- Evaluating potential threats to the business, encompassing physical security and cyber threats, and conducting assessments on vulnerabilities and impact analysis to establish exposure to these risks, and using this information to create mitigation strategies
- Developing business continuity plans, to support the continuation of operations after a disruptive event, and ensure these are tested regularly and that business impact analysis is undertaken to support recovery strategies
- Ensuring all vendors and third parties associated with the business are aligned with the ITSCM strategies, and that risks are assessed and managed in collaboration with the Third-Party Risk Manager and ensuring that appropriate measures are in place
- Identifying crisis scenarios and implementing procedures for response and crisis management, ensuring that internal teams and stakeholders are coordinated and communicated with during crises.
- Monitoring security threats to both premises and people, and making sure the business is compliant with regulatory requirements surrounding these
- Delivering training material for employees on crisis response and business continuity to ensure that operations continue running as seamlessly as possible, and this training should include drills and simulations to ensure maximum preparation
- Making sure the business is compliant with laws, regulations and standards in relation to protection and resilience, and ensuring that external auditors are communicated with as needed
- Seeking ways to continuously improve the protection and resilience activities of the business, setting KPIs as needed to monitor performance and reporting on progress for senior management
- Exposure to a fully regulated sector/industry
- At least 5 years’ experience in risk management or business continuity
- Specifical knowledge of crisis management practices, the development of resilience and protection strategies
- Leadership abilities with cross-functional teams within a crisis setting
- Technical knowledge of physical security systems, cybersecurity principles and emergency response protocols
- Familiarity with ISO 22301, 27001 and NIST