About Ernesto
French
Native or bilingual
English
Fluent
Portuguese
Fluent
Dutch
Fluent
Experience
- AccentureCyber ReferentDecember 2023 - Today (2 years and 6 months)Accenture France-Cyber Referent at GRTgaz/NatranContext: Cyber Referent for the Infrastructure and Data Center value chain at GRTgaz. My role is to support the Datacenter infrastructure team in securing infrastructures against cybersecurity threats, while ensuring compliance with regulations and maintaining coordination with internal and external stakeholders. I am responsible for cybersecurity activities such as:▪ Operational security management for the Infrastructure & Data Center scope.▪ Contribution to vulnerability detection and monitoring (Tenable=Nessus) and coordination of corrective actions.▪ Operational support to SOC teams (logs, incidents).▪ Management of privileged accounts and administrator authorizations.▪ Security compliance monitoring and exception management.▪ Cyber Acceptance: Project Security Integration (ISP)INTERNATIONAL MISSION – VINCI Concessions (NIST2 Compliance Audit, Cape Verde)▪ Support for an international entity in its NIST2 compliance.▪ Risk analysis, security recommendations, compliance implementation plan.
- Accenture FranceSOC AnalystCONSULTING AND AUDITSJune 2020 - December 2023 (3 years and 7 months)Paris, FranceContext: Provided services within the client INA's SSI team, reporting to the CISO and integrated into the Accenture SOC team.Role: Technical Account Manager (TAM) for the client, responsible for almost complete SOC management (L1, L2/L3): detection, prevention, and incident response.▪ Detection and management of security incidents reported by the SIEM (Logpoint) and IDS (Vectra).▪ Investigations into security incidents (scope, causes, remediation).▪ Active participation in crisis management during attacks; analysis, diagnosis, coordination, and communication maintenance in the crisis room.▪ Integration and enrichment of new log sources into the SIEM (applications, servers, network) to improve incident detection.▪ Optimization of correlation rules, SIEM alert tuning, and improvement of the SOC detection pipeline.▪ Vulnerability management: Definition of scan scopes, execution of scans with Qualys and their follow-up (reporting and remediation).• Communication and awareness-raising among employees.• Preparation and presentation of steering committee meetings.
- SECURIVIEW/Linkbynet,Cyber Security ConsultantSeptember 2019 - June 2020 (9 months)Context: Member of the PwC France CISO team and in close collaboration with the NIS teams based in the United Kingdom, I am responsible for cybersecurity activities such as:• Vulnerability management: Definition of scan scopes, execution of scans with Qualys and their follow-up (reporting and remediation).• Incident management: Investigation and resolution of security incidents/alerts within ITSM (ServiceNow). In some cases, contacting end-users for remediation and/or reminders of PSSI recommendations.• Analysis and monitoring of workstation administration rights needs.• Penetration testing management: Monitoring of penetration tests and implementation of a remediation plan following identified vulnerabilities.
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Master's Degree in Expert in Computer Engineering and Information Systems, ESGIEcole Supérieure de Génie Informatique (ESGI)2019Activités et associations : Architecture et management des systèmes d’information Ingénierie Système Ingénierie Réseaux Sécurité informatique avancéeActivités et associations : Architecture et management des systèmes d’information Ingénierie Système Ingénierie Réseaux Sécurité informatique avancée Le mastère en Sécurité Informatique s’adresse aux étudiants souhaitant une formation de très haut niveau sur les méthodes d’audits et tests d'intrusion, d’identification et d’analyse de malwares, de protection et de sécurisation du système d’information. Cette spécialisation permet d’acquérir l’expertise pour identifier les menaces et les vulnérabilités et garantir la pérennité de la sécurité des systèmes, des flux et des données dans un contexte d’évolution rapide de la sécurité liée aux systèmes d’information dans les entreprises. Management de projet et des équipes, Sécurité des systèmes et des réseaux, Ethical Hacking, Tests de pénétrations, Réseaux et protocoles de routage, Virtualisation VMWare, Administration Linux avancée,
- IT Security TrainingSysdream Levallois (92)2017Formation Sécurité informatique chez Sysdream Levallois (92) ➢Hacking et sécurité avancée ➢Détection, identification et éradication de malwares Activités et associations : Hacking et Sécurity avancé : Comprendre et détecter les attaques sur un SI, définir l’impact et la portée d’une vulnérabilité, réaliser un test de pénétration, Corriger les vulnérabilités et Sécuriser un réseau, et intégrer des outils de sécurité adéquats. Cybersécurity : Malwares : détection, identification et éradication