IT

Temporary 40000 - 50000 € / year (est.) Home office (partial)
Mitchells & Butlers - IT

At a Glance

  • Tasks: Join our team to ensure data protection and GDPR compliance across our organisation.
  • Company: Mitchells & Butlers, a leader in the hospitality industry with over 1,600 venues.
  • Benefits: Enjoy flexible hours, 33% discounts, private healthcare, and 26 days annual leave.
  • Other info: Exciting career growth opportunities in a supportive and innovative environment.
  • Why this job: Make a real impact on data privacy while working in a dynamic hybrid role.
  • Qualifications: 3+ years in GRC or data protection; strong understanding of GDPR required.

The predicted salary is between 40000 - 50000 € per year.

We have an exciting opportunity for a GRC Analyst – Data Protection & GDPR Compliance to join our award‑winning Business Change and Technology (BC&T) team on a 12‑month Fixed Term Contract. You will be based in Birmingham City Centre, working in a hybrid role. Reporting to the IT Licensing & Compliance Manager, these roles support Mitchells & Butlers’ governance, risk, and compliance (GRC) activities, with a strong focus on information security, privacy, and regulatory assurance across the organisation.

This specialism focuses on data protection assurance and GDPR compliance, ensuring personal data is processed lawfully, proportionately, and in line with regulatory and organisational requirements.

Benefits:

  • 35 hours per week, Monday to Friday, with flexibility around personal commitments.
  • 33% discount across all M&B brands and hotels.
  • A pension that pays, with contributions matched at 1.5x, up to 5%.
  • Private healthcare, dental plan, cycle‑to‑work, and keep‑fit schemes.
  • 26 days annual leave plus bank holidays.
  • Competitive salary.

Key responsibilities include:

  • Reviewing how personal data is used across M&B systems, business processes, and technology solutions.
  • Assessing and documenting PII risks, gaps, and recommended actions in line with GDPR, the UK Data Protection Act, and M&B risk management processes.
  • Ensuring data minimisation principles are applied by identifying unnecessary collection, processing, or retention of personal data.
  • Constructively challenging business teams where personal data processing is excessive or insufficiently justified.
  • Identifying opportunities to reduce, anonymise, or eliminate personal data processing where it is not essential to business needs.
  • Maintaining visibility of personal data usage, including data classification, sensitivity, and lifecycle controls.
  • Providing clear, pragmatic risk assessments and guidance to business stakeholders on personal data processing.

Governance, Risk & Compliance:

  • Support the review, development, and rollout of information security and data protection policies.
  • Contribute to the management of information security, third‑party, and privacy risk registers.
  • Produce compliance reports, dashboards, and metrics for management and senior stakeholders.
  • Assist with internal and external audits, including GDPR assurance, PCI DSS, and financial audits.
  • Support control reviews, evidence gathering, and policy adoption across the organisation.
  • Maintain clear, accurate, and auditable compliance documentation.

Security & Privacy Operations:

  • Track remediation of identified security, privacy, and compliance issues to ensure timely closure.
  • Support incident and breach response activities, including investigation, documentation, and follow‑up actions.
  • Review and document business, data, and supplier processes to support governance, risk, and compliance activities.
  • Provide clear, auditable documentation to evidence risk decisions, approvals, and outcomes.

What you’ll need to bring:

  • Strong understanding of GDPR, the UK Data Protection Act, and privacy and security control requirements.
  • Experience working in GRC, information security, data protection, supplier assurance, or a related compliance role.
  • Ability to interpret and assess technical and organisational controls.
  • Strong analytical skills with excellent attention to detail.
  • Confident written and verbal communication skills, able to engage across legal, technical, and operational teams.
  • Experience contributing to incident or breach investigations.
  • Ability to manage multiple competing priorities and constructively challenge established processes.

Qualifications:

  • Minimum 3 years' experience in a relevant role.
  • CIPP/E, CIPM, CompTIA Security+, or BCS Practitioner Certificate in Data Protection desirable.

Closing date Monday 25th May 2026 11:59pm

IT employer: Mitchells & Butlers - IT

Mitchells & Butlers is an exceptional employer, offering a dynamic work environment in the heart of Birmingham City Centre. With a strong commitment to employee well-being, we provide flexible working hours, generous benefits including private healthcare and a competitive pension scheme, and a vibrant culture that encourages professional growth and development. Join us to be part of a leading hospitality group that values innovation and compliance, while enjoying a 33% discount across our diverse range of pubs and restaurants.

Mitchells & Butlers - IT

Contact Detail:

Mitchells & Butlers - IT Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land IT

Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend events, join online forums, or even hit up local meetups. The more people you know, the better your chances of landing that GRC Analyst gig.

Tip Number 2

Show off your skills! Create a personal project or case study that highlights your understanding of GDPR and data protection. This not only demonstrates your expertise but also gives you something tangible to discuss during interviews.

Tip Number 3

Prepare for those tricky interview questions! Brush up on common GRC scenarios and think about how you'd handle them. Practising your responses will help you feel more confident and ready to impress.

Tip Number 4

Don’t forget to apply through our website! We’ve got loads of opportunities waiting for you, and applying directly can sometimes give you an edge. Plus, it’s super easy to keep track of your applications!

We think you need these skills to ace IT

GDPR
UK Data Protection Act
Information Security
Data Protection
Governance, Risk & Compliance (GRC)
Supplier Assurance
Analytical Skills

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the GRC Analyst role. Highlight your experience with GDPR and data protection, and don’t forget to mention any relevant qualifications. We want to see how your skills match what we’re looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you’re passionate about data protection and how your background makes you a great fit for our team. Keep it concise but engaging – we love a good story!

Showcase Your Analytical Skills:Since this role requires strong analytical skills, make sure to include examples of how you've used these in past roles. Whether it’s assessing risks or documenting compliance, we want to see your thought process in action!

Apply Through Our Website:Don’t forget to apply through our website! It’s the best way to ensure your application gets to us directly. Plus, it shows you’re keen on joining our awesome team at Mitchells & Butlers!

How to prepare for a job interview at Mitchells & Butlers - IT

Know Your GDPR Inside Out

Make sure you brush up on your knowledge of GDPR and the UK Data Protection Act. Be ready to discuss how these regulations apply to real-world scenarios, especially in relation to data minimisation and personal data processing.

Showcase Your Analytical Skills

Prepare to demonstrate your analytical skills by discussing past experiences where you've assessed risks or gaps in compliance. Use specific examples that highlight your attention to detail and ability to constructively challenge processes.

Communicate Clearly and Confidently

Practice articulating complex information security concepts in a way that's easy to understand. You’ll need to engage with various teams, so being able to communicate effectively across legal, technical, and operational areas is key.

Be Ready for Scenario Questions

Expect scenario-based questions that test your problem-solving abilities. Think about how you would handle incidents or breaches, and be prepared to outline your approach to documenting and following up on these situations.