You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Mohamed D.MD

Mohamed D.

ISO 27001 Certification Auditor | GRC Consultant

€780/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Mohamed

I support companies in structuring, auditing, and strengthening their cybersecurity, with a targeted expertise in ISO 27001, risk management, internal audit, DORA/NIS2, and cyber compliance.

Currently a Certification Engineer at a certification body, I bring a differentiating perspective: I know the expectations of a certification audit, the requirements of a compliant ISMS, and the evaluation criteria used to assess an organization's maturity.

I intervene in particular on:
• preparation for ISO 27001 certification;
• cybersecurity internal audits;
• cyber/ICT risk mapping;
• DORA and NIS2 compliance;
• drafting policies, procedures, audit reports, findings, and action plans;
• supplier reviews and security due diligence.

My approach is pragmatic, structured, and deliverable-oriented: to produce clear, auditable documents that can be directly used by IT teams, CISOs, compliance departments, or management.
  • French

    Native or bilingual

  • English

    Fluent

  • Spanish

    Conversational

Can work on-site
Paris (up to 50km), Lille (up to 15km), Lyon (up to 50km), Marseille (up to 50km)

Experience

  • Certi-Trust
    Certification Engineer
    DIGITAL AND IT
    January 2026 - Today (7 months)
    Paris, France
    Within a certification body, I am involved in activities combining ISO 27001 audits, certification offer development, and internal quality system improvement.

    My responsibilities include:

    • conducting ISO 27001 certification audits for organizations in various sectors;
    • preparing, conducting, and formalizing audits: audit plans, interviews, document reviews, findings, non-conformities, and reports;
    • analyzing and validating audit scoping to ensure consistency between the scope, staff, organizational complexity, and proposed audit time;
    • supporting sales teams in constructing and securing certification offers;
    • training and coaching sales representatives on using the audit scoping tool;
    • contributing to the development of the internal quality system: procedures, templates, audit practices, standards, and work methods;
    • participating in the harmonization and continuous improvement of ISO 27001 certification processes, focusing on compliance, operational efficiency, and mastery of applicable requirements.
    ISO 27001
  • MIF
    Cybersecurity Risk Management Manager
    BANKING AND INSURANCE
    September 2024 - Today (1 year and 11 months)
    Paris, France
    At La MIF, I held the position of ICT and Information Security Risk Management, within Internal Control, acting as a second line of defense.

    In the context of complying with the European DORA regulation, I contributed to structuring the governance framework, cyber/ICT risk management, business continuity, and information security control.

    My main responsibilities included:

    • drafting information security, ICT risk management, and business continuity policies;
    • formalizing procedures, templates, and security standards aligned with DORA requirements;
    • conducting gap analyses and compliance assessments against the DORA regulation;
    • defining, coordinating, and monitoring compliance action plans;
    • facilitating risk assessment workshops with business units;
    • carrying out a mapping of cybersecurity and ICT risks;
    • analyzing risks related to IT service providers, including in the context of pre-contractual assessments;
    • recommending and monitoring security measures adapted to identified risks;
    • reviewing the effective implementation of security controls;
    • defining and monitoring risk, security, and compliance indicators;
    • producing dashboards and reports for committees and management.

    This experience allowed me to strengthen a comprehensive approach to cybersecurity, combining governance, regulatory compliance, risk management, internal control, third-party security, and cyber maturity management in a regulated financial environment.
    IT Risk Management DORA Cybersecurity Risk Analysis ISO 27001
  • LNE
    Cybersecurity Audit Manager
    DIGITAL AND IT
    September 2023 - September 2024 (1 year)
    Paris, France
    I led certification and compliance audits on various security standards, managing the audit team and producing associated deliverables.

    My responsibilities included:

    • coordinating the audit team;
    • writing audit plans;
    • conducting on-site and remote audits;
    • leading opening and closing meetings;
    • conducting audit interviews with audited teams;
    • analyzing evidence and formalizing audit findings;
    • writing non-conformities and audit reports;
    • reviewing and approving reports produced by the audit team.

    I audited and managed a client portfolio for the following standards:

    • ISO 27001:2017 and ISO 27001:2022 — information security and management system: 13 clients;
    • VIGIK — product security: 5 clients;
    • Payment systems — product security: 16 clients;
    • CISPE — attestation of compliance with the Code of Conduct for Cloud Infrastructure Service Providers in Europe: 2 clients.
    Security Audit ISO 27001

Recommendations

Be the first to recommend Mohamed

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master of Project Management
    IPI Institut Polyinformatique
    2021
    Master's degree, Cybersecurity project management
  • Bachelor's degree, DEVSECOPS Integrator Designer
    EPSI - L'école d'ingénierie informatique
    2019
    Bachelor's degree, Concepteur integrateur DEVSECOPS

Certifications

  • ISO 27001 Lead Auditor
    Certi-Trust
    2024
  • ISO 27001 Lead Implementer
    PECB
    2021

Skill set

Categories