À propos de Thierry
Français
Bilingue ou natif
Anglais
Capacité professionnelle complète
Expériences
- Société GénéraleIT Security Operations ManagerBANQUE & ASSURANCESmai 2023 - juillet 2025 (2 ans et 2 mois)Paris, FranceManaged IT infrastructure security operations in a cloud environment (e.g.,Load Balancers, DNS, Virtualization, Messaging Middleware, Bastions),auditing and certifying cloud services according to internal security standardsbased on security controls defined by NIST 800-53, and contributing to theInformation Security Management System.• Performed architecture reviews to check for the absence of securityflaws and provided recommendations to improve security.• Performed risk analyses and proposed risk mitigations aligned with riskappetite, security policies, and regulatory requirements.• Supported product owners in defining alerting scenarios for the SIEM.• Ensured GDPR compliance in collaboration with the ComplianceManager.• Managed server vulnerabilities using Qualys for scanning and ensuringcorrections in timelines compliant with security policies.• Ensured administrator accesses were controlled by a Privileged AccessManagement solution like CyberArk by analyzing the architecture toidentify and eliminate gaps in PAM coverage.• Controlled the segregation of environments (DEV/UAT/PRD).• Confirmed that backups were operational and that tests were properlyconducted.• Verified that all network communications were properly encrypted.• Confirmed that all generated certificates used the internal PKI and werenot self-signed.• Organized and supervised penetration tests, adjusted the scope ifnecessary, analyzed reports, and proposed remediation strategies todevelopment teams.• Validated that hardening rules were respected on all servers, that theywere based on the CIS Benchmark, and validated exceptions whilemaintaining a compliant security level.• Verified the performance and acceptability of disaster recovery (DR)tests, and confirmed the business continuity plan (BCP) was in place.
- BNP ParibasIT Security Project ManagerBANQUE & ASSURANCESjanvier 2020 - avril 2023 (3 ans et 4 mois)Paris, FranceMember of the cybersecurity team focused on analyzing, hardening, testing,and remediating infrastructure components.• Led infrastructure security projects on components (e.g., backup, SIEM,WiFi, telephony, VPN gateways, Hypervisors,…) through coordinatedpenetration testing campaigns and risk assessments; guided assetowners to policy compliance, monitored risks, ensured remediationwithin delays, and established reports with corrective measures.• Authored the security standards for the messaging IBM MQ seriesmiddleware, including in-depth risk analyses; defined and piloted theimplementation and the monitoring of the targeted controls to mitigateidentified threats, ensuring alignment with governance requirements.• Escalated deviations and risks, while assisting IT teams in aligning withsecurity policies and promoting awareness of threat landscapes.
- AXAIT Security project managerBANQUE & ASSURANCESjanvier 2017 - décembre 2019 (3 ans)Paris, FranceDirected IT infrastructure remediation across EMEA, AMER, and APAC,addressing security weaknesses and ensuring policy compliance.• Coached security teams on vulnerability assessments and remediation,defining action plans based on infrastructure maturity.• Developed operational procedures, guidelines, and security standardsto support vulnerability management and IT security operations.• Tracked implementation of security controls, managed backlogs, andfacilitated upgrades/fixes while escalating risks.• Provided governance for vulnerability processes, generatingdashboards and KPIs for reporting to IT steering committees and CISO.
Recommandations
Soyez le premier à recommander Thierry
Contribuez à la réussite de ce freelance en partageant votre expérience de collaboration avec lui.
Ces profils de freelance correspondent également à vos critères
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Certifications
- Certified Information Systems Security Professional (CISSP)ISC22018
- Project Management Professional certification (PMP)PMI2009