GRC BIA Consultant
Job Summary
As part of strengthening its governance risk management and compliance framework as well as aligning with regulatory and normative requirements the IT Risk Management entity wishes to temporarily reinforce its team by engaging a consultant specializing in BCP / BIA / DRP.
The mission aims to support various business and IT entities in assessing their critical activities improving their operational resilience and integrating information security requirements into their management processes.
The consultant will be integrated into the IT Governance Risk & Compliance team and will report directly to the IT Risk Manager. They will serve as the primary point of contact between IT teams and business stakeholders for topics related to regulatory compliance business continuity and risk management.
Scope of the Mission
The consultant will be responsible for the following activities:
Business Impact Analysis
- Organize and facilitate BIA workshops with various business and IT entities.
- Assist in identifying critical processes dependencies business impacts and recovery requirements.
- Define and validate key indicators such as:
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD).
- Formalize and maintain BIA documentation.
Business Continuity and Resilience
- Contribute to the improvement and updating of BCP and DRP frameworks.
- Ensure alignment between BIA results and existing business continuity plans.
- Participate in defining and enhancing continuity and recovery strategies.
Governance Risk and Compliance
- Support business and IT entities in integrating information security requirements into their processes.
- Contribute to the evolution of the governance framework regarding risk management and compliance.
- Participate in initiatives related to regulatory and normative compliance particularly within the context of DORA and ISO 27001 requirements.
Document Review
- Review and update policies procedures standards and associated documentation.
- Guarantee alignment of documentation with regulatory normative and internal practice requirements.
Audit Follow-up
- Follow up on recommendations resulting from internal and external audits.
- Coordinate corrective actions with the relevant stakeholders.
- Produce the required evidence to close action plans.
Deliverables
Expected deliverables include but are not limited to:
- Completed and validated BIA files and reports
- Minutes of workshops and working meetings
- Updated policies procedures and reference documents
- Action plans related to audit recommendations
- Detailed mission schedule and activity tracking
- Regular progress reports.
Required Profile
Technical Skills
- Significant experience in conducting Business Impact Analyses.
- Demonstrated expertise in business continuity management.
- Strong command of risk management principles and GRC practices.
- Knowledge of ISO 27001 standard requirements.
- Good understanding of the DORA regulation and digital operational resilience challenges.
- Experience in managing and following up on audit recommendations.
Organization and Governance
- Mission Lead:IT Risk Manager.
- Department:IT Governance Risk & Compliance (IT GRC).
- Stakeholders:
- Business departments
- IT teams
- Security office / IT Risk Management;
- Internal Audit;
- Compliance.
The consultant will collaborate closely with all of these stakeholders to ensure the smooth execution of the mission and the achievement of the established objectives.
Languages
- French: Fluent.
- Dutch: Fluent.
- English is an asset.
Required Skills:
IT GOVERNANCERPOIT RISK
About Company
30 employees
Welcome to Sansaone, a dynamic force in the realm of ICT talent acquisition. Born out of a passion for excellence and a vision for connecting outstanding professionals with forward-thinking organizations, we stand as a beacon for strategic recruitment solutions in the Information and ... View more