About Mejdi
French
Native or bilingual
English
Fluent
Italian
Basic
Arabic
Native or bilingual
Experience
- La Caisse DESJARDINSInformation Security Management System ManagerNovember 2021 - Today (4 years and 7 months)CONTEXT:"DEMPTON group conseil", an international company of "DEMPTON technological solutions" engaged Mr. ARFAOUI as the SMSI Manager and Lead Implementer of ISO 27001. The mission assigned consists of ensuring the compliance of operations with security standards, particularly to meet the requirements of the client "La Caisse Desjardins".RESPONSIBILITIES:• Development and supervision of information security policies to ensure the protection of sensitive financial data.• Implementation of security procedures and standards, as well as management of compliance with current regulations.• Management of information security risk assessments and implementation of mitigation plans.• Training and awareness of banking staff to ensure a strong security culture.• Constant monitoring of the IT infrastructure, detection and management of security incidents.• Management of internal and external audits to continuously maintain and improve information security within the bank.ENVIRONMENT: Cybersecurity, IAM, SSO, CyberArK, Confluence, Jira, Encryption, Fraud sensitivity, ISO 9001, ISO 27001RESULTS: Creation and implementation of a security policy, 40% reduction in recorded security incidents, Deployment of security training and awareness programs, Implementation of a Security Operations Center (SOC)
- CIB BNP PARISBAS –PM SAFETY & TRUST - APPLICATION SECURITYJune 2021 - July 2023 (2 years and 1 month)FranceCONTEXT:In the context of applying compliance criteria, confidentiality, integrity, availability, and traceability of applications for the cybersecurity department of BNP Paribas' Corporate Investment Bank, Mr. Arfaoui acts as guarantor of application and data security. The cybersecurity service's activity covers several IT Owners and CISOs, across the following areas: Global Markets, Risk Markets, Global Banking, ALM Treasury, BP Security Services, etc. This represents over 20,000 applications for more than 50 countries. Risk and security management are key elements for clients, regulatory organizations, and senior management.RESPONSIBILITIES:• Ensure the integrity, confidentiality, and traceability of information.• Validate application compliance and adherence to GDPR.• Advise on authentication solutions to implement and assist in the creation of Risk-Cards.• Assist in the setup and implementation of pentests.• Ensure AppSec process compliance (Development, Security testing, Risk Assessment).• Participation in various SteerCo meetings (Communication and roadmap monitoring).ENVIRONMENT: Cybersecurity, IAM, SSO, CyberArK, Arcot, Siteminder, Qualys, Jira, APM, Encryption, GSF, Fraud sensitivity, WAF, SCA
- AXA GOInfrastructure Cybersecurity Project ManagerMay 2019 - May 2021 (2 years)FranceCONTEXT:In the context of infrastructure modernization, multiple migrations are initiated. Mr. Arfaoui is involved in managing 12 projects related to the migration of critical business applications, such as: MARKIT, RHEA, NEREE, NOTUS, Clymène, IFRS17, Algo, Harp, Remetrica, RMS, ESG, eframe/Agrregator, etc. Furthermore, Mr. Arfaoui is responsible for data security and acts as an expert cybersecurity referent for auditors and pentesters.RESPONSIBILITIES:• Manage teams (12 teams of 10 people) responsible for securing platforms and applications (GDPR, MTSB, Queen Jewelry, vulnerabilities & obsolescence);• Prepare and participate in committees: Project steering, internal audits, information security, risk management, training, performance indicator monitoring, management reviews;• Develop risk analysis, impacts, and related strategies, considering various factors to reduce project risk level;• Identify and define the scope of projects for the implementation and decommissioning of infrastructure environments;• Identify and define the scope of projects and control projects for platform migrations and updates (Redhat, SQL, MS Office);• Ensure the renewal of certifications for obsolete environments (Run & Build).ENVIRONMENT: SUNRISE, SILVA, CONFLUENCE, JIRA, SCALA, VM, CITRIX, CLOUD, QUALYS.RESULTS: 3/3 upgrade projects successful, 100% compliance for IFC, QMF, GDPR & Queen Jewelry. 80% of pentests remediated and 20% in RAP (Remediation Acceptance Plan).
Recommendations
Be the first to recommend Mejdi
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- COBITAliston2024
- Lead Integrator ISO 27001,Bestcerfifs,2023Lead Intégrateur ISO 27001,
Certifications
- Lead Implementer ISO 27001Bestcertifs2023
- Lead Auditor ISO27001Bestcertifs2023