Jawad Boujnane
Cybersecurity Engineer, GRC
6 years of experience excluding apprenticeship · defence and critical information systems · Paris area
I have been leading the security accreditation of classified information systems at Thales since 2022, after five years in networks and security at Atos, three of them as an apprentice. I am moving towards security architecture: designing, justifying every choice, and proving it.
Contact me on LinkedIn (new tab)Full portfolio in FrenchCV (PDF, in French)
This page is an English summary. The full portfolio (interactive model, test bench, architecture notes) and the knowledge base (20 modules, 33 validated diagrams) are in French.
| Figure | What it covers | Source |
|---|---|---|
| 6 years | in cybersecurity, 4 of them in security accreditation | , ![]() |
| 15+ | security accreditation files led end to end on classified information systems | ![]() |
| 200+ | requirements traced in multi-framework compliance matrices | ![]() |
| ≈ 40 % | fewer non-conformities found at accreditation, thanks to Security by Design | ![]() |
| 10+ | large-account clients supported in networks and security | ![]() |
Three proofs, one CV line each
Each proof ties a line of my career to something that can be opened: a diagram, a decision record, a test bench. The case studies are generic, with no client data, and written in French.
- EBIOS RM risk analysisFull EBIOS RM analyses at Thales, including one for an isolated AI workstation (locally hosted LLMs), validated at accreditation.See the proof (in French)
- Multi-framework compliance matricesIGI 1300, II 901, IM 900 and security policy matrices maintained at Thales: more than 200 requirements traced according to system sensitivity.See the proof (in French)
- Segmentation and flow matrixFive years at Atos, three of them as an apprentice at CEA Saclay then at the Île-de-France Regional Council: firewall policies, flow openings, Stormshield segmentation, 10+ large accounts.See the proof (in French)
Experience
Six years between networks, security and accreditation: from infrastructure work to risk decisions. In France, “homologation SSI” is the formal security accreditation of an information system before it goes live.
-
Sept. 2022 – present
4 years

Cybersecurity Engineer, GRC
Thales · Gennevilliers
Security accreditation department · defence and critical information systems
- Led 15+ security accreditation files for critical and classified information systems end to end: accreditation strategy, security architecture, compliance matrix, EBIOS RM risk analysis, residual vulnerabilities file (IGI 1300, II 901, IM 900)
- Conducted full EBIOS RM risk analyses: feared events, strategic and operational scenarios, treatment measures and actionable remediation plans
- Performed the EBIOS RM risk analysis of an isolated AI workstation (open-source LLMs hosted locally): generative-AI risks scoped, isolation measures validated at accreditation
- Designed and maintained multi-framework compliance matrices (IGI 1300, II 901, IM 900, security policy): 200+ requirements traced according to system sensitivity
- Formalised and rolled out a Security by Design process in project design reviews: about 40 % fewer non-conformities found at accreditation
- Coordinated internal and external audits (cyber resilience, residual vulnerabilities), reporting to business management with prioritised remediation plans
- Ran an active regulatory watch and assessed its impact on information systems
Environment
Classified information systems: programmes are not named.
-
Sept. 2020 – Sept. 2022
2 years

Network and Security Engineer
Atos · Bezons
NDCS team (Network Data Center Security) · 10+ large-account clients
- Administered and secured the network infrastructure of 10+ large-account clients, meeting availability and SLA commitments
- Handled level-2 network and security incidents and requests: flow openings, firewall policies, migrations, equipment integration
- Configured and administered heterogeneous equipment (switches, routers, firewalls) in a multi-vendor environment
- Coordinated suppliers and carriers for service continuity and contractual SLAs
Environment
Large accounts supported
-
Jan. 2020 – Sept. 2020
9 months

Apprentice Network and Security Engineer
Atos · Bezons
Île-de-France Regional Council account · security integration
- Audited and mapped the complete network architecture (LAN, Wi-Fi, proxy, firewall, DNS, DHCP), with corrective recommendations
- Deployed and integrated Stormshield solutions (access protection, network segmentation), aligned with ANSSI guidelines
Environment
Client
-
Sept. 2017 – Jan. 2020
2½ years

Apprentice Network and Security Engineer
Atos · Saclay
Managed services for CEA’s infrastructure · sensitive environment
- Handled network incidents and requests within contractual SLAs, in a critical environment
- Monitored network and security equipment (firewalls, load balancers, routers, VLANs)
- Optimised and consolidated the network infrastructure; technical documentation and standardised operating procedures
Environment
Client
Outside work: Brazilian jiu-jitsu (competitor) · travel and cultures
Skills
| Domain | Frameworks, methods and technologies | Practised at |
|---|---|---|
| GRC and accreditation | ![]() | |
| AI and security | ![]() | |
| Networks and security | ![]() | |
| Tools | , ![]() | |
| Languages and soft skills | none |
| Degree | School | Period |
|---|---|---|
| Master’s degree (M2) in IT SecurityWork-study at Atos | ESGI Paris | 2018 – 2020 |
| Bachelor’s degree in IT SecurityWork-study at Atos | ESGI Paris | 2017 – 2018 |
| DUT GEII, two-year technical degree in electrical engineering and industrial computingNetworks option | IUT de Cergy-Pontoise | 2015 – 2017 |
| Certification | Status |
|---|---|
| ISO/IEC 27001 Lead Auditor | training in progress |
| ISO/IEC 27001 Lead Implementer | next target |
| CISSP | next target |
Let’s talk security architecture and GRC
A role in GRC or security architecture? The simplest way is a message on LinkedIn.











