(Level 3) Lead SOC analyst &ndash threat hunter
For Thales Digital Factory
6/2020 -
Incident investigation and response and security alert:
&bull Threat hunting
&bull Alert optimization
&bull Detection rules efficiency audit
&bull Detection capabilities gap audit (using mitre caldera)
&bull Execution and/or drafting of operational procedures
&bull Investigation and analysis of SIEM/EDR/XDR alerts and incidents
&bull L3 support on investigations
&bull Level 1 onboarding and reflex sheet writing
&bull Staff training
&bull Cert champion
&bull KPI definition and reporting
&bull GRC support on ISO 27k compliance
&bull Correlation CTI, Vulnerabilité, incident/alertes (Virus total, OTX,
vulndb, exploitdb, anyrun&hellip)
&bull L1/L2 automation via Logicapps
&bull Implementation of new Use cases based on policies, threat
models, best practices (NIST, CISA, CIS, ANNSI...)
&bull Security and vulnerability monitoring (LinkedIn, Medium, Twitter,
cybersecurity Hub)
&bull Referent Analyst during crises, incide
&bull Definition of short-term security recommendations
&bull Recommendation on long-term security remediation
&bull Automation response via logicapp
&bull Malware Analysis
&bull Phishing analysis
&bull Investigation IOC/IOA
&bull Implementation of Workbook for reporting and trend analysis.
&bull Participation in risk analysis
&bull Continuous improvement
_For Identityprotection)&bull Azure Sentinel&bull Logicapps
Deputy CISO Delegate in France/Benelux
For SIG Group
10/2020 - 3/2021
Work closely with regional IT and business management to provide
security support, advice and oversight, identify and manage risks and
maintain compliance:
&bull Provide technical/SME support for the implementation of groupwide/regional security initiatives.
&bull Lead regional incident response to minimize impacts and
investigation of violations.
&bull Responsibility for providing operational support for security
technologies, products and services.
&bull Assist in the creation and management of regional security review
processes, including security oversight for change and
architecture review committees, and project activities.
&bull Work with security and technology risk compliance to ensure
controls are adopted and maintained in the region.
&bull Maintain knowledge of emerging threats and technologies.
&bull Conducting cybersecurity incident management.
&bull Security architecture: SIEM (Sentinel), Cloud Security (Zscaler),
Endpoint Detection & Response (Crowdstrike), Anti-Spam
Filtering (Mimecast), Operating System Security (Windows &
Linux), Network Security Technologies, vulnerability management
tools (Rapid7) and threat intelligence platforms
&bull Governance: NIST, ISO and PCI with understanding of local
regulatory requirements, Disaster recovery test, Logic Manager,
RACI, PhishER
&bull Creation and management of IAM, DR/BCP, Vulnerability
Management or Application Security programs.
&bull Internal and external audit review
&bull Conducting audits and assurance activities.
&bull Implementation of audit corrective actions
Security/Operations Engineer (soc analyst)
For EuropAssistance
1/2020 - 7/2020
Maintenance in security condition of Europe's French sitesAssistance and
reporting for the preparation of audits
Missions:
&bull Operational security monitoring (audit and compliance ):
Workstations and servers as part of the ISO 27001 process
&bull Qualification and monitoring of patch deployment: OS and
applications
Incident management:
&bull Analysis, research and corrective actions,
&bull Generali Group CERT alert analysis
&bull Execution and/or drafting of operational procedures,
&bull Technical contributor on infrastructure and security projects
&bull Execution of operational security maintenance tasks (patching,
vulnerability analysis...) and systems administration
&bull Daily checks and related reporting
&bull Incident management: analysis, solution research, execution of
corrective actions and update of incident tickets through the
ticketing tool
&bull Administration Symantec Endpoint Protection, Deep Security et
Office Scan
&bull Drafting and updating procedures
&bull Scanning and processing VAMPS vulnerability reports
&bull IS security compliance analyses
&bull Participation in Stack ELK implementation and migration projects
&bull Implementing alerts on the ELK SIEM
&bull Internal penetration testing with Kali
&bull Security analysis with MS ATP
&bull Implementation of policies and processes
&bull Malware Analysis
&bull Phishing analysis
&bull Investigation IOC/IOA
&bull Implementation of Workbook for reporting and trend analysis.
