About Maha
French
Native or bilingual
Experience
- DSI d'AXASenior IT Compliance & Risk ManagementBANKING AND INSURANCEFebruary 2022 - Today (4 years and 4 months)Paris, FranceDetails of• IT Risk Management:◦ Management of the risk register and support for business teams in implementing remediation plans◦ Development of schedules and budgets necessary for remediation◦ Simplification of Cybersecurity and regulatory requirements for non-technical stakeholders.◦ Monitoring of KPIs associated with risk treatment and closure.• Coordination of annual internal control and security audit campaigns (ISO/IEC 27001):◦ Coordination of annual testing exercises conducted by security and internal control.◦ Review and update of processes to ensure their compliance with Group policies◦ Monitoring the execution of processes with process owners throughout the year◦ Collection and consolidation of proof of execution (evidences)◦ Definition of a governance framework to manage compliance, share progress, and escalate risks to the steering committee.• IT Compliance Referent within the framework of the DORA regulation implementation◦ Translation of regulator requirements into action plans adapted to the organization◦ Review and update of internal IT processes to meet the requirements of the European DORA regulation◦ Support for IT teams in implementing compliance measures.
- La Poste & Crédit AgricoleSenior Cybersecurity ConsultantJune 2020 - January 2023 (2 years and 7 months)keys Project management for the deprecation of TLS 1.1 protocol and prohibition of vulnerable cryptographic suites on all IT security equipment (WAF, proxies, servers, etc.), to strengthen the IT system's security posture• Conduct of a POC with IBM to test the FHE (Fully Homomorphic Encryption) solution on an internal use case• Monitoring/testing of a post-quantum Time Stamping solution as part of a POC with leading companies in the electronic signature market• Risk analysis on the use of a dedicated Cloud HSM in the Cloud
- Société GénéraleRisk AnalystBANKING AND INSURANCEDecember 2018 - June 2020 (1 year and 6 months)Paris, FranceCSRO (Compliance, Security Risk Officer) at La Société Générale• Analysis of cybersecurity risks for application architectures• Analysis of HLD and LLD• Monitoring and support for teams in integrating security into projects• Proposal of mitigations and monitoring of their application• Analysis of Pentest reports• Audit of projects and certification of internal Cloud products according to internal PSSI• Assistance with PI Planning• Participation in various Scrum events (Sprint Planning, review, retrospective, daily scrum...).
Recommendations
Be the first to recommend Maha
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Risk analysis methodologyISO/IECMéthodologie d'analyse de risque
- PhD in2015Doctorat en