VML THE COCKTAIL is a global design consultancy, part of VML. We engage with bold organizations to grow a more human and transcendent business. Our approach combines creativity, design, technology, and data to create products, brands, services, and companies that relate to people, delivering impactful stories for the future.
About the role :
- Member of an IT / Data team providing IT service delivery to a multinational company in Madrid, supporting hybrid work models with remote activities for a client.
- IT operations are deployed in a highly globalized environment with outsourced operations through third parties.
- Part of the Business Center, including a Call Center, within a client-facing ecosystem where agents mainly work remotely.
Responsibilities :
- Create and manage remediation plans in response to audit discoveries and compliance violations; monitor evidence collection.
- Provide strategic risk guidance for IT projects and product management, including security assessments and technical controls evaluation.
- Assist in developing and implementing new projects with a Privacy by Design approach, ensuring compliance with internal policies and data protection procedures.
- Regularly audit procedures, practices, and documents to identify weaknesses or risks.
- Establish new procedures, protocols, and internal policies.
- Prepare and manage compliance training to raise awareness on Information Security and Data Protection.
- Identify, investigate, report, and correct compliance issues, irregularities, and violations.
- Respond to security incidents or breaches, collaborating with the Compliance Manager to ensure legal and regulatory compliance.
- Provide legal advice on data protection concerning commercial communications.
- Manage Third Party Risk, including assessment, monitoring, and mitigation, collaborating with DPO and Legal Department to ensure compliance in third-party relationships.
Requirements :
- Based in Madrid.
- At least 2 years of experience in risk management, privacy, information security, or IT roles.
- Strong work ethic and passion for legal advice and new technologies.
- Fluent in English, capable of working effectively in the language.
- Experience with validation, risk management, and change control.
- Knowledge of legal and regulatory standards such as GDPR, ISO27001, NIST2.
- Excellent analytical skills; able to manage multiple projects under strict timelines in a dynamic environment.
- Desirable experience with database security (SQL, Oracle, Azure, etc.).