About Mondher
French
Native or bilingual
English
Native or bilingual
Experience
- ITGP-GROUPE BNP PARIBASAssistant CISO - Cybersecurity GRC ExpertBANKING AND INSURANCEFebruary 2025 - January 2026 (11 months)Montreuil, France- Risk Management and Analysis related to IT production.- Perform risk analyses (EBIOS-RM methodology) on critical infrastructures and Cloud services.- Assess Cyber risks and ensure their monitoring.- Monitor partner risks.- Manage exception requests submitted for CISO approval (access rights, bypass of security controls/measures, etc.).- Governance & committee management: Prepare security committees with ITGP for a 10,000+ employee IT system.- Vulnerability scan management: Manage Qualys scans, analyze, prioritize, and track fixes.- Monitor ITGP group vulnerabilities/findings on BitSight.- Process security derogation requests within the ITG Group.- Pentests: Prepare specifications, coordinate service providers, review reports, and track remediation.- Risk Management: Assess threats and risks to critical activities (BIA) within the ISP framework, develop mitigation plans.- Security by Design: Participate in architecture reviews, define and validate security requirements according to ISO 27001.
- COMITEM – GROUPE ALAN ALLMAN ASSOCIATESCybersecurity Consultant Manager / GRC ExpertJune 2023 - March 2024 (9 months)Paris, FranceAs a Cybersecurity Manager, I assisted the Alan Allman group CISO in implementing their ISMS based on ISO 27001 and ISO 27002 standards:• Contribution to the development of the ISSP and security charter of the Alan Allman group.• Support for the Alan Allman group in complying with the ISO 27001 standard.• Develop the ISMS governance policy and the ISMS scope document for the Alan Allman group.• Audit of the overall hybrid architecture of the Alan Allman group and recommendations for its improvement by integrating an NDR solution.• Lead workshops and cybersecurity awareness training sessions for the subsidiaries of the Alan Allman group.• Development of Cybersecurity offerings.• Management of cybersecurity consultants within COMITEM.• Provide experience and expertise in project management for technical skill development.
- Online Network SecuritySenior Cybersecurity ConsultantDIGITAL AND ITJanuary 2007 - June 2023 (16 years and 5 months)Tunis, Tunisia• Internal and external penetration tests on various environments: websites, mobile applications (iOS and Android), Active Directory, Citrix, thick client applications.• Organization of phishing campaigns to assess the awareness level of the client's employees.• Physical penetration tests to assess physical security and difficulty of access to client premises.• Evaluation of SOC effectiveness through RedTeam/BlueTeam exercises.• Assessment of Microsoft infrastructure security (Active Directory, Exchange, etc.) against standards like CIS benchmarks and Microsoft guidelines.
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Principal Engineer in Electrical Engineering - Computer Science OptionNational Engineering School of Tunis1996Génie Electrique & Informatique
Certifications
- ISO 27001 Lead AuditorPECB2018
- ISO22301 Lead ImplementerPECB2019