About Karim
French
Native or bilingual
English
Fluent
Experience
- AXATech Lead / Qualys ExpertBANKING AND INSURANCEJanuary 2025 - February 2026 (1 year and 1 month)Paris, FranceRole – Tech Lead / Qualys ExpertTech Lead responsible for deploying the new Qualys ETM module, with advanced expertise inQualys platform administration (VM, Policy Audit, CSAM…).Challenges: Transitioning from a prioritization model based "on detection severity" to a risk-based modelfocused on "asset criticality and its detections" to mobilize teams responsible for remediating critical assets.As part of the ETM launch, with AXA as a Design Partner, I work closely with theQualys ETM PO, reporting malfunctions and product improvement requeststo meet expectations.Actions taken:• Integration of Qualys ETM with IT environments (Scanning Solutions and ITSM..).• Responsible for integrating external data (API, scripts, ETL)• Enrichment of Qualys assets (ServiceNow CMDB source)• Interventions in complex hybrid environments (on-premise / cloud) and multi-site.• Automation of vulnerability scans and analysis.• Evolution of the TruRisk Score calculation (formula, vulnerability and asset weights)• Optimization of correlation rules during asset integration• Management of product correction and evolution requests with the publisher (weekly meeting).• Implementation of Vulnerability Prioritization based on risk for IT/Security departments tosupport technical teams in remediation.• Creation of Dashboards: Coverage, Vulnerability, and Patch Management in UD.• Training of CDPs for presentation to entities.• Deployment on the Group's Pilot Entities.• Support for CDPs during follow-up committees/presentations of new features.• Implementation of Statistics, reports, and alerts for transition to BAU.
- BPCE Infogérance & TechnologiesSystems Security ExpertBANKING AND INSURANCEMarch 2020 - December 2024 (4 years and 9 months)Charenton-le-Pont, FranceRole: Systems Security Expert - Qualys Expert - Systems Security DepartmentDSS systems intervenes on all infrastructure elements to control and organize the remediation of vulnerabilities and hardening of equipment configurations.Challenges: Reduce the number of vulnerabilities and define, implement, and manage the hardening process.Actions taken:IT asset managementVulnerability ManagementPatch Management (Increased frequency of SRV, WKS, DC, DB cycles)Compliance of critical perimetersManagement of the Qualys infrastructure (Agent, Appliance, proxy, sensor, subscription configuration…)Automation of VM and PC vulnerability scansCollection and consolidation of Qualys data.Monitoring and remediation of cross-functional vulnerabilitiesSupport for systems/application/business teamsCreation of specific vulnerability and hardening dashboardsMonitoring the reduction of vulnerabilities and obsolescenceDefinition of Hardening ProcessesPlanning, presentation, and coordination of hardening and recovery actionsDashboard creationData historization and KPI provisionFacilitation of monthly committee meetingsAnnual review of vulnerability and hardening management processesRegulatory watch (DORA, NIST, ..)...Management:Team organization and coordinationCrisis managementAudit responses.Success factors:OrganizationPlanningCommunicationTools and Project Methodologies: QUALYS, Splunk, O365 Suite, ServiceNow, Azure, GCP, AWS,..NATIXIS CIB AMERICA – NEW YORK Nov. 2022 – April 2023NATIXIS March. 2020 – Oct 2022
- AXASenior Technical Project Manager Infrastructure / SecurityFebruary 2018 - March 2020 (2 years and 1 month)Île-de-France, FranceRole: Project Manager - Systems and Security Infrastructure (S&D French Market)The "French Market" division is the single point of contact for AXA group entities in the SOUTHERN EUROPE region. My role is to meet the infrastructure and security needs of the OPCOS (Group Entities).Projects completed:Infrastructure:Resumption of the deployment of a Group invoice management solution (17 Countries)Upgrade of ITESOFT, CODA, POPPULO Business Solutions..Separation of an AXA LE entity to ARCHITASCreation of a new AXA NEXT entityMigration of solutions to Private Cloud/AzureDeployment of servers (Core-IT, Private or Public Cloud, SaaS, PaaS, IaaS)Decommissioning of infrastructures (CITRIX, EXCHANGE)Site relocation (collines de l’arche to Java-Pont Cardinet)Security:MTSB - Hardening of configurations for 5 Entities GIE, ALM, ALE, AGRE, and AGSActions on OS, Domain Controller, IIS, APACHE, SQL, Oracle…Strengthening of the Password PolicyPatch Management: Corrections of severities 4 and 5Review of Assets to confirm the GIE perimeterISMS ParticipationISO 27001 Participation (Infra Referent)Deployment of data classification (AIP, AIP scanner,)Strengthening of PROXY Policies (On Prem, CLOUD)Correction of vulnerabilities detected during PentestsParticipation in improving QUALYS, CAS processes and toolsReview of Access Management (IAM, PAM) CyberArK, ArcSightSuccess Factors:Ability to consolidate collected informationTechnical knowledgeProject visibility.Adherence to deadlines and budgetsTechnical environment: Windows, Linux, Oracle, SQL, Private/Public Cloud, Azure, GCP, AWS, AXWAY, CyberArk,..Tools and Project Methodologies: Power BI, Excel, MS Project, SharePoint, ITIL. ServiceNow, Fireflow, Perform, Confluence
Recommendations
Be the first to recommend Karim
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4