About Sofiene
French
Native or bilingual
English
Fluent
Experience
- METSYSSenior GRC ConsultantCONSULTING AND AUDITSSeptember 2025 - Today (9 months)Boulogne-Billancourt, FranceSenior GRC Consultant – ISO 27001:2022 Program (major construction group, multi-entities)• Construction / recovery and structuring of the ISMS: policies, procedures, standards, registers, matrices, dashboards.• Risk Management (ISO 27005 / EBIOS RM depending on context): workshops, risk register, treatment plans, prioritization.• Derivation of ISO 27002 into auditable requirements: IAM/access controls, hardening, logging, vulnerabilities/patching, backup & restore, change management, workstation/server/network security, secure development.• Operational management: RACI, committee, RAID monitoring, reporting, coordination of IT/CISO/Infra/SOC/application teams.• Audit preparation (internal/external): evidence consolidation, traceability, compliance, and continuous improvement.
- ExaltInformation Security Officer / Senior GRC ConsultantCONSULTING AND AUDITSJuly 2023 - May 2025 (1 year and 10 months)Paris, FranceInformation Security Officer, Governance & Cybersecurity @ Geodis SCO (2023 - 25)Cybersecurity Governance, Implementation of the group security strategy, Compliance with security directives, Vulnerability management and monitoring, Application security, Integration of security in projects, Vendor management.Senior Consultant, Compliance @ eXalt ShelidInternal DORA compliance referent, Creation of training content, Conducting training sessions for consultants on topics such as cybersecurity awareness, Risk Management, and DORA regulatory compliance.
- DELOITTEInformation Security ConsultantCONSULTING AND AUDITSFebruary 2019 - February 2023 (4 years)Tunis, TunisiaMain Missions:Senior Consultant @ DeloitteWriting typical deliverables for the Cyber-Strategy offering, Cybersecurity watch, Contribution to tender responses, Mentoring junior profiles, Organizing and leading sharing sessions within the community.Cyber Risk, Governance & Compliance @ Industrial Sector (2021 – 2022)ISMS implementation, ISO2700 Certification compliance, ITIL maturity assessment, IT Risk Management program implementation, SI governance diagnosis (ITSM-ITIL).Cyber Resilience & Security Assessment @ Banking and Insurance Sector (2021-2022)Cyber Resilience strategy development, Disaster Recovery Plan development, Documentation of NIST controls and assessment processes, IT Compliance and regulatory compliance, Operational security hardening.Business & Cyber Resilience @ Public Sector (2022)Business Continuity Plan development, Risk management and Business Impact Analysis, Business continuity strategy development and deployment.Head of IT Risk Management @ Telecom Sector (2019-2020)Update of operational risk mapping, Risk assessment, Development of an audit plan for risk treatment.Head of ISMS & Cyber Risk Management @ Banking & Insurance Sector (2019)Update of the risk management program, Improvement of subsidiary security in line with group security strategy.
Recommendations
Be the first to recommend Sofiene
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Engineering DegreeInternational Institute of Technology2019en Technologie d'information de Communication
- Fundamental LicenseNational School of Electronics and Telecommunications2016en Sciences Technologie d'Information et de Communication
Certifications
- Certified DORA Lead ManagerPECB2024
- ISO/IEC 27001 Lead ImplementerPECB2022