You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Anass KabbajAK

Anass Kabbaj

Cyber Risk & Compliance Manager / CISO

€737/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Anass

With several years of experience in cybersecurity risk and compliance management, leading cybersecurity programs and their operational implementation for major companies in the banking and financial sector, my expertise focuses on defining and leading cybersecurity strategy and governance, managing large-scale and strategic cybersecurity projects, managing cybersecurity through a risk-based approach, managing and supervising multidisciplinary teams, leading cyber crisis management, and ensuring compliance with best practices and cybersecurity standards.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 15km)

Experience

  • Société Générale ABS
    Program Director Security & Deputy Cybersecurity Director Africa Region
    BANKING AND INSURANCE
    November 2021 - Today (4 years and 6 months)
    Paris, France
    - Accompanying the 14 subsidiaries of the SG Group in sub-Saharan Africa (AFS region) in their upgrade and compliance with cybersecurity governance in line with the group's risk appetite: cybersecurity maturity assessment based on the NIST framework, identification and management of cyber programs (application/infrastructure/network security, security culture dissemination, data security, resilience, IAM, Cloud security, third-party management, etc.), security risk management, security & privacy by design, regulatory compliance related to personal data and local regulations, etc.;
    - Managing cyber action plans within subsidiaries and monitoring recommendations from the European Central Bank and the SG Group;
    - Leading the IS governance of the 14 subsidiaries and managing IS dashboards;
    - Strengthening the cyber risk management process within subsidiaries (second-level permanent control);
    - Managing PMO teams responsible for cybersecurity projects;
    - Managing ISP teams (project expertise/security architect) in their support of security in business projects (security & privacy by design);
    - Accompanying and managing interim subsidiary CISOs;
    - Managing interim SOC teams.
    Program Management CISO Cybersecurity PMO DevSecOps NIST IAM Resilience
  • Crédit Agricole Assurances
    CISO / Senior Consultant & Cybersecurity Risk Manager
    BANKING AND INSURANCE
    November 2019 - November 2021 (2 years)
    Paris, France
    - Accompanying Group subsidiaries in France and internationally (7 subsidiaries worldwide) in their upgrade and compliance with cybersecurity governance in line with the group's risk appetite;
    - Implementing and managing the Group's IS mapping using a risk management approach;
    - Assessing cybersecurity maturity based on the NIST framework;
    - Managing and monitoring recommendations from the General Inspectorate;
    - Ensuring IS security governance and compliance with the Group Risk Department (second-level permanent control);
    - Designing, deploying, and managing Group IS dashboards and leading the IS Security Strategy and Steering Committees;
    - Assisting subsidiaries in France and internationally in their upgrade and compliance with Crédit Agricole Group's ISSP (GDPR, security rules related to the LPM and the NIS directive).
    Program Management Dashboards Risk Mapping GDPR NIST Militarization Law Cybersecurity Cybersecurity
  • GROUPE CREDIT AGRICOLE DU MAROC
    Group Chief Security Officer
    BANKING AND INSURANCE
    April 2009 - October 2019 (10 years and 6 months)
    Rabat, Morocco
     - Central Director in charge of Group Security - Safety (Group Chief Security Officer) reporting to the CEO Member of the Management Board from July 2016 to October 2019.
    Managing the Group CISO and cybersecurity teams:
    - Implementing and ensuring compliance with the Group's Information Security Policy;
    - Periodically assessing the effectiveness of risk management processes (N2 control);
    - Organizing cyber crisis management exercises;
    - Establishing an internal SOC;
    - Leading the ISMS program and PCI / DSS standard for the Group's payment activities;
    - Ensuring the availability of critical data and IT resources;
    - Leading the Group Security Committee with monitoring and reporting to the General Management;
    - Raising user awareness of security issues.

    Managing safety - security teams:
    - Guaranteeing the safety - security system for people and assets;
    - Managing the Control and Surveillance Post and operating safety - security systems;
    - Managing access control, video surveillance, anti-intrusion, and fire safety systems;
    - Ensuring compliance with current regulations.
    Cybersecurity Cybersecurity Program Management NIST CISO

Recommendations

Be the first to recommend Anass

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Executive Education on "Management and Leadership".
    HEC PARIS
    Executive Education sur « Le Management et Leadership ».
  • Master's Degree in Computer Engineering.
    INSTITUTE OF COMPUTER ENGINEERING OF LIMOGES
    2002
    Diplôme d'ingénieur en informatique Grade Master.

Certifications

  • ISO 27001 LI
    Professional Evaluation And Certification Board
    2011
  • ISO 27005
    Professional Evaluation And Certification Board
    2011

Skill set

Categories