Skip to content
Jawad Boujnane
FrançaisLinkedIn (new tab)

Jawad Boujnane

Cybersecurity Engineer, GRC

6 years of experience excluding apprenticeship · defence and critical information systems · Paris area

I have been leading the security accreditation of classified information systems at Thales since 2022, after five years in networks and security at Atos, three of them as an apprentice. I am moving towards security architecture: designing, justifying every choice, and proving it.

Contact me on LinkedIn (new tab)Full portfolio in FrenchCV (PDF, in French)

This page is an English summary. The full portfolio (interactive model, test bench, architecture notes) and the knowledge base (20 modules, 33 validated diagrams) are in French.

Key figures
FigureWhat it coversSource
6 yearsin cybersecurity, 4 of them in security accreditation,
15+security accreditation files led end to end on classified information systems
200+requirements traced in multi-framework compliance matrices
≈ 40 %fewer non-conformities found at accreditation, thanks to Security by Design
10+large-account clients supported in networks and security

Three proofs, one CV line each

Each proof ties a line of my career to something that can be opened: a diagram, a decision record, a test bench. The case studies are generic, with no client data, and written in French.

  1. EBIOS RM risk analysisFull EBIOS RM analyses at Thales, including one for an isolated AI workstation (locally hosted LLMs), validated at accreditation.See the proof (in French)
  2. Multi-framework compliance matricesIGI 1300, II 901, IM 900 and security policy matrices maintained at Thales: more than 200 requirements traced according to system sensitivity.See the proof (in French)
  3. Segmentation and flow matrixFive years at Atos, three of them as an apprentice at CEA Saclay then at the Île-de-France Regional Council: firewall policies, flow openings, Stormshield segmentation, 10+ large accounts.See the proof (in French)

Experience

Six years between networks, security and accreditation: from infrastructure work to risk decisions. In France, “homologation SSI” is the formal security accreditation of an information system before it goes live.

  1. Sept. 2022 – present

    4 years

    Cybersecurity Engineer, GRC

    Thales · Gennevilliers

    Security accreditation department · defence and critical information systems

    • Led 15+ security accreditation files for critical and classified information systems end to end: accreditation strategy, security architecture, compliance matrix, EBIOS RM risk analysis, residual vulnerabilities file (IGI 1300, II 901, IM 900)
    • Conducted full EBIOS RM risk analyses: feared events, strategic and operational scenarios, treatment measures and actionable remediation plans
    • Performed the EBIOS RM risk analysis of an isolated AI workstation (open-source LLMs hosted locally): generative-AI risks scoped, isolation measures validated at accreditation
    • Designed and maintained multi-framework compliance matrices (IGI 1300, II 901, IM 900, security policy): 200+ requirements traced according to system sensitivity
    • Formalised and rolled out a Security by Design process in project design reviews: about 40 % fewer non-conformities found at accreditation
    • Coordinated internal and external audits (cyber resilience, residual vulnerabilities), reporting to business management with prioritised remediation plans
    • Ran an active regulatory watch and assessed its impact on information systems

    Environment

    • IGI 1300
    • II 901
    • IM 900
    • ISO 27001/27005
    • EBIOS RM
    • NIST CSF
    • Security policy (PSSI)
    • ANSSI guidelines
    • Generative AI / LLM
    • Visio
    • draw.io
    • Excel

    Classified information systems: programmes are not named.

  2. Sept. 2020 – Sept. 2022

    2 years

    Network and Security Engineer

    Atos · Bezons

    NDCS team (Network Data Center Security) · 10+ large-account clients

    • Administered and secured the network infrastructure of 10+ large-account clients, meeting availability and SLA commitments
    • Handled level-2 network and security incidents and requests: flow openings, firewall policies, migrations, equipment integration
    • Configured and administered heterogeneous equipment (switches, routers, firewalls) in a multi-vendor environment
    • Coordinated suppliers and carriers for service continuity and contractual SLAs

    Environment

    • NSX-T
    • Juniper
    • Stormshield
    • Cisco
    • Fortinet
    • Palo Alto
    • Kibana
    • Efficient IP

    Large accounts supported

  3. Jan. 2020 – Sept. 2020

    9 months

    Apprentice Network and Security Engineer

    Atos · Bezons

    Île-de-France Regional Council account · security integration

    • Audited and mapped the complete network architecture (LAN, Wi-Fi, proxy, firewall, DNS, DHCP), with corrective recommendations
    • Deployed and integrated Stormshield solutions (access protection, network segmentation), aligned with ANSSI guidelines

    Environment

    • Stormshield
    • Cisco
    • Aruba
    • Windows Server
    • Linux
    • macOS

    Client

  4. Sept. 2017 – Jan. 2020

    2½ years

    Apprentice Network and Security Engineer

    Atos · Saclay

    Managed services for CEA’s infrastructure · sensitive environment

    • Handled network incidents and requests within contractual SLAs, in a critical environment
    • Monitored network and security equipment (firewalls, load balancers, routers, VLANs)
    • Optimised and consolidated the network infrastructure; technical documentation and standardised operating procedures

    Environment

    • Cisco
    • Fortinet
    • VMware
    • Windows Server
    • Nagios

    Client

Outside work: Brazilian jiu-jitsu (competitor) · travel and cultures

Skills

Skills
DomainFrameworks, methods and technologiesPractised at
GRC and accreditation
  • Security accreditation (homologation SSI) · IGI 1300, II 901, IM 900
  • EBIOS Risk Manager
  • ISO/IEC 27001 · 27005
  • NIST CSF · security policy (PSSI)
  • NIS2 · ReCyF · DORA · ANSSI guidelines
  • Multi-framework compliance matrices
  • Security audit · Security by Design
  • Classified environments
  • Cloud and SaaS security
AI and security
  • AI and LLM risk analysis
  • ISO/IEC 42001 · EU AI Act
  • OWASP Top 10 for LLM
  • AI usage governance, shadow AI
  • Securing AI systems in sensitive environments
Networks and security
  • Fortinet · Palo Alto · Stormshield
  • Cisco · Juniper
  • NSX-T · VMware · Proxmox · Hyper-V
  • VPN · VLAN · routing
Tools
  • Splunk · Kibana · Wireshark
  • Nmap · Efficient IP
  • Ansible · GitHub / GitLab · Docker
  • Visio · draw.io · Excel
,
Languages and soft skills
  • French, native
  • English, professional (B2/C1)
  • Rigorous documentation · explaining technical topics
  • Security project management · multi-party coordination · autonomy
none
Education
DegreeSchoolPeriod
Master’s degree (M2) in IT SecurityWork-study at AtosESGI Paris2018 – 2020
Bachelor’s degree in IT SecurityWork-study at AtosESGI Paris2017 – 2018
DUT GEII, two-year technical degree in electrical engineering and industrial computingNetworks optionIUT de Cergy-Pontoise2015 – 2017
Certifications
CertificationStatus
ISO/IEC 27001 Lead Auditortraining in progress
ISO/IEC 27001 Lead Implementernext target
CISSPnext target

Let’s talk security architecture and GRC

A role in GRC or security architecture? The simplest way is a message on LinkedIn.

Message on LinkedIn (new tab)CV (PDF, in French)