← Back to jobs

Technical Compliance Officer - Malta

Description

The business supplies a live casino platform and content into multiple regulated markets, each with its own technical standards, certification scheme and evidentiary expectations. The Technical Compliance Officer - Certifications translates those obligations into testable technical requirements, owns the certification lifecycle end to end - readiness, submission, findings closure, surveillance and recertification - and is the primary interface with accredited test laboratories, certification bodies and regulatory authorities.

As a second-line role it does not operate first-line controls. It defines the compliance position in technical terms, tests whether the evidence supports that position, and reports certification risk with proposed treatment.

Purpose

Certification and technical standards obligations across the licence portfolio, currently Malta (MGA), Isle of Man (GSC) and Curacao (CGA), and all certification engagements with accredited test laboratories. Scope extends to new markets as the licence footprint grows.

Main Responsibilities

Regulatory Research and Technical Translation

    Maintain a current view of the technical standards, certification schemes and regulatory instruments applying to a B2B platform and content supplier in each market in scope

    Translate regulatory text into testable technical requirements and control objectives that first-line teams can act on without further interpretation

    Run gap analyses against current posture and issue risk-ranked remediation plans naming the deliverables required to close

Requirement-to-Control Traceability

    Maintain traceability from each regulatory requirement to the control that satisfies it and the artefact that evidences it, across all jurisdictions in scope

    Keep the mapping current as requirements, controls and platform architecture change, so that certification questions are answered from the register rather than reconstructed under time pressure

    Validate mapping completeness ahead of each certification milestone and resolve unmapped or unevidenced requirements with the first line before submission

Certification and Audit Management

    Maintain a forward certification calendar by standard, jurisdiction and certified asset, sequenced against commercial expansion plans and licence renewal dates

    Run pre-audit readiness assessments and assemble submission packs - technical documentation, control evidence and test results - to the standard each body expects

    Act as primary point of contact for certification bodies and regulatory authorities, managing scope, queries, timelines, proposals and invoicing

    Track findings and non-conformities through to verified closure, and manage surveillance, change notification and recertification obligations

Regulatory Change Management

    Assess the technical impact of regulatory and scheme changes on the control environment, the certified asset base and existing certifications

    Issue impact assessments stating what has changed, which controls and assets are affected, what must be done and by when

    Maintain traceability from notification through to implementation and evidence, so that the position taken on any change can be reconstructed and defended

Risk Reporting and Cross-Functional Support

    Own certification and technical compliance entries in the compliance risk register as an independent second-line assessment of exposure, treatment and status

    Report certification risk and readiness to the compliance forum with proposed treatment, escalating where evidence gaps or timelines put a licence or a market at risk

    Brief first-line teams on the jurisdiction-specific requirements bearing on their work, and support new market entry with technical feasibility assessments and realistic certification timelines

Key Relationships

    First line: Product, Engineering, Integrations, DevOps and Studio Operations

    Second line: Regulatory and Technical Compliance, Governance, Legal and Data Protection

    External: accredited test laboratories, certification bodies and regulatory authorities

Main Requirements

    Minimum two years in gaming or iGaming, ideally B2B, supporting a portfolio of certified products and platforms; live studio exposure an advantage

    Direct dealings with accredited test laboratories and certification bodies across readiness, submission, findings tracking and closure

    A record of translating regulatory or scheme requirements into technical requirements that first-line teams could implement

    Managing certification and compliance gaps through to evidenced closure, including remediation planning and follow-up

    Multi-jurisdictional B2B licensing exposure across three or more regulated markets

    ISO/IEC 27001 ISMS operation, control design and evidence practice

    Working understanding of RNG and game certification, live studio technical standards and platform architecture

Skills and attributes

    Precise analytical reading of regulatory text, clear on what is mandatory, what is recommended and what is interpretation

    Structured writing - requirements, gap analyses, impact assessments and audit correspondence that stand up to external scrutiny

    Organised across parallel certification timelines, and able to hold a defensible position with external bodies and internal stakeholders

    Comfortable using AI tools for research, analysis and documentation, with the judgement to verify output before relying on it

    A second-line mindset: evidence over assertion, and independence from the activity being assessed

    Education and certifications

    Degree in business, management or computer science, or equivalent professional experience - ideal

    ISO/IEC 27001 Lead Auditor or Lead Implementer - beneficial

CISA, CRISC or equivalent - advantageous

What’s in it for you?

    Experience a dynamic and team-orientated work environment

    Opportunities for personal growth and learning

    An open, inclusive and supportive team where you will be valued, and your suggestions will be welcome

    24 days paid holiday per year, in addition to local public holidays

    Birthday Leave, a paid day off in the month of your birthday

    Competitive Salary

    Hybrid Working (3 days office/2 days home)

    Risk Benefits such as Private Medical Insurance and Life Assurance (2x annual salary)

    Annual Wellness Allowance

    Team Building Opportunities

    Monthly Lunch Allowance

    Parking (limited)

    Local discounts and more…

    Our team is committed to keeping remuneration and benefits under constant review to make sure what we offer stays relevant.

Get similar jobs in Malta by email

We'll email you when new jobs similar to this one appear.

Similar jobs

Explore more regulatory affairs manager jobs in Malta.

Finding similar jobs…