About Noam
- Cyber strategy and roadmap
- IS Security Governance, PSSI, policies, and procedures
- Cyber project management: scoping, budget, vendors
- CISO dashboards and KPIs
- Employee awareness
- Supervision of cyber projects
- Executive Committee presentations
- Risk mapping, EBIOS RM, ISO 27005
- Treatment and remediation plans
- GDPR, NIS2, DORA compliance
- Third-party risk management (TPRM)
- Securing IT/OT environments (IEC 62443)
- Risk analysis on industrial systems
- IT/OT segmentation and convergence
- Support for OIV (Operators of Critical Importance) and critical sectors
- Maturity assessment
- Implementation of an ISMS (scope, gaps)
- Documentation and preparation for certification audits
- BUILD & RUN, continuous improvement
- IT audits (compliance and organizational)
- Prioritization of corrective actions
- Post-audit team support
- Crisis exercises and incident response
- IT, business, and management coordination
- Business continuity and disaster recovery plans (BCP/DRP)
- AFNOR IEC 62443 Trainer
- Cyber warfare and geopolitical issues
- CISSP Training
French
Native or bilingual
English
Fluent
Experience
- ChapsVisionCybersecurity Consultant / External CISOCONSULTING AND AUDITSOctober 2023 - June 2026 (2 years and 8 months)Paris, France
Context
Supporting critical organizations, industrials, and large accounts in structuring their cybersecurity in the face of evolving threats, regulatory requirements (NIS2), IT/OT convergence, and digital sovereignty.Sensitive clients: OIV, industrials, energy, and major technology groups.Missions
External CISO & Cybersecurity Governance- Cybersecurity governance for organizations without a full-time internal CISO.
- Strategic direction and support for IT/OT teams
- Security roadmaps aligned with business objectives.
Risk Analysis & Compliance- Risk analyses
- Risk treatment plans.
- Support for NIS2 compliance.
Industrial Cybersecurity (OT)- Cybersecurity specifications for critical industrial environments.
- Security measures adapted to OT/IT constraints.
- Analysis of industrial architectures and security recommendations.
- Implementation of best practices with the teams.
AI Governance & Cybersecurity- Support for AI usage governance.
- Review of AI cybersecurity best practices for vendor solutions and tools (Chaps).
- Risks related to new uses (confidentiality, sensitive data, supplier dependency, sovereignty).
Cyber Crisis Management (+15 exercises)- Scenario and timeline design
- Scenario facilitation
- Lessons learned
Resilience- BCP/DRP design
Methods & Frameworks
- EBIOS RM, ISO 22301 / ISO 27005, NIS2, NIST AI RMF
- IS Security Governance, IT/OT Risk Analysis
- OT Security, AI Governance, Digital Sovereignty
Results
- Structuring of cybersecurity approaches in critical environments.
- Improved visibility of cyber risks for management.
- Action plans reducing threat exposure.
- Preparation for new regulatory requirements.
- Enhanced resilience level
- Nexa digital groupCybersecurity Speaker & ConsultantEDUCATION AND E-LEARNINGSeptember 2023 - Today (2 years and 11 months)Paris, France
Context
Supporting students, professionals, and organizations on current cybersecurity issues, with an approach combining technical expertise, strategy, and understanding of business impacts.Missions
Cybersecurity Training & Awareness- Design and delivery of cybersecurity training.
- Transfer of IT security fundamentals to technical and non-technical audiences.
- Awareness of new cyber threats.
Cybersecurity Consulting- Intervention on security governance issues.
- Presentation of best practices for structuring a cyber strategy.
- Support for organizational issues related to cybersecurity.
Conferences & Specialized Content- Industrial cybersecurity.
- Economic and strategic impact of cyberattacks.
- Cyber geopolitics.
- Cyber warfare and new digital power dynamics.
Topics Covered
- Cybersecurity strategy
- IS Security Governance
- Cyber risks
- Industrial cybersecurity
- Employee awareness
Results
- Training of technical profiles and decision-makers on cyber issues.
- Acculturation of organizations to digital risks.
- Development of a better understanding of the business impacts of cybersecurity.
- Risk&CoGRC Cybersecurity and Industrial Security ConsultantCONSULTING AND AUDITSSeptember 2022 - October 2023 (1 year and 1 month)Levallois-Perret, France
Context
Consulting mission with industrial players wishing to strengthen their security level, structure their IS Security Governance, and improve their cyber risk management.Missions
Cybersecurity Risk Management- Conducting risk analyses according to EBIOS RM and ISO 27005 methodologies.
- Identification of threats, vulnerabilities, and business impacts.
- Construction of risk maps.
- Definition of treatment plans and security recommendations.
IS Security Governance- Drafting and evolution of PSSI
- Creation of security frameworks and procedures
- Support for structuring cybersecurity initiatives
Network and Architecture Security- Network architecture analysis
- Identification of weaknesses
- Security recommendations adapted to industrial constraints
Methods and Frameworks
- EBIOS RM
- ISO 27001
- ISO 27005
- ISO 22301
- Risk Analysis
- IS Security Governance
- Industrial Security
Results
- Strengthening the cyber maturity of supported organizations
- Formalization of security governance processes
- Improved management of industrial cyber risks
Reviews
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Risks, International Security, and CybersecurityEcole de Guerre Economique2020Cybersécurité - Mise en conformité - Sécurité réseau - Chefferie de projet cyber - Intelligence économique - gestion des risques - Veille
Certifications
- ISO27001 Lead ImplementorPECB