You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Thierno NTN

Thierno N

GRC Cybersecurity Consultant

€550/day
Paris, FR
3-7 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Thierno

GRC Cybersecurity Consultant specializing in governance, risk management, regulatory compliance, and operational security.
Certified ISO/IEC 27001 Lead Auditor, ISO 27005, and EBIOS RM, with experience in ISO/IEC 27001, GDPR, DORA, and NIS2 compliance, ISMS implementation, risk analysis, security audits, and security integration in projects.
Versatile, structured, and quickly operational profile in GRC topics.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km)

Experience

  • MSC LOGISTICS
    GRC CYBERSECURITY CONSULTANT
    LOGISTICS AND SUPPLY CHAIN
    January 2025 - April 2026 (1 year and 3 months)
    CONTEXT: SUPPORT FOR THE IMPLEMENTATION OF AN ISMS AND ISO 27001 CERTIFICATION

    Develop the project approach and methodology. Reformulate needs, frame the project, and define the scope. Define the committee structure, identify stakeholders and the project team. Build the schedule and action plan. Create the RACI matrix and project risks. Identify mandatory/non-mandatory certification documents. Produce the security risk assessment policy. Monitor compliance with policies, standards, directives, and procedures. Produce the risk analysis and the SoA (Statement of Applicability). Produce the asset inventory, KPIs, and control plans. Prepare internal audit, correct non-conformities, and prepare for certification. Review Security Assurance Plans (SAP). Procedure for integrating security into developments and proposing the implementation of a secure CI/CD pipeline with Pre-commit: [truffleHog, gitleaks, git hooks], for SAST: [gitlab SAST Semgrep or sonarqube], for SCA: Snyk or OWASP Dependency-check or gitlab dependency Scanning for DAST: Gitlab DAST, OWASP Zap for Docker: Trivy, GitLab Container Scanning For IaC [checkov, tfsec] for monitoring [Falco, Prometheus & Grafana]….

    Deliverables: Project kick-off, Gap analysis, project scope, RACI (directors, CISO, IT, business units), Security policy, Asset inventory, EGERIE Risk Analysis, Risk Treatment Plan, Incident Management Procedure, Security Assurance Plan (SAP), SoA (Statement of Applicability), ISMS Manual, Security Governance in Projects (SiP)…
    Technical Environment: Microsoft Azure Cloud, SAST, SCA/DAST, Sonarcloud, Zero Trust, Power Apps, Power Automate, SharePoint, Jira, Confluence, Azure DevOps, Egerie…
  • DALKIA
    SECURITY CONSULTANT SIP
    ENERGY AND UTILITIES
    December 2023 - December 2024 (1 year)
    Dalkia, Bourgoin-Jallieu, France
    CONTEXT: INTEGRATE SECURITY IN PROJECTS (SiP) IN AN ON-PREMISE AND MULTI-CLOUD ENVIRONMENT (Azure - Google Cloud Platform (GCP) – AWS).

    Support operational teams in integrating security into projects by involving the security team as early as possible. Conduct risk analyses before the start of each project (Security by Design). Ensure the processing of personal data by completing the questionnaire (PDP). Personal Data Protection during the project study phase or the launch of a new application. Support Data Privacy teams in addressing information security requirements and ANSSI recommendations in collaboration with legal, purchasing, and management control teams. Study contract clauses with a focus on security measures implemented for the protection of data and information systems infrastructure, subcontractors, suppliers, and outsourcing providers. Monitor the action plan for recommendations addressing risks identified during project studies. Work with network infrastructure and data center teams (AWS and Windows AD). Participate in various committees (data protection committees, infrastructure security, or monitoring of vulnerability remediation indicators). Assist the security incident response team: Manage and track corrections following SOC alerts. Provide expertise in case of crisis or major incident. Cloud and SaaS security. Ensure the security of Infrastructure as Code (IaC) with tools like checkov, tfsec, terrascan. Monitor alerts generated by the Splunk SIEM.

    Deliverables: Asset inventory, Risk analysis sheet, Risk treatment action plan, Identity and access management procedure, define security policies, rules, directives, and charters for the entire information system, disseminate these rules (awareness).
  • CLIENT : SOCIETE GENERALE (SG)
    AUDIT COORDINATOR WITH STATUTORY AUDITORS
    April 2022 - December 2023 (1 year and 8 months)
    Scope of the NIS program and agile project work methodology. Translation of directive obligations into operational requirements and concrete measures. Identification of actors and contact points. Mapping of critical assets and business processes and essential services. Organization of weekly workshops and follow-up committees. Definition of a schedule and action plan. Risk analysis (Mapping of critical assets and business processes). Definition of major risk scenarios. Implementation of an incident management process. Classification of significant incidents (Early warning ≤ 24h, Notification ≤ 72h, Final report ≤ 1 month). SOC / CERT / CSIRT coordination. Supplier risk assessment via an assessment. Monitoring of critical service providers. Implementation of compliance indicators. Reporting to management and stakeholders during committee meetings.

    Deliverables: RACI (directors, CISO, IT, business units), Security policy, Asset inventory, Cyber risk register, Mapping of essential services, Risk treatment plan, Incident management procedure, Security assurance plan.

    Technical Environment: IT & OT infrastructure security, Network security (segmentation, firewall, IDS/IPS), Endpoint security, IAM / MFA, Vulnerability & patch management, Backups & restoration, CyberArk, AS400, Qualys, Production environments (Win OS/AD, UNIX, Z/Os Mainframe, Illumio, PDIS, COBRA, Garfild, YOGA, OS obsolescence, Vulnerability, isolation.

Recommendations

Be the first to recommend Thierno

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • EBIOS RM (Risk Manager) ISO
    PECB
    2020
    EBIOS RM (Risk Manager) ISO
  • Risk Manager Tools
    EGERIE
    2018
    Risk Manager Tools

Categories