
Zineb Gridda
Freelance Consultant · ICT Expert / IT & Audit Trainer
16+ years across IT advisory, audit and GRC for banking, fintech and the public sector — CISA, ISO 27001 LI/LA, NIS2 and DORA.
Bio
Zineb is an ICT expert and IT & audit trainer with 16+ years of experience across banking, fintech, public institutions and consulting. She currently runs a CISO-as-a-Service practice in Brussels, leading ISMS programs aligned with NIS2 and DORA — including managing a team of lead implementers for the Proximus Group.
Her career spans IT Audit Expert at KBC Group, Principal Process Engineer and Internal Audit Expert at BNP Paribas Fortis, IT Manager at Sopra Steria, and audit & project management roles at EY and BCG. She has delivered IT due diligence, ISMS implementations, customer-journey programs and IT operating models for clients across Europe, Africa and the Middle East.
Zineb is a PECB-accredited ISO 27001/27002 trainer and an ISACA-accredited CISA trainer. She served as a Board Director of ISACA Belgium (2020–2024) and regularly runs workshops on NIS2, DORA, COBIT, ITIL and IT audit — from KBC's 80+ EU auditors to financial institutions in Uganda and the UAE.
Focus areas
Experience
CISO mandates including Securoad; managing NIS2/ISO 27001 lead implementers for Proximus Group; internal & external audits, NIS2/DORA alignment, CISA & ISO 27001 trainings.
Internal and IT audits and advisory across Europe and the USA. Formalized and delivered trainings to 80+ auditors on CISA, SAFE Agile, ITIL, NIS2, DORA, COBIT and ISO 27K.
Department process review, ISMS implementation aligned with NIS2, Group-level IT strategy & operations audits (ITIL, COBIT, DORA, ITGC). Member of the Belgium Gender Diversity Board.
End-to-end missions: ISMS aligned with NIS2, IT security evaluation, process & project management, internal controls, digital communication, internal audits.
Internal/external audits on ISMS, ISO 27001/27002, COBIT 5, SOC 2 and SOCR. SAP financial implementation lead and change manager on a €1B+ multi-country program.
IT due diligence, IT operating model and customer journey for major banks and a transport operator; new IT security organization design (ISO 27K, NIST, COBIT 5).
CISA trainings, professional events for 200+ IT experts, brand and communication refresh.
© Drimt · Digital Risks Management Tools