Define and implement a practical compliance framework across products, marketing, and infrastructure
Partner with product, marketing, clinical, security, legal, IT, finance, HR, operations, and leadership to integrate compliance into business decisions
Ensure GDPR, healthcare advertising, and NIS2 compliance; enable Privacy by Design and Compliance by Design
Lead risk management activities including DPIAs, LIAs, and other assessments; identify and mitigate privacy, data, marketing, and communications risks
Oversee audits, monitor compliance, manage incidents, whistleblowing and reporting processes
Develop global compliance strategy that meets local regulatory requirements and balance global and local needs
Create internal policies, deliver training, and build a culture of compliance and privacy awareness
Track regulatory changes and update company policies; represent compliance priorities to leadership
Build and lead a small team of compliance experts over time; report directly to the CFO
Requirements
5+ years in senior compliance roles, with mandatory experience in a regulated market
Healthcare sector experience (digital and/or physical) is a plus
Proven track record in fast-paced startups or scaleups, working closely with product and marketing teams
Strong knowledge of European regulations including data protection (GDPR), healthcare, digital marketing, and consumer protection
Ability to anticipate and address evolving AI regulations
Global or pan-European experience; ability to balance local compliance needs with global strategy
Fluency in Italian and English; presence in Italy is a strong advantage
Familiarity with compliance frameworks and best practices (e.g., ISO 27001, Legislative Decree 231/2001) is a plus
Excellent communication skills; proactive and hands-on