You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Romain FessardRF

Romain Fessard

Cybersecurity Expert ⏐ CISO - GRC - ebios RM ⌘

€445/day
1 project
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Romain

Romain in a nutshell:

🔐 Expert in Information System Security (ISS), Networks, and IT Audit

After 10 years in the Air Force, I developed a rigorous, methodical, and results-oriented approach to managing and securing information systems.
This experience taught me to analyze risks, anticipate threats, and protect critical infrastructures, while supporting teams in implementing reliable and compliant solutions.

🎓 Graduate of two complementary Master's degrees:
  • Master's in Java & Networks
  • Master's in Information System Manager
Today, I put my expertise at the service of companies to strengthen their security, resilience, and digital compliance.

My core expertise:
  • 🔐 Information System Security (ISS)
  • DORA (BPCE 2 years)
  • Risk analysis and management (EBIOS, ISO 27005)
  • Development and implementation of security policies
  • Regulatory compliance (ISO 27001, GDPR, organizational cybersecurity)
  • Sensitive data protection and incident management

🌐 Networks & Telecommunications:
  • Design, deployment, and security of network infrastructures
  • System administration, supervision, and hardening
  • Implementation of VPN, firewall, network segmentation, and monitoring solutions
  • Network performance diagnostics and optimization

📊 IT Audit & Project Management
  • Conducting technical and organizational audits
  • Vulnerability assessment and corrective action plan
  • Management of ISS projects and coordination of technical teams
  • Monitoring and improvement of IT processes

What sets me apart:

✅ 10 years of military experience, ensuring rigor, discretion, and operational efficiency
✅ A global vision combining security, network, and IT governance
✅ Transverse expertise: technical, regulatory, and strategic
✅ Ability to translate technical challenges into clear and concrete decisions
  • English

    Fluent

  • French

    Native or bilingual

Can work on-site
Paris (up to 50km), Lille (up to 50km), Rouen (up to 50km), Nanterre (up to 50km), Lyon (up to 50km)

Experience

  • Pass Culture - Pôle Tech
    Malt logoOn Malt
    Organizational and Technical Audit
    PUBLIC SECTOR
    March 2026 - March 2026
    Paris, France
    Phase 1 – Audit & Interviews (Fraud + Cybersecurity)
    Structured interviews with Fraud and Cybersecurity teams (optionally Cloud Infrastructure and Backend).
    Mapping of the IT ecosystem, tools, processes, and workflows during a fraud event.
    Phase 2 – Understanding current detection practices
    Collection and analysis of methods currently used by teams to detect fraud:
    – How signals are identified, by whom, and how often
    – What escalation and qualification processes are in place
    – What limitations and friction points are encountered daily.
    Phase 3 – Recommendations for Investigation & Graph Analytics
    Tool recommendations: data absorption, weak signal and anomaly detection, graph modeling (link analysis), isolation of relevant aggregates, generation of investigation reports.
    Phase 4 – Fraud Management over time
    Recommendation of a ticketing and fraud case tracking system:
    – Traceability, task assignment, reports, conclusions
    – Integration with existing tools or recommendation of a dedicated tool.
    Phase 5 – Organizational & Vendor Recommendations
    – Recommendations for processes and collaboration between Cybersecurity / Fraud (rituals, roles, organization)
    – Possible proposal for organizational change
    Organizational and technical audit – Improvement of fraud detection, investigation, and management.

    – Shortlist of specialized fraud prevention vendors to strengthen team bandwidth.
    Deliverable: recommendations report.
    Cybersecurity Audit Cybersecurity Awareness Cybersecurity Governance Cybersecurity Strategy Cybersecurity Project Management
  • RM3A
    GRC Consultant - EBIOS RM
    DIGITAL AND IT
    December 2022 - November 2025 (2 years and 11 months)
    Le Plessis-Robinson, France
    Cybersecurity Activity Management:

    • Client portfolio management
    • Supporting our clients in their cyber strategy in line with business development
    • Audit, consulting, and training on various topics (risk management, governance, technical, compliance)
    • Defining the security policy for the company's entities, defining ISS functional chains and business continuity plans,
    • Analyzing product and system security, writing security procedures and operating methods, performing malware reverse engineering,
    • Supporting the integration of security into projects: development and testing organization plan, developing proof of concepts, integrating security products,
    • Supporting system approval,
    • Conducting architecture, configuration, code, and organization audits.

    Interim CISO:

    • Definition of IT security plan/roadmap
    • Project implementation (Ebios RM risk analysis, maturity audit)
    • Awareness raising, training, skill transfer.
    • Writing policies (ISS Policy, Security Policy, incident, cyber crisis...)

    Standards and methods:

    • ISO/IEC 27001
    • ISO/IEC 27002 information security requirements
    • ISO/IEC 27005 Risk Manager
    • EBIOS Risk Manager
    EBIOS RM ISO 27001 approval Risk Management
  • NEOMA Business School
    Cybersecurity Engineer
    EDUCATION AND E-LEARNING
    February 2021 - November 2022 (1 year and 10 months)
    76130 Mont-Saint-Aignan, France
    Governance, action plan,
    Conducting and writing a security audit over 2 years
    Management of all cyber aspects in Rouen, Paris, Reims using various software (umbrella, Meraki, Varonis...)
    Creation of different GPOs to secure the park
    Project in progress: Installation and configuration of a SIEM

Recommendations

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master responsable en securite des systemes d information, Sécurité / sûreté de l''information des systèmes informatiques
    Université de Technologie de Troyes
    2020
    Master responsable en securite des systemes d information, Sécurité / sûreté de l''information des systèmes informatiques
  • BIA, Aéronautique
    Académie de Rouen
    2018
    BIA, Aéronautique

Certifications

Skill set

Categories