Sandra Garcés +**-**-**-**-**-** *********@*****.*** London, E1W 1NX
Summary
Provide innovative, responsive and sustainable approaches to strengthen firms’ endeavours to conduct
responsible business; supported by 10 years’ experience as auditor and consultant: designing, assessing,
implementing and training risk management for oil, utilities, energy, manufacturing and financial sectors.
Specific knowledge: resilience and business continuity, compliance, risk management, innovation
strategies, sustainable innovation, information security and corporate governance.
Achievements and Experience
2009 – 2012 Alpina (Dairy Factory) – Business Continuity (BC) and Information Security (IS) Corporate Manager.
As Head of BC and IS for Colombia, Ecuador, Venezuela, US and Per ú I contributed to the firm’s goals through:
Protecting and enhancing the firm’s brand
Designing and implementing an Incident / Crisis Management Plan; resulting in successful management of
•
high impact incidents such as health issues for food products, product recall coordination and media control.
Supporting firm’s reputation as a reference for good practices in incident, BC and IS management; acting as
•
guest lecturer to share successful management systems implementations and successful incident controls.
Designing, implementing and standardizing good practices across countries
Defining corporate practices, balanced scorecards and strategic plans for Incident, BC and IS for all
•
countries.
Ensuring synergies in the BC and IS definitions and roll out plans:
•
Aligning and integrating these models with the corporate risk management systems (sustainable
o
development system, self control reports and operational risk and compliance practices)
Using a country as a pilot and spreading the model through: quick customization and delivering
o
training programs to the remaining countries. Work with cross teams for all firm’s processes, facilities
and countries: IT, business owners, HR, Customer Service, Country Managers, operators, among
others.
Contributing to processes standardization and efficiency, via alignment and rationalization of controls across
•
processes and countries.
Improving the governance, compliance and sustainability frameworks.
•
Performance Metrics: from zero initial coverage in BC and IS to:
5 countries with incident plans in place (100% geographies)
•
Sandra Garcés +**-**-**-**-**-** *********@*****.*** London, E1W 1NX
53 processes reporting IS controls in four countries (100% critical process and 80% countries coverage)
•
4 key products with BC plans and controls reports (60% of key products)
•
5 countries with BC and IS awareness campaigns. (100% coverage). It includes 52 training sessions reaching
•
more than 1200 people face to face
260 action plans to improve the risk, governance and compliance systems.
•
Redesign and improvements for: senior committees, code of ethics, compliance and risk policies.
•
Deloitte (Colombia) 2006 – 2009 Senior Consultant / 2003 – 2005 Consultant
As senior consultant I contributed to Deloitte’s goals through:
Supporting the foundation and on going improvement of the Business Continuity line service for
Colombia and its subsequent spreading to LATAM region:
Defining proposals, budgets and work plans to sell and deploy BC services; with a notable increase from one
•
client to more than 16 clients after four years.
Designing, implementing and training seniors and consultants in the use of templates and tools to perform BC
•
engagement (BIA, RIAs, strategies, Incident / crisis, testing, training materials, among others). From 4 people
with knowledge to more than 24 managers, seniors and consultants to cope with BC engagements. 45 BC
plans designed, 540 BC testing hours and 700 training hours delivered.
Serving as quality assurance for risk projects’ implementation; recognition received in all client service
•
surveys.
Ensuring high quality IT control assurance, operational, SOX and compliance consulting and audit
programs:
Designing, performing and applying follow up to proposals and work plans for new and current engagements.
•
25 clients, 4 industrial sectors, all customers’ satisfaction surveys with positive feedback.
Using regular coaching and feedback to my direct reports so as to design their professional development
•
programs, strength their skills and promote their careers. More than 12 consultants coached.
Involved in regular trainings, workshops and accreditations processes. More than 20 trainings (350 hours)
•
and 3 professional accreditations obtained.
Other activities
Trainer for ISACA’s CISA and CISM accreditations
•
BC, IS and incident management teacher at universities and facilitator for private firms
•
Sandra Garcés +**-**-**-**-**-** *********@*****.*** London, E1W 1NX
Partner in a non profit foundation to promote resilience and business continuity management practices to
•
SMEs by local and internationals forums.
Studies
Master of Business Administration (Expected 2014). Major in Innovation and Sustainable Development.
•
Grenoble Graduate School of Business. British and French accreditations.
Systems and Computer Engineer (IT background). Universidad de los Andes, Colombia. 2002
•
Professional Accreditations
MBCI Member of the Business Continuity Institute. 2012 Business Continuity Institute BCI UK.
•
MBCP Master Business Continuity Professional. 2012 DRII USA.
•
CISA Certified Information System Auditor. 2008 ISACA USA.
•
CISM Certified Information Security Manager. 2008 ISACA USA.
•
Soft Skills
Passion, engagement, project management, problem solving, analytical thinking, goal and challenge oriented,
service client, team work, coaching and senior communication skills.
Languages
English proficient Spanish native
References are available on request.