About Thomas
French
Native or bilingual
English
Fluent
Experience
- Netatmo (Groupe Legrand)2025 | Fixed-price projects – Netatmo (Legrand Group)February 2025 - December 2025 (10 months)Senior Consultant – Cyber Risk & Cyber Resilience Act (CRA)Fixed-price consulting mission for Netatmo (Legrand Group) to support cyber risk analysis and compliance with the Cyber Resilience Act (CRA), in connection with ISO 27001 requirements and risk governance challenges.Deliverables & responsibilitiesConducting a risk analysis report aligned with CRA requirementsDeveloping a risk treatment plan with action prioritizationConducting a Cyber Resilience Act gap analysisPerforming an ISO 27001 ↔ Cyber Resilience Act mappingAssisting management in arbitrating risks to be included in the CRA risk map
- PyroallianceHead of Information SecurityFebruary 2025 - Today (1 year and 4 months)March 2025 – Present Independent (client PyroAlliance – Ariane Group subsidiary)Interim CISO / Interim Head of Information Security – NIS 901 scopeMission:Acting as Interim CISO / Head of Information Security to manage the NIS 901 accreditation process and regain control of the cybersecurity governance of a critical IT system, in an industrial and regulatory context with high stakes.NIS 901 Governance & Accreditation• Defining and managing the NIS 901 accreditation strategy, in line with regulatory requirements and business objectives• Comprehensive structuring of the IT system and site mapping, including flows and architectures, serving as a foundation for security decisions• Conducting risk analysis and formalizing risk scenarios• Implementing an ISMS dashboard and a decision-oriented management system• Building the ISMS documentation corpus (policies, procedures, standards)• Defining structuring ISMS strategies: IT system urbanization, BCP/DRP, integrating security into projects, cyber awareness• Deploying a security assurance plan and a cyber and security crisis management systemResource & Third-Party Management• Scoping and recruiting external service providers (defining needs, interviews, profile validation)• Structuring supplier management: security questionnaires, assessments, security assurance plansExecutive Governance• Active participation and presentation of arbitration and progress in Executive Committee and GRC/operational Committee meetings• Supporting management decision-making on the prioritization of ISMS risks and actionsScope & Organization• On-premise industrial environment – ~500 users• Managed team: 1 Head of Information Security, 1 Deputy Head of Information Security, 3 consultantsTechnical Environment (Summary)• On-premise infrastructure, VMware, Active Directory, Exchange• EDR: Trellix | Monitoring & indicators: Power BI
- Africa Global LogisticGRC ManagerLOGISTICS AND SUPPLY CHAINOctober 2023 - February 2025 (1 year and 4 months)Paris, FranceInterim CISO – Cyber Governance & Risk – Africa Global Logistics (AGL, MSC Group) International environment – critical & multi-site scopeInterim Cyber Governance Lead mission to structure and manage the cybersecurity governance of an international group, in a context of maturity improvement, preparation for ISO 27001:2022, and transformation of GRC practices.Governance & ComplianceStructuring and drafting the ISMS documentation corpus (policies, procedures, standards)Implementing and managing a GRC dashboard focused on compliance monitoring and decision supportPreparation and support for ISO 27001:2022 certificationFacilitating the GRC committee and management review (preparing materials, presenting arbitration decisions)Audit & AssuranceManaging the Statement of Applicability (SoA) control mappingSupporting internal and ISO 27001 certification auditsCoordinating evidence provision and monitoring the remediation planRisk Management & Security IntegrationConducting risk analyses using the EGERIE toolIntegrating security into infrastructure, cloud, and development projectsMethodological support to the operational security team on governance aspectsAwareness & Security CultureDesigning and deploying the cybersecurity awareness programIntegrating security from onboardingRaising awareness among development teams on best practices (OWASP Top 10) via Secure Code WarriorManagement & CoordinationDefining and monitoring security indicators (Power BI dashboards)Contributing to RUN activities with a governance approach (access management, change security)Scope & OrganizationInternational Group – ~23,000 usersFunctional coordination of a team composed of 1 Head of Information Security and ~10 consultantsTechnical Environment (Summary)SIEM: Splunk | Alert Management: TheHive
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Networks and Systems Bachelor's DegreeUniversity of Rouen2015
- Master's degree in Digital Security ExpertAston school2016
Certifications
- ISO 27001 Lead ImplementerPECB2017
- ISO 27005 Risk ManagerPECB2017