About Amara
French
Native or bilingual
English
Fluent
Experience
- Société Générale-Cloud Security ConsultantMay 2022 - December 2024 (2 years and 7 months)Avenue du Val de Fontenay, Fontenay-sous-Bois, FranceWithin the ISR team - Group Cloud Security - 2.5 years Tasks and missions:• "Go to Cloud" migration project: Security support for application migration to the Cloud• General Company AWS Cloud Design: Secure architecture and risk analysis for hosted applications,• AWS Cloud IAM Design: Implementation of IAM Policies, Permission Boundaries, and Trusted Relationships. 1 Security Referent for the BDDF business (Retail Banking) ITIM: integration of security into Cloud projects, Risk Analysis, Access Recertification for the AWS cloud perimeter and privileged accounts. 1 Security Supervision: SI security events, Management and operation of a security monitoring platform (Cnapp Palo Alto), Management and qualification of security alerts, Remediation of confirmed alerts.• Drafting security policies for the Cloud perimeter.• Participation in BCE (European Central Bank, the regulator) audit: Review and Implementation of BCE recommendations, Drafting of the evidence file for the ITIM BU, Continuation of post-audit work
- EnedisISP AnalystENERGY AND UTILITIESFebruary 2019 - April 2022 (3 years and 2 months)92000 Nanterre, FranceCyber risk analyst on various projectsEbios RM risk analysis on the Enedis DMZ network zone construction project-Implementation of network zones serving as DMZs with the objective of protecting the internal IS from the outside (internet).-Scope: network infrastructure router/switch/Firewall, Proxy, WAF, AD directory, DNS, application servers, internet-exposed web portal...- Conducted 5 Ebios RM workshops and defined the security workstream (Drafting risk sheets and associated measures sheets) + restitution meeting.Ebios RM risk analysis on the DSIIMMO Project:-Context: project to implement LAN WLAN WAN network infrastructure within the future Enedis IT department premises.-Scope of risk analysis: infrastructure and network equipment (router, switch, wifi access point, ToIP, SAC), office automation (printers, workstations, server), remote site interconnection, infrastructure equipment (Directory, PKI, NAC, etc.), WAN network.-Execution of the 5 EbiosRM workshops and monitoring of the security workstream.Risk analysis (based on Iso 27005) on the deployment of WAFs and AV solutions: risk analysis and drafting of risk sheets and associated measures sheets.Risk analysis (based on Iso 27005) on the HR business application (hosted on AWS Cloud): risk analysis and mapping of cyber threats, risks, and security recommendations.ISP RUN: daily ISP activity (integrating security into projects)-Cyber support for projects from design to production.-Risk analysis using the internal AR tool for applications.-Participation in IT department validation committees for application commissioning.-Analysis of PSSI derogationsContractual Support on several Projects-Drafting and evaluation of PAS (Security Assurance Plans) from bidders.
- BNP P.IS Security and Cryptography EngineerFebruary 2018 - January 2019 (11 months)92 Route De Montreuil, Montfort, FranceOn assignment at GROUPE BNP Paribas within the cybersecurity expertise team Tasks and missions:• Level 3 Support (engineering) on: O Electronic Signature Solution MORPHO/IDEMIA Dictao• PKI Infrastructure, Certification Authority, Strong Authentication (HID middleware) Cryptographic Module HSM (Hardware Security Module): Bull HSM• Deployment of the new Bull TrustWay Proteccio firmware (X143 V143) qualified RGS (reinforced level) + Key Ceremony. Audit and elDAS certification (European elDAS certification for GROUPE BNP Paribas)• Pre-audit preparation• Correction of minor and major deviations RUN activities on the E-signature platform (ticket management, incident management, service continuity)
Recommendations
Be the first to recommend Amara
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- MASTER 2 CRYPTIS - Information Security and CryptologyUniversity of LIMOGES2017MASTER 2 CRYPTIS - Sécurité informatique et cryptologie
- Engineering degree in Computer NetworksENSA Tanger2016Cycle ingénieur en Réseau informatique