VML THE COCKTAIL is a global design consultancy, part of VML. We engage with bold organizations to grow a more human and transcendent business by combining creativity, design, technology, and data to create impactful stories and products for the future.
About the role :
- Member of an IT / Data team providing IT service delivery to a multinational company in Madrid, supporting hybrid work models with remote activities for a client.
- Operate in a highly globalized environment with outsourced operations managed through third parties.
- Work within a Business Center that includes a Call Center, part of a client-facing ecosystem with mainly remote agents.
Responsibilities :
- Create and manage remediation plans for audit findings and compliance violations, monitoring evidence collection.
- Provide strategic risk guidance for IT projects and product management, including security assessments and technical control evaluations.
- Assist in developing and implementing projects with a Privacy by Design approach, ensuring compliance with internal policies and data protection laws.
- Regularly audit procedures, practices, and documents to identify risks or weaknesses.
- Establish new procedures, protocols, and internal policies.
- Prepare and manage Compliance Training to raise awareness on Information Security and Data Protection among employees.
- Identify, investigate, report, and correct compliance issues and violations.
- Respond to security incidents or breaches alongside the Compliance Manager, ensuring legal and regulatory compliance.
- Provide legal advice on data protection, especially regarding commercial communications.
- Manage Third Party Risk, assessing and mitigating risks related to vendors and external partners, collaborating with DPO and Legal Department to ensure compliance.
Requirements :
- Based in Madrid.
- At least 2 years of experience in risk management, privacy, information security, or IT roles.
- Strong work ethic with a passion for legal advice and new technologies.
- Fluent in English for effective communication.
- Experience with validation, risk management, and change control processes.
- Knowledge of legal and regulatory standards like GDPR, ISO27001, NIST2.
- Excellent analytical skills, capable of managing multiple projects under strict deadlines in a dynamic environment.
- Desirable experience with database security (SQL, Oracle, Azure, etc.).