&bull Participation in risk analysis
&bull Continuous improvement
Network/Security/Telephony Project Coordinator
For La Mutuelle Générale
7/2019 - 2/2020
Networks/Security:
&bull Review of flow rules on checkpoint and fortinet
&bull Opening flows
&bull Functional recipe
&bull Reporting
Network:
&bull Vlan Review
&bull Creating vlan
&bull Functional recipe
&bull Conduction migration lab terminal MR 33 to MR45
&bull Reporting
Telephony:
&bull Review of active lines alcatel
&bull Pre-migration stress analysis
&bull Line creation and skype directory update
&bull Alcatel Omnivista to Skype Line Migration
&bull Reporting
Mission:
&bull Level 2 and 3 Advanced Support for Critical Incidents
&bull Architecture and preparation for complex changes (HLD: logical
schemas and flow diagram)
&bull LAN and VLAN redesign on Catalyst for various centers
&bull Telephony migration
&bull WiFi migration
&bull Administration skype , active directory et omnivista
Security Network Engineer
For Canon
10/2018 - 7/2019
Networks/Security:
&bull Hardware: Cisco, Catalyst, ASA, BlueCoat
&bull Networks: Ethernet (802.3*),MPLS,WiFi (802.11a/b/g/n).
&bull Network protocols: TCP/IP stack, Qos, CoS, MPLS-EXP).
&bull Protocoles de routage : BGP, OSPF, EIGRP, MPLS LDP, MP-BGP
&bull Virtual private networks: IPSec VPN, MPLS VPN, SSL VPN.
&bull Level 2 protocol: Spanning-Tree, Etherchannel, Dot1Q & ISL
&bull Operating systems: Windows, Linux, IOS
Cyber-Security:
&bull Management of rights, authorizations and monitoring of user
accounts
&bull Analysis and Tracking of AlienVault logs and events
&bull Application of security standards and best practices
&bull Cisco IDS/IPS
&bull Languard openvas scanner
&bull Drafting security policies and procedures
&bull Web authentication (oAuthx, openID Connect...)
&bull Vulnerability Scanning with Qualys and OpenVAS
&bull Vulnerability fixes
&bull Audit and action plan security evolution
&bull Implementation of new antivirus and Siem solutions
&bull Implementation and monitoring of good operational safety
practices
&bull Security Incident Resolution
&bull Certification Cyberark Trustee
Mission:
&bull Level 2 and 3 Advanced Support for Critical Incidents
&bull Architecture and preparation for complex changes (HLD: logical
schemas and flow diagram)
&bull Making DMZ Interconnects on Cisco ASA
&bull LAN and VLAN redesign on Catalyst for various centers
&bull Routing Optimization for Flow Partitioning Centers
&bull PE-CE interconnect for new customer sites on the MPLS backbone
in CANON environments
&bull Setting up Catalyst stack stacks
Security/Operations Engineer (soc analyst)
For Volkswagen Bank 1 year
11/2017 - 10/2018
Context:
Maintenance in safety condition of Volkswagen FRANCE French sites and
reporting for audit preparation
Missions:
&bull Operational security monitoring (audit and compliance ):
Workstations and servers as part of the ISO 27001 process
&bull Qualification and monitoring of patch deployment: OS and
applications
&bull Incident management:
&bull Analysis, research and corrective actions,
&bull VWFS CERT Alert Analysis
&bull Execution and/or drafting of operational procedures, oTechnical
contributor on infrastructure and security projects
&bull Execution of operational security maintenance tasks (patching,
vulnerability analysis...) and systems administration
&bull Daily checks and related reporting
&bull Incident management: analysis, solution research, execution of
corrective actions and update of incident tickets through the
ticketing tool
&bull Corrective Action Plan and Improvement
&bull Maintenance of the IT OPERATIONS document repository
Operational security
&bull MCS Windows 7 & Microsoft 2008/2012/2016, VMware
virtualization technologies
&bull Active directory administration and Exchange 2010 (GPO, User
Rights Management and Network Shares) Hardening (Windows
OS hardening) by GPO and editing of registries
&bull Administration Symantec Endpoint Protection et VPN SSL
(PulseSecure)
&bull SAN Storage Management (datacore)
&bull Administration DNS, DHCP, configuration IP Support niveau 2
infrastructures SI,
&bull Drafting and updating procedures
&bull Analysis and processing of NESSUS/MVM vulnerability reports
&bull ECB IS Security Compliance Analyses
&bull Participation in SCCM and Symanetc Enpoint Protection Manager
implementation and migration projectsKeeping CMDB HPSM up to date
&bull Administration Cyberark
Technical environment:
PAM Cyberark, SIEM Qradar, Suite MS 7/2008/2012/2016, VMware,
Symantec EP, Devicelocker, RSA, Mcafee vulnerability manager, Nessus,
SCCM, HPSM, CMDB
S e c u r i t y N e t w o r k E n g i n e e r
For THALES/Imprimerie Nationale Adentis For 5 months
6/2017 - 11/2017
Architecture for the rationalization of the infrastructure and the
implementation of new services as part of the moving project,
maintenance in operational condition and project support
Missions:
&bull Writing Functional file project NOC Writing functional file SOC
project Writing functional file (UMLs)
&bull Writing of ...