You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Fabrice BernitFB

Fabrice Bernit

GRC Cybersecurity Analyst - ISP - ISO 27001 Audit

€700/day
Paris, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Fabrice

Cybersecurity expert with over 9 years of experience in GRC, risk analysis (EBIOS RM, ISO 27005), security architecture, and project support. I assist project teams (RSP / ISP) in structuring security approaches, conducting SSI audits and documentation, and ensuring regulatory compliance (LPM, GDPR, DORA, NIS2, etc.).
In-depth experience in classified systems accreditation (National Defense), critical IT system security, project documentation (PES, PACS, compliance matrix, etc.), and awareness training sessions. Good command of GRC tools, risk treatment plan management, and resilience requirements (BCP/DRP).
ISO 27001:2022 Lead Implementer (PECB) & Auditor (LSTI) Certified
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km), Bordeaux (up to 10km), Rennes (up to 10km), Lyon (up to 10km), Lille (up to 10km)

Experience

  • CAGIP / BNPP / LCL (pour le compte de OPPIDA groupe APAVE) – Paris (75)
    ISO 27001 / HDS / DORA Auditor
    BANKING AND INSURANCE
    March 2025 - October 2025 (7 months)
    Main missions:
    • Responding to calls for tender.
    • Site visits
    • Documentation drafting: pre-scoping meeting, compliance matrix, results presentation.

    Added value:
    Methodological support for audited banking clients' partners, risk exposure, and awareness of regulatory requirements.
    ISO 27001 Security Audit
  • Thales DMS
    RSP Support for IT System Accreditation
    DEFENSE AND MILITARY
    February 2023 - January 2025 (1 year and 11 months)
    Élancourt, France
    Context & Objective: Support for Project Security Managers (RSP) for the accreditation and re-accreditation of non-outsourced, classified IT systems.
    Thales DMS Site (on behalf of Thales TSN / Cybermaker) – Elancourt (78) / Brest (29) / Istres (13)
    Key results: 20 classified IT systems supported and HPE validated in 23 months.

    Main missions
     Analysis & Scoping: Identification of stakeholders, IT system mapping, choice of accreditation approach.
     Documentation drafting: QCC, Accreditation Strategy, PES, Compliance Matrix, PACS, FSRR, presentation materials.
     Risk Analysis: Conducting EBIOS RM analyses (compliance or full via All4Tech Agile Risk Manager). Risk Analysis referent for support teams.
     Validation & Coordination: Review with RSPs and OSSI before submission to authorities.
     Training & Awareness: Coaching junior consultants and disseminating ANSSI best practices to Project teams.
     Integration of Security Elements into Projects (ISP): Proposal of security measures (PACS / MCH / PCA / DRP) and monitoring of existing measures.
  • DGA
    Project Manager - Risk Analysis
    DEFENSE AND MILITARY
    April 2022 - January 2023 (9 months)
    Paris, France
    Context & Objective: Project Manager responsible for conducting risk analysis (EBIOS RM methodology) for the accreditation of the SIGALE solution (inter-ministerial arms export licensing management).
    DIAG Site (on behalf of ATOS/Cybermaker) – Bruz (35) – Paris Balard (75)
    Key results: Accreditation of the solution, ensuring compliance with cybersecurity requirements and system resilience.

    Main missions
     Inventory and Identification: Inventory of Business Assets, Supporting Assets, Risk Sources, and associated vulnerabilities of COTS.
     Risk Analysis with development of Strategic/Operational Scenarios:
     Proposal of security measures (PACS / MCH / DRP / BCP) and monitoring of existing measures.
     Documentation and Communication:
    • Drafting of the Residual Risks summary sheet.
    • Leading 5 workshops including preparation of materials and drafting of minutes.
    • Development of the final Risk Analysis report, PDS, and PES report.
     Security Watch:
    • Monitoring COTS vulnerabilities and CERT watch to maintain operational security.
    Added value: This mission ensured rigorous risk management and strengthened the security of the SIGALE solution, while guaranteeing effective communication and precise documentation to stakeholders.

Recommendations

Be the first to recommend Fabrice

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • D.E.S.S. LASER Engineering (Master 2) – Graduated with honors (Lille)
    D.E.S.S. Ingénierie LASER (Master 2) – Major de sa promotion (Lille)

Certifications

  • CISA Certification (Certified Information Systems Auditor)
    CERTyou
  • ISO 27001 Lead Auditor Certification
    LSTI
    2025

Skill set

Categories