05 ago
|
Sparagus
|
España
To strengthen its IT Governance, Risk & Compliance (IT GRC) framework and support ongoing regulatory and compliance initiatives, our client is looking for an IT GRC Consultant specialized in Business Continuity to temporarily reinforce its IT Governance, Risk & Compliance team.
The consultant will support both business and IT teams in assessing critical business activities, improving operational resilience, and integrating information security requirements into business processes.
Reporting directly to the IT Risk Manager, the consultant will act as the primary point of contact between IT teams, business stakeholders, Security, Audit, and Compliance on all matters related to business continuity, risk management, and regulatory compliance.
Key Responsibilities :
Business Impact Analysis (BIA)
- Organize and facilitate Business Impact Analysis (BIA) workshops with business and IT stakeholders.
- Identify critical business processes, dependencies, business impacts, and recovery requirements.
- Define and validate key continuity metrics, including:
- Recovery Time Objective (RTO)
- Recovery Point Objective (RPO)
- Maximum Tolerable Downtime (MTD)
- Prepare, maintain, and update Business Impact Analysis documentation.
Business Continuity & Disaster Recovery
- Contribute to the development, maintenance, and continuous improvement of Business Continuity Plans (BCP) and Disaster Recovery Plans (DRP).
- Ensure consistency between BIA outcomes and existing continuity plans.
- Support the definition and enhancement of business continuity and disaster recovery strategies.
- Contribute to strengthening the organization's operational resilience.
Governance, Risk & Compliance
- Support business and IT teams in integrating information security requirements into their processes.
- Contribute to the evolution of the Governance, Risk & Compliance (GRC) framework.
- Participate in regulatory compliance initiatives, particularly related to DORA and ISO 27001.
Documentation
- Review and update policies, procedures, standards, and related documentation.
- Ensure documentation complies with regulatory requirements, industry standards, and internal best practices.
Audit & Follow-up
- Monitor the implementation of recommendations resulting from internal and external audits.
- Coordinate remediation action plans with the relevant stakeholders.
- Prepare and provide the evidence required to close corrective actions.
Expected Deliverables
The consultant will be responsible for delivering, among others:
- Completed and validated Business Impact Analysis (BIA) reports.
- Minutes of workshops and project meetings.
- Updated policies, procedures, standards, and reference documentation.
- Action plans related to audit recommendations.
- Detailed project planning and activity tracking.
- Regular progress reports.
Required Profile :
Technical Skills
- Proven experience conducting Business Impact Analysis (BIA).
- Strong expertise in Business Continuity Management (BCM).
- Solid understanding of Governance, Risk & Compliance (GRC) principles.
- Good knowledge of ISO 27001.
- Good understanding of the DORA regulation and digital operational resilience requirements.
- Experience monitoring audit recommendations and remediation plans.
- Experience drafting and maintaining policies, procedures, and standards.
Soft Skills
- Strong analytical and problem-solving skills.
- Pragmatic and results-oriented approach.
- Excellent written and verbal communication skills.
- Ability to facilitate workshops and interact effectively with both business and technical stakeholders.
- Strong stakeholder management skills.
- Autonomous, well-organized, and detail-oriented.
Languages
- Fluent in French and Dutch.
- English is considered an asset.
📌 Consultant grc / bia (España)
🏢 Sparagus
📍 España