I assess the maturity of security operations and services using frameworks such as NIST CSF 2.0, SOC-CMM, SIM3, C2M2 and CSA CCM, and turn the results into metrics and executive dashboards. My experience includes aligning information security and AI management systems with ISO 27001, ENS and ISO 42001, risk analysis with MAGERIT, and defining security master plans.
With a background in software development and digital product management, I define and verify security controls across the development lifecycle (SSDLC, DevSecOps): OWASP SAMM and ASVS, and SAST, DAST and SCA checks in CI/CD pipelines. I translate regulatory requirements such as GDPR and the AI Act into controls that teams can actually apply. As an ISC2 member, I adhere to its Code of Ethics.
Outside work, I run a local agentic AI lab (Ollama, CrewAI, MCP) designed with privacy by design, so data never leaves my network, and a secure home automation setup with network segmentation (VLANs), Thread and Matter, with no third-party cloud dependency.