12/01/2023 updated

**** ******** ****
100 % available

IAM Engineer

France
Only remote
Master of Science in Computer Engineering
France
Only remote
Master of Science in Computer Engineering

Profile attachments

CV - Tahar IBRI

Java (Programming Language)Active DirectoryComputing PlatformsSystems EngineeringAuthenticationsC Sharp (Programming Language)Software as a ServiceCloud Computing SecurityComputer SecurityComputer EngineeringData IntegrityExtract Transform Load (ETL)Data LossData MigrationData SecurityIBM DB2DebuggingDisaster RecoveryMulti-Factor AuthenticationVMware ESX ServersMicrosoft Exchange ServerTivoli Management FrameworkIdentity ManagementWildFly (JBoss AS)Enterprise Messaging SystemsMicrosoft SoftwaresWindows ServersNetwork SegmentationPCI Data Security StandardsPublic Key InfrastructureIBM Resource Access Control FacilityRole-Based Access ControlRegression TestingMigration ManagerSkype for BusinessSingle Sign-OnTokenizationVirtualizationWeb ServicesSystem AvailabilityData ProtectionCybercrimeReal Time DataSailPointLegacy Systems
Microsoft Active Directory, MS AD, Active Directory, C#, Cloud Security, Computer Engineering, Security architecture, cybersecurity, Cyber Security, system platform, cyber threats, data integrity, data loss, data migration, data security, disaster recovery, Messaging System, ETL, ETL process, IBM DB2, RACF, Identity and Access Management, IAM, Identity Management, access governance, Access Management, IT infrastructure, Java, legacy systems, MS Exchange, Microsoft Technologies, Windows 7, migration strategy, two-factor authentication, network segmentation, PCI-DSS, Public Key Infrastructure, PKI, real-time data, regression testing, role-based access control, SailPoint, Single Sign-On, Skype, debugging, SaaS, high availability, systems engineering, IBM Tivoli, tokenization, authentication, VMware ESXi, Virtualization, webservices, WebService, JBoss, Windows Server 2008R2, Windows Server 2008 R2, Windows Server

Languages

EnglishFluentFrenchNative speaker

Project history

IBM Identity Management Specialist (Cybersecurity & IAM Architect)

BPCE Infogérance & Technologies

Banking & Financial Services

>10.000 team member

Overview:

At BPCE, I successfully orchestrated a three-phased project to strategically optimize,
migrate, and modernize the Identity and Access Management (IAM) ecosystem,
culminating in a transition to SailPoint IIQ- a Next-Gen Identity Governance
Platform.

Situation Analysis:

BPCE was operating on an outdated ITIMv5 infrastructure requiring a complete
overhaul to mitigate security risks, enhance compliance, and boost operational
efficiency without causing business disruptions.



Role & Responsibilities:

* End-to-end project management of the IAM modernization lifecycle, from
optimizing legacy systems to final SailPoint transition.

* Architectural design and roadmapping for migrating IBM Identity Manager V5
to V6, followed by enterprise-wide shift to SailPoint IIQ.

* Demonstrated leadership in project management, team coordination,
stakeholder engagement, risk assessment, and compliance.

Key Contributions:

* Phase 1: Optimization (ITIM5)

* Upgraded ITIMv5 with new functionalities, catering to customer
integrations and business needs.

* Refined provisioning and deprovisioning rules to accommodate new
scopes while ensuring access governance aligned with RBAC and
ABAC models.

* Developed new connectors and enhanced existing ones leveraging
ITIM Java extensions and C# tools ensuring strengthened
interoperability.




* Phase 2: Migration (ISIM6)

* Installed and configured the new ISIMv6 platform, aligning it with the
organization's cybersecurity and operational objectives.

* Crafted a meticulous migration strategy, focusing on data integrity,
system compatibility, and rigorous testing scenarios. Successfully
achieved a 99% uptime during the data migration process.

* Collaborated closely with Identity & Access Governance (IAG) teams,
replacing outdated webservices feeding ITIM5 with the newer, more
efficient ISIM built-in WebService integration.

* Supported the L2 support team in the transition, emphasizing the
migration of their monitoring tools from the old ITIM5 environment to
new ISIM6 platform.

* Conducted training sessions and knowledge transfer for both the L2
support team and end-users, promoting IAM best practices and
proficiency with the new platform.

* Phase 3: Transition to SailPoint IIQ

* Performed comprehensive gap analysis and infrastructure assessment.

* Designed and implemented a seamless data migration strategy,
focusing on high availability and disaster recovery options.

* Gradually decommissioned ISIMv6 in favor of SailPoint IIQ, integrating
the new solution with existing systems.

Result & Impact:

* Successfully migrated and modernized the IAM infrastructure, enhancing
global security, compliance, and user experience.

* Achieved a 99.9% uptime during the migration phase, ensuring business
continuity.

* Significantly elevated BPCE's cybersecurity posture enabling accelerated
digital transformation.

