Our engineer’s CV

Engineer / BCP-DR & GRC — Grégory Murer

Business Continuity & Disaster Recovery Testing Manager at BNP Paribas Fortis — GRC, operational resilience and cybersecurity expert with 27+ years supporting Belgian organisations and critical infrastructure.

Profile

Business continuity, disaster recovery (BCP/DR), governance, risk and compliance (GRC) expert with 27+ years of experience. Leads the end-to-end BCP/DR testing lifecycle, security governance, risk management and regulatory compliance (ISO 27001, ISO 22301, ISO 27005, NIS2, DORA, GDPR, CSSF) in large organisations and critical infrastructure. Dual expertise — strategic governance and technical engineering (cloud, IAM/PKI/SSO, SOC/SIEM). Founder of XpandIT.be; repeatedly entrusted with deputizing for the CISO function, including acting-CISO and CISO-as-a-Service.

Key skills

  • Continuity & resilienceBCP/DR testing, tabletop, failover, RTO/RPO, DORA / NBB-ECB, resilience culture
  • Governance & strategyISMS policy, cybersecurity roadmap, advisory to senior management and boards
  • Program & project managementIncluding digital transformation and change management
  • Compliance & frameworksISO 27001:2022 (Lead Implementer), ISO 22301, ISO 27005, NIS2, DORA, GDPR, CyFun
  • Risk managementCIS, OWASP Risk Rating, MONARC, risk and vulnerability mapping and monitoring
  • Crisis & incidentsCSIRT coordination (L3+), recovery priorities, crisis cells
  • Technical securityCloud (GCP/AWS/Azure), IAM/PAM/PKI/SSO, SOC/SIEM/EDR, industrial/IoT (IEC 62443)
  • Third-party & vendorsSupplier risk reviews, cloud brokers, supply-chain security
  • AwarenessTraining delivery, technical outreach, risk committee facilitation

Professional experience

Business Continuity & Disaster Recovery Testing Manager

Jul 2026 – present

BNP Paribas Fortis — Brussels, Belgium · Hybrid

Ensuring the bank stays resilient when it matters most. Leads the end-to-end lifecycle of BCP/DR testing across BNP Paribas Fortis’ Belgian entities, bridging Group-level strategy with local operational reality.

  • Group-to-local alignment — Receiving Business Continuity & Disaster Recovery frameworks from Paris headquarters and translating them into actionable plans tailored to each Belgian entity’s operational, regulatory and technical context.
  • Test orchestration — Designing, planning and driving the execution of BCP/DR exercises: tabletop simulations, failover tests, and full-scale recovery scenarios.
  • Constructive challenge — Challenging business and IT teams on their continuity assumptions, recovery capabilities (RTO/RPO) and test readiness — because a plan that hasn’t been tested is just a hypothesis.
  • Incident recovery decisions — Determining restart priorities and recovery sequencing following incidents, balancing business criticality, dependencies and risk exposure.
  • Regulatory resilience — Contributing to compliance with operational resilience requirements (DORA, NBB/ECB expectations) through evidence-based testing and continuous improvement.
  • Cross-entity coordination — Acting as the pivot between Group HQ, Belgian entities, IT operations and business lines to embed a genuine culture of resilience.

Founder & Principal Cybersecurity Consultant

Feb 2026 – present

XpandIT.be — Liège, Belgium · Freelance / Hybrid

  • CyberMurmureur; NIS2 / CyFun / DORA implementation stewardship; ISO 27001 audits; cybersecurity awareness.

GRC Engineer and CISO deputy

Sept 2025 – Jun 2026

iHub (Deep), subsidiary of Post.lu — Kayl, Luxembourg · On-site

  • Led the identification, analysis, and monitoring of IT risk within a multi-entity regulated financial environment.
  • Conducted technical risk assessments and cloud security evaluations (architecture and data-flow decomposition per OWASP Risk Rating and ISO 27005).
  • Managed the full regulatory audit lifecycle: ISO 27001:2022, ISO 22301, DORA, and CSSF circulars, including third-party and supplier risk.
  • Drove continuous improvement of risk management processes; coordinated cross-functional risk awareness initiatives.
  • Acted as deputy/backup CISO, ensuring continuity of the CISO function and representing information security matters when the CISO was unavailable.

