You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Yann BoumahYB

Yann Boumah

Information Systems Security Manager

€778/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Yann

I am looking for assignments in the field of governance and information systems security. I am bilingual (French and English), dynamic, and proactive in the field of digital transformation and information systems security.

I have a talent for teaching because I enjoy simplifying my work and making it accessible to all types of profiles (including senior executives).

If you would like to know more, please visit my YouTube channel CYBER Pour Tous (where I simplify Cybersecurity technical concepts and make them accessible to everyone).
  • French

    Native or bilingual

  • English

    Native or bilingual

Can work on-site
Paris (up to 50km)

Experience

  • Pagny Associés
    Cybersecurity Expert - IS Auditor
    CONSULTING AND AUDITS
    May 2024 - June 2024
    Marne La Vallée, France
    Audit of information systems governance: identify potential risks, ensure controls are in place, and guarantee information systems hygiene and alignment with the organization's strategic objectives.

    Operational Audit – Intrusion and Penetration Testing: identify and exploit information systems security flaws before they are compromised by malicious actors (hackers).
  • GIE GPIS
    Information Systems Security Officer
    PUBLIC SAFETY
    April 2022 - February 2024 (1 year and 10 months)
    Paris, France
    Develop the information systems security strategy and policy (PSSI) with senior management;
    Implement all IT documentation, including a DSSI memo;
    Establish a regulatory framework for data protection in collaboration with the DPO;
    Manage teams and organize IT operations;
    Implement an Information Security Management System (ISMS)
    o IS Audit and implementation of control points in project mode according to ISO 27001 & CIS controls standards;
    o Implement an information systems risk management and assessment program (EBIOS & ISO 27005);
    o Cyber crisis management - drafting a BCP/DRP resulting from risk analysis;
    o Implementation of a proprietary SIEM solution and establishment of security indicators;
    o Raise awareness and advise users (strategic, technical, and end-users) on cyber risks incurred;
    o Conduct technological watch on security solutions.
    Define and approve solutions to be implemented and draft specific technical clauses (CCTP);
    Participate in calls for tender and candidate selection for structuring projects;
    Support the company in digital transformation and security:
    Lead an access control and video surveillance implementation project;
    Approve the budget for the 2023 Security and Information Systems Department (DSSI).
  • Leaders League
    Chief Information Security Officer
    PRESS AND MEDIA
    May 2018 - March 2022 (3 years and 10 months)
    Paris, France
    Develop the IT strategy and policy (including Security: PSSI) with senior management;
    Analyze the needs of business departments, define and manage IT department budgets;
    Manage teams and organize IT operations;
    Implement an Information Security Management System (ISMS)
    o IS Audit and implementation of control points in project mode according to ISO 27001 standard;
    o Manage, assess, and identify information systems risks (EBIOS & ISO 27005);
    o Implementation of a BCP/DRP resulting from risk analysis: Crisis Management;
    o Drafting of the BIA (Business Impact Analysis)
    o Implementation of a SIEM solution and establishment of security metrics;
    o Raise awareness and advise users (strategic, technical, and end-users) on cyber risks incurred;
    o Conduct technological watch on security solutions
    Define and approve solutions to be implemented and draft calls for tender resulting from risk analysis;
    Support the company in digital transformation and security:
    o Implementation of an ERP (Netsuite) with the Finance Department;
    o Implementation and security of Digital Workplace solutions to improve collaborative work for total mobility: Microsoft 365 / 3CX digital telephony / VPN
    o Complete overhaul and modernization of the entire system, network, and data protection infrastructure;
    o Design and architect the Azure cloud architecture to ensure data transformation and protection.

Recommendations

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Professional Bachelor's Degree in Information Systems and Data Management
    University of Evry (Paris Saclay)
    2018
    Conception intégration et gestion des systèmes d'information Analyse de production des systèmes réseaux et application Protection des données
  • Master's Degree in Digital Security Expert Training (ESD)
    Aston SQLI School (Paris Sud)
    2019
    Concevoir un plan stratégique de sécurité Structurer une solution technique et organisationnelle répondant aux besoins de sécurité Conduire un audit de sécurité des systèmes d’information Maintenir en condition opérationnelle de la sécurité de l’information Accompagner la mise en œuvre de la politique de sécurité d’un système cible

Skill set (8)

Categories