You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Erwan BagdatliEB

Erwan Bagdatli

Supermalter

CDP | PMO · IT, CYBER & GRC · CISM | CISA | DORA

€850/day
12 projects
Paris, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Erwan

🔐 IT & Cybersecurity Project Director | IS Governance | GRC | Compliance & Operational Resilience | Encryption & Certificate Management | PMO

🔹 Expert in IT project management, cybersecurity, and regulatory compliance
🔹 Specialized in IS governance, GRC, risk management, and auditability
🔹 Expertise in DORA, data encryption, certificate management, and cryptographic controls

Certified: CISM | CISA | PMP | CSA ServiceNow
ServiceNow: ITSM | CMDB | GRC | SPM | ITOM

🎯 My Approach
With over 16 years of experience in IT project management, cybersecurity, and IS governance, I support companies in structuring, securing, and ensuring the compliance of their information systems.

I work in critical environments with an approach focused on risks, compliance, auditability, indicators, and remediation, in conjunction with IT, Cyber, business, supplier, and management teams.

🔥 My Areas of Expertise
✅ IT & Cybersecurity Project Portfolio Management – Steering IS security and modernization programs.
✅ Governance, Risk & Compliance – Structuring processes, controls, roles, risks, remediations, and audit evidence.
✅ Regulatory Compliance – ISO 27001, TISAX, ISO/SAE 21434, NIS2, DORA, GDPR.
✅ DORA & Operational Resilience – Requirements analysis, control formalization, and audit elements.
✅ Encryption & Cryptographic Controls – Encryption at rest, in transit, in use, algorithms, exceptions, and compensating measures.
✅ Digital Certificate Management – Centralized registry, lifecycle, renewal, expiration, revocation, owners, and risks.
✅ ITSM & ServiceNow – ITSM, CMDB, GRC, SPM, ITOM steering, and continuous improvement.
✅ Supplier Management & TPRM – Certifications, third-party risks, Procurement/IT/Cyber integration.
✅ PMO & Executive Reporting – KPIs, dashboards, roadmaps, RAID log, action plans, and management reporting.
  • French

    Native or bilingual

  • English

    Fluent

  • Turkish

    Native or bilingual

Can work on-site
Paris (up to 50km)

Experience

  • Renault
    GOVERNANCE, CYBERSECURITY PROJECT DIRECTOR
    AUTOMOBILE
    February 2024 - Today (2 years and 4 months)
    Boulogne-Billancourt, France
    Governance, Risk & Compliance Cybersecurity Project Director, with over 16 years of experience in IS governance, IT projects, cybersecurity, and regulatory steering. I support organizations in securing IS, project compliance, and managing cyber risks.

    🎯 Main Expertise:

    Compliance: ISO 27001, TISAX, ISO/SAE 21434, NIS2, DORA, GDPR.
    Governance: processes, milestones, deliverables, roles between GRC, IT, Cyber, and business units.
    Audit & Control: planning, remediation, reporting, KPIs, and audit preparation.
    Resilience: BCP, DRP, IS policy, remediation plans, and auditability.
    Suppliers: assessment, certifications, risks, and Procurement/IT link.

    🚀 Key Achievements:

    Steering GRC cybersecurity compliance initiatives.
    Transfer of control activities to RNTBCI: methods, flows, training.
    Implementation of dashboards: KPIs, risks, action plans, compliance.
    Support for entities and subsidiaries: harmonization, audit support, control optimization.

    💡 Cross-functional Skills:

    PMP, PRINCE2, Scrum, PMO, change management, audit & compliance.
    Infrastructure, application, and business process cybersecurity.

    🔗 SAP & Compliance:

    Logistics MM, WM, SD, PP: securing supplier, inventory, and production flows.
    Finance FI, CO, TR: access control, ISO 27001 and GDPR compliance.
    HR HCM: personal data protection and critical access.

    🔐 DORA – Encryption & Certificates:

    Analysis of encryption requirements at rest, in transit, and in use.
    Definition of cryptographic controls for critical applications.
    Structuring key requirements, certificates, and algorithms.
    Drafting procedures, controls, audit evidence, and compliance elements.
    Contribution to the centralized certificate registry and lifecycle monitoring.

    ✅ Deliverables:

    Policies, procedures, guides, dashboards, risk maps, audit reports.
    Project Director Cybersecurity Audit Cybersecurity Governance Cybersecurity SAP
  • Engie IT SA
    CYBERSECURITY PROJECT MANAGER
    ENERGY AND UTILITIES
    April 2021 - February 2024 (2 years and 10 months)
    Nanterre, France
    Within ENGIE's Global Security Operations Center (GSOC), I managed cybersecurity projects and strengthened operational security covering IT, OT, and digital usage environments in an international context.

