You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Freelancer profile translated to English.
Back to original language

About Hamza

Internal Audit Director and GRC (Governance, Risk, and Compliance) expert with over 13 years of experience in the banking sector. Specializing in IT risk and cybersecurity mastery, regulatory compliance (DORA, GDPR, PSD2, ISO 27001, AML/CFT), and data governance. Recognized expertise in supervising IT audits, cyber risk mapping, compliance management, and coordination with European and African regulators. Committed leader, promoter of a security and control culture, and key player in the RPAI 2025 certification.
  • French

    Native or bilingual

  • Arabic

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km)

Experience

  • ATTIJARI WAFA BANK Europe-
    Director of General Audit Europe
    BANKING AND INSURANCE
    July 2019 - Today (7 years and 1 month)
    Paris, France
    • Development and deployment of an integrated internal audit strategy covering governance, risks, compliance, and cybersecurity, in alignment with IFACI, ISO 27001, DORA, GDPR, and PSD2 standards.
    • Management of a transversal GRC framework ensuring the banking group's compliance with European regulatory requirements and international best practices.
    • Operational coordination of remediation plans and compliance missions with regulators and supervisory authorities in France, Spain, Italy, Germany, Belgium, and the Netherlands.
    • Supervision of over 80 international audit missions in operational, risk, compliance, IT, information system security, and operational resilience domains.
    • Conduct of specialized cybersecurity and IT security audits: protection of sensitive data, access governance, incident monitoring, and business continuity planning (BCP/DRP) assessment.
    • Design and maintenance of a consolidated risk map integrating cyber, regulatory, operational, and third-party risk management (TPRM) dimensions, accompanied by key risk indicators (KRIs).
    • Implementation of a proactive vulnerability management process and follow-up of corrective action plans aimed at strengthening the information system's security posture and resilience.
    • Regular reporting to audit and risk committees: summary of key findings, assessment of emerging risks, follow-up of recommendations, and continuous improvement plan.
    • Management and coaching of a multidisciplinary team of auditors, developing skills in GRC, cybersecurity, regulation, and data governance.
    • Achievement of IFACI RPAI 2025 certification, confirming the maturity and compliance of the internal audit function with GRC and cybersecurity market best practices.
    Internal Audit Regulatory Compliance: DORA, GDPR, PSD2, ISO 27001, AML/CFT Operational and Cyber Risk Management Data Security and Business Continuity
  • ATTIJARI WAFA BANK
    Audit Mission Manager - Risks and Subsidiaries
    BANKING AND INSURANCE
    March 2012 - July 2019 (7 years and 4 months)
    Casablanca, Morocco
    • Conduct of strategic audit missions covering the Group's international subsidiaries (Tunisia, Mali, Mauritania, Gabon) as well as specialized entities (asset management, leasing, securitization, payment processing, custody).
    • Assessment of internal control and compliance frameworks in operational, IT, risk, and data security domains.
    • Execution of IT and cybersecurity audits on production environments, access management, data protection, and critical processes. (Mission conducted jointly with Deloitte France).
    • Analysis of the maturity of risk management frameworks and operational resilience of infrastructures (BCP/DRP).
    • Participation in the review of digital transformation projects and assessment of risks related to dematerialization and information systems.
    • Development and updating of internal audit guides and methodologies.
    • Drafting of summary notes and investigation reports for senior management and the General Inspection, particularly in the context of investigating fraud cases and compliance anomalies, ensuring complete traceability and transparent communication with governance bodies.
    • Coordination and supervision of multidisciplinary teams on audit missions; coaching junior auditors in developing their skills in GRC and IT.
    Internal Audit Data Security and Business Continuity Operational and Cyber Risk Management
  • PHILIPS FRANCE,
    End-of-studies Internship in Internal Control - Accounting
    March 2011 - December 2011 (9 months)
    Longchamp - Suresnes, Paris, France
    • Implementation of a SharePoint-based sharing platform within SBSF (following an e-learning course on SharePoint).
    • Daily follow-up with the Shared Service Center in India/Poland for rebates and accounting entries.
    • Participation in the accounting tasks of a newly acquired local subsidiary.
    • Execution of monthly account closings and analysis of travel expenses.

Recommendations

Be the first to recommend Hamza

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master Grande Ecole
    NEOMA (Ex Rouen Business School)
    2012
    Master Grande Ecole
  • null
    ISCAE: Higher Institute of Commerce and Business Administration
    2010

Certifications

  • AML/CFT Operational Expertise
    Esbanque
    2021
    Risk Analysis Embargoes Anti-Money Laundering TRACFIN
  • IFACI Certification
    IFACI
    2025
    Audit Knowledge of Standards and Regulations Internal Audit and Strategic Risk Mapping Risk Mapping

Skill set

Categories