12/01/2023 updated


100 % available
IAM Engineer
France
Only remote
Master of Science in Computer EngineeringJava (Programming Language)Active DirectoryComputing PlatformsSystems EngineeringAuthenticationsC Sharp (Programming Language)Software as a ServiceCloud Computing SecurityComputer SecurityComputer EngineeringData IntegrityExtract Transform Load (ETL)Data LossData MigrationData Security
Microsoft Active Directory, MS AD, Active Directory, C#, Cloud Security, Computer Engineering, Security architecture, cybersecurity, Cyber Security, system platform, cyber threats, data integrity, data loss, data migration, data security, disaster recovery, Messaging System, ETL, ETL process, IBM DB2, RACF, Identity and Access Management, IAM, Identity Management, access governance, Access Management, IT infrastructure, Java, legacy systems, MS Exchange, Microsoft Technologies, Windows 7, migration strategy, two-factor authentication, network segmentation, PCI-DSS, Public Key Infrastructure, PKI, real-time data, regression testing, role-based access control, SailPoint, Single Sign-On, Skype, debugging, SaaS, high availability, systems engineering, IBM Tivoli, tokenization, authentication, VMware ESXi, Virtualization, webservices, WebService, JBoss, Windows Server 2008R2, Windows Server 2008 R2, Windows Server
Languages
EnglishFluentFrenchNative speaker
Project history
Overview:
At BPCE, I successfully orchestrated a three-phased project to strategically optimize,
migrate, and modernize the Identity and Access Management (IAM) ecosystem,
culminating in a transition to SailPoint IIQ- a Next-Gen Identity Governance
Platform.
Situation Analysis:
BPCE was operating on an outdated ITIMv5 infrastructure requiring a complete
overhaul to mitigate security risks, enhance compliance, and boost operational
efficiency without causing business disruptions.
Role & Responsibilities:
* End-to-end project management of the IAM modernization lifecycle, from
optimizing legacy systems to final SailPoint transition.
* Architectural design and roadmapping for migrating IBM Identity Manager V5
to V6, followed by enterprise-wide shift to SailPoint IIQ.
* Demonstrated leadership in project management, team coordination,
stakeholder engagement, risk assessment, and compliance.
Key Contributions:
* Phase 1: Optimization (ITIM5)
* Upgraded ITIMv5 with new functionalities, catering to customer
integrations and business needs.
* Refined provisioning and deprovisioning rules to accommodate new
scopes while ensuring access governance aligned with RBAC and
ABAC models.
* Developed new connectors and enhanced existing ones leveraging
ITIM Java extensions and C# tools ensuring strengthened
interoperability.
* Phase 2: Migration (ISIM6)
* Installed and configured the new ISIMv6 platform, aligning it with the
organization's cybersecurity and operational objectives.
* Crafted a meticulous migration strategy, focusing on data integrity,
system compatibility, and rigorous testing scenarios. Successfully
achieved a 99% uptime during the data migration process.
* Collaborated closely with Identity & Access Governance (IAG) teams,
replacing outdated webservices feeding ITIM5 with the newer, more
efficient ISIM built-in WebService integration.
* Supported the L2 support team in the transition, emphasizing the
migration of their monitoring tools from the old ITIM5 environment to
new ISIM6 platform.
* Conducted training sessions and knowledge transfer for both the L2
support team and end-users, promoting IAM best practices and
proficiency with the new platform.
* Phase 3: Transition to SailPoint IIQ
* Performed comprehensive gap analysis and infrastructure assessment.
* Designed and implemented a seamless data migration strategy,
focusing on high availability and disaster recovery options.
* Gradually decommissioned ISIMv6 in favor of SailPoint IIQ, integrating
the new solution with existing systems.
Result & Impact:
* Successfully migrated and modernized the IAM infrastructure, enhancing
global security, compliance, and user experience.
* Achieved a 99.9% uptime during the migration phase, ensuring business
continuity.
