About Yassine
French
Native or bilingual
English
Native or bilingual
Experience
- prevaiaCybersecurity ConsultantBANKING AND INSURANCEJuly 2024 - Today (1 year and 11 months)Paris, France• Functional specification of compliance modules (NIS2, DORA, ISO 27001) in conjunction with technical teams (DevOps, data scientists, and developers)• Definition of the third-party risk management (TPRM) methodology: scoring based on operational security criteria (vulnerability management, SOC, BCP), criticality, and questionnaires• Client support for DORA/NIS2 compliance: gap analysis, remediation tracking• Relay client feedback to the product team: prioritization of developments, tracking of fixes and improvements• Production of operational documentation: guides, procedures, and training materials
- Stellantis Finance & ServicesCybersecurity ConsultantBANKING AND INSURANCEApril 2023 - June 2024 (1 year and 2 months)Poissy, France• Management of the third-party risk (TPRM) security program, deployment across 12 countries• Benchmark, selection, and integration of the TPRM SaaS solution: testing, corrective feedback, and functional enhancements• Risk analysis, prioritization, and remediation plans for critical ICT providers• Multi-country coordination and change management: Cyber/CISO, Procurement, Legal, Compliance, and Business units• Writing security standards: runbooks, operational procedures, governance (RACI)• Facilitation of steering committees and reporting to CISOs/EXCOM
- Arval - BNP GroupTribe Security OfficerBANKING AND INSURANCEFebruary 2022 - April 2023 (1 year and 2 months)Rueil-Malmaison, France• Operational liaison for the CISO: interface between project teams and the security department.• Identification and monitoring of infrastructure and application vulnerabilities, coordination of pentests, and remediation validation• DevSecOps/SSDLC: code reviews, vulnerability scans, CI/CD pipelines• Security by Design in projects & applications: definition of requirements and monitoring of remediation plans• Risk analyses EBIOS & ISO27005: impact assessment, threat scenarios, and treatment plans
Recommendations
Be the first to recommend Yassine
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- networks and securityUniversity of Caen Normandy2012networks and security,
Certifications
- CISSPSANS INSTITUTE
- OSCEOFFENSIVE SECURITY2016