You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Mathieu GueryMG

Mathieu Guery

Part-time CISO, ISMS management, ISO27001 / HDS

€700/day
Toulouse, FR
8-15 years

Average response time: 24 hours

Freelancer profile translated to English.
Back to original language

About Mathieu

🛡️Cybersecurity Expert | Part-time CISO, ISMS Manager, IS27001/HDS, ISO42001

I am a cybersecurity expert with 7 years of experience, specializing in supporting startups and SMEs in the health sector towards ISO 27001 and HDS compliance.

My approach is simple: move fast, without sacrificing quality. As a CISO, I have led and maintained a dual ISO 27001 + HDS certification. My technical background allows me to understand and follow subjects in depth.

I am passionate about AI, its ethical and security challenges that it introduces.

---- SUPPORT ----

👨‍💻 Part-time CISO: I take charge of your company's security function, from security policy to COMEX/CODIR reporting, without the constraints of a senior recruitment.

📖 ISO 27001 & HDS Support: Gap analysis, internal audit, or ISMS construction. I guide you from A to Z until you obtain certification.

🤖 ISO 42001 Support: Gap analysis, internal audit, or construction of the AI Management System (AIMS) / integration of an AIMS into an ISMS.

🚀 ISMS Management: Implementation or takeover of your management system, dashboards, risk and non-conformity management. I adapt to your needs and constraints to ensure the smooth operation of your ISMS and prepare/renew your certifications in the best possible way.

☣️ Risk Analysis: EBIOS RM or ISO 27005 method. Clear, actionable deliverables, not a document that ends up in a drawer.

---- AUDITS ----

🔎 Internal Audit ISO 42001

🔎 Internal Audit ISO 27001

🔎 Internal Audit HDS

I mainly work with health SaaS startups, medical software publishers, and SMEs that want to structure their security without building an internal team.

Available remotely.
  • French

    Native or bilingual

  • English

    Fluent

Remote only
Primarily works remotely

Experience

  • Epigene Labs
    RSSI
    BIOTECH
    June 2024 - March 2026 (1 year and 9 months)
    Paris, France
    COMPLIANCE:
    • ISO27001 and certifications in less than 10 months;
    • Implementation and maintenance of risk analysis;
    • Scripting (Python, Google App Script) to automate our ISMS;
    • Daily monitoring of security and regulatory news;
    • Security committees with Management and stakeholders to strengthen our security posture, our commitments, decisions, and objectives;
    • Supplier management and security questionnaires;
    • AI security assessment to anticipate the AI Act (European regulation).
    MONITORING AND TRACEABILITY:
    • Aggregation of SaaS logs in Azure Log Analytics Workspace;
    • Azure Web Application Firewall (WAF) policies and alerts;
    • Development of a DLP bot on Slack;
    • Regular log review;
    • Configuration and troubleshooting of Azure logs and alerts;
    • Incident management and crisis unit.
    DEVSECOPS:
    • Integration of security into our CI/CD pipeline (Github → Terraform → Azure) with Aikido;
    • Secure Software Development Lifecycle (Secure SDLC);
    • Organization of pentests and treatment of identified vulnerabilities;
    • Vulnerability management program, triage, and correction;
    • Github Actions to automate security and Azure backups;
    • Terraform for IaC (Infrastructure as Code) on Azure;
    • Azure NSG to enforce VPN usage and Azure Bastion for VMs;
    • Python scripts for Azure access review, RBAC control, network audit, and FinOps;
    • Identification of vulnerabilities in Github code.
    OTHER:
    • IAM: implementation of MFA, RBAC, and the principle of least privilege;
    • Work in a low-budget environment with the development of internal solutions;
    • Cybersecurity awareness for employees to reduce human errors and social engineering attacks;
    • Physical security and remote work policies;
    • Securing IT equipment with Omnissa MDM and Admin By Request.
    ISO 27001 HDS artificial intelligence Risk Analysis CISO
  • Deepdef
    Azure Security Architect
    CONSULTING AND AUDITS
    February 2024 - May 2024 (3 months)
    Toulouse, France
    • Design and drafting of an architecture file for the implementation of MFA and eSSO solutions, ensuring security and scalability;
    • Application hardening through security policies with Intune, Entra ID, and Azure;
    • Access management, compliance, and configuration hardening.
    DevSecOps Microsoft Azure airbus Authentication MFA
  • Capgemini
    Airbus BigData – Kubernetes Security Engineer
    CONSULTING AND AUDITS
    January 2023 - January 2024 (1 year)
    Toulouse, France
    • Conducting risk analyses according to the EBIOS RM method on an on-premise Big Data platform based on Kubernetes;
    • Securing and hardening Rancher/Kubernetes clusters;
    • Applying CIS Benchmarks to secure Kubernetes clusters;
    • Defining and implementing DevSecOps processes to integrate security into the development cycle.
    Risk Analysis DevSecOps Kubernetes Rancher CIS Benchmark

Recommendations

Be the first to recommend Mathieu

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Engineering school Security of Information Technology Security of embedded systems
    INSA Centre Val de Loire
    2019
    Engineering school Security of Information Technology Security of embedded systems
  • Scientific Baccalaureate
    Mention Très Bien Lycée Anguier – Eu
    2014
    Baccalauréat Scientifique

Certifications

  • ISO42001 Lead Implementer
    PECB
    artificial intelligence AIMS AI Governance Internal Audit Governance ISO 42001 AI Security AI Compliance AI Act
  • ISO27001 Lead Auditor
    PECB
    Internal Audit ISO 27001 Cybersecurity ISO 27001 Lead Auditor IS Governance Gap Analysis Security Audit GDPR Compliance

Skill set

Categories