You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Ibrahim ChadouliIC

Ibrahim Chadouli

Information Security Analyst

€400/day
Paris, FR
0-2 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Ibrahim

Ibrahim, cybersecurity engineer (IoT/GRC), graduated 2024 (SecNumedu/ANSSI). 2 years as Security Analyst at AXA IM: SOC, vulnerability management, ISO 27001 compliance.

Key experience:
• Forensic internship at La Poste: Deployment of TinyCheck (Raspberry Pi) to detect stalkerware, integrated into Parisian police stations.
• SOC: Expertise on Azure Sentinel (SIEM), Cybereason (EDR), Vectra (NDR), Zscaler. Incident management (phishing, malware), technical coordination, and security KPI monitoring.
• Vulnerabilities: Qualys optimization for patch prioritization, critical CVE tracking, and false positive reduction.
• GRC: Cryptographic policies (TLS, AES, RSA) aligned with ISO 27001, reporting automation (Python, VBA), and documentation.
• Results: Cryptographic compliance boosted from 60% to 90%, team awareness, and integration of best practices.

Expertise:
• SOC & Forensic: Proactive detection, incident response, resilience enhancement.
• Risk Management: Protection of critical data through a methodical approach (risks, vulnerabilities).
• Automation: Control optimization, cost/error reduction through scripts (Python, Power Query).
• Global Support: Audit, security policies, remediation, and training.

Passionate about innovation, I offer tailor-made solutions to secure your IoT projects and infrastructures. Contact me to discuss your challenges!
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km)

Experience

  • AXA Investment
    Information Security Analyst
    BANKING AND INSURANCE
    August 2022 - August 2024 (2 years)
    Paris, France
    I worked under the CISO within the Information Security team, between the SOC (three consultants) and governance (about ten people). I primarily focused on incident response and threat management, dedicating 30% of my time to compliance and security controls.

    SOC Operations: Monitoring and Incident Response
    • Proactive monitoring via SIEM, EDR, NDR, XDR, DLP, and XSOAR.
    • Real-time threat detection, analysis, and assessment to accelerate incident response.
    • Security incident management (logs, phishing, malware), investigation coordination, and remediation.
    • Vulnerability management oversight with Qualys: prioritization and tracking of critical CVEs.
    • Optimization of detection rules and reduction of false positives.
    • Updating SOC procedures and strengthening resilience against cyberattacks.

    Governance and Automation of Cryptographic Controls
    • Analysis of internal requirements (AXA IM) and standards (ISO 27001) for the cryptographic policy.
    • Configuration of Qualys to scan for TLS (1.2+) compliance, encryption (AES 128/256), RSA signature (>2048 bits), and valid certificates.
    • Planning and execution of scans (test → UAT → production), prioritization of fixes.
    • Automation of mapping and reporting (Power Query, VBA) to minimize manual errors.
    • Assessment and documentation of risks related to exceptions in coordination with Security, Operations, and Development teams.
    • Coordination of remediation plans between application and platform teams.
    • Formalization of a cryptographic control procedure to ensure the sustainability of best practices.
    • Presentation of the compliance score to the GRC committee, improving the rate from 60% to 90% before my departure.
  • Le Groupe La Poste
    Forensic Project: Spyware Detection
    PUBLIC SECTOR
    April 2022 - July 2022 (3 months)
    Paris, France
    Within the Digital Forensic Investigation Department – specializing in forensic analysis of professional equipment for internal incidents (harassment, theft, fraud, etc.) – I led an innovative project, proposed as part of a La Poste group internal competition to fund and support high-potential development projects.

    Designed a portable device to detect spyware on phones and tablets.
    Implemented Kaspersky's TinyCheck solution on a Raspberry Pi 4 to identify stalkerware.
    Validated the device's effectiveness by conducting tests (installing spyware on a phone).
    Deployed the tool on a large scale by conducting demonstrations and preparing five devices for five police stations in Paris.

Recommendations

Be the first to recommend Ibrahim

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Engineering Degree in Connected Objects & Cybersecurity
    ESILV
    2024
    Diplôme d'Ingénieur en Objets connectés & Cybersécurité
  • Bachelor's Degree in Computer Engineering
    ECE
    2022
    Licence Ingénierie Informatique

Skill set

Categories