purchase orders and supplier onboarding administration.
  • Support the onboarding of new team members, and maintain team process notes and how-to guides.
  • Contribute to improvements in team processes, templates and trackers to make them simpler and more efficient.

WHO WE ARE LOOKING FOR

The skills, experience, and aptitudes we are looking for are listed below but please don’t be discouraged from applying if you don’t meet every single one of these criteria – having a ‘can do’ attitude is sometimes more important than being able to tick every box:

  • A genuine interest in data protection and privacy. You do not need to be highly experienced — we will train you. An interest in the subject and an aptitude for it matter more than the number of years on your CV.
  • A degree in law, risk management, business or a related field, or equivalent practical experience. Progress towards a privacy or compliance qualification (for example the IAPP CIPP/E, or the Practitioner Certificate in Data Protection) is welcome but not required.
  • Some experience in a privacy, risk, compliance, legal, audit, operations or administrative role. Financial services, pensions or fintech experience is helpful but not essential.
  • An awareness of UK GDPR concepts — personal data, lawful basis, data subject rights and personal data breaches — or the readiness to pick them up quickly.
  • Strong organisational skills, with the ability to run several cases and workstreams at once, keep tasks moving across teams and meet deadlines without close supervision.
  • Excellent attention to detail, particularly when handling personal data and maintaining registers and records.
  • Sound judgement and discretion, with an understanding of why confidentiality matters when working with sensitive information.
  • Good analytical skills, comfortable working with data and turning it into clear, useful reporting.
  • Confident written and verbal communication skills, with the ability to deal with internal stakeholders and client requests professionally.
  • A collaborative, proactive approach — someone who spots what needs doing and picks it up.

WHO WE ARE

We work in partnerships with governments and financial institutions in the UK and internationally. Our cloud-native digital platform is revolutionising how people around the world think about, and save for, their retirement.

At heart, we’re a financial technology business. What we do is all about innovation, and using the power of digital change to put the customer first. Our Engineers will tell you that working at Smart gives you the opportunity to play your part in developing world-class technological solutions, working with – and learning from – like-minded people.

You’ll also find that, across our business, our colleagues love Smart’s culture, and how what we do means better financial outcomes for savers. That feels worthwhile, and it means that what we do, collectively, goes way beyond the nine to five of a typical working day.

Don’t just take our word for it – you can see what our colleagues say about working at Smart on LinkedIn Life and Glassdoor.

BENEFITS

At Smart, one of the eight principles we work to is “We want happy and good people in our team”. We created a list of benefits that helps us achieve this goal:

  • 25 days’ holiday per year, increasing with length of service.
  • £500 annual training budget to spend on your professional development
  • Extensive private healthcare, including dental, eyecare and EAP
  • Enhanced sick leave (three months’ pay per year)
  • Enhanced maternity and paternity (maternity – 6 months fully paid/paternity – 3 weeks fully paid)
  • Death in service insurance cover
  • Fully-paid five-week sabbatical after five years of employment
  • In office wellbeing, such as manicures, massages and barbers.
  • Smart employees also enjoy a 50% discount on orders from our sister company Arena Flowers, Britain's most ethical florist. They offer unique hand-tied bouquets, luxury flowers, letterbox flowers, plants and gifts to spend on friends and loved ones or even for yourself.

At Smart, we are committed to creating an inclusive and equitable workplace where everyone feels valued, respected, and empowered to do their best work.

About risk & resilience roles for ex-police

Risk management, business continuity and emergency-planning roles. Contingency planning, threat assessment and multi-agency coordination experience from policing is directly transferable.

See all risk & resilience jobs in London

Why this fits a police background — match score 65/100

  • Working to legislation & regulation

What risk & resilience roles pay ex-police

Advertised UK ranges, editorial estimates reviewed July 2026

Resilience / BC analyst£35,000–£48,000
Business continuity / resilience manager£50,000–£70,000
Crisis management lead£65,000–£85,000
Head of resilience£80,000–£110,000+
Full risk & resilience salary guide →

More risk & resilience jobs for ex-police

  • Your risk assessment, incident command and multi-agency coordination experience directly apply to aviation security risk management.

    Posted 2 days ago

  • Full-time

    Your incident command and multi-agency coordination experience directly apply to crisis management and operational resilience planning.

    Posted 3 days ago

  • Full-time

    Your experience managing complex enforcement operations and contractor performance in a high-pressure public-facing environment is directly transferable.

    Posted 3 days ago

  • Risk Manager - Rail

    Turner & Townsend · London

    Full-time

    Turner & Townsend is a global professional services company with over 22,000 people in more than 60 countries. Working with our clients across real estate, infrastructure, energy and natural resources, we transform together delivering outcomes that improve people’s lives.

    Posted 3 days ago