Enable job alerts via email!

GRC and Data Privacy Specialist

TN United Kingdom

United Kingdom

Hybrid

GBP 40,000 - 70,000

Full time

27 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a GRC and Data Privacy Specialist to enhance their compliance and data protection efforts. This role involves developing and maintaining a robust GRC strategy, ensuring adherence to GDPR and PCI DSS standards, and providing internal consultancy on privacy matters. With a flexible hybrid working model and a commitment to employee well-being, this position offers a unique opportunity to make a significant impact in a fast-paced retail environment. Join a team dedicated to excellence and innovation in data protection.

Benefits

25% Colleague Discount
Financial Wellbeing Support
Seasonal Incentive Schemes
Retail Management Apprenticeship Programmes
Discounts across UK retailers
Employee Assistance Programme

Qualifications

  • Experience managing privacy operations compliant with GDPR and PECR.
  • Strong organizational and time management abilities.

Responsibilities

  • Develop and maintain policies for GRC and Data Protection Strategy.
  • Conduct audits to verify compliance with GRC policies.

Skills

GDPR Knowledge
PECR Understanding
Risk Management
Compliance Standards
Organizational Skills
Communication Skills

Tools

OneTrust
Microsoft Auditing and Compliance

Job description

Social network you want to login/join with:

GRC and Data Privacy Specialist, Wakefield 41 Industrial Estate

col-narrow-left

Client:

Card Factory

Location:
Job Category:

Other

-

EU work permit required:

Yes

col-narrow-right

Job Reference:

0577c86673a0

Job Views:

7

Posted:

24.04.2025

Expiry Date:

08.06.2025

col-wide

Job Description:

Job Introduction

cardfactory are excited to announce a new opportunity for a GRC and Data Privacy Specialist to join our growing team. Working closely with the GRC Manager and DPO, you will build and maintain cardfactory’s GRC and Data Protection Strategy to aid in developing and maintaining privacy, GRC, and related policies, help to describe and define compliance requirements, and facilitate regulatory compliance.

Based at Junction 41 in Wakefield, with free parking and a flexible, hybrid way of working, this is a fantastic opportunity to make a real impact in our team. Colleagues are required to work in the office for a minimum of 1-2 days per week, with the expectation of additional attendance when needed.

Role Responsibility

  • Develop, implement, communicate, maintain, and review the strategy with relevant stakeholders at cardfactory.
  • Develop and maintain policies, procedures, and documentation to support an effective GRC and Data Protection Strategy including all necessary documents under the UK GDPR.
  • Ensure cardfactory meets compliance standards, including PCI DSS, GDPR, and other relevant regulations.
  • Conduct audits and monitoring to verify compliance with policies and procedures related to the GRC and Data Protection Strategy.
  • Provide internal expertise and consultancy on privacy, data protection, and the PECR.
  • Update or create training materials related to data protection and GRC.
  • Stay informed about the latest trends, risks, and legal precedents in Data Protection.
  • Collaborate with Security colleagues to manage risks associated with third-party suppliers and service providers.
  • Ensure they meet required compliance and security standards for contracted services.

The Ideal Candidate

  • A good knowledge and working understanding of the GDPR and PECR
  • Prior experience of managing privacy operations compliant with the GDPR and PECR.
  • Good attention to detail, strong organisational and time management abilities.
  • Excellent written and oral communication skills, with the ability to adapt communication styles to suit and influence audiences of varying seniority, business areas, and locations.
  • Demonstrable experience in risk management.
  • The ability to implement a holistic security program of strategy, policies, processes, and technologies.
  • Being able to balance legislative requirements taking into consideration a commercial viewpoint.
  • Experience of implementing and managing Governance, Risk, and Compliance programs.
  • Experience working in fast-paced and complex environments (retail experience would be beneficial).
  • Experience with ISO27001, ISO27701, ISAE 3000/3402, or other information security / GRC standards.
  • Experience in using GRC tools, such as OneTrust or Microsoft Auditing and Compliance.

About the Company

Card Factory is the UK’s leading specialist retailer of greeting cards, dressings, and gifts with over one thousand stores across the UK and Ireland. In 2020, we launched our exciting 5-year business strategy including our vision of becoming a true Omni-channel retailer. This strategy sees significant investment into our colleagues across the business, creating multiple opportunities to join a fast-paced environment and be part of our exciting journey.

In return, we offer a wide range of benefits to support your physical, mental, and financial well-being.

  • 25% Card Factory colleague discount in-store and online
  • Financial Wellbeing Support, Financial Education Tools, Salary Advance
  • Seasonal incentive schemes
  • Retail Management Apprenticeship Programmes with local providers, with access to a virtual internal network for learning together
  • Discounts across 100’s of UK retailers
  • Employee Assistance Programme – access to tools to support mental, physical, and financial wellbeing
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.