Mohamad Safla – Cybersecurity Engineer and Consultant in Paris
I help organizations strengthen cybersecurity governance, manage cyber risks, address regulatory requirements and automate recurring security controls.
Through MS-Security Consulting, I provide a pragmatic approach combining governance, compliance, operational security and purpose-built automation.

Work connected to teams’ operational realities
I connect governance, compliance, operational security and tool development to turn cybersecurity requirements into tracked actions.
Governance, risk and compliance
I help organizations structure and improve their cybersecurity approach.
- EBIOS RM risk assessments
- ISO/IEC 27001:2022 audit preparation
- Support with DORA and PCI DSS requirements
- Security policies, procedures and standards
- Security control planning and monitoring
Operational security
I help implement practical controls that contribute to protecting information systems.
- Access and permission reviews
- Technical security controls
- Vulnerability management and monitoring
- Configuration hardening
- Phishing awareness campaigns
- Remediation tracking and documentation
Security controls automation
I design tools and automations to reduce manual work, make controls more reliable and improve reporting.
- Python scripts
- REST API integrations
- Security dashboards and KPIs
- Recurring control automation
- Result centralisation
- Automated reporting and distribution
A pragmatic and documented approach
An intervention designed to integrate smoothly into existing processes without adding friction.
A combined GRC and technical view
My experience across governance, compliance, controls and development helps connect regulatory requirements with teams’ operational realities.
Prioritised recommendations
Each engagement aims to produce understandable, actionable recommendations ranked by risk, impact and required effort.
Usable deliverables
Analysis, procedures, reports and tools are documented so teams can use and maintain them.
Clear communication
The scope, objectives, limits and outcomes of an engagement are communicated clearly, without unnecessary complexity.
About Mohamad Safla
I am a cybersecurity engineer, an EFREI Paris graduate and CompTIA Security+ certified. My experience covers cybersecurity governance, risk assessment, compliance, operational security and security control automation, including work related to ISO/IEC 27001:2022, EBIOS RM, DORA and PCI DSS.
“My objective is to help organizations translate cybersecurity risks and requirements into practical, measurable and realistic action plans.”
MS-Security Consulting
Independent consulting and advisory activity by Mohamad Safla.
A trusted collaboration in a demanding fintech environment
MS-Security Consulting currently supports Skaleet on cybersecurity governance, compliance, control and automation topics.

Skaleet — Core Banking Platform
This collaboration takes place in a demanding fintech environment combining regulatory compliance (ISO 27001, DORA, PCI DSS), operational challenges and reliable security oversight.
✓ Recommended by Skaleet CISO
« flawless commitment, adaptability and results exceeding expectations. »
View LinkedIn recommendationPractical areas of support
- Cybersecurity governance and oversight
- Security plans and controls
- EBIOS RM risk assessment
- Compliance and audit preparation
- Security automation and reporting
Practical tools for tracking and improving controls
This section presents publishable work that is distinct from client references.
Security monitoring and automation project
Design of a monitoring and automation tool for tracking an annual security control plan, centralising results and supporting reporting.
What the project covers
- Tracking an annual security control plan
- Centralisation of results and remediation actions
- Dashboards for oversight and reporting
Professional skills
Governance, risk and compliance
Operational security
Development and automation
A format adapted to the defined need
Focused engagement
For an analysis, targeted review, document review or clearly defined advisory need.
Project support
To structure a compliance approach, conduct a risk assessment, prepare an audit or develop a security tool.
Temporary team support
To temporarily complement a cyber team across governance, compliance, control or automation activities.
From €400 excluding tax per day, depending on scope, duration and engagement conditions.
A clear and detailed quotation is prepared following an initial scoping call.
Let’s discuss your cybersecurity needs
Would you like to structure your security approach, prepare for an audit, improve controls or automate reporting? Based in Paris, I work across the Paris region, France and Europe. I am mobile across Europe and can also work remotely depending on the needs of the engagement.