You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Vincent DraghiVD

Vincent Draghi

GRC Cybersecurity | Agentic AI Risks, ISO 42001

€720/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Vincent

Cybersecurity as a strategic growth lever.

🔐 I transform risk management into a competitive advantage for your critical projects.
With 10 years of experience in cybersecurity, compliance auditing, and risk management, I support organizations in reducing their exposure to cyber risks, regulatory compliance, and protecting their critical assets and data.

🎯 Measurable results for my clients:
  • Reduced exposure to cyber risks in critical areas — Banking & Finance, Insurance, Local Authorities… — through a pragmatic approach to security risk management.
  • Protection of assets valued at several million euros, across over 200 complex projects and successful compliance audits.
  • Compliance in regulated sectors with high stakes.
⭐ Skills:
✓ vCISO / Governance, Risk & Compliance (GRC) — ISO 27001, ISO 42001, NIST CSF
✓ Technical experience to audit and assess complex projects (Artificial Intelligence - LLM, RAG, MCP, AI Agents / Cloud including Azure-AWS-GCP / Public and private Blockchain…)
✓ Risk analysis methodologies — EBIOS RM, ISO 27005
✓ Regulatory compliance — GDPR, NIS2, AI Act
✓ Third-party risk management & supplier assessment (TPRM)
✓ Security automation & reporting — Power BI, Power Automate, Power Apps

📩 Want to strengthen your security posture against current threats and ensure compliance to avoid financial penalties?
Contact me — response within 24 hours.
  • French

    Native or bilingual

  • English

    Fluent

  • Vietnamese

    Basic

Can work on-site
Paris (up to 50km)

Experience

  • AXA
    Cloud Azure, AWS, GCP, AI, Vendor Risk Project Consultant
    CONSULTING AND AUDITS
    September 2023 - Today (2 years and 11 months)
    Paris, France
    Managed a cybersecurity risk portfolio for an asset management company of €50M+ across various business departments.

    Assessed risks for diverse projects including: ML, MCP, AI Agents, blockchain using the ISO 27005/EBIOS RM methodology, helping the project team identify and reduce 95% of High/Critical vulnerabilities and risks before production deployment.
    Reviewed complex multi-cloud architectures.

    Evaluated/performed due diligence on maturity levels with third-party vendors. Analyzed questionnaires and evidence, which reduced exposure to supply chain attack risks.

    Improved the KRI visualization dashboard and security tools, helping my team and all evaluators automate their analyses and accelerate them by over 45%.
    Cloud Architect Risk Analysis Cloud computing Cybersecurity artificial intelligence
  • Bnpparibas
    IT Risk Officer
    CONSULTING AND AUDITS
    January 2022 - June 2023 (1 year and 5 months)
    Île-de-France, France
    - Managed risks and indicators with vendors, subcontractors, and clients (per NIST), performed due diligence, reviewed contracts and security addenda, audited evidence, and strengthened client relationships and security assurance plans.
    - Assessed cloud risks (Ebios RM), reviewed architecture diagrams.
    - Integrated security into projects (security measures per 27002).
    - Conducted Shadow IT campaigns (declaration, assessment, evaluation, treatment).
    - Managed vulnerabilities in the CI/CD toolchain (DevSecOps).
    - Strong interaction with CSIRT and SOC teams for investigations.
    Risk Analysis AWS Microsoft Azure TPRM
  • Mairie de Clamart
    Deputy CISO/SI Innovation and Security Project Manager
    PUBLIC SECTOR
    December 2020 - January 2022 (1 year and 1 month)
    Clamart, France
    IT Project Management:
    - Unified CRM/DMS/CEM applications and improved user journey.
    - Identity management (IAM, employee onboarding/offboarding).
    - ISO 9001 and ITIL (knowledge management, process sheets).
    - MFA, strong authentication.
    Compliance and Information Security:
    - Implemented an ISMS (ISO 27001) and drafted an ISPS.
    - Risk analysis, management, and security plan, supported by France Relance/ANSSI.
    - Awareness campaigns.
    - Security workshops: password policy redesign, directory and cloud hardening...
    - Monitoring and protection of sensitive data via a DLP platform, automated reporting to the DPO.
    CISO GDPR ISO 27001 IAM Cybersecurity

Recommendations

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Cloud Architecture and Security paths (Bronze level)
    BNP Paribas
    2022
    Cloud Architecture and Security paths (Bronze level)
  • IT Security Project Manager
    IPI Institut Poly Informatique
    2021
    Chef de projet sécurité informatique

Certifications

  • CISSP
    ISC2
    2023
    Audit IT-Security ISO 27001 CISSP Cybersecurity
  • AI-102 Azure AI Engineer Associate
    Microsoft
    2025
    Microsoft Azure artificial intelligence

Skill set

Categories