About Atef
French
Native or bilingual
English
Native or bilingual
Norwegian Bokmål
Fluent
Experience
- AxioneGroup CISOTELECOMMUNICATIONSMarch 2025 - Today (1 year and 3 months)Paris, France•Audit of NIS2 maturity and definition of the cyber roadmap•GRC: definition of cyber policies, procedures, and standards•Definition of a new operating model and redesign of the cyber team with the creation of three poles of 5 FTEs•Define the organization for the execution of the cyber program (resources, organization chart, committee structure)•Creation of operational and managerial KPIs•Contribution and response to tenders and management of Third-Party risks•Technical and managerial coaching of the new internal CISO•Monitoring and quality control of the cyber program for NIS2 compliance, including:oRedesign of the SIEM/SOCoRedesign of the infrastructure and application vulnerability managementoHardening of East-West and North-South network segmentationoRedesign of the administration SIoSecuring directories (consolidation and hardening)oHardening and implementation of the password policyoGeneralization of MFAoSpecifications for WAF deploymentoSpecifications for PAM solution deploymentoSpecifications for IGA solution deployment
- SolocalGroup CISOSOFTWARE PUBLISHINGJuly 2024 - Today (1 year and 11 months)Paris, France• Cybersecurity maturity audit based on the NIST Framework and definition of the cyber roadmap• Redesign of the cyber organization by creating three poles (GRC, Architecture, and SOC) and increasing staff from 2 to 5 FTEs in five months• Define the organization for the execution of the cyber program (resources, organization chart, committee structure)• Monitoring and quality control of the cyber program, including:o Hardening of internet exposureo Cloud security (VM, PAAS, and containers)o Continuation of the Microsoft 3-Tier model deploymento Rationalization and audit of WAF and Anti-DDoS (CloudFlare) deploymento Workstation security and generalization of EDR (Defender/S1) deploymento Creation of a vulnerability management system and improvement of the infrastructure & code vulnerability management process (Nessus)o Improvement of the incident and cyber crisis response process by the SOCo Improvement of Third-Party risk management processeso Creation of cyber risk registers and improvement of enterprise risk management processeso Creation of operational and managerial KPIso Organization of training for employees and developers (SoSafe, SecDojo)
- TDFCybersecurity DirectorINTERNET OF THINGS (IOT)December 2023 - June 2024 (6 months)• Definition of the cyber program and budget estimation (€2.1M) pre-Olympics• Definition of the organization for the execution of the cyber program (resources, organization chart, etc.)• Monitoring and quality control of the cyber program for 15 projects from December to June 2024, including:o Cyber crisis management during the Olympics (Process, toolkit, Business Continuity Plan/Disaster Recovery Plan, backup site, etc.)o Securing the AD and deployment of Semperis ADFR and DSP toolso Deployment of an F5 WAFo Securing broadcast industrial systems (hardening of network equipment, Radio & DTT, implementation of a Radius server)o Deployment of a SIEM (Logpoint)o Deployment of an EDR (Trellix) and NDR (Stamus)o Deployment of an anti-DDoS & anti-phishing solution
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- PhD thesis, networks & cybersecurityNorges Teknisk-Naturvitenskapelige Universitet (NTNU)2015Doctor of Philosophy (PhD), Telematik
Skill set
Categories
- Other