About Sebastian
- Part-time CISO: governance and management of your IT security adapted to your budget and objectives.
- ISO 27001: from maturity audit to certification: GAP analysis, ISMS implementation, audit preparation, Lead Implementer support.
- GRC — Governance, Risk & Compliance :structuring or redesigning your GRC framework. Cyber mapping, policies, KPI & reporting management, regulatory compliance (NIS2, EU AI act) and alignment of security strategy / business strategy.
- IT Security, Cyber & AI Maturity Audit: independent assessment of your compliance and risk level with a prioritized roadmap.
- Training & Awareness: CISSP certification preparation, fundamental cyber awareness, AI agent security and AI governance. A program tailored to your security objectives.
- Risk Analysis & Security Policies :design and management of risks adapted to your business context.
French
Native or bilingual
English
Fluent
Spanish
Native or bilingual
Experience
- FreelanceGRC & Cybersecurity ConsultantApril 2024 - Today (2 years and 2 months)During my GRC, IS Security & Cybersecurity missions, I support companies in their strategic and business requirements by:
- Supporting ISO 27001 certification: Implementation and maintenance of the ISMS and Annex A security measures (policies & procedures, threat management, asset management, access management, supplier management, application of least privilege principles, need to know, etc.)
- Part-time CISO support
- Risk analysis according to EBIOS RM
- Compliance gap analysis with ISO 27001, NIS 2
- Incident management: BCP / BIA / DRP / Test simulation
- IS Security & Cybersecurity support: Maturity audit, Security by design, Zero trust, IAM with Microsoft Entra, EDR/XDR, Data Loss Prevention (DLP), Threat modeling, SDLC.
- AI: Governance (ISO 42001), policies, usage, and security of AI agents.
- ICSCISOTELECOMMUNICATIONSDecember 2021 - December 2023 (2 years)Perpignan, FranceAs CISO, my missions were of 2 types:1-) Governance in security => ISMS implementation, risk analysis, writing of the IS Policy and policies required for ISO 27001 certification, awareness of ISMS and cybersecurity risks.2-) Operational => Study, management, and participation in projects: Network security, identity management, endpoint security (EDR, MDM).
- COOPERATIVECIOAGRICULTURESeptember 2019 - November 2021 (2 years and 2 months)Perpignan, FranceIT Department and CISO Management.Governance, risk, and compliance.Carried out a complete IT system overhaul project => Study, design, and management of the implementation of a new infrastructure (Network, Servers, Storage, Backup, Virtualization, ERP...) by applying ISO 27001 / 27002 security measures.Wrote IS Security policies.
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- ISO 27001 Lead ImplementerSkills4all2024
- CISSPCertyou2024Certified Information Systems Security Professional
Certifications
- ISO 27001 LEAD IMPLEMENTERBestcertifs2024
- CISSPISC²2024