You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Aurélien V.AV

Aurélien V.

OT Project Manager | CISSP | PRINCE2 | IEC 62443

€720/day
Bordeaux, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Aurélien

For 20 years, I have been helping industrial and high-stakes organizations modernize and secure their critical systems.

I assist them in transitioning:

- from slow IT/OT convergence to secure and accelerated integration of industrial environments (Covea, Airbus)

- from obsolete and vulnerable systems to modernized and resilient infrastructures (Orange, Socram Banque, AG2R)

- from multiple critical incidents to significant risk reduction and enhanced service continuity (AG2R La Mondiale, Bouygues Telecom, Airbus)

- from low operational visibility to clear indicators enabling management to steer effectively

- from regulatory non-compliance risks to sustainable and controlled compliance (AG2R La Mondiale, Orange, Covéa)

In summary, my interventions as an internal or external provider help reduce strategic risks, overcome infrastructure or compliance hurdles, and strengthen team efficiency.

If you would like to know more, you can contact me via Malt messaging or.

Best regards,
Aurélien
  • French

    Native or bilingual

  • German

    Basic

  • English

    Native or bilingual

Can work on-site
Bordeaux (up to 10km), Bordeaux (up to 50km)

Experience

  • SOCRAM BANQUE
    Technical Project Manager Cybersecurity
    BANKING AND INSURANCE
    March 2024 - December 2024 (9 months)
    Niort, France
    CONTEXT: The company suffered from obsolete IT and telephony infrastructures, impacting the security and continuity of services provided. The situation was urgent as the lack of an obsolescence management strategy facilitated the exploitation of vulnerabilities.

    My responsibility was to manage the infrastructure upgrade, coordinate and assist the SECOPS team, ensure the security of the information system, and improve its performance.

    ● End-to-end management of obsolete network and telephony infrastructure upgrade projects;
    ● Facilitation of progress meetings with stakeholders;
    ● Implementation of activity dashboards and presentation of key indicators to management;
    ● Supervision of daily security incident management for the IS (SIEM, EDR, WAF, FIREWALL, SANDBOXING, VULNERABILITY SCANNER, ANTISPAM);
    ● Assistance in incident resolution through pivot analysis and investigations with concerned users;
    ● Coordination of the SECOPS team (4 people) and priority tracking.

    RESULTS:
    ● Significant strengthening of IS security, with a reduction in critical incidents and unaddressed security alerts;
    ● Better KPI visibility for management, enabling quick and effective decision-making;
    ● Notable time savings allowing resources to be allocated to other SECOPS service modernization projects;
    ● Successful modernization of telephony and network infrastructures, enabling rapid return on investment and system stability.

    Technical environment: AGILE PROJECT METHOD, SEKOIA SIEM, SENTINEL ONE EDR, NESSUS SCANNER, FORTINET SANDBOXING, FORTINET ANTISPAM, PALO ALTO and FORTINET FIREWALL, UBIKA WAF, ALCATEL LUCENT TELEPHONY (OXE)
    Project Coordination IS Architecture Cybersecurity Security Incident Management SecOps
  • GROUPE COVEA
    IT/OT Cybersecurity Consultant
    BANKING AND INSURANCE
    April 2023 - December 2023 (8 months)
    Niort, France
    CONTEXT: The company lacked OT expertise, thus slowing down the delivery of convergence studies between the building network and the corporate network. As an OSE (Operator of Essential Services), it also faced certain obligations and could be audited at any time. Therefore, it was exposed to sanction risks in case of non-compliance with these obligations.

    My role was to support business projects in identifying security risks and to provide my network and security expertise for the GTB (Building Management System) scope.

    ● Conducting EBIOS RM risk analyses, then drafting technical recommendations to reduce these risks for the GTB scope;
    ● Contributing to the definition of security requirements for projects;
    ● Monitoring recommendations and gap analyses post-audits and pentests;
    ● Qualifying IT department subcontractors against cybersecurity and regulatory compliance requirements (OSE, GDPR);
    ● Compliance studies for projects with the Security-by-Design approach;
    ● Feasibility study for a GTB solution in the Cloud;
    ● Supporting Business Owners (MOA) in classifying personal and sensitive data (DICP criteria).

    RESULTS:
    ● Structuring modernization of OT infrastructures in the real estate scope, enabling more effective management of building network obsolescence;
    ● Significant acceleration of the connection between the building network and the corporate network, thus improving IT/OT convergence;
    ● Strengthening project compliance with the regulatory obligations of an OSE;
    ● Notable reduction in project deliverable delivery times, thus achieving objectives set by management;
    ● Improvement in project handling times for cyber visa and DICP studies, enhancing the quality of business projects.

    Technical environment: EBIOS RM METHOD, SMARTBUILDING, IEC 62443, GDPR, CIS BENCHMARKS, CONFLUENCE, JIRA
    EBIOS RM IT Risk Management Security by Design IEC 62443 Industrial Cybersecurity
  • AG2R LA MONDIALE
    Technical Project Manager Cybersecurity
    BANKING AND INSURANCE
    April 2022 - March 2023 (11 months)
    Tours, France
    CONTEXT: The company struggled to keep up with cybersecurity projects due to a lack of follow-up on IT teams' contributions to SECOPS projects. This led to difficulties in identifying information system weaknesses in an OSE environment.

    My responsibility was to manage IT teams' contributions to cybersecurity projects within the SECOPS team and to contribute to IT department projects in their risk analysis needs.

    ● Management of IT contributions to certain Cybersecurity program workstreams, including:
    -> Regulatory compliance: synchronization of compliance studies with the IT department, then breakdown, formalization, tracking, and management of various action plans;
    -> Drafting and updating DSSI security standards;
    -> System hardening: technical implementation of system hardening rules (from CIS and ANSSI) and adaptation to the AG2RLM scope for the SECOPS service;
    ● Conducting an EBIOS RM risk analysis on disconnected backup and managing the action plan;
    ● Analysis of standard cybersecurity processes;
    ● Creation of a dashboard integrating relevant KPIs from various IT department services and SECOPS tools;
    ● Facilitation of various project committees;
    ● Drafting meeting minutes.

    RESULTS:
    ● Significant discovery of several vulnerabilities in the company's Datacenter, allowing for the proposal of an action plan and rapid, sustainable remediation of these vulnerabilities;
    ● Great improvement in coordination between IT departments and the SECOPS service;
    ● Notable increase in SECOPS activity visibility thanks to the operational dashboard, facilitating the consideration of these KPIs in management decision-making.

    Technical environment: AGILE PROJECT METHOD, NEXPOSE, CYBERARK, VARONIS DATAPRIVILEGE, IMPERVA, MACAFEE CASB, MICROSOFT DEFENDER ANTIVIRUS.
    EBIOS RM Cybersecurity SecOps Risk Analysis and Management Technical Project Management

Recommendations

Be the first to recommend Aurélien

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master Program Manager
    EDHEC Business School
    2022
  • Advanced Technician in Corporate IT Networks and Telecommunications
    AFPA Champs Sur Marne
    2004

Certifications

  • CISSP
    ISC2
    2014
    Cloud Computing Access Control Cryptography Physical Security Cybersecurity Cybersecurity Governance
  • GSEC
    GIAC
    2015

Skill set

Categories