You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Emmanuel MessierEM

Emmanuel Messier

IT Cyber Project Management

€850/day
Paris, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Emmanuel

Transition manager and project director, I have spent most of my career in IT service companies.
Thanks to this experience, I have developed adaptability and integration skills that allow me to approach my missions quickly.

🎯 My objectives:

Support you in crisis situations or in the replacement of an operational manager in IT production.

Take charge of projects or programs for the evolution of your infrastructures, integrating a strong focus on security/compliance, and ensure efficient build-to-run.



  • French

    Native or bilingual

  • English

    Conversational

Can work on-site
Paris (up to 50km), Rouen (up to 100km)

Experience

  • Crédit Agricole Group Infrastructure Platform
    Program Director
    BANKING AND INSURANCE
    December 2024 - Today (1 year and 6 months)
    Guyancourt, France
    Direction of projects for strengthening security and certification within the infrastructure scope:

    PCI-DSS Certification Project:
    - Ensure the maintenance in security operational condition (MCS) for the certified infrastructure scope since 2023:
    o Hardening control, patch management, network segmentation, etc.
    o Monitor the scope's compliance with the PSSI.
    o Monitor periodic controls (Authorization Review, internal and external scans (ASV), internal and external penetration tests, firewall rule review, Wifi scans, etc.).
    o Monitor vulnerability management.
    o ...
    - Integrate scope extensions for certification by carrying out scoping and pre-audit phases.
    - Compile dossiers with audit evidence,
    - Support and assist CA-GIP employees during certification audits with QSA.
    - Lead remediation of non-conformities.
    - Conduct PCI-DSS self-assessments on the infrastructure of certifiable applications.
    - Manage the RUN and BUILD budget (2,000 man-days)
    - Steering Committee
    - Project Committee

    EPI (The European Payments Initiative) Certification Project:

    On the same model as my PCI-DSS project management mission, I am managing the certification project for the infrastructure supporting the EPI application.
    Budget: 300 man-days.

    LPM 2025 Re-approval Project:

    Within the infrastructure scope, manage teams for the triennial PASSI LPM audit:
    • Configuration audits (OS, databases, and middleware),
    • Architecture audits (Network, databases, and middleware, SIA (administrative information system), PDTA (administrative workstation),
    • Organizational audit (PSSI, security awareness, approval, etc.),
    • Penetration tests on the infrastructure scope.
    Security Approval LPM Information Security Policy Infrastructure
  • CREDIT AGRICOLE PAYMENT SERVICES
    Project Management
    BANKING AND INSURANCE
    January 2022 - September 2024 (2 years and 9 months)
    Guyancourt, France
    Management of security strengthening and certification projects:

    PCI-DSS Certification Project for the Merchants Scope:
    - Dossier compilation
    - Support for certification audits with the client and QSAs
    - Organization of semi-annual firewall rule reviews
    - Management of non-conformity remediation
    - Organization of Penetration Tests, configuration audits, etc.
    - Steering Committee
    - Project Committee

    Project to Identify and Implement Alternative Solutions for Direct Access to Production Servers for Business Units (Log and Database Consultation).
    - Identification of use cases for read and write access to production servers
    - Study of use case compliance
    - Project to build alternative solutions
    - Development of waivers for use cases that cannot be brought into compliance
    - Project Committee
    - Steering Committee
    - Reporting

    Triennial LPM (Military Programming Law) Approval Renewal Project:
    - Analysis of architectural and application evolutions in relation to regulations.
    - Analysis of network segmentation compliance level
    - Update of documentation (PSSI, Cyber Crisis, MCS, maintenance in approval condition, ....)
    - Collection and analysis of compliance evidence for 20 regulatory rules
    - Approval dossier (Update, integration of compliance evidence)
    - Organization of PASSI audits (Penetration Testing, Configuration, Architecture, Physical, and Organizational)
    - Management of security operational condition (MCS)
    - Management of vulnerability remediation resulting from PASSI audits
    - Organization of semi-annual network firewall rule reviews
    - Management of non-conformity remediation
    - Tenders
    - Steering Committee
    - Project Committee
    Regulatory Compliance Project Management Security Audit Vulnerability Management LPM PCI DSS Budget Monitoring tenders Steering Committee ISO 27001 CSP NIS
  • CREDIT AGRICOLE PAYMENT SERVICES
    Project Management
    BANKING AND INSURANCE
    March 2021 - December 2021 (10 months)
    Guyancourt, France
    Within the framework of the Operational Excellence Program Management, leading the project in all its components.

    Identifying and launching projects to achieve the following 3 objectives:

    Reduce the number of incidents
    - Mapping of production risks by payment process (applications, payment & community infrastructures)
    - Evolution of internal processes:
    . Project Management
    . Change Management
    . Problem Management
    . Etc…

    Have end-to-end customer-oriented payment supervision
    - Inventories of existing sensors, end-to-end process coverage, within the IS, distributors, and partners
    - Definition of an operational model for 24/7 business supervision
    - Evolution of internal processes to ensure the implementation of customer-oriented business supervision
    - Study the possibility of implementing processes and tools for detecting and exploiting "weak signals"

    Resolve incidents with responsiveness and appropriate communication
    - Analysis of incidents and their management by payment process (instructions and procedures applied, escalation process, communication, etc.)
    - Incident management systems to improve responsiveness (instructions, harmonization of SLA/DICP, etc.)
    - Crisis management processes HO and HNO (escalation crisis sheets, entity contacts, Customer/Distributor on-call system, etc.)
    - Communication process (Who communicates? When and how?)




Recommendations

Be the first to recommend Emmanuel

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Skill set (50)

Categories