You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Ernesto Francisco IsabelEF

Ernesto Francisco Isabel

Cybersecurity Engineer

€600/day
Paris, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Ernesto

INFORMATION SYSTEMS SECURITY ENGINEER
Cyber / SOC Referent | Resilience & Operational Security, vulnerabilities & compliance |
Polyglot (FR/PT/NL/EN) and accustomed to critical, sensitive, and large enterprise environments.

Information systems security engineer, cyber referent, and SOC analyst, I offer my services for freelance/payroll missions. With operational experience in large enterprises and critical environments, I can undertake missions in incident detection and response, operational security, vulnerability management, and compliance.
Relevant strengths for your needs:
- SOC and SIEM: detection, investigation, and incident response on Logpoint, with integration of new log sources and tuning of correlation rules
- EDR and network detection: operation and management of CrowdStrike and Vectra for investigation and remediation
- Vulnerability management: execution and management of Qualys scans, reporting, and remediation coordination
- Operational security: management of authorizations and privileged accounts, management of exceptions, and project security integration
- Compliance and audit: support for NIST compliance, international mission experience
- Complementary tools: knowledge of Microsoft Sentinel and Copilot for Security, Splunk ES, ServiceNow
Recent missions: assignments at GRTgaz as an Infrastructure and Datacenter Cyber Referent, SOC service for INA with technical responsibility and incident coordination, and NIST2 support for VINCI Concessions. I am used to working as a service provider with internal teams and stakeholders.

Thank you in advance to those who share this post or put me in touch.

#OpenToWork #Cybersecurity #SOC #Compliance #CyberDefense #NIST #ISO27001
  • French

    Native or bilingual

  • English

    Fluent

  • Portuguese

    Fluent

  • Dutch

    Fluent

Can work on-site
Paris (up to 50km)

Experience

  • Accenture
    Cyber Referent
    December 2023 - Today (2 years and 6 months)
    Accenture France-Cyber Referent at GRTgaz/Natran
    Context: Cyber Referent for the Infrastructure and Data Center value chain at GRTgaz. My role is to support the Datacenter infrastructure team in securing infrastructures against cybersecurity threats, while ensuring compliance with regulations and maintaining coordination with internal and external stakeholders. I am responsible for cybersecurity activities such as:
    ▪ Operational security management for the Infrastructure & Data Center scope.
    ▪ Contribution to vulnerability detection and monitoring (Tenable=Nessus) and coordination of corrective actions.
    ▪ Operational support to SOC teams (logs, incidents).
    ▪ Management of privileged accounts and administrator authorizations.
    ▪ Security compliance monitoring and exception management.
    ▪ Cyber Acceptance: Project Security Integration (ISP)

    INTERNATIONAL MISSION – VINCI Concessions (NIST2 Compliance Audit, Cape Verde)
    ▪ Support for an international entity in its NIST2 compliance.
    ▪ Risk analysis, security recommendations, compliance implementation plan.
    Cybersecurity Incident Management Cyber Engineer SOC NIST Cyber Referent
  • Accenture France
    SOC Analyst
    CONSULTING AND AUDITS
    June 2020 - December 2023 (3 years and 7 months)
    Paris, France
    Context: Provided services within the client INA's SSI team, reporting to the CISO and integrated into the Accenture SOC team.
    Role: Technical Account Manager (TAM) for the client, responsible for almost complete SOC management (L1, L2/L3): detection, prevention, and incident response.

    ▪ Detection and management of security incidents reported by the SIEM (Logpoint) and IDS (Vectra).
    ▪ Investigations into security incidents (scope, causes, remediation).
    ▪ Active participation in crisis management during attacks; analysis, diagnosis, coordination, and communication maintenance in the crisis room.
    ▪ Integration and enrichment of new log sources into the SIEM (applications, servers, network) to improve incident detection.
    ▪ Optimization of correlation rules, SIEM alert tuning, and improvement of the SOC detection pipeline.
    ▪ Vulnerability management: Definition of scan scopes, execution of scans with Qualys and their follow-up (reporting and remediation).
    • Communication and awareness-raising among employees.
    • Preparation and presentation of steering committee meetings.
    SIEM EDR Linux Vulnerability Management Cyber Engineer
  • SECURIVIEW/Linkbynet,
    Cyber Security Consultant
    September 2019 - June 2020 (9 months)
    Context: Member of the PwC France CISO team and in close collaboration with the NIS teams based in the United Kingdom, I am responsible for cybersecurity activities such as:
    • Vulnerability management: Definition of scan scopes, execution of scans with Qualys and their follow-up (reporting and remediation).
    • Incident management: Investigation and resolution of security incidents/alerts within ITSM (ServiceNow). In some cases, contacting end-users for remediation and/or reminders of PSSI recommendations.
    • Analysis and monitoring of workstation administration rights needs.
    • Penetration testing management: Monitoring of penetration tests and implementation of a remediation plan following identified vulnerabilities.

Recommendations

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master's Degree in Expert in Computer Engineering and Information Systems, ESGI
    Ecole Supérieure de Génie Informatique (ESGI)
    2019
    Activités et associations : Architecture et management des systèmes d’information Ingénierie Système Ingénierie Réseaux Sécurité informatique avancéeActivités et associations : Architecture et management des systèmes d’information Ingénierie Système Ingénierie Réseaux Sécurité informatique avancée Le mastère en Sécurité Informatique s’adresse aux étudiants souhaitant une formation de très haut niveau sur les méthodes d’audits et tests d'intrusion, d’identification et d’analyse de malwares, de protection et de sécurisation du système d’information. Cette spécialisation permet d’acquérir l’expertise pour identifier les menaces et les vulnérabilités et garantir la pérennité de la sécurité des systèmes, des flux et des données dans un contexte d’évolution rapide de la sécurité liée aux systèmes d’information dans les entreprises. Management de projet et des équipes, Sécurité des systèmes et des réseaux, Ethical Hacking, Tests de pénétrations, Réseaux et protocoles de routage, Virtualisation VMWare, Administration Linux avancée,
  • IT Security Training
    Sysdream Levallois (92)
    2017
    Formation Sécurité informatique chez Sysdream Levallois (92) ➢Hacking et sécurité avancée ➢Détection, identification et éradication de malwares Activités et associations : Hacking et Sécurity avancé : Comprendre et détecter les attaques sur un SI, définir l’impact et la portée d’une vulnérabilité, réaliser un test de pénétration, Corriger les vulnérabilités et Sécuriser un réseau, et intégrer des outils de sécurité adéquats. Cybersécurity : Malwares : détection, identification et éradication

Skill set (11)

Categories