MS
MS-Security Consulting
Curriculum Vitae

Mohamad Safla’s resume

A readable and printable HTML version, accompanied by the original PDF document.

Download resume (PDF)

Summary

Cybersecurity engineer with experience in governance, risk assessment, IT audit, operational security and automation. I work with IT and business teams on security controls, vulnerabilities and remediation tracking.

Professional experience

Cybersecurity engineer

Skaleet - B2B fintech (Core Banking System)

January 2026 - present
  • Operational management of an annual security control plan covering scoping, evidence collection, reporting and remediation tracking.
  • Initial qualification of SOC alerts and coordination with technical teams.
  • Automation of recurring controls and reporting using Python, Ansible and security APIs.
  • Contribution to the preparation of the second ISO 27001 surveillance audit, including evidence preparation, implementation review and gap tracking.
  • Coordination of Cyber Resilience Act preparation work, including gap analysis, documentation and remediation tracking with security, DevOps and legal teams.
  • Periodic privileged access reviews through the EzeeLogin bastion and corrective action tracking based on the least privilege principle.
  • Strengthening of asset, Shadow IT and Shadow AI governance through automated workstation and server inventory controls.
  • Contribution to security policies, including a Coordinated Vulnerability Disclosure Policy and an AI Acceptable Use Policy.

Cybersecurity engineer intern

Skaleet - B2B fintech (Core Banking System)

April - October 2025
  • End-to-end EBIOS RM risk assessment and risk treatment plan documentation.
  • Execution of an annual security control plan and tracking of vulnerabilities, gaps and remediation actions.
  • Contribution to DORA compliance activities and ISO/IEC 27001:2022 and PCI DSS audit preparation.
  • Design of an internal tool to automate security control tracking, evidence collection and remediation follow-up using Python, JavaScript and APIs.
  • Centralisation of findings from Cyberwatch and engineering tools to improve vulnerability and security control oversight.

GRC and assurance cybersecurity intern

Clearstream Fund Centre

November 2023 - April 2024
  • Security and architecture reviews of critical banking applications.
  • Review of IT risk assessments and support for risk reduction prioritisation.
  • Consolidation of findings into a security posture report presented to the executive committee.
  • Analysis of DORA requirements in a regulated financial environment.

Core skills

Governance and consulting

  • Security control planning
  • Cybersecurity project management
  • IT and business coordination
  • Reporting and remediation tracking

Audit and compliance

  • ISO/IEC 27001:2022
  • DORA
  • PCI DSS
  • Cyber Resilience Act
  • Audit preparation
  • Evidence collection and gap analysis

Risk assessment

  • EBIOS RM
  • Strategic and operational scenarios
  • Risk treatment plans
  • Residual risk

Threats, vulnerabilities and access

  • SOC alerts
  • Vulnerability management
  • Cyberwatch
  • Application and architecture reviews
  • Privileged access reviews
  • EzeeLogin
  • Asset inventory

Automation

  • Python
  • JavaScript
  • Ansible
  • REST APIs
  • Security control and reporting automation

Tools and methods

  • Jira
  • Confluence
  • Burp Suite
  • Kali Linux
  • Coordinated Vulnerability Disclosure Policy
  • AI Acceptable Use Policy
  • Scrum and Agile

Additional information

Certification

CompTIA Security+

Languages

  • French - native
  • English - fluent, CEFR C1 (TOEIC 945/990)

Education

  • Engineering degree - Cybersecurity, Infrastructure & Software, EFREI Paris (2023-2025)
  • International exchange semester in Computer Science and Cryptography, AGH University of Science and Technology, Krakow (2022)
  • Bachelor’s degree in Computer Science with integrated preparatory classes, EFREI Paris (2019-2023)