Curriculum Vitae
Mohamad Safla’s resume
A readable and printable HTML version, accompanied by the original PDF document.
Summary
Cybersecurity engineer with experience in governance, risk assessment, IT audit, operational security and automation. I work with IT and business teams on security controls, vulnerabilities and remediation tracking.
Professional experience
Cybersecurity engineer
Skaleet - B2B fintech (Core Banking System)
January 2026 - present
- Operational management of an annual security control plan covering scoping, evidence collection, reporting and remediation tracking.
- Initial qualification of SOC alerts and coordination with technical teams.
- Automation of recurring controls and reporting using Python, Ansible and security APIs.
- Contribution to the preparation of the second ISO 27001 surveillance audit, including evidence preparation, implementation review and gap tracking.
- Coordination of Cyber Resilience Act preparation work, including gap analysis, documentation and remediation tracking with security, DevOps and legal teams.
- Periodic privileged access reviews through the EzeeLogin bastion and corrective action tracking based on the least privilege principle.
- Strengthening of asset, Shadow IT and Shadow AI governance through automated workstation and server inventory controls.
- Contribution to security policies, including a Coordinated Vulnerability Disclosure Policy and an AI Acceptable Use Policy.
Cybersecurity engineer intern
Skaleet - B2B fintech (Core Banking System)
April - October 2025
- End-to-end EBIOS RM risk assessment and risk treatment plan documentation.
- Execution of an annual security control plan and tracking of vulnerabilities, gaps and remediation actions.
- Contribution to DORA compliance activities and ISO/IEC 27001:2022 and PCI DSS audit preparation.
- Design of an internal tool to automate security control tracking, evidence collection and remediation follow-up using Python, JavaScript and APIs.
- Centralisation of findings from Cyberwatch and engineering tools to improve vulnerability and security control oversight.
GRC and assurance cybersecurity intern
Clearstream Fund Centre
November 2023 - April 2024
- Security and architecture reviews of critical banking applications.
- Review of IT risk assessments and support for risk reduction prioritisation.
- Consolidation of findings into a security posture report presented to the executive committee.
- Analysis of DORA requirements in a regulated financial environment.
Core skills
Governance and consulting
- Security control planning
- Cybersecurity project management
- IT and business coordination
- Reporting and remediation tracking
Audit and compliance
- ISO/IEC 27001:2022
- DORA
- PCI DSS
- Cyber Resilience Act
- Audit preparation
- Evidence collection and gap analysis
Risk assessment
- EBIOS RM
- Strategic and operational scenarios
- Risk treatment plans
- Residual risk
Threats, vulnerabilities and access
- SOC alerts
- Vulnerability management
- Cyberwatch
- Application and architecture reviews
- Privileged access reviews
- EzeeLogin
- Asset inventory
Automation
- Python
- JavaScript
- Ansible
- REST APIs
- Security control and reporting automation
Tools and methods
- Jira
- Confluence
- Burp Suite
- Kali Linux
- Coordinated Vulnerability Disclosure Policy
- AI Acceptable Use Policy
- Scrum and Agile
Additional information
Certification
CompTIA Security+
Languages
- French - native
- English - fluent, CEFR C1 (TOEIC 945/990)
Education
- Engineering degree - Cybersecurity, Infrastructure & Software, EFREI Paris (2023-2025)
- International exchange semester in Computer Science and Cryptography, AGH University of Science and Technology, Krakow (2022)
- Bachelor’s degree in Computer Science with integrated preparatory classes, EFREI Paris (2019-2023)