You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Yazan HawashYH

Yazan Hawash

GRC/CISO Cybersecurity Consultant

€800/day
Paris, FR
8-15 years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Yazan

🔐 GRC & Outsourced CISO Cybersecurity Consultant
I assist companies in their cybersecurity governance, risk management (GRC), and regulatory compliance. My role as an outsourced CISO is to transform your cybersecurity risks into a clear, adapted action plan compliant with international standards.

🎯 My key expertise:

Cybersecurity & GRC: Risk analysis (EBIOS RM, ISO 27005), information security governance management.

ISO 27001: Implementation and management of an ISMS, preparation and support for ISO/IEC 27001 certification.

Regulatory Compliance: NIS2, GDPR, PCI DSS, compliance audits, and remediation plan implementation.

Outsourced CISO: Cybersecurity strategy definition, security policy implementation (PSSI), incident management, operational monitoring.

Cybersecurity Awareness & Training: Dedicated sessions for employees, managers, and executives (PECB Certified Trainer, Microsoft SC-200, IBM Cybersecurity Analyst).

✅ What I bring you:

Comprehensive expertise in Governance, Risk, and Compliance (GRC).

Operational and strategic support as an outsourced CISO.

Solid preparation for your ISO 27001, ISO 27005, and regulatory (NIS2, GDPR) audits.

A trusted partner to strengthen your cybersecurity and reduce your IT risks.

🎓 My certifications (quality guarantee):

CISM – ISACA

ISO/IEC 27001 Lead Implementer – PECB

ISO 27005 Lead Manager – PECB

Microsoft SC-200 Security Operations Analyst

IBM Cybersecurity Analyst Professional

PECB Certified Trainer
  • French

    Native or bilingual

  • English

    Fluent

Can work on-site
Paris (up to 50km), Bordeaux (up to 50km), Lille (up to 50km), Lyon (up to 50km), Strasbourg (up to 50km)

Experience

  • BNP Paribas
    Head of Security Equipment
    September 2022 - Today (3 years and 9 months)
    • Management of security projects (NDR, SBXs, IDS/IPS) and operational monitoring.
    • Supervision of 8 cybersecurity solutions (IPS/IDS, NDR, mail and web Sandboxes, etc.).
    • Critical challenge of technical architectures proposed by IT teams and security recommendations.
    • Redesign of the IPS architecture on Fortinet.
    • Operational monitoring of IT/GRC projects in conjunction with business and technical teams.
    • Leading strategic meetings and monitoring team objectives.
    • Development and implementation of cybersecurity strategies and risk management in line with IT governance (GRC).
    • Manage the monitoring of IDS/IPS inspection coverage at the interconnection points of intra-Inter Datacenter networks.
    • Implement security policies on managed solutions.
    • Perform changes with impact assessment.
    • Investigate security incidents reported by the PDIS SOC.
    • Ensure on-call duty outside of business hours.
    • Write activity reports.
    Technical Environment: Microsoft Defender O365, PaloAlto, Fortinet, Cisco, Vectra, McAfee Trellix, gatewatcher, Entrust
    Audit cybersécurité GRC Gestion de projet PSSI ISMS
  • BUT
    Deputy CISO GRC - Technical
    February 2021 - September 2022 (1 year and 7 months)
    • Management of 7 security solutions:
    • Implementation, supervision, and optimization of IT infrastructure protection tools, including DarkTrace, Cyberwatch, DLP, IAM, IPS/IDS, and Sandboxes.
    • Risk Management and Compliance (GRC): Ensure application of security policies (PSSI, ISO 27002, GDPR, ISO 27001), monitor security audits, system compliance, implement SI security procedures in case of crisis, conduct penetration tests to exploit vulnerabilities, write observation reports, and propose relevant recommendations.
    • Incident Supervision and Cyberattack Response: Coordinate security incident management in collaboration with operational teams and SOC.
    • Development of Cybersecurity Strategies: Develop continuous improvement plans, manage authorizations and access (privileged accounts), define an access request procedure, implement Key Performance Indicators (KPIs), and monitor corrective actions.
    • Team Awareness and Training: Implement awareness programs to improve cybersecurity culture within the company.
    • Collaboration with Management: Regular reporting to the CISO and coordination with IT and business teams to align cybersecurity with the company's strategic objectives.
    • Support IT teams in remediating detected vulnerabilities.
    Technical Environment: Darktrace, Cyberwatch, Office 365, SentinelOne
    GRC PSSI Audit cybersécurité ISO 27001 ISO 27005
  • EDF
    SOC Analyst N3 Tech Lead
    September 2019 - February 2021 (1 year and 5 months)
    Advanced Security Incident Management: Supervision of critical cybersecurity incidents (phishing, account compromise, ransomware, APT threats), coordination of responses, and monitoring of corrective actions.
    - Optimization of Detection Systems: Management of detection scenario improvements (SIEM, IPS/IDS, NDR, Proxy, Antivirus, firewall) to reduce false positives and improve threat detection speed.
    - Advanced Threat Investigation: In-depth analysis of logs and Indicators of Compromise (IOCs), implementation of Yara rules and IPS signatures to block new threats.
    - Fine-tuning existing use cases to improve detection performance.
    - Vulnerability Management and Remediation: Definition of correction plans and monitoring of patch application in collaboration with IT teams.
    - Development and Automation of SOC GRC Processes: Implementation of quick reference guides, incident procedures (Confluence, Playbooks) to improve response speed and SOC efficiency.
    - Watch and Threat Intelligence (CTI): Qualification of Cyber Threat Intelligence (CTI) and implementation of new detection rules to anticipate emerging threats.
    - Training and Awareness: Coaching and skill development for SOC analysts, organization of internal workshops on cybersecurity best practices and forensic analysis.
    formation cybersécurité Audit cybersécurité SIEM PSSI GRC

Recommendations

Be the first to recommend Yazan

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Diplôme d'Ingénieur Réseaux et Sécurité (Master degree)
    ESIEE
    2019
    Diplôme d'Ingénieur Réseaux et Sécurité

Certifications

  • Certified ISO 27005 Lead Manager
    PECB
    2025
    https://www.credly.com/earner/earned/badge/e90e3d92-b3bb-4155-b32e-ecb964c88493
    Détermination des critères de risque et seuils d’acceptabilité Intégration de la gestion des risques dans la gouvernance de l’entreprise Rédaction de rapports et tableaux de bord de risques Mise en œuvre d’une gestion des risques SI alignée sur ISO 27005 Identification, analyse et évaluation des risques cybersécurité Définition et mise en œuvre d’un plan de traitement des risques GRC Utilisation de méthodes reconnues (EBIOS RM, ISO 27005) Suivi et revue périodique des risques Communication et sensibilisation des parties prenantes aux risques
  • ISO/IEC 27001 Lead Implementer
    PECB
    2025
    https://www.credly.com/badges/259be31c-fe5a-46f8-b841-0246aa7fecbc
    Gestion des informations documentées Mise en œuvre de mesures correctives Rédaction d’un dossier commercial de mise en œuvre du SMSI Gestion des audits internes et préparation à l’audit externe Gestion d’un projet de mise en œuvre d’un SMSI Mise en œuvre du SMSI Consultant GRC Suivi des performances du SMSI Définition de la PSSI et des politiques de sécurité associées Amélioration continue du SMSI (PDCA)

Skill set

Categories