You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Guillaume MorillonGM

Guillaume Morillon

GRC Cybersecurity Expert - LPM, ISO27001, EBIOS RM

€900/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Guillaume

Cybersecurity initially seemed like an obscure and complex subject. Being curious by nature, I wanted to understand its various aspects. I began to take an interest in it by focusing on the technical side towards the end of my studies in 2012. Understanding and mastering the methods and tools used to launch cyberattacks should allow me to deduce the measures to protect against them. After a work-study network engineering degree, a lot of monitoring and training on the subject, as well as technical training, I defined a list of measures and participated in implementing them within the information system of a large international group (now considered vital). This significantly improved the cybersecurity level of the perimeter. I quickly realized that without follow-up, purely technical security measures were very quickly bypassed, forgotten, or obsolete. I then became interested in organizational methods to maintain and improve an organization's cybersecurity level. The ISO 27001 standard seemed to address this issue correctly by proposing the creation and implementation of processes, procedures, indicators, etc. for the security management system in a continuous improvement approach. I therefore obtained the ISO 27001 Implementer/Lead Implementer certification in 2019. Since then, I have implemented this standard in various contexts and have had to work on other demanding frameworks (LPM and RGS, for example). In the course of these missions, I have had to communicate, raise awareness, gain acceptance, implement, etc. And this, with many different stakeholders, ranging from operational staff to directors. I participated in the development of risk analyses using the "EBIOS RM" and "ISO 27005" methods.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 15km)

Experience

  • Sodexo
    Cybersecurity Expert
    PUBLIC SECTOR
    November 2023 - Today (2 years and 7 months)
    Support technical and business management in implementing cyber measures for various public sectors to meet contractual requirements.
    Development of EBIOS RM risk analyses.
    Development of approval files.
    Project management.
  • Société Générale
    Cybersecurity Expert
    BANKING AND INSURANCE
    September 2022 - November 2023 (1 year and 2 months)
    Integration of security into projects.
    Development of risk analyses.
    Project monitoring.
    Supervision of technical audits (Pen-tests).
    Raising business awareness on cybersecurity.
  • Veolia Eau
    ISO 27001 Standard Implementer
    RAW MATERIALS INDUSTRY
    October 2021 - Today (4 years and 8 months)
    Toulouse, France
    Implementation of ISO 27001 compliance for the SIIV perimeter:
    Establishment of a statement of applicability.
    Establishment of a risk treatment plan for DG approval.
    Establishment of a cyber action plan to be implemented for the perimeter, taking into account business needs, existing cybersecurity measures, and regulatory and contractual context.
    Assistance to operational teams in carrying out security tasks.
    Development of project progress indicators.
    Drafting of documentation expected by an auditor.
    Gathering of evidence expected during an audit.
    LPM ISO 27001 Risk Analysis Awareness

Recommendations

Be the first to recommend Guillaume

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • General Engineer - Specialization in Telecommunications and Networks
    ECE Paris
    2015

Certifications

  • Implementer/Lead Implementer ISO 27001
    LSTI
    2019
    ISMS Continuous Improvement Cybersecurity ISO 27001
  • Hacking and Security, Level 2, Expertise
    Orsys
    2018
    Metasploit Nmap Kali Linux

Skill set

Categories