About Walid
Arabic
Native or bilingual
French
Native or bilingual
English
Fluent
Experience
- Société GénéraleSenior Cybersecurity ConsultantBANKING AND INSURANCENovember 2022 - Today (3 years and 7 months)
- Integrating security into IT projects in line with the bank's SecureByDesign framework.
- Identifying security needs, assessing application sensitivity, and analyzing associated risks.
- Monitoring application security throughout the lifecycle: vulnerability management, supporting evolutions, implementing recommendations.
- Contributing to the validation of technical and security architecture documents.
- Actively participating in steering committees (COPIL) and security committees (COSEC).
- Supporting regulatory compliance: GDPR, DORA, NYDFS, HARIBO, SECAIA, etc.
- Coordinating and monitoring internal and external audits (source code, technical and application infrastructure, site audits).
- Supporting procurement processes: drafting security requirements, participating in presentations, evaluating technical eligibility.
- Negotiating security clauses in contracts and validating supplier security assurance plans.
- Conducting SSI (Information System Security) risk analyses and monitoring action plans.
- Serving as the primary security contact for business teams.
- Managing security waivers and exceptions.
- Supervising and upskilling junior cybersecurity consultants
- ELECTRICITE DE FRANCE (EDF)Senior Application Security ConsultantOctober 2017 - December 2022 (5 years and 2 months)92000 Nanterre, France
- Integrating security into IT projects and validating technical choices within the Technical and Economic Architecture Committee.
- Reviewing technical architecture documents (DAT) to ensure compliance with the PSSI (Information System Security Policy) and defense-in-depth principles.
- Leading and conducting risk analyses on systems, applications, and infrastructures.
- Supporting project, infrastructure, and business teams on security requirements.
- Assisting the procurement process: defining security requirements, scoring, technical evaluation, and participating in presentations.
- Drafting SSI reference documents and security guides for technologies used (OS, middleware, application tools).
- Conducting and leading vulnerability audits and source code audits.
- Processing deviation and waiver forms (FED): risk analysis and recommendations for compensatory measures.
- Contributing to technology and regulatory watch, and drafting technical recommendations.
- Resys- ConsultantsInformation Security ConsultantJanuary 2010 - September 2017 (7 years and 8 months)Tunisia
- Conducting comprehensive SSI audits: organizational, technical, physical, penetration tests, with associated action plans.
- Providing methodological expertise in system, application, and architecture security.
- Supporting the design and security of IS: reviewing architectures, integrating security requirements into projects.
- Defining and implementing security frameworks: PGSSI, PSSI, policies, and procedures. Advising CISOs/RSIs for the dissemination of SSI policies and their application.
- Performing SSI risk analyses (ISO 27005 methodologies) and defining treatment plans.
- Contributing to the implementation and evolution of the ISMS and BCP.
- Monitoring technical audits (pentests, configuration audits), remediation, and tracking actions.
- Designing SSI dashboards and operational monitoring indicators.
- Implementing security awareness campaigns and internal communication materials.
- Active monitoring of cybersecurity threats and best practices (logical and physical).
Recommendations
Be the first to recommend Walid
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Master's Degree, Computer SecurityInstitut supérieur d'informatique2009Diplôme de Mastère, Sécurité Informatique
- National Engineering Degree, TelecommunicationsEcole Supérieur Privé d'Ingénierie et de technologies2006Diplôme National d'Ingénieur, télécommunications
Certifications
- Information Security Lead Auditor ISO 27001LSTI France
- Information Security Risk Manager ISO 27005LSTI France