About Raffaele
Italian
Native or bilingual
French
Native or bilingual
English
Native or bilingual
Spanish
Native or bilingual
Experience
- DEXIAChief Information Security Officer IT security and business continuity consultantBANKING AND INSURANCEMarch 2022 - December 2025 (3 years and 9 months)París, FranceDexia (Euronext: DEXB) is a bank created from the alliance in 1996 between Crédit Communal de Belgique (1860) and Crédit Local de France (1987). Its registered office is in Brussels. The IT department and the Information Security department are centralized at the Paris La Défense headquarters. The latter is responsible for ICT security for the entire group.Responsibilities and projects carried out:• Leading the CISO function in a highly regulated banking environment.• Defining the cybersecurity strategy and the IS security governance model.• Leading ICT risk, BCP, and operational resilience programs.• Preparing a strategy for alignment with DORA and NIS2.• Managing critical vendors and multi-vendor environments.Governance, Risk, and Compliance (GRC)• Corporate and regulatory GRC frameworks• Research and Audit - DORA: ICT Risk, Third Party Risk, Resilience Testing• Research and Audit - NIS2: Governance, reporting, incident management• Regulatory audits and preparation for external supervisors• ISO 27001 / NIST / PCI-DSS integration
- AXACybersecurity Senior Consultant Software & Infrastructure Security ArchitectBANKING AND INSURANCESeptember 2021 - February 2022 (5 months)Madrid, SpainAXA Partners Spain is a Spanish subsidiary of AXA Partners Holding SA, France. The Global Security Center (GSC) is a cybersecurity department of the AXA group. Its mission is to provide a catalog of IT security services to AXA partners (subsidiaries) worldwide.Responsibilities and projects carried out• Consulting on software and infrastructure projects from a security perspective.• Review and validation of security architectures and "security by design".• Creation and launch of the Security Architecture Committee.• Application risk assessments (AISRA) and access reviews (IAM).• Support for internal certifications and security assurance processes.Governance, Risk, and Compliance (GRC)• Security governance applied to the project lifecycle (controls and evidence).• Application and architecture risk management (assessment, recommendations, monitoring).• Alignment with ISO 27001 / ISO 27002 and corporate frameworks.• Internal audits: preparation of evidence and remediation plans.• Third parties: review of requirements and measures in multi-vendor environments.
- GSKLead of Cybersecurity and MCO Stream Archiving & DecommissioningPHARMACEUTICALS INDUSTRYSeptember 2020 - April 2021 (7 months)Roma, ItalyResponsibilities and projects carried out• Leading the controlled decommissioning of "in-scope" applications.• Defining the plan for data withdrawal, archiving, and migration.• Coordination with IT, business, compliance, and site managers.• Control of security and continuity requirements during withdrawal.• Creation of artifacts: checklist, RACI, risk and issue tracking.Governance, Risk, and Compliance (GRC)• Decommissioning governance (criteria, approvals, traceability, and evidence).• Risk assessment and treatment (data, access, continuity, contractual).• Compliance with internal requirements (quality, security, validation, and policies).• Third parties/support: management of maintenance contracts and orderly closure.• Auditability: documentation and evidence for internal reviews.
Recommendations
Be the first to recommend Raffaele
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- ISO/IEC 27001:2022 - Information Security2025ISO/IEC 27001:2022 - Information Security
- RISK MANAGER™2025RISK MANAGER™