You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Thierry HarmandTH

Thierry Harmand

Information System Consulting and Cybersecurity

€950/day
Toulouse, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Thierry

Experience:
More than 15 years in the public health sector, first as head of application and system maintenance for an ERP dedicated to health information systems, then as Director of Information Systems for a hospital center. I have led application modeling and development projects, managed SI strategic alignment projects, system architecture, deployment of the electronic health record, development of SI security (BCP, DRP, ISMS), operational efficiency (ITSM) in line with risk management and continuous quality improvement approaches.

Specifics:
Cybersecurity skills acquired during my career, based on a pragmatic approach to aligning the IS with business strategy and revolving around IS management through value and risk control.
Director of Information Systems for over 12 years, I led IS and SSI governance through the drafting and implementation of two successive master plans, the computerization of the patient's medical record, and by participating in the steering of the convergence of regional health information systems. I then leveraged these skills as a cybersecurity consultant.

My conviction:
Adopt a transversal vision, position myself in support of business functions, with a collaborative team approach, in a dynamic of continuous improvement, pragmatic IT and SSI governance, by controlling risks and in line with the requirements and constraints of business processes.
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Toulouse (up to 50km), Bordeaux (up to 50km), Montpellier (up to 50km), Paris (up to 50km), Rouen (up to 50km)

Experience

  • EXPLEO GROUP
    Senior Cybersecurity Consultant
    November 2023 - October 2025 (1 year and 11 months)
    Senior cybersecurity consultant in Defense, Space, and Aeronautics sectors.
    • Conducted a risk analysis for satellite ground segment asset lifecycle management platforms, in accordance with ISO 27005:2022 using the EBIOS RM methodology, with analysis of the system's security architecture. Review of the compliance baseline and associated requirements. Review of regulatory frameworks.
    • Supported the security accreditation of military aircraft safety maintenance systems. Managed compliance with security requirements. Defined a secure system architecture. Defined safety maintenance procedures.
    • Internal R&D activity on advancements in post-quantum cryptography.
    Compliance Management Risk Management SSI Governance
  • GTD International
    Information Security Officer
    DIGITAL AND IT
    July 2022 - October 2023 (1 year and 3 months)
    Responsible for the information security governance of GTD International, risk and compliance management. Responsible for security management for GTD International clients and projects.

    Mission:
    • Advise and assist Management, and the Information Systems Department, in defining information systems security policies;
    • Draft and maintain the necessary documentation to conduct security accreditation procedures from start to finish. (Accreditation strategy, Risk assessment, PES, …);
    • Organize and lead governance meetings;
    • Support project managers in considering various security frameworks (RGS, IGI1300, II901, LPM…);
    • Control and ensure compliance with security requirements for the accredited site;
    • Conduct risk analysis and assessment;
    • Risk management (EBIOS, EBIOS RM, ISO27005).
    • Implement a continuous improvement plan for the ISMS;
    • Contribute as a Security expert to secure IS architecture committees;
    • Lead technical and organizational initiatives related to information security;
    • Participate in employee awareness and training;
    • Supervise internal, external, and certification audits;
    • Maintain active monitoring of regulatory requirements applicable to classified networks within the company's scope.

    Activities 2022 – 2023:
    • Renewal of the company's ISO 27001 certification;
    • Definition of a security architecture (system and network) for the company's sensitive information systems.
    • Definition, review, and validation of security requirements for Defense and Space sector clients' projects.

    Areas of activity: ✓ Defense; ✓ Space; ✓ Development.
  • SCALIAN
    Senior Cybersecurity Consultant
    January 2020 - June 2022 (2 years and 5 months)
    Riyadh Saudi Arabia
    Senior cybersecurity consultant on assignment for clients in the banking, space, and railway sectors on topics related to governance, risk management, compliance, and IS design and architecture.
    Riyadh Metro:
    • Risk analysis ISO 27005 / EBIOS 2010
    • Analysis of system and network security architecture
    Various projects and internal:
    • IS security governance
    • IS security accreditation
    • Risk management
    • Compliance management
    • Definition, analysis, and review of system and network architecture
    • Integration of cybersecurity into projects
    • Definition of sensitive IS security architecture.
    • Crisis management
    Areas of activity: ✓ IT Service Company ✓ Railway ✓ Banking ✓ Space ✓ Tertiary

Recommendations

Be the first to recommend Thierry

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Level III Title
    CESI Mont Saint Aignan
    2002
    Analyste Programmeur

Certifications

Skill set

Categories