À propos de Marwane
Français
Bilingue ou natif
Anglais
Capacité professionnelle complète
Arabe
Bilingue ou natif
Expériences
- SodexoCSIRT expertRESTAURATIONoctobre 2023 - Aujourd'hui (2 ans et 8 mois)Paris, FranceProactively monitor enterprise systems and networks using industry-leading SIEM and EDR technologies (QRadar, Azure Sentinel / Defender, CrowdStrike) to detect early indicators of compromise, advanced persistent threats, and anomalous behavior. Conduct in-depth digital forensic investigations across Windows and UNIX environments to uncover root causes, trace attacker movements, and collect admissible evidence for potential legal escalation. Orchestrate rapid incident containment and mitigation, leveraging real-time intelligence and automation to neutralize threats and minimize business impact. Collaborate seamlessly with cross-functional teams—including internal CSIRT, global IT security teams, external partners, service providers, and law enforcement when necessary—to coordinate end-to-end incident response. Continuously track emerging threats, vulnerabilities, and adversary tactics (TTPs) to enhance threat models and inform detection strategy. Engineer advanced detection capabilities, developing tailored signatures, YARA rules, and correlation logic for intrusion prevention systems (IPS), malware detection platforms, and SIEMs—optimizing visibility across hybrid infrastructures.
- Orange CyberdéfenseSOC Information Security Managerjuin 2022 - octobre 2023 (1 an et 4 mois)Paris, FranceLeadership across multidisciplinary teams including SOC/CyberSOC analysts, service delivery managers, threat engineers, pre-sales architects, and the Use Case Factory. Strategic oversight of detection scopes, continuously assessing and expanding threat coverage across hybrid environments (on-prem, Azure, AWS). Facilitation of client and stakeholder meetings, driving alignment through operational steering (COSUI), technical committees (COTECH), executive reviews (COPIL), and strategic governance boards (PERCO, COMAC, COSTRAT). Design and presentation of KPIs and success metrics, enabling data-driven decision-making and operational visibility. Lifecycle management of detection rules and log sources, ensuring optimal signal-to-noise ratio and actionable alerts. Vulnerability management and remediation orchestration, aligning with risk posture and compliance requirements. Operational continuity (MCO) and service continuity (MCS) for all detection related platforms, ensuring resilience and high availability. Coordination and prioritization of SOC activities, ensuring team performance, incident readiness, and continuous improvement. Direct client request handling and escalation management, fostering trust and transparency throughout the engagement. Project ownership for detection perimeter extensions, including integrations with Microsoft Sentinel, Azure, AWS, and other cloud-native technologies. Use case development, scenario implementation, and rule fine-tuning, tailored to client-specific threat models and regulatory requirements. MITRE ATT&CK framework coverage assurance, translating adversary behavior into actionable detections. Proactive threat hunting operations, leveraging contextual intelligence to uncover stealthy and sophisticated attack patterns. Change management oversight in accordance with ITIL/ITSM best practices, ensuring smooth transitions and minimal service disruption.Personal [IMAGE] [IMAGE] [IMAGE]
- Société Générale ABSSOC Managerseptembre 2021 - juin 2022 (9 mois)Strategic planning and orchestration of daily SOC operations, ensuring seamless detection, response, and monitoring across enterprise environments. Operational leadership during major cybersecurity incidents, acting as a key stakeholder in crisis management and incident containment. Coordination with CERT and CSIRT teams, especially under crisis conditions, to synchronize actions across all operational security units and maintain situational awareness. SOC vision and strategy definition, aligning detection capabilities with regulatory mandates, evolving threat landscapes, and the organization's risk appetite. Design and implementation of escalation and notification workflows, supported by real-time KPI dashboards presented during executive meetings (COPIL, COSUI). Evaluation of SOC tool effectiveness, leading continuous improvement initiatives and driving corrective action plans based on operational performance and threat coverage gaps. Threat-informed detection strategy development, leveraging a global view of the organization's vulnerability exposure and attack surface. Architecture and deployment of SOC toolsets, including: Event collection pipelines (SIEM/EDR/NDR) Secure access to security platforms Suspicious event investigation and triage Alert lifecycle management Workflow automation for incident tracking and resolution
Recommandations
Soyez le premier à recommander Marwane
Contribuez à la réussite de ce freelance en partageant votre expérience de collaboration avec lui.
Ces profils de freelance correspondent également à vos critères
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Formations
- Certified Ethical Hacker (CEH)Certified Ethical Hacker (CEH)
- Cryptography and PKIBrandon UniversityCryptography and PKI