About Arnaud
French
Native or bilingual
Spanish
Basic
English
Fluent
Experience
- ALSSI ConsultingFreelance Missions (ALSSI Consulting)CONSULTING AND AUDITSNovember 2020 - Today (5 years and 7 months)Montpellier, FranceMissions recently carried out:
- Part-time CISO
- ISO 27001 Audit (mock, internal, pre-certification)
- Cyber maturity audit
- Compliance audit
- Risk analysis (EBIOS RM)
- ISO 27001 certification support
- ISO 27001 version change support (2013 ==> 2022)
- Editeurs de logiciels en mode SaaSPart-time CISOSOFTWARE PUBLISHINGNovember 2020 - September 2023 (2 years and 10 months)Risk assessmentWriting of the ISP adapted to the company's challengesDevelopment of a roadmap that the organization can adopt (time/resource constraints)Support for IT and developer teams in improving SSI maturitySupport for sales teams in "selling" the security of offers
- Groupe SIIGroup CISO and OCSSIDIGITAL AND ITApril 2017 - October 2020 (3 years and 6 months)Paris, FranceIn a context of ISO27001 certification for our French activities:
- Aligns security objectives with business goals and defines the security roadmap
- Supports business units in integrating security into internal and client IT projects
- Analyzes risks and implements associated treatment plans (EBIOS 2010/RM)
- Defines/writes the security framework (e.g., Policies, directives)
- Defines the audit program and manages organizational and technical audits
- Defines control, awareness, and SSI communication plans
- Develops indicators and monitors security dashboards
- Leads Management Reviews and SSI committees with the CODIR and COMEX
- Manages the continuous improvement of the ISMS
- Manages security approvals for IT systems (II901, II920 standards)
- Manages major incident response
- Conducts legal, regulatory, and technological watch
- Participates in the company's compliance with GDPR (e.g., protection measures)
- Manages and leads the SSI Correspondents in our 10 establishments
Key achievements:- Extension of ISO27001 certification to new sites
- Study and deployment: Risk analysis/consolidation framework, SIEM/SOC, strong authentication (internal PKI), SSI incident management, vulnerability management, simplified project risk analysis methodology, integration of security into development.
- Evolution of the ISMS towards national ISO27001 certification
Recommendations
Be the first to recommend Arnaud
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Computer Engineering (Specialization in Systems and Networks)EPITA - Paris 13th1995
Certifications
- EGERIE Manager CertifiedEGERIE Software2019
- GDPR: MOOC for DPOsCNIL2019