Local GRC Ops Expert — CISO-as-a-Service for local entities

Mar 2022 – Sept 2025

AXA Group Operations — Brussels, Belgium · Hybrid

  • Primary point of contact for NIS2, ISO 27001, ISO 22301 and DORA across local entities; liaison with CISOs and Security Leaders.
  • Owned risk-management dashboards for NIS2, ISO 27001, ISO 22301 and DORA programs.
  • Coordinated risk-champion forums and produced compliance deliverables; disseminated requirements and risk culture.
  • Led migration of the risk framework from NIS/OWASP to NIS2/CyFun; built KPI/KGI/KRI dashboards for senior management.
  • Conducted risk/vulnerability/threat impact assessments; advised on remediation, hardening and supply-chain security controls.
  • Point of contact for third-party security reviews and supply-chain risk assessments.
  • Led group-wide rollout of Qualys vulnerability management across local AXA entities; coordinated deployment and SOC integration.
  • Owned SOC use-case lifecycle: detection logic, alert-threshold tuning and collaboration with SOC analysts.
  • Delivered CISO-as-a-Service coverage for local AXA entities without dedicated security leadership (Yuzzu, Ardenne Prévoyante, AXA IM).

Cyber Security Instructor

Nov 2023 – Feb 2024

IFAPME — Belgium · Freelance

  • Hands-on cybersecurity bootcamp for ULG students: vulnerability assessments, penetration testing, cloud security, Bash/Python automation.

External Security Project Manager

Oct 2017 – Feb 2022

bpost — Belgium · Freelance / Hybrid

  • Led security and compliance projects: risk assessment, budgeting, coordination of multidisciplinary teams.
  • Implemented security frameworks and built internal/third-party audit roadmaps; embedded DevSecOps practices into the project lifecycle.
  • Deputized for the CISO in meetings with Higher Management, presenting security risk dashboards and reporting in his absence.

DB Migration Consultant

Jan 2021 – Aug 2021

Medical practices — Saint-Vith, Belgium · Freelance

  • Tuned failing Python migration scripts; completed database migration (Python, Monarch RMOD, PowerShell, AD, Windows Servers).

Freelance Embedded System Engineer / ETCS Compliance

Sept 2015 – Oct 2017

SNCB — Belgium · On-site

  • Embedded Java systems on Siemens AM08 trains for ETCS compliance — safety-critical (SIL) railway signalling, secure communication protocols.

Cybersecurity & Process IoT/SCADA Consultant

Jan 2007 – Aug 2015

Beryllium Erbium Brewery & industrial clients — Belgium, Brazil, USA · Freelance

  • Risk assessments and security architecture reviews for industrial automation (IEC 62443); SCADA and industrial protocols (Siemens/Rockwell PLCs). Engagements including Egisa / USP (São Paulo), Bodebrown, Dama Bier, Crafted at the Port (Los Angeles).

Cyber Security Engineer

Oct 2002 – Mar 2005

Proximus — Brussels, Belgium

  • Secured project management; designed load-balancing for Brussels–Ghent data centres (Cisco CSS).
  • Tuned/managed Checkpoint Firewalls on Nokia; SunOne LDAP with full replication and automated backup; Perl/Python; FCCU liaison.

IT Manager

Dec 2001 – Oct 2002

mediafiles — Louvain-la-Neuve, Belgium

  • IT Manager as the company grew from 5 to 25 people; Netgear VPN/firewalls, Windows/Linux servers, OpenSQL.

Cyber Security Engineer

Sept 1999 – Dec 2001

European Space Agency (ESA) — Noordwijk, Netherlands · Freelance

  • Secured the Galileo satellite data uplink (QNX/C) — recruited after independently identifying a critical GNSS vulnerability. NATO Secret clearance.

