You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Jean-Pierre MbomaJM

Jean-Pierre Mboma

Cyber GRC Risk Manager - ISO 27001, DORA, NIS2

€620/day
Paris, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Jean-Pierre

Cyber Risk Manager specializing in GRC. Certified ISO 27001 Lead Implementer, I support companies in their information security governance, risk analysis, and compliance projects (EBIOS RM, DORA, NIS2, ISO 27001).

4 years of experience in the fintech, banking, and industry sectors with assignments at BPCE and TotalEnergies.
Available for freelance missions in France, full remote or hybrid.
  • French

    Native or bilingual

  • English

    Native or bilingual

Can work on-site
Paris (up to 50km)

Experience

  • SPENDESK
    CYBERSECURITY & RISK OFFICER
    BANKING AND INSURANCE
    January 2025 - September 2025 (7 months)
    Paris, France
    Spendesk – Cybersecurity Risk Framework & Regulatory Compliance

    • Design of a comprehensive Cyber Risk Framework: risk identification, construction of risk scales and matrices
    • Implementation of a risk map aligned with regulatory compliance objectives (DORA, ISO 27001, DSP2)
    • Identification of dreaded events for Spendesk and associated impacts
    • EBIOS RM risk analysis and proposal of action/remediation plan
    • Identification and monitoring of fraud scenarios
    • Mapping of IT processes and services supporting critical and significant dreaded events
    Improvement of regulatory compliance with a 60% reduction in non-conformities.

    Key skills: risk management, EBIOS RM methodology, DORA/ISO compliance, GRC management, communication with business departments.
    DORA ISO 27001 EBIOS RM
  • BPCE
    Cybersecurity Consultant – Third-Party Risk & Governance
    BANKING AND INSURANCE
    January 2023 - January 2024 (11 months)
    Charenton-le-Pont, France
    Intervention in LOD2 within a banking group, dedicated to assessing the cybersecurity maturity of third parties (service providers, suppliers, critical partners).

    • Design of a unified security questionnaire, aligned withISO 27001, NIST, SecNumCloud, PCI DSSstandards.
    • Conducting cyber maturity assessments of third parties (questionnaires, documentary reviews, scoring)
    • Mapping between Group IS Policy, internal controls, and international standards.
    • Analysis of service provider security and governance arrangements (policies, controls, incident management, **BCP/DRP**)
    • Challenge and supervision of LOD1, review of control quality and assessment results
    • Identification of gaps and creation of new level 2 controls to strengthen security coverage.

    Structuring of IS Security Governance Risk Management Cyber Regulatory Compliance (ISO 27001, DORA, NIS, DSP2) Workshop Facilitation Internal Controls
  • TOTAL ENERGIE
    Cybersecurity Consultant – Risk Management & Compliance
    ENERGY AND UTILITIES
    January 2022 - January 2023 (1 year and 1 month)
    Colombes, France
    Support for TOTAL Energies, OSE, in bringing its information systems into compliance with the NIS directive.

    • Audit and risk analysis: detailed assessment of risks associated with the information systems of the essential service operator.
    • Mapping analysis: Mapping of information systems (IT assets, applications, networks and interconnections, etc.)
    • Gap analysis: identification of gaps between current security practices and NIS directive compliance standards.
    • Identification and implementation of remediation plans
    • Coordination of stakeholders (business, IT, security) and progress reporting
    • Increase in NIS compliance rate from 50% to 97%.

    Audit Risk Analysis Risk Mapping NIS Workshop Facilitation

Recommendations

Be the first to recommend Jean-Pierre

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • M2 MANAGEMENT AND CONSULTING IN IT SYSTEMS
    ESGI
    M2 MANAGEMENT ET CONSEIL EN SI
  • BACHELOR'S DEGREE IN MATHEMATICS AND COMPUTER SCIENCE
    UNIVERSITY PARIS 10 NANTERRE
    LICENCE MATHEMATIQUE ET INFORMATIQUE

Certifications

  • ISO 27001
    PECB
    2024
    Risk Analysis Risk Mapping Internal Audit Cybersecurity Governance ISO 27001 IS Security IS Governance Business Continuity Plan Implementation of an ISMS Information Security

Skill set

Categories