About Yann
French
Native or bilingual
English
Native or bilingual
Experience
- Pagny AssociésCybersecurity Expert - IS AuditorCONSULTING AND AUDITSMay 2024 - June 2024Marne La Vallée, FranceAudit of information systems governance: identify potential risks, ensure controls are in place, and guarantee information systems hygiene and alignment with the organization's strategic objectives.Operational Audit – Intrusion and Penetration Testing: identify and exploit information systems security flaws before they are compromised by malicious actors (hackers).
- GIE GPISInformation Systems Security OfficerPUBLIC SAFETYApril 2022 - February 2024 (1 year and 10 months)Paris, FranceDevelop the information systems security strategy and policy (PSSI) with senior management;Implement all IT documentation, including a DSSI memo;Establish a regulatory framework for data protection in collaboration with the DPO;Manage teams and organize IT operations;Implement an Information Security Management System (ISMS)o IS Audit and implementation of control points in project mode according to ISO 27001 & CIS controls standards;o Implement an information systems risk management and assessment program (EBIOS & ISO 27005);o Cyber crisis management - drafting a BCP/DRP resulting from risk analysis;o Implementation of a proprietary SIEM solution and establishment of security indicators;o Raise awareness and advise users (strategic, technical, and end-users) on cyber risks incurred;o Conduct technological watch on security solutions.Define and approve solutions to be implemented and draft specific technical clauses (CCTP);Participate in calls for tender and candidate selection for structuring projects;Support the company in digital transformation and security:Lead an access control and video surveillance implementation project;Approve the budget for the 2023 Security and Information Systems Department (DSSI).
- Leaders LeagueChief Information Security OfficerPRESS AND MEDIAMay 2018 - March 2022 (3 years and 10 months)Paris, FranceDevelop the IT strategy and policy (including Security: PSSI) with senior management;Analyze the needs of business departments, define and manage IT department budgets;Manage teams and organize IT operations;Implement an Information Security Management System (ISMS)o IS Audit and implementation of control points in project mode according to ISO 27001 standard;o Manage, assess, and identify information systems risks (EBIOS & ISO 27005);o Implementation of a BCP/DRP resulting from risk analysis: Crisis Management;o Drafting of the BIA (Business Impact Analysis)o Implementation of a SIEM solution and establishment of security metrics;o Raise awareness and advise users (strategic, technical, and end-users) on cyber risks incurred;o Conduct technological watch on security solutionsDefine and approve solutions to be implemented and draft calls for tender resulting from risk analysis;Support the company in digital transformation and security:o Implementation of an ERP (Netsuite) with the Finance Department;o Implementation and security of Digital Workplace solutions to improve collaborative work for total mobility: Microsoft 365 / 3CX digital telephony / VPNo Complete overhaul and modernization of the entire system, network, and data protection infrastructure;o Design and architect the Azure cloud architecture to ensure data transformation and protection.
Recommendations
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Professional Bachelor's Degree in Information Systems and Data ManagementUniversity of Evry (Paris Saclay)2018Conception intégration et gestion des systèmes d'information Analyse de production des systèmes réseaux et application Protection des données
- Master's Degree in Digital Security Expert Training (ESD)Aston SQLI School (Paris Sud)2019Concevoir un plan stratégique de sécurité Structurer une solution technique et organisationnelle répondant aux besoins de sécurité Conduire un audit de sécurité des systèmes d’information Maintenir en condition opérationnelle de la sécurité de l’information Accompagner la mise en œuvre de la politique de sécurité d’un système cible