GRC Analyst - Data Protection and GDPR

HAYS Specialist Recruitment
B31Jp, B3 1JP, United Kingdom
Last month
£45,000 – £50,000 pa
Applications closed

Related Jobs

View all jobs

Information Security Analyst - ISO 27001

Spectrum IT Recruitment London, United Kingdom
£80,000 – £88,000 pa Hybrid Clearance Required

Security Testing Analyst

Oscar Technology London, United Kingdom
£30,000 – £35,000 pa

Cyber Security Analyst - Fridays Off

eTech Partners London, United Kingdom
£65,000 – £70,000 pa Hybrid

Cyber Security Analyst - 1 day a week - Remote

eTech Partners London, United Kingdom
£65,000 – £70,000 pa On-site

Cyber Security Analyst - Fridays Off

eTech Partners Nottingham, United Kingdom
£65,000 – £70,000 pa On-site

Cyber Platforms Senior Engineer

Connells Group HQ Mk78Jt, MK7 8JT, United Kingdom
On-site

Salary

£45,000 – £50,000 pa

Job Type
Contract
Work Location
Hybrid
Seniority
Mid
Education
Degree
Posted
18 May 2026 (Last month)

Benefits

Company discounts Pension contribution matched at 1.5x, up to 5% Private healthcare Dental plan Cycle to work Keep-fit schemes 26 days annual leave plus bank holidays

GRC Analyst - Data Protection & GDPR

Fixed Term Contract, 12 months - £45k - £50k

Location: Hybrid - Birmingham


Your new company:


I am looking to recruit a GRC Analyst, focusing on Data Protection and GDPR, to join a leader in the hospitality space, with the role focusing on GRC activities, with a strong focus on information security, privacy, and regulatory assurance across the organisation.


The role responsibilities:


This role focusses on data protection assurance and GDPR compliance, ensuring personal data is processed lawfully, and in line with regulatory and organisational requirements. Key parts of the role:

  • Reviewing how personal data is used across systems, business processes, and technology solutions.
  • Identifying opportunities to reduce, anonymise, or eliminate personal data processing where it is not essential to business needs.
  • Support the review, development, and rollout of information security and data protection policies.
  • Contribute to the management of information security, third party, and privacy risk registers.
  • Assist with internal and external audits, including GDPR assurance, PCI DSS, and financial audits.
  • Track remediation of identified security, privacy, and compliance issues to ensure timely closure.
  • Support incident and breach response activities, including investigation, documentation, and follow-up actions.


You will need:

  • Strong understanding of GDPR, the UK Data Protection Act, and privacy and security control requirements.
  • Experience working in GRC, information security, data protection, supplier assurance, or a related compliance role.
  • Ability to interpret and assess technical and organisational controls.
  • Strong analytical skills with excellent attention to detail.
  • Confident written and verbal communication skills, able to engage across legal, technical, and operational teams.
  • Experience contributing to incident or breach investigations.
  • Ability to manage multiple competing priorities and constructively challenge established processes.
  • Minimum 3 years' experience in a relevant role.
  • CIPP/E, CIPM, CompTIA Security+, or BCS Practitioner Certificate in Data Protection, desirable.


What you'll get in return:

  • Salary of between £45k-£50k
  • Hybrid working
  • Company discounts
  • A pension contribution matched at 1.5x, up to 5%.
  • Private healthcare, dental plan, cycle to work, and keep-fit schemes.
  • 26 days annual leave plus bank holidays.

Hays Specialist Recruitment Limited acts as an employment agency for permanent recruitment and employment business for the supply of temporary workers. By applying for this job you accept the T&C's, Privacy Policy and Disclaimers which can be found at hays.co.uk

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.