Project Manager, Data Protection & Cloud Security

Société Générale

Banking & Financial Services

>10.000 team member

Overview:

Championed the design, development, and deployment of a robust Data Protection
Platform focused on safeguarding data during its transition from internal servers to
external cloud platforms, particularly SaaS applications.

Situation Analysis:

Société Générale faced critical challenges in securely transitioning sensitive data to
the cloud.

Role & Responsibilities:

* End-to-end project management, from conceptualization to implementation
and monitoring.

* Security architecture planning, stakeholder engagement, and oversight of
compliance initiatives.

Key Contributions:

* Blueprint Design: Defined the security blueprint incorporating DLP and
encryption techniques.

* Service Integration: Managed integration of a real-time tokenization system
for sensitive data.

* ETL Management: Implemented integrated ETL process to securely
transform sensitive data fields using tokenization, encryption and hashing
algorithms.

* Documentation : Authored comprehensive documentation, including test logs,
operational, installation, and architectural guidelines.

* Anomaly Resolution : Managed post-implementation anomalies through
corrective action plans and vendor management, ensuring continuous
improvement.

Result & Impact:

* Successful implementation of a comprehensive real-time data protection
platform, securing sensitive data in transit to the cloud.

* Strengthened cybersecurity infrastructure ensuring client trust and business
continuity.

Data Protection Specialist & Cybersecurity Consultant

Société Générale; Fontenay-sous

Banking & Financial Services

>10.000 team member

Overview:

I spearheaded integration and management of a Tokenization Platform to protect
sensitive banking data in compliance with stringent PCI-DSS regulations.

Situation Analysis:

Société Générale required a state-of-the-art solution to secure sensitive financial
data, especially in the face of rising cyber threats and strict compliance mandates like
PCI-DSS.

Role & Responsibilities:

* Served as the lead for the integration of the Tokenization Platform, which
included technical architecture, security protocols, and client integrations.

* Played a key role in liaising between technical teams, vendors, and
stakeholders to achieve project milestones.

Key Contributions:

* Test Planning : Crafted rigorous test scenarios and quality gates to validate
the robustness of the Tokenization service.

* Technical Documentation : Authored comprehensive documentation detailing
architecture, security requirements, and best practices.

* Client Integration : Facilitated seamless integration into client-facing
WebService and zOS applications.

* Deployment: Orchestrated deployment of Tokenization Platform in a highly
secure environment implementing strict network segmentation to limit PCI
scope.

Result & Impact:

* Deployed data protection via Tokenization system platform achieving 100%
PCI-DSS compliance.

* Enabled secure handling of sensitive financial data, reinforcing the
cybersecurity infrastructure and gaining client trust.

* Reduced PCI-DSS compliance maintenance costs by 55% for application
integrating the tokenization system, effectively rendering these applications
out of scope.

IBM Identity Management Specialist & Cybersecurity Architect

Crédit Agricole Consumer Finance

Banking & Financial Services

5000-10.000 team member

Overview:

As an experienced IBM Identity Management specialist, I spearheaded the
comprehensive upgrade and migration of the IBM Tivoli Identity Manager (ITIM)
platform from version 5.1 to the more robust and secure ISIM 6.0.

Situation Analysis:

Credit Agricole's existing ITIM platform was outdated and needed overhaul to align
with modern cybersecurity standards and best practices.

Role & Responsibilities:

* Orchestrated the entire project, from architectural planning to migration and
post-migration support.

* Collaborated closely with internal IT teams and external vendors to ensure
seamless integration with source and target systems including MS AD, MS
Exchange, RACF, and Top Secret.

Key Contributions:

* Architectural Planning : Defined the overall migration roadmap, leveraging
Identity Governance and Access Management best practices.

* Implementation : Installed the new ISIM 6 platform and managed data
migration from ITIM 5, ensuring no data loss.

* Documentation : Created an extensive documentation, covering architecture,
installation, and operational guidelines.

* Team Training : Delivered tailored functional and technical training sessions
for IT teams, highlighting ITIM functionalities and new features in ISIM 6.0.

Result & Impact:

* Successfully upgraded the ITIM platform, achieving compliance with modern
cybersecurity standards.

* Completed timely migration with zero data loss and no business disruption.

* Conducted regression testing to validate the system's reliability and
functionality.

* Elevated the skill level of the IT team through targeted training.

IBM Identity Management Specialist & Operations Analyst

Crédit Agricole Consumer Finance

Banking & Financial Services

1000-5000 team member

Overview:

I joined CACF facing challenges with the ITIM5 platform. My role was two-fold:
resolve technical issues and upskill teams on this crucial identity management
solution for 10,000+ employees.

Situation Analysis:

The ITIM5 platform suffered instability with recurring incidents like certificate
expirations and replication errors. Moreover, loss of expert resources caused a
knowledge gap within technical and business teams.

Role & Responsibilities:

* Quick incident response and proactive maintenance to ensure platform
availability and security.

* Designed and deployed advanced workflows for dormant and deactivated
account cleanup to refine the user base.

* Ongoing training for teams, especially ITIM5 administrators, on day-to-day
management.

Key Contributions:

* Incident Management : Diagnosis and corrected incidents, enhancing
reliability and uptime.