* Significantly elevated BPCE's cybersecurity posture enabling accelerated
digital transformation.
At BPCE, I successfully orchestrated a three-phased project to strategically optimize,
migrate, and modernize the Identity and Access Management (IAM) ecosystem,
culminating in a transition to SailPoint IIQ- a Next-Gen Identity Governance
Platform.
Situation Analysis:
BPCE was operating on an outdated ITIMv5 infrastructure requiring a complete
overhaul to mitigate security risks, enhance compliance, and boost operational
efficiency without causing business disruptions.
Role & Responsibilities:
* End-to-end project management of the IAM modernization lifecycle, from
optimizing legacy systems to final SailPoint transition.
* Architectural design and roadmapping for migrating IBM Identity Manager V5
to V6, followed by enterprise-wide shift to SailPoint IIQ.
* Demonstrated leadership in project management, team coordination,
stakeholder engagement, risk assessment, and compliance.
Key Contributions:
* Phase 1: Optimization (ITIM5)
* Upgraded ITIMv5 with new functionalities, catering to customer
integrations and business needs.
* Refined provisioning and deprovisioning rules to accommodate new
scopes while ensuring access governance aligned with RBAC and
ABAC models.
* Developed new connectors and enhanced existing ones leveraging
ITIM Java extensions and C# tools ensuring strengthened
interoperability.
* Phase 2: Migration (ISIM6)
* Installed and configured the new ISIMv6 platform, aligning it with the
organization's cybersecurity and operational objectives.
* Crafted a meticulous migration strategy, focusing on data integrity,
system compatibility, and rigorous testing scenarios. Successfully
achieved a 99% uptime during the data migration process.
* Collaborated closely with Identity & Access Governance (IAG) teams,
replacing outdated webservices feeding ITIM5 with the newer, more
efficient ISIM built-in WebService integration.
* Supported the L2 support team in the transition, emphasizing the
migration of their monitoring tools from the old ITIM5 environment to
new ISIM6 platform.
* Conducted training sessions and knowledge transfer for both the L2
support team and end-users, promoting IAM best practices and
proficiency with the new platform.
* Phase 3: Transition to SailPoint IIQ
* Performed comprehensive gap analysis and infrastructure assessment.
* Designed and implemented a seamless data migration strategy,
focusing on high availability and disaster recovery options.
* Gradually decommissioned ISIMv6 in favor of SailPoint IIQ, integrating
the new solution with existing systems.
Result & Impact:
* Successfully migrated and modernized the IAM infrastructure, enhancing
global security, compliance, and user experience.
* Achieved a 99.9% uptime during the migration phase, ensuring business
continuity.
* Significantly elevated BPCE's cybersecurity posture enabling accelerated
digital transformation.
Overview:
Championed the design, development, and deployment of a robust Data Protection
Platform focused on safeguarding data during its transition from internal servers to
external cloud platforms, particularly SaaS applications.
Situation Analysis:
Société Générale faced critical challenges in securely transitioning sensitive data to
the cloud.
Role & Responsibilities:
* End-to-end project management, from conceptualization to implementation
and monitoring.
* Security architecture planning, stakeholder engagement, and oversight of
compliance initiatives.
Key Contributions:
* Blueprint Design: Defined the security blueprint incorporating DLP and
encryption techniques.
* Service Integration: Managed integration of a real-time tokenization system
for sensitive data.
* ETL Management: Implemented integrated ETL process to securely
transform sensitive data fields using tokenization, encryption and hashing
algorithms.
* Documentation : Authored comprehensive documentation, including test logs,
operational, installation, and architectural guidelines.
* Anomaly Resolution : Managed post-implementation anomalies through
corrective action plans and vendor management, ensuring continuous
improvement.
Result & Impact:
* Successful implementation of a comprehensive real-time data protection
platform, securing sensitive data in transit to the cloud.
* Strengthened cybersecurity infrastructure ensuring client trust and business
continuity.
