Security
& stuffsince 2004
CISO. I assess what threatens information systems, I contain it, and I explain how. The rest comes from the field: engagements, incidents, and personal research.
CISO Paris FR Handle @zackhimself
about
Profile
Who I am
I started working in IT in the early 2000s and security never let go of me since. I learned early how to assess the risks weighing on an information system, and how to contain them.
Client work and personal research both feed that practice, and keep it moving.
What I do
- Audits
- Penetration testing and passive audits.
- IT management
- Estate administration, migrations, standardisation.
- Threat watch
- Public scene as well as underground. No source gets snubbed: the point is to stay one step ahead.
- Awareness
- Seminars, technical write-ups and tutorials, plus plain-language versions for everyone else.
Languages
- Spoken
- French, English, Arabic.
- Hobbies
- Reading and writing. Fencing. Hunting for new attack vectors.
rated out of 4 stars
Skills
- Hacking
- Risk management
- Speaking & awareness
- Teaching
- Incident management
2004 to now
Career
-
2018 → now()
Chief Information Security Officer
MNT, Henner, Leboncoin, Believe
-
2014 → 2018
Security consulting
Davidson Consulting, Capgemini, PwC
-
2008 → 2014
System & Security Engineering
Wengo, Vivendi group
-
2006 → 2008
Security stuff
Confidential
-
2004 → 2006
System & Security Engineering
Davimi
responsible disclosure
Feats of arms
Vulnerabilities reported over the course of my research. Among the organisations helped:
- Evernote
- Drupal
- eLearnSecurity
- EDF
- Viadeo
- GDF
- Samsung
- Star Wars
- Swatch
- leboncoin
- Melty Network
- Canal+
~/randomNotes
Notes
[zack@localhost]$ cat ~/randomNotes
zack [at] this domain