I hold a French RNCP Level 7 qualification in cybersecurity solutions development (EQF 7, Master's level) and I'm looking to join an in-house security team where I can both implement and analyse cybersecurity solutions — from technical hardening to governance.
Before moving into cybersecurity, I spent years as a QSE (quality, safety, environment) manager and logistics operations leader, which gave me a strong foundation in process discipline, regulatory compliance, and risk management — including OT/IT environments. I bring that operational mindset directly into security work.
What I can show today:
- 🏢 Identity & Access Management — Active Directory OU design, GPO hardening aligned with CIS Benchmarks, PingCastle assessment
- 🔍 SIEM & Threat Detection — Wazuh agents, custom decoder and rules, MITRE ATT&CK mapping, detections validated with controlled tests
- 🔥 Network Security — pfSense segmentation (WAN / LAN / DMZ, default-deny), Suricata IDS/IPS, OpenVAS vulnerability scanning
- 📋 GRC — ISO 27001 and EBIOS RM (PECB), NIS2 — technical controls justified against the frameworks
| Certification | Issuer | Year |
|---|---|---|
| Expert en développement de solutions de cybersécurité — RNCP 38463, Level 7 (EQF 7) | AN21 / CSB School | 2024 |
| ISO/IEC 27001 Provisional Implementer | PECB | 2024 |
| EBIOS Provisional Risk Manager | PECB | 2024 |
| Certified in Cybersecurity (CC) | ISC2 | 2026 |
All labs simulate the security programme of LogiSecure SA, a fictional Belgian parcel logistics operator for B2B e-commerce (500 employees, Brussels HQ, automated sorting conveyors on the OT side). As a courier service provider it is an NIS2 important entity, and it uses ISO 27001 and IEC 62443 as reference frameworks. Each project extends the same environment instead of starting from scratch.
Built so far: Active Directory lab.local · pfSense perimeter (WAN / LAN / DMZ) · Suricata IDS/IPS · Wazuh SIEM · OpenVAS
📌 Programme hub — company context and lab architecture: logisecure-enterprise-security-program
A project is listed once its repository is published, plus the one in progress. Every figure below is evidenced in its repository.
| Repository | Status | Evidenced results |
|---|---|---|
| logisecure-active-directory | ✅ Completed | AD domain with OU design · 4 GPOs (password, lockout, audit, hardening) · Wazuh agents on DC01 and WKS01 · custom MITRE-mapped rules · PingCastle risk reduced on Privileged Accounts (50 → 40) and Stale Objects (41 → 36) |
| logisecure-pfsense-segmentation | ✅ Completed | 12 firewall rules, default-deny on every interface · DMZ→LAN traffic blocked, shown in firewall logs · Suricata scan alerts decoded in Wazuh and mapped to T1046 · OpenVAS validated against nmap |
| logisecure-ebios-rm-assessment | 🔄 In progress | EBIOS RM risk assessment of LogiSecure SA |
The flagship detection rule never fired — found four months later
My custom T1110 rule shared its ID with an example rule that Wazuh ships by default, so Wazuh kept the example and dropped mine — for four months, with one unread warning line as the only signal. I found it during the pfSense project and proved the fix with the same controlled failed logon, before and after. The lesson: a detection is proven by making it fire, not by showing that the file exists.
| Framework | Where it is applied |
|---|---|
| MITRE ATT&CK | Detections mapped to T1046 (Suricata scan alerts in Wazuh), T1078 and T1087 (custom Wazuh rules) · Mitigations for T1110 (account lockout) and T1557 (LLMNR disabled) |
| CIS Benchmarks | GPO hardening — password and lockout policies, NTLMv2 only, SMB signing |
| ISO 27001:2022 · NIS2 Art. 21 | Default-deny firewall rules justified against ISO 27001 A.8.20 and NIS2 Art. 21 |
All lab environments simulate the fictional enterprise LogiSecure SA, used solely for educational and portfolio purposes.