About Lounis
French
Native or bilingual
English
Fluent
Arabic
Native or bilingual
Kabyle
Native or bilingual
Spanish
Conversational
Experience
- Tribun Health,Information Security ManagerMEDICALJuly 2023 - Today (2 years and 11 months)Paris, FranceFull implementation of an Information Security Management System (ISMS certified ISO 27001:2022 in 2025):
- Developed the organization's information security strategy, ensuring alignment with business and security objectives.
- Conducted information security risk assessments and implemented a risk treatment plan.
- Ensured compliance with all applicable legal, regulatory, and contractual requirements.
- Managed security incidents (ManageEngine, Wazuh, WatchGuard).
- Managed configurations and vulnerabilities (ManageEngine, Active Directory, Entra ID, Azure policies).
- Established a BCP/DRP to support business continuity.
- Facilitated regular employee training programs on security best practices.
- Integrated security into the development, deployment, and maintenance lifecycle, ensuring compliance with Food & Drug Administration requirements.
- Integrated security into vendor and human resource management.
- Chaired the information security committee and provided updates on ISMS status.
- Trained and mentored information security interns.
- Implemented a SIEM (Wazuh).
System Administration:- Managed and implemented the data migration project to SharePoint.
- Managed Azure infrastructure, including virtual machines, storage, and networking, to ensure optimal performance and security.
- Managed and maintained Active Directory and company IT assets (hardware inventory and software license management).
- Managed VMware vSphere, including virtual machines, storage, and networking.
- Administered Microsoft 365 solutions (Exchange, Teams, SharePoint, Dynamics...)
- Serma Safety & Security,GRC ConsultantCONSULTING AND AUDITSMarch 2020 - June 2023 (3 years and 3 months)Paris, FranceProject Manager – Risk Analysis Service Center (EBIOS RM Methodology) – (Equans)
- Led over 50 risk analyses for a major industrial client: scoping, coordinating deliverables, presenting results.
- Facilitated steering committee meetings with client stakeholders, monitored actions, and reported progress.
- Managed resources and planning: defined workloads, allocated consultants, and supervised production.
- Reviewed, validated, and continuously improved deliverables (risk analyses, treatment plans, mappings).
Consultant in Risk and Compliance Service Center - (Allianz):- Performed over 25 EBIOS RM risk analyses on strategic projects involving critical business processes.
- Conducted in-depth assessments of BCP and DRP for strategic suppliers involved in critical processes.
- Analyzed the operational capability of service providers to maintain key activities in case of crisis or disruption.
- Assessed the security maturity of service providers.
Cybersecurity Auditor mandated by clients (Société Générale):- Conducted on-site audits, covering both organizational aspects (ISMS governance, business continuity, incident management) and physical aspects (access control, facility security, off-site backups).
Risk Consultant (Sebia):- Supported FDA approval for medical devices (AAMI TIR 57, EBIOS RM, STRIDE, Secure Architecture).
Security and Risk Architect (Alstom):- Supported the security-by-design approach for the automated metro project (IEC62443).
ISMS Referent (Bpifrance):- Supported project teams from the scoping phase.
- Evaluated cloud architectures (Azure, AWS).
- Promoted DevSecOps best practices.
- Performed ISO 27005 risk analyses on application projects.
- ALD Automotive,Assistant CISOBANKING AND INSURANCESeptember 2017 - September 2019 (2 years)Paris, FranceRisk Management:
- Security risk analysis (Web Application, AS400, Salesforce, GED…).
- Conducted Business Impact Analysis (BIA).
Security Audit Follow-up (Pentest):- Analyzed audit reports and presented findings to the IT department.
- Monitored remediation plans.
Participation in PSSI Drafting:- Wrote security policies and procedures.
Project Management:- Managed user rights and authorizations.
- Led workshops to gather business needs.
- Created new security profiles, roles, and groups.
- Updated the rights matrix.
Application Compliance with GDPR:- Identified and classified personal data in applications.
- Reviewed processing purposes (DPO, Business Owners).
Employee Cybersecurity Awareness:- Led IT security awareness workshops (monthly for new employees at ALD Automotive).
- Assisted employees with phishing alerts.
DLP Alert Handling:- L2 Correspondent for the information leakage prevention system.
- Investigated and followed up on action plans in case of leaks.
Workstation Management (Tanium):- Monitored patch management.
- Tracked CVE remediation.
- Monitored and managed Shadow IT.
Recommendations
Be the first to recommend Lounis
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Master in Computer SecuritySorbonne University (UPMC Campus)2019Master en sécurité informatique
Certifications
- Certified ISMS Lead AuditorCerti-Trust2021
- Certified ISMS Foundation ISO 27001Certi-Trust2021