About Soufiane
English
Fluent
French
Native or bilingual
Arabic
Native or bilingual
Experience
- AXA PartnersSR. CONSULTANT – CYBER SECURITY PROGRAM ADVISORBANKING AND INSURANCEAugust 2025 - Today (1 year)• Led the revamp of the Vulnerability Management program, including the creation of new governance policies, operating procedures, and framework documentation to standardize practices across business units.• Defined and executed the enterprise vulnerability management strategy, aligning with AXA Partners' risk appetite, regulatory obligations, and international security frameworks (CIS, ISO 27001, NIST, DORA).• Established a risk-based prioritization model combining exploit intelligence, asset criticality, and MITRE ATT&CK mapping to drive more informed remediation decisions.• Provided strategic advisory to the CSO and GRC leadership on risk reduction roadmaps, remediation prioritization, and vulnerability lifecycle optimization.• Conducted an in-depth review of the penetration testing framework, optimizing scope management, vendor governance, and methodology alignment with OWASP and NIST SP 800-115.• Designed and implemented automated vulnerability validation workflows integrated with Tenable, Qualys, and SolvNow Service Management to enhance remediation traceability.• Integrated OSINT and threat intelligence into the cybersecurity program to strengthen external exposure management, detect credential leaks, and support proactive risk identification.• Developed and operationalized an OSINT collection framework for brand monitoring, asset discovery, and threat attribution.• Supported regulatory readiness (DORA, ISO 27001) by aligning vulnerability and threat management processes with compliance• Championed the automation of key security workflows using API integrations and Python scripting, reducing assessment cycles and increasing operational efficiency.• Partnered with cross-functional stakeholders to drive the harmonization of global cybersecurity policies following organizational restructuring and merger driven transformations.
- ConcentrixCYBER SECURITY MANAGERNovember 2023 - August 2025 (1 year and 9 months)• Cyber Security SME, leading a global Cyber Security Program.• Built our global Vulnerability Management program and scale it to the entire enterprise (Infrastructure, Endpoints, Cloud)• Providing overall cyber security guidance in hardening controls of critical infrastructure.• Managing an international team of cyber security analysts and engineers• Developed methodologies for prioritizing vulnerabilities based on risk assessment, assets criticality and business impact.• Overseeing the implementation of a robust security patch management program to address vulnerabilities efficiently.• Integrated threat intelligence into vulnerability management processes for proactive identification of emerging threats.• Implemented automation tools and scripts to streamline vulnerability scanning and reporting processes.• Ensured compliance with industry standards and frameworks, such as CIS, ISO 27001, and NIST, in
- WebhelpCYBER SECURITY ENGINEERFebruary 2022 - November 2023 (1 year and 9 months)• Designed the architecture and maintained the on prem vulnerability management solution (+200 servers deployed across the globe)• Performing Internal and External PCI-DSS vulnerability assessment• Leading the SecOps advisory team• Managed PKI servers, ensuring secure and efficient operations, including the generation and management of both internal and external certificates.• Implemented automation tools and scripts to streamline vulnerability scanning and reporting processes.• API integration, leveraging advanced methodologies to develop and enhance automation tools, resulting in streamlined workflows and increased operational efficiency.• Active Directory assessment and hardening, implementing security best practices to identify vulnerabilities, mitigate risks, and enhance the overall resilience of directory services.• Ensured compliance with industry standards and frameworks, such as CIS, ISO 27001, and NIST, in vulnerability management practices.• Effectively communicated with cross-functional teams, top executives, and stakeholders about cyber security posture, pain areas, initiatives and outcomes
Recommendations
Be the first to recommend Soufiane
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- 3W Academy – Full Stack Web Developer Microsoft Azure – AZ-900 Microsoft Azure – SC-900 Fortinet Network Security Expert ( 1-2-3) Tenable.ad Specialist Tenable.sc Expert Oracle Cloud Infrastructure Associate OSCP3W Academy – Full Stack Web Developer Microsoft Azure – AZ-900 Microsoft Azure – SC-900 Fortinet Network Security Expert ( 1-2-3) Tenable.ad Specialist Tenable.sc Expert Oracle Cloud Infrastructure Associate OSCP
- MASTER, CYBER SECURITY SPECIALIZATIONSUNIVERSITÉ INTERNATIONALE DE RABAT, RABAT (MOROCCO)MASTER, CYBER SECURITY SPECIALIZATIONS
Certifications
- Tenable.ad specialistTenable2023
- CISSPISC2