About Franck
French
Native or bilingual
Spanish
Fluent
English
Fluent
Experience
- KeringIdentity & Continuity Manager (Interim)LUXURY GOODSJuly 2023 - February 2024 (7 months)Paris, FranceManager of security, identity, and continuity solutions - Protect & Recover (NIST framework)Objectives: Ensure interim coverage during recruitment and reduce team turnover.Program Management: IAM; AD; IGA; PAM; DLP; BIA/DRP; WAF; Obsolescence; Vulnerabilities...Leading the Protect & Recover team, facilitating MOE workshops for security policies and functions.Replacement of solutions and services (AD Security, BIA/DRP services tests): Requirements definition;Technical and functional evaluations; Procurement support (RFP, RFQ), privacy, and legal.Definition of the Protect & Recover security roadmap 2024-2026: Server/Workstation; User; Identity; Cloud;Application; Mobile; BIA; Resilience; Crisis management.Client environment: Workday; SAP IDM; Okta; AD (+65k accounts); Entra ID; Tenable.ad; PKI AD CS; Wallix;Teleport; Cybereason; AWS; GCP; Azure; Zscaler; Panorays; Splunk; Jira; ServiceNow...
- KEOLIS BORDEAUX METROPOLE MOBILITEDeputy CISOTRANSPORTATIONOctober 2020 - July 2023 (2 years and 9 months)Bordeaux, FranceObjectives: Compliance with LPM; Improve IT security maturity; Address tripartite governance (private-public)GOVERNANCE / RISKS / COMPLIANCECompliance: LPM (legal) and II 901 (interministerial instruction)• Definition and Management of "Security Assurance Plan" (PAS) roadmaps• Budget: Production of a technical memorandum & CAPEX / OPEX Monitoring (+ €4M)• Daily CISO coaching in a strong political context and sustained pressure• Rollout & Project Management: Mapping / Micro-segmented infrastructure study / Hardening (access, AD, network segmentation, filtering gateway, secure exchanges) / Backup / SIA / Privileged access (Bastion) / Incident detection / SIEM / Proxy / PSSI, charters, rules / IS Security KPIs / PCI / Crisis management / Audit, Pentest / Approval...• Supplier relations (qualification, third-party questionnaire, PAS, maintenance contract refactoring) and commitment monitoring• NIS V2 impact analysisIntegration / Remediation:• Monitoring, selection assistance, and implementation of security solutions (On-prem or SaaS), governance or technical (Compliance; Vulnerability; Probe...), managed services (SOC/EDR; PDIS...) and outsourced services (Audits; Studies; PRIS...)Client environment: Confidential
- MAIFAssistant CISO - Freelance Cybersecurity GRC ExpertBANKING AND INSURANCEMay 2019 - December 2020 (1 year and 7 months)Niort, FranceObjectives: Design the IS Security Policy based on the "Zero Trust" model; Manage risks; Raise user awarenessStrategy / Governance• Operational support for the Group's PSSI development: Charter; Rules (2); Glossary; Processes• Collaboration with experts on IT security and risk aspects• Advice and drafting of specifications for industrializing IS security activitiesAwareness: Monitoring and organizing communication actions on cyber risksRisk and Compliance: Mapping of IS Security Risks "ACPR": Inventory of risk management measuresAudit & Control - Security health of the Third-Party Ecosystem: PoC for monitoring and rating the Cyber risks of essential suppliersSecurity Assurance Plan (PAS) - Supplier Relations: Compliance review of standard and advanced PASISP: Identification of IS security rules applicable to project scopesMy environment:(1) tools: Office; SharePoint; ServiceNow; SecurityScorecard; RSA Archer; Dataviz(2) +21 technical & functional topics: Access and Authorizations; Operating systems; Administration; Development; Workstation; Wired/wireless network; Telephony; Internet access; Public Cloud; Malware; Logs; Backup; Mobile equipment; Sensitive information; Messaging; HR awareness and training; ISP; Subcontracting; Certificate and cryptographic secret; API; Tokens... representing +450 IS security rules(3) regulatory: Solva 2; ACPR; GDPR; NISClient environment:Mega; Assyst; Jira; Fortinet; Cisco; F5; Kaspersky; McAfee; EMM; MDM; Qualys; EJBCA; Yogosha; Bastion; MFA (PingID); Yubikey; CASB; DLP; SSO (Pingfederate); CybelAngel; Bluecoat; Hadoop; Alteryx; Spotfire; Azure; AWS; Git; Bug Bounty; SOC; Telecom operators...
Recommendations
Be the first to recommend Franck
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- MBA MaCYB - Cybersecurity Management and IS GovernanceEcole de Guerre Economique (EGE)2022
- General Engineer (Master's degree)CESI, Blanquefort2004Management Projet & Ressources Humaines / Organisation d’entreprise
Certifications
- eSCM-CL (eSourcing Capability Model for Client Organizations)eSourcing partners, Boulogne-Billancourt2015
- ISO 27001PECB