At a Glance
- Tasks: Conduct risk assessments and manage third-party supplier compliance.
- Company: Join Mitchells & Butlers, a leader in the hospitality industry.
- Benefits: Enjoy flexible hours, 33% discounts, private healthcare, and 26 days leave.
- Why this job: Make an impact on data security and compliance in a dynamic environment.
- Qualifications: 3+ years in GRC or related fields; strong analytical and communication skills.
- Other info: Be part of a diverse team that values inclusion and collaboration.
The predicted salary is between 40000 - 50000 £ per year.
We have an exciting opportunity for a GRC Analyst – Third Party Risk Management to join our award‑winning Business Change and Technology (BC&T) team on a 12‑month Fixed Term Contract. You will be based in Birmingham City Centre, working in a hybrid role. Reporting to the IT Licensing & Compliance Manager, these roles support Mitchells & Butlers’ governance, risk, and compliance (GRC) activities, with a strong focus on information security, privacy, and regulatory assurance across the organisation.
You will be well rewarded with:
- 35 hours per week, Monday to Friday, with flexibility around personal commitments.
- 33% discount across all M&B brands and hotels.
- A pension that pays, with contributions matched at 1.5x, up to 5%.
- Private healthcare, dental plan, cycle‑to‑work, and keep‑fit schemes.
- 26 days annual leave plus bank holidays.
The Opportunity – GRC Analyst
This specialism focuses on supplier assurance and third‑party risk management, ensuring that vendors handling M&B data or connecting to M&B systems operate in line with security, privacy, and compliance expectations.
Key Responsibilities Include:
- Conducting and coordinating security and privacy risk assessments for new and existing third‑party suppliers.
- Evaluating supplier controls relating to data protection, information security, data hosting, subcontractor usage, and system access.
- Catalouging and maintaining records of M&B data shared with third parties, including purpose of use, information security classification, data sensitivity, and processing location.
- Ensuring third‑party data handling arrangements clearly define data retention, archiving, and deletion requirements in line with M&B policies and regulatory obligations.
- Performing data cataloguing activities directly, or coordinating with BC&T teams to ensure data ownership and accountability are clearly assigned.
- Maintaining third‑party risk documentation and tracking remediation actions with suppliers and internal teams.
- Working closely with Vendor Management, Procurement, Legal, Information Security, and IT to ensure supplier risks are identified early and addressed prior to onboarding or renewal.
- Escalating high‑risk supplier findings to the IT Licensing & Compliance Manager and relevant stakeholders.
What You’ll Need To Bring:
- Strong understanding of GDPR, the UK Data Protection Act, and privacy and security control requirements.
- Experience working in GRC, information security, data protection, supplier assurance, or a related compliance role.
- Ability to interpret and assess technical and organisational controls.
- Strong analytical skills with excellent attention to detail.
- Confident written and verbal communication skills, able to engage across legal, technical, and operational teams.
- Experience contributing to incident or breach investigations.
- Ability to manage multiple competing priorities and constructively challenge established processes.
Qualifications:
- Minimum 3 years’ experience in a relevant role.
- CIPP/E, CIPM, CompTIA Security+, or BCS Practitioner Certificate in Data Protection desirable.
At M&B, a career isn’t just about clocking in. We care about our people and value every contribution from a diverse workforce that reflects our guests and communities. By fostering a culture of inclusion, respect, and collaboration, we create an environment where colleagues can thrive and deliver great guest experiences.
Join us and be a part of a great team.
GRC Analyst - Third Party Risk Management in Birmingham employer: Mitchells & Butlers PLC
Contact Detail:
Mitchells & Butlers PLC Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land GRC Analyst - Third Party Risk Management in Birmingham
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those already working at Mitchells & Butlers. A friendly chat can give you insider info and maybe even a referral!
✨Tip Number 2
Prepare for the interview by brushing up on your knowledge of GDPR and data protection laws. Show us you know your stuff and can handle the technical questions with confidence.
✨Tip Number 3
Practice your communication skills! You’ll need to engage with various teams, so being able to explain complex ideas simply is key. Try mock interviews with friends or use online resources.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, it shows you’re genuinely interested in joining our awesome team at Mitchells & Butlers.
We think you need these skills to ace GRC Analyst - Third Party Risk Management in Birmingham
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the GRC Analyst role. Highlight your experience in GDPR, data protection, and any relevant compliance roles. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about third-party risk management and how your background makes you a great fit for our team. Keep it engaging and personal!
Show Off Your Analytical Skills: Since this role requires strong analytical skills, be sure to include examples of how you've used these skills in past positions. We love seeing how you tackle challenges and find solutions!
Apply Through Our Website: Don't forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at Mitchells & Butlers PLC
✨Know Your GRC Basics
Make sure you brush up on your knowledge of GDPR, the UK Data Protection Act, and other relevant compliance regulations. Being able to discuss these confidently will show that you understand the core responsibilities of a GRC Analyst.
✨Prepare for Scenario Questions
Expect questions that ask how you would handle specific situations related to third-party risk management. Think of examples from your past experience where you successfully assessed supplier controls or managed data protection issues.
✨Showcase Your Analytical Skills
Be ready to demonstrate your analytical skills during the interview. You might be asked to interpret technical controls or assess risks, so practice explaining your thought process clearly and concisely.
✨Engage with the Team Dynamics
Since this role involves working closely with various teams, be prepared to discuss how you would collaborate with legal, IT, and vendor management teams. Highlight any past experiences where teamwork led to successful outcomes in compliance or risk management.