À propos de Moad
- compréhension des vecteurs d’attaque applicables aux SI, applications web et environnements cloud,
- capacité à analyser et exploiter les résultats de pentests,
- priorisation des vulnérabilités selon le risque réel pour le métier,
- traduction des failles techniques en plans de remédiation concrets et actionnables pour les équipes IT, Ops, Dev et Cloud.
Français
Bilingue ou natif
Anglais
Bilingue ou natif
Allemand
Notions
Expériences
- ConfidentielInformation Security OfficerGRANDE DISTRIBUTIONjanvier 2023 - Aujourd'hui (3 ans et 5 mois)Paris, France
- Risk analysis for critical projects (ISO 27005, EBIOS).
- Compliance audits with minimum security standards.
- Cybersecurity project support (Project Security Assessment Tool).
- Evaluation of vendor security maturity (Security Insurance Plan).
- Integration of security controls in Azure (Azure security services, identity/access management, WAF, data security, MFA, etc.).
- Monitoring security strategy implementation in SG/Azure landing zone.
- Development and enforcement of IT security policies.
- Support for Ops/Dev teams and follow-up on remediation from pentesting and security bulletins.
- Preparation of temporary cybersecurity risk exceptions.
- Secure application design and architecture.
- Training users on cybersecurity tools.
- AD hardening, assessment using Bloodhound, Purple Knight and PingCastle to identify misconfigurations, vulnerabilities, and security gaps, ensuring compliance with group policies.
- Development of hardening guides for technical teams.
- Concentrix GroupCybersecurity Architectoctobre 2021 - décembre 2022 (1 an et 2 mois)
- Planning, researching, and designing reliable, powerful, and flexible security architectures for all IT projects
- Performing vulnerability testing on the completed infrastructure, including risk analyses and security assessments
- Researching the latest security standards, new security systems, and updated authentication protocols
- Defining, creating, implementing, and maintaining all needed corporate security policies and procedures, making sure that all employees abide by them
- Developing requirements for all IT assets including routers, firewalls, local area networks (LANs), wide-area networks (WANs), virtual private networks (VPNs),
- Reviewing and approving the installation of all firewalls, VPN, routers, servers, and IDS scanning technologies
- Preparing cost estimates for all cybersecurity measures and identifying any potential integration issues
- Designing critical public infrastructures (PKIs), including digital signatures and certification authorities (CA)
- AD assessment (Tenable.ad), support & assistance in the remediation process.
- Providing technical guidance and supervision for security teams
- ConfidentielSenior Cybersecurity consultant / Team Leaderjanvier 2017 - octobre 2021 (4 ans et 9 mois)
- Security configuration and operations standards for security systems and applications, including policy assessment, network security appliances, and host-based security systems.
- Develop and validate baseline security configurations for operating systems, applications, and networking and telecommunications equipment.
- Perform internal and external technical control and vulnerability assessments to identify control weaknesses and assess the effectiveness of existing controls and recommend remedial action.
- Security monitoring and log analysis
- AD vulnerability Assessments.
- IT infrastructure/ Application security configuration reviews
- Maintain and follow up continuous improvement process
Recommandations
Soyez le premier à recommander Moad
Contribuez à la réussite de ce freelance en partageant votre expérience de collaboration avec lui.
Ces profils de freelance correspondent également à vos critères
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Formations
- Master's degreeNational Institute of Posts and Telecommunications (INPT)2022Master's degree
- State engineer in computer scienceUniversity of Mohamed V (ENSIAS)2011State engineer in computer science
Certifications
- OffSec Certified Professional+ (OSCP+)Offsec2025
- OffSec Certified Professional (OSCP)OffSec2025