Other experience

RoleDateOrganisation
Instructor — MicrobreweryJan – Jun 2015IFAPME — Freelance
Keynote speaker — brewing processes2010 – 2015Freelance — Brazil, Canada, USA, Italy
Head IT Brewer2007 – 2013La Fleuracoise — Cantal, France · Independent
System AdministratorJun 2005 – Jan 2007Ubisoft / Gameloft Studios — Aurillac, France
LDAP – Oracle DB EngineerMar – Jun 2005Smals — Brussels (eHealthbook / SPF Santé)

Certifications & training — thematic overview

Deduplicated LinkedIn licences and certifications, grouped by theme. Multi-module Skillsoft / LinkedIn Learning pathways are summarised as a single cycle line.

Artificial intelligence & agents

Anthropic Claude, MCP, Gemini, prompt engineering and cloud AI (Bedrock, Vertex).

Several Anthropic certificates from April 2026 belong to the same AI Fluency / Claude cycle.

TrainingIssuerDate
Claude Code in ActionAnthropicMar 2026
Claude 101 / Claude Code 101AnthropicMar–Apr 2026
Building with the Claude APIAnthropicApr 2026
Introduction + Advanced Topics — Model Context Protocol (MCP)AnthropicApr 2026
Claude in Amazon Bedrock / Claude with Vertex AIAnthropicApr 2026
AI Fluency Framework (foundations, educators, students, nonprofits, teaching)AnthropicApr 2026
AI Capabilities and LimitationsAnthropicApr 2026
Advanced prompt engineeringLinkedIn LearningAug 2025
Building apps with Google GeminiLinkedIn LearningAug 2025

Governance & standards

ISO 27001 Lead Implementer, Annex A controls, and compliance frameworks.

TrainingIssuerDateExpires
ISO 27001 Certified Lead Implementer — I27001LICertiprofJun 2026Jun 2029
ISO 27001:2022-Compliant Cybersecurity: The Annex A ControlsLinkedIn LearningJul 2025

Audit & GRC

CISA, CRISC and audit / risk practice modules.

Six CISA 2019 Skillsoft modules grouped as one pathway (April 2025).

TrainingIssuerDate
CISA 2019 pathway — Skillsoft modules (Digital Evidence, PKI & Data Protection, Performance & Management, IAM & Data Classification, Data Privacy & Risk, IT Management Frameworks)SkillsoftApr 2025
CRISC 2023: Network SecuritySkillsoftDec 2024
Cybersecurity Outsourcing: Vendor Selection and ManagementLinkedIn LearningJul 2024

Continuity & resilience

Operational resilience and disaster coping.

TrainingIssuerDate
Resilience911: Resilience — The Art of coping with disasterBen-Gurion University of the NegevApr 2026
CompTIA Cybersecurity Analyst+: Business ContinuitySkillsoftOct 2023

Offensive cybersecurity / CEH / web & wireless

CEH v12, CySA+, (ISC)² CC, OWASP and related modules.

CEH v12 pathway: ~30 Skillsoft modules (Dec 2024 – Jan 2025), deduplicated. CySA+: full series Oct–Dec 2023.

TrainingIssuerDate
CEH v12 pathway — Skillsoft modules (recon, scanning, enumeration, malware, sniffing, web app, SQL injection, wireless, DoS…)SkillsoftDec 2024 – Jan 2025
OWASP Top 10: Securing Web Applications + SQL Injection Testing (sqlmap)SkillsoftDec 2024
CompTIA CySA+ pathway — Skillsoft modules (threat intel, crypto, firewalls, malware, hardening, forensics…)SkillsoftOct–Dec 2023
Certified in Cybersecurity (CC) — Skillsoft modulesSkillsoftNov 2024 – Feb 2025
DevSecOps principles / methodologiesSkillsoftOct–Nov 2024
Advanced IT security & cybersecurityLinkedIn LearningAug 2021
Managing cybersecurity incidents at workLinkedIn LearningAug 2021
Check Point Certified Expert (CCSE) / CCNA / CCSOCDimension Data2003
OPSECDCSAFeb 2021

Cloud & identity

Azure Entra ID, Docker, Azure Fundamentals, Active Directory, Splunk.

