You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Carl B.CB

Carl B.

Cyber GRC Consultant | ISO 27001 & Awareness

€600/day
Paris, FR
3-7 years

Average response time: 4 hours

Freelancer profile translated to English.
Back to original language

About Carl

GRC Cybersecurity Consultant with 5 years of experience, I conduct ISO 27001 audits and pre-audits, risk analyses (EBIOS RM, ISO 27005, ISO 31000), compliance diagnostics (NIS2, DORA, GDPR), and cybersecurity awareness programs.

I help companies quickly assess their cyber maturity level and achieve compliance through short-term assignments: diagnostics, pre-audits, ISMS documentation review, action plans, crisis management, or security questionnaire responses.

ISO 27001 Audit & Diagnostics
  • ISO 27001 Gap analysis and IS security maturity assessment
  • ISO 27001 Pre-audit and ISMS documentation review
  • NIS2 / DORA / AI Act compliance diagnostics
  • GDPR diagnostics (processing mapping, register, DPIA)
  • Third-party audits and security questionnaire responses (due diligence, CyberVadis)

Risk Analysis and Management
  • Cyber risk analysis and risk management (EBIOS Risk Manager, ISO 27005, ISO 31000)
  • Business Impact Analysis (BIA) / cyber impact analysis and RTO/RPO mapping
  • Security assurance plan

Crisis Management & Cybersecurity Awareness
  • Drafting cyber crisis management manuals and crisis exercises
  • Cybersecurity awareness: simulated phishing campaigns, workshops, e-learning

Security Coordination
  • Integrating security into IT projects, defining security requirements, and interfacing between IT, business, and technical teams

I have worked at Capgemini, Nomios, and Niji on regulated environments and large accounts (banking, finance, insurance, public sector). I adapt quickly to the context and maturity level, whether discussing with an IT Director or working directly with technical teams.

Certified ISO 27001 Lead Auditor and ISO 27005 Risk Manager/ EBIOS RM. Available immediately for assignments in Paris and remotely.
  • French

    Native or bilingual

  • English

    Native or bilingual

Can work on-site
Paris (up to 50km)

Experience

  • Niji
    Senior GRC Consultant
    DIGITAL AND IT
    September 2025 - Today (11 months)
    Paris, France
    • Contribution to NIS2, DORA, and AI Act regulatory compliance efforts, as well as supplier risk management.
    • Support for large organizations and the public sector in cybersecurity awareness programs (phishing, e-learning, workshops).
    • Conducting risk analyses on IT and business projects, integrating security into projects, and defining security requirements.
    NIS2 DORA Cybersecurity Awareness AI Act
  • TILT (incubé chez Station F)
    Co-founder
    TECH
    January 2024 - Today (2 years and 6 months)
    Paris, France
    - Creation and launch of an innovative SaaS solution for cybersecurity awareness, combining pedagogy, gamification, and performance.

    - Offer structuring, market positioning, and full sales cycle management (prospecting, demonstration, closing)

    - Leading workshops and conferences (200+ participants) in companies and higher education

    - Product management based on user feedback and coordination of a multidisciplinary team (tech, sales, content)

    - Strengthening key skills: communication, team management, business orientation, simplification of cybersecurity issues
    Cybersecurity Awareness autonomy proactivity Adaptability and flexibility Communication
  • Nomios
    Senior Cybersecurity Consultant
    DIGITAL AND IT
    March 2025 - September 2025 (6 months)
    Boulogne-Billancourt, France
    Led a complete BIA analysis validated by business departments, with RTO/RPO mapping
    Structured a security assurance plan enabling client compliance within the framework of a call for tenders
    Mapped over 100 assets and formalized IS security policies to initiate ISO 27001
    Identified 15 major non-conformities in the TISAX audit, with recommendations submitted to the IT Director
    Contributed to the signing of several projects through technical presentations and pre-sales proposals
    BIA TISAX Security Assurance Plan Pre-sales Cybersecurity Governance

Recommendations

MS
BW
LS
+1
Mohamad Safla and 3 other people have recommended Carl

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master's degree, Sécurité / sûreté de l'information des systèmes informatiques
    ECE Paris
    2022
    Master's degree, Sécurité / sûreté de l'information des systèmes informatiques
  • Inseec U. London
    2019

Certifications

  • ISO27001
    PECB
    2023
    ISO 27001 Lead Auditor
  • ISO27005
    PECB
    2023
    Risk Analysis ISO 27005 EBIOS RM

Skill set

Categories