You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Laurent VerniqueLV

Laurent Vernique

RSSI - IAM/PAM - GRC

€890/day
Nantes, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Laurent

My professional background has allowed me to hold various positions of strong responsibility requiring both technical skills and resource management and project management skills. These different skills are crucial for successfully completing projects within defined costs and deadlines, but also essential for ensuring seamless operation of information systems.
All my actions are structured around 4 main themes in order to position the IT department and IT security at the heart of the company's business so that they are a real competitive advantage and contribute effectively to its development:
- Implement information system governance,
- Bring innovation to the business,
- Give back control to the business over its production tool
- Reduce costs
- Ensure the security of information systems
  • English

    Conversational

  • French

    Native or bilingual

Can work on-site
Nantes (up to 50km), Nantes (up to 50km), Paris (up to 30km)

Experience

  • La Banque Postale
    CSSI Expert IAM/PAM
    BANKING AND INSURANCE
    January 2025 - Today (1 year and 5 months)
    Nantes, France
    Within the CSSI team responsible for managing derogations or exceptions to the IS Security Policy: Information System Security Policy of La Banque Postale, supporting the deployment of the IS Security Policy within the IT department, maintaining KRIs (Key Risk Indicators) and Security Reporting for the IT department as well as for subsidiaries. This is an RPS (Security Pivot Relay) mission for DSIBA, meaning acting as a security officer for IAM (Identity & Access Management) and PAM (Privileged Access Management) for La Banque Postale's IT department. This activity will be carried out in conjunction with correspondents in the various DSIBA departments, correspondents from the Cybersecurity Department, and CISOs. The mission will primarily consist of: - Implementing a new governance organization for DSIBA's IAM and PAM, around Sailpoint & CyberArk products - Participating in the development of new access profiles according to business needs - Identifying toxic combinations and privileged accounts (PAM) - Developing a derogation management model - Defining the new access review organization
    Sailpoint Cyberark
  • Grant Thornton
    Senior Cybersecurity Consultant
    July 2023 - December 2024 (1 year and 5 months)
    Paris, France
    2nd: Define and apply the necessary security controls to ensure a level of security corresponding to the group's expectations. Monitor the evolution of the Bitsight rating for the group's applications exposed on the internet. Respond to employee requests as needed. Monitor the various user account certification campaigns.
  • Société Générale
    PAM Consultant
    BANKING AND INSURANCE
    May 2022 - June 2023 (1 year and 1 month)
    PAM (Privilege & Access Management) Program within the IT Department:
    1 - Context and objectives of the service
    "User" privileges
    Reduction of privileged accounts and securing exceptions (controls) according to the rules set by the Group CISO
    Monitoring and handover to RUN of the project (Securing privileged accounts)
    Study of project V2.5 daily password renewal and MFA implementation
    2 / "Generic Accounts" privileges
    Securing generic accounts (management of their life cycle) and their associated privileges according to the rules set by the Group CISO.
    The contribution to these projects includes participation in scoping and applicability workshops based on the IT department's context; proposal and validation of objectives by the CISO; implementation of internal governance (communication, change management, implementation, definition and implementation of controls); reporting/alerting on objective achievement.

Recommendations

Be the first to recommend Laurent

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Data Protection Officer
    CNIL
    2018
    Le délégué à la protection des données (DPO) Avec une fonction située au cœur de la conformité au règlement européen sur la protection des données (RGPD), le délégué à la protection des données (DPO) conseille et accompagne les organismes qui le désignent dans leur conformité.

Skill set

Categories

  • Other