You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Yazan HawashYH

Yazan Hawash

GRC/CISO Cybersecurity Consultant

€800/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Yazan

🔐 GRC & Outsourced CISO Cybersecurity Consultant
I support companies in their cybersecurity governance, their risk management (GRC), and their regulatory compliance. My role as an outsourced CISO is to transform your cybersecurity risks into a clear, adapted action plan that complies with international standards.

🎯 My key expertise:

Cybersecurity & GRC: Risk analysis (EBIOS RM, ISO 27005), information security governance management.

ISO 27001: Implementation and management of an ISMS, preparation and support for ISO/IEC 27001 certification.

Regulatory Compliance: NIS2, GDPR, PCI DSS, compliance audits, and implementation of remediation plans.

Outsourced CISO: Definition of cybersecurity strategy, implementation of security policies (PSSI), incident management, operational monitoring.

Cybersecurity Awareness & Training: Dedicated sessions for employees, managers, and executives (PECB Certified Trainer, Microsoft SC-200, IBM Cybersecurity Analyst).

✅ What I offer you:

Comprehensive expertise in Governance, Risk, and Compliance (GRC).

Operational and strategic support as an outsourced CISO.

Solid preparation for your ISO 27001, ISO 27005, and regulatory (NIS2, GDPR) audits.

A trusted partner to strengthen your cybersecurity and reduce your IT risks.

🎓 My certifications (guarantee of quality):

CISM – ISACA

ISO/IEC 27001 Lead Implementer – PECB

ISO 27005 Lead Manager – PECB

Microsoft SC-200 Security Operations Analyst

IBM Cybersecurity Analyst Professional

PECB Certified Trainer
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km), Bordeaux (up to 50km), Lille (up to 50km), Lyon (up to 50km), Strasbourg (up to 50km)

Experience

  • CrĂ©dit Agricole
    NDR Project Consultant
    BANKING AND INSURANCE
    September 2025 - Today (11 months)
    Support for a strategic cybersecurity project focused on threat detection and response capabilities. Management of security topics, stakeholder coordination, security and information system (SSI) requirements monitoring, risk management, participation in project committees, and support for teams in implementing security actions.
  • BNP Paribas
    Security Equipment Manager
    September 2022 - Today (3 years and 11 months)
    ‱ Management of security projects (NDR, SBXs, IDS/IPS) and operational monitoring.
    ‱ Supervision of 8 cybersecurity solutions (IPS/IDS, NDR, Mail and Web Sandboxes, etc.).
    ‱ Critical challenge of technical architectures proposed by IT teams and security recommendations.
    ‱ Redesign of the IPS architecture on Fortinet.
    ‱ Operational monitoring of IT/GRC projects in conjunction with business and technical teams.
    ‱ Facilitation of strategic meetings and monitoring of team objectives.
    ‱ Development and implementation of cybersecurity and risk management strategies aligned with IT governance (GRC).
    ‱ Manage the monitoring of IDS/IPS inspection coverage at the interconnection points of intra-datacenter networks.
    ‱ Put security policies into production on managed solutions.
    ‱ Implement changes with impact assessment.
    ‱ Investigate security incidents reported by the PDIS SOC.
    ‱ Provide on-call support during non-business hours.
    ‱ Write activity reports.
    Technical Environment: Microsoft Defender O365, PaloAlto, Fortinet, Cisco, Vectra, McAfee Trellix, gatewatcher, Entrust
    Cybersecurity Audit GRC Project Management PSSI ISMS
  • BUT
    Deputy CISO GRC - Technical
    February 2021 - September 2022 (1 year and 7 months)
    ‱ Management of 7 security solutions:
    ‱ Implementation, supervision, and optimization of IT infrastructure protection tools, including DarkTrace, Cyberwatch, DLP, IAM, IPS/IDS, and Sandboxes.
    ‱ Risk and compliance management (GRC): Ensuring the application of security policies (PSSI, ISO 27002, GDPR, ISO 27001), monitoring security audits, ensuring system compliance, establishing SI security procedures in case of crisis, conducting penetration tests to exploit vulnerabilities, writing observation reports, and proposing relevant recommendations.
    ‱ Incident supervision and cyber attack response: Coordination of security incident management in collaboration with operational teams and the SOC.
    ‱ Development of cybersecurity strategies: Development of continuous improvement plans, managing access rights and authorizations (privileged accounts), defining an access request procedure, implementing key performance indicators (KPIs), and monitoring corrective actions.
    ‱ Awareness and training of teams: Implementation of awareness programs to improve cybersecurity culture within the company.
    ‱ Collaboration with management: Regular reporting to the CISO and coordination with IT and business teams to align cybersecurity with the company's strategic objectives.
    ‱ Supporting IT teams in remediating detected vulnerabilities.
    Technical Environment: Darktrace, Cyberwatch, Office 365, SentinelOne
    GRC PSSI Cybersecurity Audit ISO 27001 ISO 27005

Recommendations

Be the first to recommend Yazan

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Network and Security Engineering Degree (Master's degree)
    ESIEE
    2019
    DiplÎme d'Ingénieur Réseaux et Sécurité

Certifications

  • Certified ISO 27005 Lead Manager
    PECB
    2025
    https://www.credly.com/earner/earned/badge/e90e3d92-b3bb-4155-b32e-ecb964c88493
    Determination of risk criteria and acceptance thresholds Integration of risk management into corporate governance Writing risk reports and dashboards Implementation of an IS risk management aligned with ISO 27005 Identification, analysis, and assessment of cybersecurity risks Definition and implementation of a risk treatment plan GRC Use of recognized methods (EBIOS RM, ISO 27005) Monitoring and periodic review of risks Communication and awareness of stakeholders about risks
  • ISO/IEC 27001 Lead Implementer
    PECB
    2025
    https://www.credly.com/badges/259be31c-fe5a-46f8-b841-0246aa7fecbc
    Management of documented information Implementation of corrective actions Writing a business case for ISMS implementation Management of internal audits and preparation for external audit Management of an ISMS implementation project ISMS implementation GRC Consultant Monitoring of ISMS performance Definition of PSSI and associated security policies Continuous improvement of the ISMS (PDCA)

Skill set

Categories