You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Sylvain ZyssmanSZ

Sylvain Zyssman

ISO 27001 | IT Audit & Governance | CTO

€700/day
3 projects
Les Sables-d'Olonne, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Sylvain

I step in when technical or organizational debt puts an IT project at risk.

👉 Level 3s saturated by operations
👉 AI POCs that never go into production
👉 ISO 27001 or DORA preparation without a clear vision
👉 Delivery slowed down by unclear governance

These are the contexts in which I intervene.

Head of Engineering / Transitional CTO, focused on IT governance, risk management, and structuring decisions.

Certified ISO 27001 Lead Auditor. I use ISO and DORA as decision frameworks, not checklists.

Remote first, but on-site possible for short missions, launches, or critical situations, in France or Europe.

If your situation matches one of these cases, send me a few lines of context.
  • French

    Native or bilingual

  • English

    Fluent

  • Spanish

    Conversational

  • Japanese

    Basic

Can work on-site
Les Sables-d'Olonne (up to 50km), Paris (up to 50km), Nantes (up to 50km), Bordeaux (up to 50km), Caen (up to 50km)

Experience

  • DataSZ - Audit, Architecture & Conseil Technique
    Head of Engineering / IT Audit & Transformation
    DIGITAL AND IT
    February 2012 - Today (14 years and 4 months)
    (Multiple clients – AI, healthcare, legal, B2C)

    Intervention Contexts

    • IT organization at risk (security, delivery, governance)
    • Regulated environments (healthcare, legal, SaaS)
    • Large-scale AI / data projects
    • Companies in difficulty requiring technical restructuring

    Key Missions

    IT Audit & Governance
    • Technical and organizational audits (healthcare, legal, critical projects)
    • Support for projects with regulatory requirements including NIS2 (continuity, supply chain security, incident governance)
    • Risk analysis (security, isolation, access, continuity)
    • Definition of structured remediation paths
    • Clarification of responsibilities and governance
    ISO 27001 ISMS Implementation
    • Scoping of the certification perimeter (SaaS, K8s infrastructure, CI/CD pipeline)
    • Gap analysis ISO/IEC 27001:2022 on 93 controls, identification and prioritization of non-conformities
    • Development of the SoA, PSSI, and incident management policy
    • ISMS implementation in a dedicated GRC tool
    • Multi-regulatory context ISO 27001 / NIS2 / GDPR
    • Monitoring of DORA metrics on K8s/Grafana pipeline
    Large-Scale Architecture & AI
    • Design of a multi-entity datalake (80 centers, millions of documents)
    • LLM search engine with strict isolation per entity
    • Cloud, security, and data governance arbitration
    • Abstraction of LLM providers to limit strategic dependency
    Rescue & Structuring
    • Takeover of 3 high-risk projects
    • Restructuring of teams and processes
    • Securing delivery and customer relaunch

    Results

    • secure and isolated architectures
    • reduction of regulatory risks
    • stabilized delivery
    • controlled and viable AI adoption
    Management Consulting ISO 27001 Audit IT Risk Management DORA Compliance Governance, Risk & Compliance (GRC)
  • MYPL
    IT Audit & Security - Regulated Medical Environment (Oncology)
    MEDICAL
    August 2023 - February 2024 (6 months)
    Les Sables d'Olonne, France

    Context


    System used in an international hospital environment, handling sensitive health data for clinical trials.

    High risk for:
    • patient data confidentiality
    • application robustness
    • access isolation
    • operational continuity

    Identified risks:

    • database and sensitive data management vulnerabilities
    • lack of strict isolation
    • incomplete application security
    • insufficiently formalized project governance

    My intervention

    • comprehensive technical audit (code, architecture, application security)
    • structured IT risk analysis (EBIOS-compatible approach: risk sources, scenarios, security measures)
    • architecture restructuring for robustness & maintainability
    • redefinition of project processes to secure delivery
    • coordination with hospital teams & international partners
    Results

    • secure and stable architecture
    • reduction of regulatory and operational risk
    • improvement of system maintainability
    • secure delivery in a high confidentiality context
    Risk Analysis IT Governance IT Audit Data Governance Data Security
  • Olympe.legal
    Audit & Cloud Governance - Sensitive Legal Data
    LEGAL
    April 2023 - July 2023 (3 months)
    Les Sables d'Olonne, France

    Context


    Platform handling sensitive legal data, exposed to risks of vendor lock-in and extraterritoriality (Cloud Act).

    Critical Issues:

    • data confidentiality
    • control over cloud dependencies
    • access governance
    • delivery continuity and robustness
    Identified risks:

    • potential exposure to extraterritorial legislation
    • strong dependency on existing infrastructure
    • insufficiently formalized access governance
    • poorly structured delivery pipeline

    My intervention

    • end-to-end audit of the IS, cloud architecture & dependencies
    • analysis of regulatory exposure (Cloud Act, DORA, ISO 27001)
    • structured IT risk analysis (EBIOS-compatible approach: risk sources, scenarios, security measures)
    • design of a secure sovereign architecture
    • dedicated VMs
    • network segmentation
    • strict environment isolation
    • implementation of formalized access governance
    • CI/CD structuring without disruption for the teams
    • redefinition of technical & organizational processes
    Results

    • reduction of regulatory risk, legal exposure, and better control of technological dependencies
    • isolated & controlled architecture
    • clarified access governance
    • secure DevOps and ML industrialization trajectory
    IT Audit IT Governance Risk Analysis and Management Data Governance DORA Compliance

Reviews

5.0

Out of 2 ratings

MehdiM

Mehdi

CODE IS LAW

Reviewed on 9/7/2023

Efficient, competent, and responsive. We will work with Sylvain again as soon as possible.
A

Aurélien

Pulsem

Reviewed on 5/11/2023

I hired Sylvain for a Python script development mission. It went very well. Sylvain demonstrated professionalism and expertise perfectly suited to the project. His deep knowledge of technologies related to machine learning, data science, and LLMs proved invaluable in creating the script I needed. He also asked the right questions, clarified requirements, and proposed creative solutions to perfectly meet my needs quickly and efficiently, while always being available and accessible when needed. Working with Sylvain was a very positive experience. His technical expertise, adaptability, and commitment to the mission's success were remarkable. I highly recommend Sylvain to any individual or company looking for his skills for any data science, data engineering, or MLOps development project. I would gladly work with him again for my own projects.

Recommendations

Camille SayousCS
FU
FU
Camille Sayous and 2 other people have recommended Sylvain

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Master of Science - MS
    OpenClassrooms
    1 year training on openclassrooms.com, leading to a Data Scientist diploma (Bac+5 / Master of science) All notebooks and detailed reports (French) can be found at https://github.com/sylzys/Master-of-Science---Data-Scientist All assessors are professionals in DS / ML/ DL field Started March '21. Current project: 9 out of 11 (current project progress: 20%) Main topics: marketing clustering, sentiment analysis, risk analysis, image segmentation, recommendation engines, chatbots..
  • Software Engineer (Bachelor Degree) / Software Engineering Manager (RNCP Level II Title)
    CESI
    2013
    work/study training program

Certifications

  • Lead Auditor ISO 27001
    Skills4All
    Risk Analysis IT Governance ISO27001 IT Audit ISO 27001 Cybersecurity Governance ISO 27001 Lead Auditor GRC DORA Compliance

Skill set

Categories