IT Governance and Data Protection Manager

Randstad España·Reus, Spain

What they offer

  • Permanent contract

    Full-time hours.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Work on-site in Reus

    No relocation package mentioned.

  • Have 4+ years of experience

    Senior-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 27 days ago
Read the full advert

About the role

Do you have experience as an IT Governance and Data Protection Manager and are you ready to take the leap into a co-leadership position in a dynamic corporate environment?

We are selecting an IT Governance and Data Protection Manager for our client, a leading hotel chain, for an on-site position at its headquarters.

We are looking for a professional to work in collaboration with the Chief Information Officer (CIO) in the role of IT Governance and Data Protection Manager. Your main mission will be to establish and maintain the group's IT governance framework, ensuring alignment between IT and business, regulatory compliance — including personal data protection — and effective management of technological risks, acting as the guardian of the policies, processes, and controls that support operations across all its locations.

What you'll do

  • Define, document, and keep the IT governance framework (policies, internal regulations, procedures) updated, aligned with best practices standards (COBIT, ITIL, ISO 27001).
  • Manage the IT service catalog, ensuring it accurately reflects the offering to business units and hotels.
  • Define and monitor IT KPIs for the Systems Department, consolidating reporting to senior management and committees.
  • Act as the liaison between different IT areas (Infrastructure, Applications, Cybersecurity, Data, Service Desk) to ensure coherence of technological decisions with the group's strategy.
  • Coordinate IT governance committees (Architecture, Security, Projects) and follow up on their agreements.
  • Identify, assess, and prioritize the group's technological risks, maintaining an up-to-date risk map.
  • Define and implement internal IT controls and verify their effectiveness through periodic reviews.
  • Oversee compliance with sector regulations (GDPR/LOPDGDD, PCI-DSS in payment systems, local regulations in each country of operation).
  • Coordinate internal and external IT audits, following up on resulting action plans.
  • Manage relationships with critical vendors regarding contractual compliance and service level agreements (SLAs).
  • Ensure compliance with GDPR and LOPDGDD in the processing of customer, employee, and vendor data across all group entities.
  • Keep the Record of Processing Activities (ROPA) updated and coordinate its review with business areas.
  • Conduct and oversee Data Protection Impact Assessments (DPIA) for projects involving sensitive or large-scale data processing.
  • Manage the exercise of ARCO-POL rights (access, rectification, cancellation, opposition, portability, limitation) and notifications of data breaches to the AEPD and equivalent authorities.
  • Act as the point of contact with the Data Protection Officer (DPO) and with the Legal and Internal Audit departments.
  • Define and maintain policies for data retention, transfer, and international data transfers, particularly relevant given the group's multi-country operations (Dominican Republic, Mexico, Jamaica, Canary Islands, and mainland Spain).
  • Develop and maintain the internal IT regulatory framework (information security, acceptable use, information classification, third-party management, etc.).
  • Design and coordinate training and awareness plans on data protection and IT best practices for employees and hotel managers.
  • Support business areas in reviewing contracts with technology vendors from a governance, risk, and compliance (GRC) perspective.
  • Keep governance documentation accessible and up to date for use in audits, certifications, and due diligence processes.

Requirements

  • Education: University degree in Computer Science, Telecommunications, Law, Business Administration, or a related field. Certifications such as CIPP/E, CIPM, ISO 27001 Lead Auditor/Implementer, COBIT, or ITIL are highly valued, as is specific training as a Data Protection Officer.
  • Experience: Minimum 4-5 years of experience in IT governance, regulatory compliance, IT auditing, or data protection. Previous experience as a DPO or supporting a DPO is valued. Experience in the hotel, tourism, or multi-country business sector is highly valued.
  • Technical skills: In-depth knowledge of GDPR, LOPDGDD, and data protection regulations in the countries where the group operates. Familiarity with governance and control frameworks (COBIT, ITIL, ISO 27001, ISO 22301). Knowledge of GRC tools and ROPA/DPIA management tools. Advanced Excel and reporting skills.
  • Languages: Spanish: native or bilingual proficiency. English: advanced level (B2/C1), essential due to the group's international environment.

Benefits and conditions

  • Stability: Permanent contract, full-time position.
  • Work-life balance schedule: Monday to Thursday from 8:30 AM to 2:00 PM and 3:00 PM to 6:00 PM, and Friday from 8:30 AM to 2:30 PM.
  • Work model: On-site at the corporate headquarters, with availability for occasional travel to hotels and local offices.

This job was automatically translated to English, .

About the company

Randstad España

Randstad España

Staffing

View company profile
International company

Randstad España is a staffing agency.They recruit for client companies, so the employer you would work for is not named on this ad.