    🎯 Cybersecurity Project Management

    - End-to-end management: deadlines, costs, deliverable quality.
    - Transition to RUN phase: integration into operations (technical & contractual criteria).
    - Production deployment governance: coordination, action tracking, milestones.
    - Steering committee facilitation and executive reporting.

    📊 PMO & Governance

    - Collection, prioritization, and tracking of technical change requests.
    - Continuous improvement: identification of friction points, corrective actions.
    - Implementation of dashboards and KPIs to measure performance and cyber maturity.

    🔐 IT & OT Cybersecurity

    - Monitoring of critical sites via Splunk: integration of firewalls, antivirus, VPN, USB solutions.
    - Operational resilience: BCP/DRP, continuity testing, team awareness.
    - Endpoint protection (EPP/EDR), vulnerability management, asset monitoring.
    - Detection & analysis: alert monitoring, data quality and performance tracking.

    🚀 Featured Projects

    - Implementation of IT/OT monitoring for critical sites via Splunk.
    - Management and steering of critical systems resilience (BCP/DRP).
    - Optimization of performance indicators and production deployment governance.

    ✅ Key Skills: project management, PMO, IT/OT cybersecurity, security governance, Splunk, BCP/DRP, audit & compliance, international coordination.
    Cybersecurity PMO SOC Strategic PMO VPN
  • TotalEnergies SE
    PROJECT PORTFOLIO MANAGER
    ENERGY AND UTILITIES
    April 2021 - December 2022 (1 year and 9 months)
    Nanterre, France
    Assignment within Marketing & Services (M&S) in collaboration with TGITS to steer strategic IT and cybersecurity transformation projects, enhance infrastructure resilience, and deploy solutions in international subsidiaries.

    🎯 IT & Cybersecurity Project Steering

    - Coordination of workstation, WAN, and Datacenter projects.
    - Scoping, needs analysis, cost, deadline, and risk tracking.
    - Integration of security requirements: Microsoft 365 Security, Active Directory, Zero Trust.
    - Facilitation of Steering Committees/Working Groups, action tracking (RIDA), and KPI reporting.

    🔐 Securing Critical Infrastructure

    - Active Directory: securing administrator accounts, intrusion detection.
    - Deployment of Microsoft Defender for Identity (monitoring abnormal behaviors).
    - Windows Server 2019 upgrade and patch management.
    - Support to subsidiaries for IT compliance and audit preparation.

    🚀 IT Transformation & Collaboration

    - Microsoft 365 Migration: domain controller updates, Defender for Identity agent deployment.
    - ServiceNow CMDB: IT data integration, asset traceability.
    - ITBM (APM/PPM): project portfolio and IT governance optimization.

    👥 Training & Support

    - Awareness of IT and cybersecurity best practices.
    - User training on ServiceNow and Microsoft 365 tools.

    ✅ Key Skills: IT & cybersecurity project management, critical infrastructure, Active Directory, Microsoft 365, Zero Trust, Defender for Identity, ServiceNow (CMDB, ITBM), international steering, IT governance, audit & compliance.
    ServiceNow ITSM Cybersecurity Project Management (PMO) Business Analyst Project Manager

Reviews

5.0

Out of 1 rating

A

Arnaud

Sia Partners

Reviewed on 11/8/2021

Recommendations

Mikail DoganMD
PM
Ayi Selom TekoAS
Mikail Dogan and 2 other people have recommended Erwan

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • GENERAL ENGINEER
    ESIGELEC
    2009
    Spécialisation en Management des SI, Réseau et Télécom
  • ELECTRONIC SYSTEMS TECHNICIAN DEGREE
    LYCEE PAUL ELUARD
    2005

Certifications

  • CISA - Certified Information Systems Auditor
    ISACA
    2026
    Regulatory Compliance and Audit Risk and Control Audit IT General Controls (ITGC) Assessment Protection of Information Assets IS Audit Methodology IS Lifecycle Audit Operational Audit Execution IT Governance and Management Audit Reporting and Communication IT Operations and Resilience Audit
  • CISM - Certified Information Security Manager
    ISACA
    2026
    Information Security Strategy Security Controls Information Security Program Regulatory Compliance Budget Management and Indicators Awareness and Security Culture Security Governance Security Incident Management Operational Resilience and Continuity Cyber Risk Management

Skill set

Categories