TrainingIssuerDate
Azure: Configure and manage Microsoft Entra IDLinkedIn LearningJul 2025
Docker essentialsLinkedIn LearningJul 2025
Microsoft Azure Fundamentals: Cloud ComputingSkillsoftDec 2023
Active DirectorySkillsoftDec 2024
CompTIA Security+: Virtualization, Cloud Computing & Cloud CybersecuritySkillsoftOct 2023
Splunk Fundamentals 1SplunkFeb 2021
Sun One Directory Server — Analysis & Planning L5Sun MicrosystemsMar 2003
SharePoint Server 2019 administrationLinkedIn LearningAug 2021
Linux system architecture / Python 3 essentialsLinkedIn Learning2021
IoT fundamentalsLinkedIn LearningAug 2021

Project management & Agile

PRINCE2, Agile, Kanban, ITIL, change management, Six Sigma.

PRINCE2 and Agile pathways: Skillsoft modules grouped (Mar–Apr 2025).

TrainingIssuerDate
KBPC | Kanban Foundation International CertificationKanban Foundation InternationalMay 2026
PRINCE2® 2017 pathway — Skillsoft modules (overview, adoption, planning & risk, control & close, quality, initiate)SkillsoftMar–Apr 2025
Agile pathway — Skillsoft modules (principles, planning, tracking, stakeholders, exam concepts)SkillsoftApr 2025
ITIL® 4 Foundation — key concepts + First LookSkillsoft / LinkedInNov 2024 – Mar 2025
Six Sigma Green Belt + Lean Six Sigma with PythonLinkedIn LearningJul 2025
Change management — leading change, Decision Analysis, CompTIA Project+/A+, SSCP Asset & ChangeLinkedIn / SkillsoftJul 2025
Project Management — Basics and IntermediateAXASept 2023
Technical Program Management: Solving Complex ProblemsSkillsoftDec 2024

Forensics / academic info sec

University programmes and information-security pathways.

TrainingIssuerDate
Unlocking Information Security II: An Internet PerspectiveTel Aviv UniversityApr 2026
Computer Forensics (edx)Rochester Institute of Technology2020–2021
CompTIA A+ / Project+ modules (info mgmt, change, mobile OS security)Skillsoft2024–2025

Leadership / soft skills

Management, ethics and inclusion.

TrainingIssuerDate
Being an effective manager in turmoilSkillsoftAug 2025
Military Healthcare EthicsKing's College LondonMay 2026
Fighting Gender Bias at WorkLinkedIn LearningJun 2024
Building a professional network remotelyLinkedIn LearningJan 2025

Education

InstitutionProgrammeDate
Tel Aviv UniversityUnlocking Information SecuritySept 2020 – Jun 2021
HEC LiègeMaster’s in Business Administration and ManagementSept 2021 – Jun 2023
Abide UniversityPhD, Environmental Psychology — thesis: How Climate Change Modifies the Perception of Mass Migration in Passive Transit CountriesMay 2022
Rochester Institute of Technology (edX)Computer ForensicsSept 2020 – Jun 2021
Université Henri Poincaré, Nancy 1Microbiology laboratory techniques2008
UCLouvain FUCaM MonsManagement Science1999 – 2001
UCLouvainEngineering degree, PhysicsSept 1992 – Jun 1997
ICET MonsUndergraduate diploma, MarketingSept 1997 – Jun 1999

Languages

  • EnglishNative or bilingual proficiency
  • FrenchNative or bilingual proficiency
  • HebrewElementary (Duolingo 12 — Oct 2023)
  • DutchElementary (Duolingo 13 — Jul 2026)

Let’s work together

BCP/DR testing, NIS2 diagnostic, GRC governance or CISO-as-a-Service: a 30-minute call to clarify the need.

Contact