MS
MS-Security Consulting
Cybersecurity engineer and consultant

Mohamad Safla Cybersecurity Engineer and Consultant in Paris

I help organizations strengthen cybersecurity governance, manage cyber risks, address regulatory requirements and automate recurring security controls.

Through MS-Security Consulting, I provide a pragmatic approach combining governance, compliance, operational security and purpose-built automation.

Diplômé EFREI Paris
CompTIA Security+
ISO 27001 • EBIOS RM • DORA
Mohamad Safla, cybersecurity engineer and consultant
Mohamad Safla Paris, France
Areas of focus

Work connected to teams’ operational realities

I connect governance, compliance, operational security and tool development to turn cybersecurity requirements into tracked actions.

Governance, risk and compliance

I help organizations structure and improve their cybersecurity approach.

  • EBIOS RM risk assessments
  • ISO/IEC 27001:2022 audit preparation
  • Support with DORA and PCI DSS requirements
  • Security policies, procedures and standards
  • Security control planning and monitoring

Operational security

I help implement practical controls that contribute to protecting information systems.

  • Access and permission reviews
  • Technical security controls
  • Vulnerability management and monitoring
  • Configuration hardening
  • Phishing awareness campaigns
  • Remediation tracking and documentation

Security controls automation

I design tools and automations to reduce manual work, make controls more reliable and improve reporting.

  • Python scripts
  • REST API integrations
  • Security dashboards and KPIs
  • Recurring control automation
  • Result centralisation
  • Automated reporting and distribution
Approach

A pragmatic and documented approach

An intervention designed to integrate smoothly into existing processes without adding friction.

01

A combined GRC and technical view

My experience across governance, compliance, controls and development helps connect regulatory requirements with teams’ operational realities.

02

Prioritised recommendations

Each engagement aims to produce understandable, actionable recommendations ranked by risk, impact and required effort.

03

Usable deliverables

Analysis, procedures, reports and tools are documented so teams can use and maintain them.

04

Clear communication

The scope, objectives, limits and outcomes of an engagement are communicated clearly, without unnecessary complexity.

About

About Mohamad Safla

I am a cybersecurity engineer, an EFREI Paris graduate and CompTIA Security+ certified. My experience covers cybersecurity governance, risk assessment, compliance, operational security and security control automation, including work related to ISO/IEC 27001:2022, EBIOS RM, DORA and PCI DSS.

My objective is to help organizations translate cybersecurity risks and requirements into practical, measurable and realistic action plans.

MS-Security Consulting

Independent consulting and advisory activity by Mohamad Safla.

Client reference

A trusted collaboration in a demanding fintech environment

MS-Security Consulting currently supports Skaleet on cybersecurity governance, compliance, control and automation topics.

Current client
Fintech • Core Banking
Skaleet Core Banking Platform

Skaleet — Core Banking Platform

This collaboration takes place in a demanding fintech environment combining regulatory compliance (ISO 27001, DORA, PCI DSS), operational challenges and reliable security oversight.

✓ Recommended by Skaleet CISO

« flawless commitment, adaptability and results exceeding expectations. »

View LinkedIn recommendation

Practical areas of support

  • Cybersecurity governance and oversight
  • Security plans and controls
  • EBIOS RM risk assessment
  • Compliance and audit preparation
  • Security automation and reporting
Projects and deliverables

Practical tools for tracking and improving controls

This section presents publishable work that is distinct from client references.

Watchtower

Security monitoring and automation project

Design of a monitoring and automation tool for tracking an annual security control plan, centralising results and supporting reporting.

Python
Docker
REST APIs
Security controls

What the project covers

  • Tracking an annual security control plan
  • Centralisation of results and remediation actions
  • Dashboards for oversight and reporting
Skills

Professional skills

Governance, risk and compliance

ISO/IEC 27001:2022
EBIOS RM
DORA
PCI DSS
Cyber Resilience Act
Cyber risk management
Policies and procedures
Security control plans
Audit preparation

Operational security

IAM
Access reviews
Vulnerability management
Technical controls
Hardening
Linux
Docker
Security analysis tools

Development and automation

Python
JavaScript
REST APIs
Dashboards
Tool integration
Reporting automation
Result centralisation
Engagement formats

A format adapted to the defined need

Focused engagement

For an analysis, targeted review, document review or clearly defined advisory need.

Recommandé

Project support

To structure a compliance approach, conduct a risk assessment, prepare an audit or develop a security tool.

Temporary team support

To temporarily complement a cyber team across governance, compliance, control or automation activities.

From €400 excluding tax per day, depending on scope, duration and engagement conditions.

A clear and detailed quotation is prepared following an initial scoping call.

Prise de contact

Let’s discuss your cybersecurity needs

Would you like to structure your security approach, prepare for an audit, improve controls or automate reporting? Based in Paris, I work across the Paris region, France and Europe. I am mobile across Europe and can also work remotely depending on the needs of the engagement.