About Gilles Fabrice
French
Native or bilingual
English
Fluent
Experience
- UFFTech Lead Java - DevSecOpsBANKING AND INSURANCEDecember 2022 - Today (3 years and 6 months)Bois-Colombes, FranceAs a DevSecOps security tech lead, I am responsible for integrating cybersecurity into the entire application lifecycle, from design to implementation. My responsibilities include:
- Defining and implementing application security requirements and secure development standards
- Analyzing and remediating cross-cutting vulnerabilities in applications and infrastructures
- Migrating and securing CI/CD tools (Gitlab, Jenkins, Sonar) to address security flaws
- Administering and configuring secure development tools (Gitlab, Jenkins, Sonar)
- Conducting security-oriented code reviews and applying OWASP best practices
- Implementing and administering advanced security tools (Checkmarx, Qualys, SonarQube) and integrating vulnerability analysis steps into CI/CD pipelines
- Planning and executing penetration tests (Pentests), analyzing results, and reporting
- Remediating application, server, and network vulnerabilities identified during audits
- Actively participating in operational security and governance meetings
- Securely migrating Cloud VMs and applications while adhering to security standards
- Designing and implementing secure deployment pipelines (Jenkins, Kubernetes, Docker)
- Introducing security aspects to CI/CD tools.
- Migrating tools such as Gitlab, Jenkins, SQUASH Test to non-vulnerable versions
- SOCIETE GENERALEIT Project Technical Manager - DevSecOpsBANKING AND INSURANCEMarch 2018 - November 2022 (4 years and 8 months)Fontenay-sous-Bois, FranceI was part of the Business Solution Center (RESG/BSC) entity, a shared services center dedicated to providing the Société Générale Group's entities and departments (Finance, Risks, Human Resources, etc.) with comprehensive IT solutions.Key Responsibilities:
- Implementing security best practices in the development and deployment cycle
- Training and supporting technical teams towards a DevSecOps culture
- Setting up a continuous vulnerability monitoring platform for rapid detection and remediation
- Coordinating technical and security teams to ensure a cross-functional and effective approach
- Managing production security incidents and implementing corrective measures
- Estimating and validating projects for evolution, incorporating security constraints
- Creating secure deployment scripts with Ansible, including secret and access management
- Implementing an Identity and Access Management (IAM) strategy to enhance the security of development and production environments
- Training 20 developers on security and continuous deployment best practices
- Setting up secure CI/CD pipelines (Jenkins, Kubernetes, Docker) with vulnerability scans
- CARREFOURJAVA/JEE Development Engineer + DevOpsRETAIL (LARGE RETAILERS)February 2017 - May 2018 (1 year and 3 months)91300 Massy, FranceProject: Design and implementation of a secure continuous and automatic deployment toolKey Responsibilities:
- Creating secure deployment scripts with Ansible, including access and secret management
- Setting up a continuous integration (CI) pipeline with automatic triggering upon Git commits
- Designing Jenkins pipelines (Jenkinsfile) with integration of security tests
- Integrating security testing tools into the CI/CD pipeline (SAST, DAST, SCA)
- Optimizing the ELK search engine (Java 8, Stream, Lambda, JProfiler)
Securing ElasticSearch queries and implementing event monitoring- Participating in security audits and implementing recommendations
- Developing secure Java Web Services with REST API and Jersey
- Automating SSL/TLS certificate management to ensure communication security
- Implementing a real-time monitoring system to detect security flaws quickly
- Securing and encrypting data during indexing phases
Recommendations
Be the first to recommend Gilles Fabrice
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- General Engineer with a specialization in JAVA/JEE developmentESIGELEC2013