About Carl
- ISO 27001 Gap analysis and IS security maturity assessment
- ISO 27001 Pre-audit and ISMS documentation review
- NIS2 / DORA / AI Act compliance diagnostics
- GDPR diagnostics (processing mapping, register, DPIA)
- Third-party audits and security questionnaire responses (due diligence, CyberVadis)
- Cyber risk analysis and risk management (EBIOS Risk Manager, ISO 27005, ISO 31000)
- Business Impact Analysis (BIA) / cyber impact analysis and RTO/RPO mapping
- Security assurance plan
- Drafting cyber crisis management manuals and crisis exercises
- Cybersecurity awareness: simulated phishing campaigns, workshops, e-learning
- Integrating security into IT projects, defining security requirements, and interfacing between IT, business, and technical teams
French
Native or bilingual
English
Native or bilingual
Experience
- NijiSenior GRC ConsultantDIGITAL AND ITSeptember 2025 - Today (11 months)Paris, France
- Contribution to NIS2, DORA, and AI Act regulatory compliance efforts, as well as supplier risk management.
- Support for large organizations and the public sector in cybersecurity awareness programs (phishing, e-learning, workshops).
- Conducting risk analyses on IT and business projects, integrating security into projects, and defining security requirements.
- TILT (incubé chez Station F)Co-founderTECHJanuary 2024 - Today (2 years and 6 months)Paris, France- Creation and launch of an innovative SaaS solution for cybersecurity awareness, combining pedagogy, gamification, and performance.- Offer structuring, market positioning, and full sales cycle management (prospecting, demonstration, closing)- Leading workshops and conferences (200+ participants) in companies and higher education- Product management based on user feedback and coordination of a multidisciplinary team (tech, sales, content)- Strengthening key skills: communication, team management, business orientation, simplification of cybersecurity issues
- NomiosSenior Cybersecurity ConsultantDIGITAL AND ITMarch 2025 - September 2025 (6 months)Boulogne-Billancourt, FranceLed a complete BIA analysis validated by business departments, with RTO/RPO mappingStructured a security assurance plan enabling client compliance within the framework of a call for tendersMapped over 100 assets and formalized IS security policies to initiate ISO 27001Identified 15 major non-conformities in the TISAX audit, with recommendations submitted to the IT DirectorContributed to the signing of several projects through technical presentations and pre-sales proposals
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Master's degree, Sécurité / sûreté de l'information des systèmes informatiquesECE Paris2022Master's degree, Sécurité / sûreté de l'information des systèmes informatiques
- Inseec U. London2019
Certifications
- ISO27001PECB2023
- ISO27005PECB2023