You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Numa ResplandyNR

Numa Resplandy

Cybersecurity Consultant | GRC, Resilience & IAM

€450/day
Lyon, FR
3-7 years

Average response time: 12 hours

Freelancer profile translated to English.
Back to original language

About Numa

Cybersecurity is no longer just the concern of large corporations.Regulatory requirements, cyber insurer audits, supply chain attacks, the rise of generative AI: all organizations are exposed, and not all have the internal resources to structure their response.

This is precisely where I come in.

For over 5 years, I have been supporting public and private organizations (healthcare, education, energy, industry) in France and North America in structuring their security in a pragmatic way.

My approach: cybersecurity that serves the business, driven by people, processes, and technologies, not the other way around.

🎯SHORT MISSIONS (a few days to a few weeks)

→ **Maturity Assessment**: Posture evaluation (NIST CSF, ISO 27001), gaps, and prioritized roadmap.
→ **Targeted Risk Analysis**: EBIOS RM or ISO 27005 on a critical application or scope.
→ **Flash IAM Audit**: Review of authorization model, orphan accounts, recertification, tiering.
→ **Express Scoping**: NIS2, ISMS, cyber governance (scope, milestones, and deliverables clarified).
→ **Crisis Exercise**: Tailored scenario, facilitation, debriefing.



**📌 IDEAL FORMAT**: audit to pass, project that's stalling, CISO needing a sparring partner, management wanting an independent assessment.


🛠️LONG MISSIONS (1 to 12+ months)

→ **Outsourced / Part-time CISO**: A cyber referent to support you, without the cost of recruitment.
→ **ISMS Construction**: From initialization to ISO 27001 certification audit.
→ **Compliance Program**: NIS2, GDPR, DORA, etc.
→ **IAM Redesign**: Policy, processes, recertification, tooling.
→ **Resilience**: BCMS ISO 22301, BIA, BCP/DRP, exercises.



**📌 Expertise**: GRC, Resilience, IAM, AI Governance (AI Act, ISO 42001), Awareness.
  • French

    Native or bilingual

  • English

    Native or bilingual

Can work on-site
Lyon (up to 20km), Paris (up to 10km), Marseille (up to 10km), Montpellier (up to 10km), Clermont-Ferrand (up to 10km)

Experience

  • Anciles
    Cybersecurity Consultant (GRC, IAM, Resilience)
    CONSULTING AND AUDITS
    September 2025 - Today (9 months)
    Lyon, France
    I help VSEs, SMEs, and mid-sized companies structure and manage their cybersecurity in a pragmatic and business-appropriate way.

    📌 What we can achieve together:

    ▸ Cyber maturity assessment (NIST CSF, ISO 27001) and definition of a target trajectory
    ▸ Structuring your cyber governance: committees, roles, responsibilities, management indicators
    ▸ Implementation of an ISMS and support towards ISO 27001 certification
    ▸ Scoping and deployment of your risk management program (ISO 27005)
    ▸ Risk assessment: identification, analysis, mapping, and treatment plan (EBIOS RM)
    ▸ Regulatory compliance: NIS2, GDPR, DORA, etc.
    ▸ Development of your business continuity and disaster recovery plans (BCP/DRP, ISO 22301)
    ▸ Design and facilitation of cyber crisis exercises
    ▸ IAM Governance: access policies, identity lifecycle, authorization reviews
    ▸ Raising awareness among your teams on cyber issues

    📩 Feel free to contact me to discuss your project!
    Cybersecurity Governance ISMS Identity and Access Management (IAM) Risk Management Business Continuity Plan
  • Université de Sherbrooke
    Development of Information Security Program and Cyber Governance
    EDUCATION AND E-LEARNING
    October 2023 - May 2026 (2 years and 7 months)
    Montréal, Canada
    I assisted the university (9 faculties, 30,000 students, 8,000 employees) in defining and deploying an information security program. Alongside the CISO, I contributed to structuring cyber governance, implementing a risk management framework, and conducting an assessment of the organization's maturity.

    Governance
    ▸ Definition of information security governance, including organizational structures (security committees, CISO, security liaisons), key governance processes, and responsibilities (RACI matrix for security roles).
    ▸ Design of a governance dashboard (performance KPIs, risk KRIs) for management oversight.

    Maturity Assessment
    ▸ Identification and analysis of applicable standards and regulations and their integration into the NIST CSF 2.0 reference framework.
    ▸ Consolidation of results and production of summary documents for the management committee (maturity mapping, gaps, recommendations).
    ▸ Development of an upgrade roadmap based on the analysis results and monitoring of measure implementation.

    Risk Management
    ▸ Definition of the university's internal and external context, stakeholders, and risk appetite criteria.
    ▸ Drafting of the risk management policy in accordance with ISO 27005 & ISO 27001 standards.

    Business Continuity
    ▸ Definition of the university's business continuity program: dedicated governance, roles and responsibilities of stakeholders (crisis committee, faculty liaisons), and integration into the overall security framework.
    NIST CSF Cybersecurity Governance ISO 27005 ISO 22301 Governance, Risk & Compliance (GRC)
  • RATP
    Risk analysis of a critical application
    TRANSPORTATION
    March 2025 - June 2025 (3 months)
    Paris, France
    I conducted a risk analysis using the EBIOS Risk Manager method on a critical business application used by many network users. The mission led to the identification of strategic and operational scenarios, risk mapping, and reduction of the system's attack surface.

    ▸ Collection and analysis of the technical context: network architecture, critical flows, application dependencies, business interfaces.
    ▸ Validation of risk criteria and consequence/likelihood scales for framing the risk assessment.
    ▸ Conducting a complete risk analysis according to the EBIOS RM method (workshops 1 to 5).
    ▸ Construction of a risk map and identification of priority scenarios impacting business services.
    ▸ Definition of a risk treatment plan with prioritization of measures following a cost/benefit logic.
    EBIOS RM Risk Analysis Risk Management ISO 27005 Strategic Recommendation

Recommendations

Be the first to recommend Numa

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Engineering Degree - Information Systems and Cybersecurity
    ECE Paris
    2020

Certifications

Skill set

Categories