Championed the design, development, and deployment of a robust Data Protection
Platform focused on safeguarding data during its transition from internal servers to
external cloud platforms, particularly SaaS applications.
Situation Analysis:
Société Générale faced critical challenges in securely transitioning sensitive data to
the cloud.
Role & Responsibilities:
* End-to-end project management, from conceptualization to implementation
and monitoring.
* Security architecture planning, stakeholder engagement, and oversight of
compliance initiatives.
Key Contributions:
* Blueprint Design: Defined the security blueprint incorporating DLP and
encryption techniques.
* Service Integration: Managed integration of a real-time tokenization system
for sensitive data.
* ETL Management: Implemented integrated ETL process to securely
transform sensitive data fields using tokenization, encryption and hashing
algorithms.
* Documentation : Authored comprehensive documentation, including test logs,
operational, installation, and architectural guidelines.
* Anomaly Resolution : Managed post-implementation anomalies through
corrective action plans and vendor management, ensuring continuous
improvement.
Result & Impact:
* Successful implementation of a comprehensive real-time data protection
platform, securing sensitive data in transit to the cloud.
* Strengthened cybersecurity infrastructure ensuring client trust and business
continuity.
Overview:
I spearheaded integration and management of a Tokenization Platform to protect
sensitive banking data in compliance with stringent PCI-DSS regulations.
Situation Analysis:
Société Générale required a state-of-the-art solution to secure sensitive financial
data, especially in the face of rising cyber threats and strict compliance mandates like
PCI-DSS.
Role & Responsibilities:
* Served as the lead for the integration of the Tokenization Platform, which
included technical architecture, security protocols, and client integrations.
* Played a key role in liaising between technical teams, vendors, and
stakeholders to achieve project milestones.
Key Contributions:
* Test Planning : Crafted rigorous test scenarios and quality gates to validate
the robustness of the Tokenization service.
* Technical Documentation : Authored comprehensive documentation detailing
architecture, security requirements, and best practices.
* Client Integration : Facilitated seamless integration into client-facing
WebService and zOS applications.
* Deployment: Orchestrated deployment of Tokenization Platform in a highly
secure environment implementing strict network segmentation to limit PCI
scope.
Result & Impact:
* Deployed data protection via Tokenization system platform achieving 100%
PCI-DSS compliance.
* Enabled secure handling of sensitive financial data, reinforcing the
cybersecurity infrastructure and gaining client trust.
* Reduced PCI-DSS compliance maintenance costs by 55% for application
integrating the tokenization system, effectively rendering these applications
out of scope.
I spearheaded integration and management of a Tokenization Platform to protect
sensitive banking data in compliance with stringent PCI-DSS regulations.
Situation Analysis:
Société Générale required a state-of-the-art solution to secure sensitive financial
data, especially in the face of rising cyber threats and strict compliance mandates like
PCI-DSS.
Role & Responsibilities:
* Served as the lead for the integration of the Tokenization Platform, which
included technical architecture, security protocols, and client integrations.
* Played a key role in liaising between technical teams, vendors, and
stakeholders to achieve project milestones.
Key Contributions:
* Test Planning : Crafted rigorous test scenarios and quality gates to validate
the robustness of the Tokenization service.
* Technical Documentation : Authored comprehensive documentation detailing
architecture, security requirements, and best practices.
* Client Integration : Facilitated seamless integration into client-facing
WebService and zOS applications.
* Deployment: Orchestrated deployment of Tokenization Platform in a highly
secure environment implementing strict network segmentation to limit PCI
scope.
Result & Impact:
* Deployed data protection via Tokenization system platform achieving 100%
PCI-DSS compliance.
* Enabled secure handling of sensitive financial data, reinforcing the
cybersecurity infrastructure and gaining client trust.
* Reduced PCI-DSS compliance maintenance costs by 55% for application
integrating the tokenization system, effectively rendering these applications
out of scope.