* Feasibility Study : In-depth analysis to develop a cleaning tool for dormant
accounts.

* Testing & Validation : Rigorous testing and validation procedures to ensure
the effectiveness of the cleaning tool.

* Stakeholder Engagement : Hands-on training for teams on ITIM5 covering
general operations and advanced debugging techniques.

Result & Impact:

* Rapid IAM platform stabilization increasing user and stakeholder confidence.

* Significantly reduced risks from dormant and non-compliant accounts by
removing 15% inactive accounts.

* Empowered teams to proactively administer and evolve the tool through
continuous training.

Cyber Security Specialist & PKI Architect

CHU de Lille

Pharmaceuticals & Medical Technology

>10.000 team member

Overview:

As a Cyber Security Specialist at CHU de Lille, a leading healthcare institution, I was
entrusted with the critical task of implementing a robust Public Key Infrastructure
(PKI) to bolster the security framework for confidential medical documents.

Situation Analysis:

CHU de Lille required a state-of-the-art PKI solution to safeguard the integrity and
confidentiality of sensitive medical documents, in compliance with healthcare
regulations such as RGS**.

Role & Responsibilities:

* Led planning, installation, and deployment of the PKI solution.

* Served as the primary liaison between the cybersecurity team and the
healthcare professionals to understand and meet the security requirements for
medical documents.

Key Contributions:

* Architectural Design : Crafted a comprehensive architecture and migration
plan, incorporating best practices in PKI management and cryptographic
standards.

* Technical Setup : Installed and configured EJBCA 6.2.0 and JBoss EAP 6.3
on a Windows Server 2008R2, ensuring optimized performance and security
features.

* Quality Assurance : Conducted exhaustive tests, including non-regression
and functional tests, to validate the robustness of the PKI solution.

* User Acceptance Testing (UAT) : Prepared and executed UAT scenarios,
collecting feedback from end-users and making necessary adjustments.

* Production Rollout : Seamlessly migrated the validated PKI solution to the
production environment, following a detailed deployment checklist.

Result & Impact:

* Achieved successful PKI implementation meeting all security and compliance
requirements including RGS**.




* Significantly enhanced CHU de Lille's security posture for safeguarding
sensitive medical documents.

IBM Identity Management Specialist & IAM Architect

Sonelgaz

Energy, Water & Environment

>10.000 team member

Overview:

At Sonelgaz, a leading utility company, I played a critical role in establishing and
fortifying the organization's Identity and Access Management (IAM) framework,
impacting over 75,000 employees across multiple departments.

Situation Analysis:

With a rapidly growing employee base and evolving security needs, Sonelgaz
required a robust IAM solution to ensure secure, efficient, and compliant access to
various internal systems.

Role & Responsibilities:

* Pioneered the implementation of IBM Tivoli Identity Manager (ITIM) for an
initial user base of 10,000, later scalable to the entire organization.

* Served as the key architect for integrating ITIM with IBM Tivoli Access
Manager for Enterprise Single Sign-On (TAM E-SSO) and Microsoft Active
Directory.

Key Contributions:

* ITIM Deployment : Successfully implemented ITIM 5.1, focusing on automated
account provisioning, role-based access control, and custom connector
development.

* TAM E-SSO Integration : Installed and configured TAM E-SSO 8.2.0, creating
a seamless and secure authentication experience by defining application
profiles and implementing two-factor authentication.

* Active Directory Configuration : Installed and configured Microsoft Active
Directory 2008 R2, focusing on optimal replication topology, FSMO roles, and
Group Policy Objects (GPOs).

Result & Impact:

* Achieved a remarkable transformation of Sonelgaz's IAM capabilities,
enhancing overall security, user experience, and organizational efficiency.




* Received commendations for successfully managing this large-scale project
with minimal disruption to business operations.

System and Security Engineer

Intervalle Technologies
Overview:

Early in my career, I served as a System and Security Engineer at Intervalle
Technologies, where I was responsible for multiple transformative initiatives aimed at
modernizing the company's IT infrastructure.

Situation Analysis:

Intervalle Technologies sought to capitalize on emerging technologies to advance its
internal systems and meet the growing demands of the business landscape.

Role & Responsibilities:

* Spearheaded multiple projects aimed at improving internal communication,
system performance, and technological readiness for future challenges.

Key Contributions:

* Messaging System: Designed and deployed an internal messaging system
using Open-Xchange, thereby enhancing organizational communication and
collaboration.

* Virtualization: Led the migration from VMware ESXi 4.1 to the more scalable
and efficient VMware ESXi 5.1.

* Proof of Concepts (PoCs) : Actively contributed to PoCs, rigorously
evaluating the feasibility and efficacy of emerging technologies.

Result & Impact:

* Laid a solid foundation for my career, acquiring a multi-faceted skill set in
systems engineering, virtualization, and cybersecurity.

* Left a lasting impact on the company's technological readiness, preparing it for
future scalability and innovation.

Contact form

Log in to get in touch

You need to be logged in to use the contact form.

Sign upLog in