À propos de Sad
Français
Bilingue ou natif
Anglais
Capacité professionnelle complète
Arabe
Bilingue ou natif
Expériences
- BNP ParibasIT/cyber risk governance consultantBANQUE & ASSURANCESmars 2022 - Aujourd'hui (4 ans et 3 mois)Paris, FranceProject Manager for IT/Cyber Risk Management Framework Restructuring and Review at the Group Level, involving:Framework Analysis:Reviewing the current framework used by the GROUP for managing IT risks.Familiarizing oneself with key components of the framework, such as policies, procedures, standards, best practices, and various guidelines.Relevance Assessment:Evaluating the relevance of the framework in relation to the GROUP’s specific needs through workshops with different entities.Verifying whether the framework covers all essential aspects of IT risk management.Process Examination:Reviewing processes related to risk identification, assessment, treatment, and monitoring.Ensuring alignment of these processes with the GROUP’s strategic objectives and operational applicability.Implementation:Examining how the framework is being implemented within the organization.Monitoring and providing training to operational teams on the new framework.Verifying adherence to framework guidelines and ensuring access to necessary resources.
- EY Services Francecyber risk consultantCONSEIL & AUDITseptembre 2017 - janvier 2022 (4 ans et 5 mois)Paris, FranceAs an experienced IT/Cyber strategy consultant at EY, I have successfully worked with various clients across different sectors, including financial institutions, public organizations, and industries. My expertise lies in developing governance documents, implementing robust security processes, managing risks, and providing valuable insights on cyber threats. Here's a summary of my activities:1 - Governance and Security Processes:a - Drafting governance documents (security policies, operational procedures).b - Implementing information security processes based on recognized standards (ISO 27k and NIST).2 - Risk Management and Information Protection:a - Classifying information assets of major business lines.b - Identifying and analyzing risk scenarios related to information assets (based on IRAM v2).c - Evaluating existing measures for information protection .3 - Change Management and awareness:a - Selecting, implementing, and using technology solutions (i.e data protection...).b - Developing awareness materials and providing technical and functional training.
Recommandations
Soyez le premier à recommander Sad
Contribuez à la réussite de ce freelance en partageant votre expérience de collaboration avec lui.
Ces profils de freelance correspondent également à vos critères
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Formations
- ingénieur en SIEcole Mohammadia d'Ingénieurs2017