You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Ethan BakEB

Ethan Bak

CISO/Senior Manager GRC, TPRM & Security Architect

EUR 1'200/Tag
Lausanne, CH
15+ Jahre

Durchschnittliche Reaktionszeit: 1h

Über Ethan

Is your organization navigating DORA, NIS 2, the EU AI Act, or FINMA compliance while trying to build a resilient security architecture?
I help CISOs, CIOs, and executive teams turn complex regulatory pressure into structured, actionable security programs.
With 15 years of cybersecurity leadership across financial services, energy, and management consulting — including 5 years as Senior Manager at PwC France — I bring a rare hybrid expertise that combines three capabilities most consultants deliver separately: strategic GRC leadership, hands-on security architecture, and end-to-end project delivery.
What sets me apart is my depth in AI Security: I design LLM governance frameworks aligned with NIST AI RMF and EU AI Act, and I conduct adversarial testing of AI systems — a niche few senior profiles can offer.
Typical engagements include: fractional/virtual CISO missions, Zero Trust & cloud security architecture (AWS, Azure, GCP), large-scale TPRM programs (1,400+ vendor assessments/year at PwC), DORA/FINMA/NIS 2 compliance roadmaps, SOC design and deployment (IT & OT/ICS), and C-suite security reporting via Power BI dashboards.
Advanced training completed: CISSP · CISM · CISA · CRISC · CCSP · TOGAF · CEH · CARP · CAISP · AIGP · OSCP
Based in Gaillard (74), 15 min from Geneva — available for Swiss, French, and international remote contracts
  • Französisch

    Muttersprachlich oder zweisprachig

  • Englisch

    Muttersprachlich oder zweisprachig

  • Spanisch

    Konversationssicher

Vor Ort möglich
Lausanne (bis zu 50 km)

Projekt- und Berufserfahrung

  • PwC
    Senior Manager GRC, TPRM & Security Architect
    BERATUNG & AUDITS
    Januar 2020 - September 2025 (5 Jahre und 8 Monate)
    France
    ▸ GRC Leadership — Supervised GRC programs: third-party risk, internal controls, audits, regulatory compliance (ISO 27001, NIST CSF, GDPR, DORA, EBA).
    ▸ TPRM at Scale — Managed 1,400+ annual vendor security assessments end-to-end: scope, questionnaires, evidence collection, scoring, risk committees, go/no-go decisions. KYS due diligence and contractual security requirements (MSA, SLA, OLA).
    ▸ Cloud Security — Validated 300+ architectures/yr. Secure GCP→M365 migration. Azure Key Vault + GCP KMS on 100% of critical workloads. 70% reduction in critical cloud vulnerabilities via Prisma Cloud CSPM.
    ▸ AI Governance — Built LLM governance framework (EU AI Act, NIST AI RMF). Adversarial testing with Garak, Counterfit, Cranium, HiddenLayer.
    ▸ Team Management — Managed 2 teams (8 experts): SOC + vulnerability management. Monthly COMEX reporting via Power BI. 40% vulnerability reduction KPI.
    IT-Architektur GRC (Governance, Risiko & Compliance) Datenschutz (GDPR, CCPA) Management von Cybersecurity-Vorfällen Analyse de risques
  • Inetum → ESP Bank
    Cybersecurity Architect & Project Manager
    BANKEN & VERSICHERUNGEN
    Juni 2019 - Dezember 2019 (6 Monate)
    Paris, Frankreich
    ▸ TOGAF ADM architecture design integrating SentinelOne, Cisco NAC, Wallix Bastion — HLD/DAT documentation.
    ▸ Security audit of existing architectures: network flow correction, firewall optimization for GDPR compliance.
    ▸ Digital transformation & change management: process modernization and post-deployment impact validation.

    🗂 PM: End-to-end project management of OOdrive migration and RSA deployment
    • · KPI dashboards for steering committees
    ◦ · Deliverable planning (ITIL).

    Tech: Windows 10/7, RSA, Wallix Bastion, SentinelOne, Cisco NAC, Citrix, Change Auditor
    Gestion de projet Audit de sécurité IT-Architektur Cybersecurity GRC
  • Inetum → LCL Bank (Crédit Agricole Group)
    Cybersecurity Architect & Security Project Manager
    BANKEN & VERSICHERUNGEN
    September 2016 - Juni 2019 (2 Jahre und 9 Monate)
    Paris, Frankreich
    Nearly 3-year engagement at LCL, a major French retail bank within the Crédit Agricole Group. Dual role as Security Architect and Project Manager, responsible for the Windows 10 migration program, endpoint security modernization, and security governance reinforcement across the bank's entire IT estate.
    ▶ Migration & Security Modernization▸ Windows 10 Migration Piloted the full technical migration from Windows 7 to Windows 10 across the entire workstation fleet, with SCCM deployment for centralized patch and configuration management.▸ Endpoint Security Reinforcement Integrated SentinelOne (EDR) and Symantec Endpoint Protection v14.2 for advanced protection of workstations and servers.▸ Privileged Access Management Deployed CyberArk for administrator identity and secrets management aligned with Crédit Agricole Group policies.▸ Network Access Control Deployed Cisco NAC for network segmentation and policy-based access restriction across the bank's infrastructure.
    Analyse de risques Management von Cybersecurity-Vorfällen Audit de sécurité Gestion de projet Cybersécurité

Empfehlungen

Sei die erste Person, die Ethan empfiehlt

Teile Deine Erfahrung aus der Zusammenarbeit mit diesem Freelancer.

Diese Freelancer passen auch zu Ihren Kriterien

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Ausbildung und Abschlüsse

  • Azure AI Engineer Associate (AI-102)
    Azure AI Engineer Associate (AI-102)
  • Microsoft Responsible AI
    Microsoft Responsible AI

Fähigkeiten

Kategorien