logo

Jérémie COLLOMB

Chief Information Security Officer - CISO

Experiences

CISO

HR Path
Since January 2021
  • Construction and implementation of Cybersecurity strategy
  • Change of vision and paradigm: simplify day-to-day operations to increase security
  • Creation and management of an international cybersecurity team (from 0 to 7 people): Security Operations, compliance, Incident Detection Response & Vulnerabilities
  • Implementation of a compliance strategy and framework to address future certifications, customer needs, and regulatory changes
  • Management of ISO/IEC 27001 compliance, extension of scope and transition from version 2017 to 2022
  • Ensuring compliance and obtaining SOC 2 Type 2 Report
  • Cyber M&A management for all acquisitions
  • Building trust relationship and proximity with the business lines for project security and delivery
  • Deployment of a scope targeted by French regulations on Restricted Distribution (II901) in 3 months
  • Implementation of various security measures like Email Protection, Internet Protection, SIEM, EDR.
Permanent Contract Paris (75) - France

CISO Deputy

Galeries Lafayette
October 2017 - December 2020
  • Project management and process definition for Identity and Access Management (IAM)
  • Implementation of security into project management (IT or business)
  • Security Operation Center project guidance, technical expertise, and process definition
  • Vulnerability management with Qualys, Rapid7 and a Bug Bounty platform
  • Definition and implementation of patch management process
  • Complete rework and redefinition of security policy and strategy
  • Security advisement and help to IT and business teams
Permanent Contract Paris (75) - France

IT Security in Apprenticeship

SAFRAN Aircraft Engines
September 2014 - September 2017
  • Chief Information Security Officer Deputy
  • Arellia project setting up - Local users and administrators management
  • Vulnerabily management - Tenable Nessus
  • NAS Shares analytics setting up - Varonis Datadvantage
  • Obsolescence management of users and applications account
  • Antiviral platform management
Apprentice Evry (91) - France

Project Manager - Last Project

Agence Française pour la Biodiversité
September 2016 - March 2017
  • Project manager to research and realize a pioneer submarine drone
  • Submarine drone with a position of 50cm precision
  • Innovator project with benefit on geomatic and open-source community
  • Conference about the project at Foss4G Europe (in English - July 2017)
School project Champs-sur-Marne (77) - France

Internship in network division

Groupe APICIL
April 2014 - June 2014
  • Load balancer Zeus (Riverbed Stingray) migration to F5 Big-Ip
  • Security and configuration management of load-balancers
  • Management of the load-balancing supervision environment
Internship Lyon (69) - France

Educations

Computer Science and Networks Engineers in apprenticeship

ESIPe - ESIEE Paris
September 2014 - September 2017

Diploma certified by the CTI (French engineering accreditation institution)

DUT Informatique - diploma of higher education in computing

Institut Universitaire de Technologie (IUT) , Université Claude Bernard Lyon 1
2014

Semester 4 fully in English

French Baccalaureate majoring in Electronic

Lycée Notre Dame de Bel Air, Tarare (69)
2012

Cinema and Audio Visual option

Skills

Security

  • Security strategy for top management with understandable security measures and actions
  • Risk analysis and audit on internal processes, on third party and during M&A
  • Compliance mastering on ISO/IEC 27001:2017-2022, SOC 2 Type 2, TISAX, UK Cyber Essential
  • Definition and implementation of security policy, appropriate KPI, global governance
  • Security awareness and communication (videos, quiz, phishing…)
  • Security incident management (definition, implementation, communication)
  • SIEM project management and implementation (Splunk)
  • Security Operation Center detection rules definition and improvement with proper knowledge and process on Threat Intelligence (OpenCTI)
  • Policy definition and associated configuration/assistance on Artificial Intelligence (GPT and mainly statistical processing)

Network

  • Security infrastructure management: firewall (Fortinet, Stormshield), Proxy (Zscaler ZIA), VPN (Zscaler ZPA)
  • Intrusion detection probe management (IPS/IDS): Fortinet, Gatewatcher, Zscaler
  • Mobile security strategy definition on M365 (Conditionnal Access, Intune)

System

  • Definition, implementation and controls associated to system layer: EDR/EPP (Trellix, Harfang, TrendMicro, Cybereason), hardening (CIS based))
  • Security assistance for Windows (Server & Desktop), MacOS, Linux (Red Hat & Debian)
  • Encryption technologies management (HSM, PKI, and data encryption)
  • Study and Analysis for PAM deployment (server & computer)

Cloud

  • Microsoft365 security configuration and audit
  • Microsoft Azure Cloud, Google Cloud Platform Security and cloud partners knowledge
  • Security support for setting up cloud instances

Languages

  • English: Fluent
  • French: Native language

Interests

Sports

  • Climbing
  • Hiking
  • Skiing

Passions

  • Photo & Video (from capture to editing),
  • Security (threats, evolution)
  • Travel