About Houfani
English
Fluent
French
Native or bilingual
Experience
- Haute Autorité de SantéExpert Cybersécurité/GRC/Risk managementHEALTH AND WELLNESSOctober 2024 - Today (1 year and 8 months)Saint-Denis, FranceDesigned security strategy aligned with the IT/business for 2024/2025- Identify the features to be developed for 2024/2025,- Analyze the security needs of each feature,- Plan the secure design (Threat modeling and Security assessment) workshops with the business and the IT,- Perform the secure design: Threat modeling (STRIDE) and Security assessment,- Identify the non-compliance and initiate the risk form with remediation plan- Security requirements identification to implement during the development,Control the security requirement implementation with the IT team and Business during the SDLC- Workshop with the IT team to identify which security measures should be implemented during the sprints- Define the security gates and the rules- Plan periodically meeting with the IT team to control the implementation of security requirements during the development- Risk management performed on the non-complianceWriting procedural documents on :- Habilitation procedure- Incident management- Integration Security in the project procedure- Risk management procedurePerform ISP (integration of security in the project) :- Perform an assessment of securtiy for the new project- Perform thrid party assessment for outsourced developement- Identify the non-compliance and initiate a risk form- Follow the risk form and the implementation of remediation planReport the posture of security to the management (reporting of metric and KPI)Train the business on the following topics :- Risk management- Secure design- Security best practices- Agility Vs Security- Data classification processParticipate of Disaster recovry test and make a Retex to improve the process
- BNP Paribas Personal FinanceExpert security/DORA auditorBANKING AND INSURANCEFebruary 2023 - October 2024 (1 year and 8 months)Paris, France- Audit DORA• Analyze framework Dora for ICT Risk management, Digital resilience test and ICT related incident.• Assessment to identify gap analysis between DORA regulation and the cyber requirements implemented.• Design Application Security process to address all mandatory security requirements for Digital resilience Test during the development (Agile).• Drafting training course on Application Security and DORA topic for developers and TechLead to acculturate them.• Support local IT Risk team to understand what it expected for the DORA pilar « Digital resilience test » and « ICT related incident »• Design a Security Test strategy to help team to be compliance with the Security requirement• Train IT team/Product Owner in different location (Bucarest, Madrid, Munich and Milan) Application Security and DORA Security Champion role Security test strategy Vulnerability management ISP : Integration security in the project Agile Vs Security• Control the compliance with the DORA/GDPR/NIST/ISO 27001 framework Control periodically the procedural and identify the non-compliance Perform security review on the application and system. Perform scan on the application and system to identify the vulnerabilities Report the result with the non-compliance Create risk-form baes on the non-compliance Help the IT team to define and implement the remediation plan Follow the remediation plan achievement and the risk form
- BNP Paribas Personal FinanceExpert cybersecurity ISP/Third partyBANKING AND INSURANCEFebruary 2022 - February 2023 (1 year)Levallois-Perret, France- Implement security in the project: ISP• Integration security in the project Procedure drafting• Coaching Tribe leader and Security champion on Risk management procedure and good practices• Perform with business the secure design (implement Threat modeling methodology) to identify the possible case of fraud or non-compliance on use cases• Perform Security Assessment for all new project and take care are compliance with DORA/NIST/PCI-DSS• Workshop with the IT team to identify which security measures should be implemented during the sprints• Define the security gates and the rules• Plan periodically meeting with the IT team to control the implementation of security requirements during the development- Third party audit when the product is outsourced- Analyse the thrid party questionnaire
Recommendations
Be the first to recommend Houfani
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4
Education
- Master of Science in Cyber SecurityUniversity of Technology of Troyes (UTT)2020Master in Forensics and Cyber security
- Master in New Technology and E-businessSchool of Management - Business School (ESG)2005Master in New Technology and E-business
Certifications
- ISO27001 Lead implementorPECB2021
- ISO27001 Lead auditorPECB2021