Jérémie
Kassianoff

DevSecOps Consultant: Cybersecurity, Compliance & Cloud

I reduce the attack surface of information systems and align organizations with ISO 27001, NIS2 and SecNumCloud, from audit to remediation.

12 rue de la Part-Dieu, 69003 Lyon, France+33 4 44 44 95 44cybernetics.fr
LinkedIn
Jérémie Kassianoff
15 yrs
of professional experience
12
professional placements
19
professional certifications
1
SaaS platform (video)

Profile

An independent consultant since 2020 and founder of Cybernetics, I work across the whole defensive chain: asset mapping, risk measurement, vulnerability remediation and regulatory compliance.

My scope spans legacy infrastructure (Windows, Linux, hypervisors, network) as much as modern environments (AWS, Azure, Kubernetes, IaC). I translate framework requirements - GDPR, ISO 27001, NIS2, SecNumCloud - into actionable remediation roadmaps, prioritized by real severity and business exposure.

I have worked on international projects (EMEA, APISA, APAC) at Ingenico, Virbac and Energy-Pool, while designing a Cyber Asset Attack Surface Management platform since 2021.

Skills

The technical foundation I bring to engagements.

Systems & virtualization

WindowsLinuxmacOSVMwareHyper-VVeeam

Network & perimeter security

StormshieldFortiGatePalo AltoJunOSCisco MerakiCloudflare

Microsoft 365 & identity

Microsoft 365Entra IDIntuneExchangeSharePointPurview

Detection, vulnerabilities & secrets

Defender XDRTrend Vision OneQualys VMDRDatadogKeeper

Cloud, IaC & containers

AWSAzureOVHcloudScalewayTerraformAnsibleDockerKubernetesKyvernoKubescapeGitLabGitHub

Standards & frameworks

ISO 27001ISO 27005NIS2PCI DSSRGPDOWASP

Experience

Twelve roles since 2012, from field support to multi-cloud compliance.

STORMSHIELDCurrent

May 2026 - present
Application Security Consultant
Freelance · France
  • Designed and drove vulnerability remediation programmes across multi-cloud infrastructures, prioritizing risk based on CVE severity and business exposure.
  • Extended security coverage to Kubernetes compliance posture through policy-as-code enforcement (Kyverno) and continuous misconfiguration scanning against CIS, NSA and MITRE frameworks (Kubescape).
  • Ensured continuous alignment with ISO 27001 and NIS2, translating regulatory requirements into actionable remediation roadmaps.
KubernetesKyvernoKubescapeISO 27001NIS2Multi-cloud

INGENICO

Nov. 2025 - May 2026
Security & Patch Management Consultant
Freelance · Valence site, hybrid · UK-based manager, international context
  • Security & compliance strategy: managed vulnerability remediation based on CVE analysis, ensuring adherence to ISO 27001 and PCI DSS.
  • Led end-to-end patch cycles across multi-environment infrastructure: Windows, Linux, VMware hypervisors, network and storage devices.
  • Controlled operational impact together with business stakeholders, with strict adherence to maintenance windows.
  • Tooling: Qualys Enterprise TruRisk Platform (VMDR), Trend Vision One, Cisco Meraki, FortiGate.
Qualys VMDRTrend Vision OneVMwarePCI DSSPatch management

VIRBAC

Dec. 2024 - Dec. 2025
Data Security Consultant
International context - EU, APISA, LATAM, NAM regions
  • Led the rollout of backup data security best practices across the group's subsidiaries: kick-off with all stakeholders, assessment grid for pilot countries, validation of the support & operations RACI catalogue.
  • Backup policies validated by headquarters; authored integration prerequisites, standard operating procedures and the security & compliance best practices audit matrix.
  • Audited the German, South African, Uruguayan and US sites, then deployed the new data security architecture.
  • Veeam Backup Enterprise Manager, Backup & Replication, Veeam One; AWS IAM, Secrets Manager, KMS, SSM, EC2, S3. ISO 27001:2022 compliance.
VeeamAWSISO 27001:2022Audit international

ENERGY-POOL

June 2022 - Dec. 2024
DevSecOps Consultant
  • Led the transformation of the industrial equipment VPN architecture: solution deployed and provisioned as IaC on AWS (CloudFormation, cloud-init, Terraform, Ansible).
  • Resources: EC2, EBS, S3, ASG, Secrets Manager, KMS, SSM, SQS, SES, Lambda. Production incident resolution alongside the DevOps team.
  • Change management and ISO 27001:2022, ISO 9001 and GDPR recommendations.
  • Additional engagement (July - Dec. 2024): Microsoft Azure architect - Defender XDR, Intune, SharePoint; review of Stormshield/Fortinet rules and Entra ID conditional access.
AWSTerraformAnsibleAzureDefender XDRRGPD

COMPTE R

Apr. 2021 - Apr. 2022
Systems, Security & Network Consultant
  • Modernized the infrastructure and authored the group's security policy: 180 workstations, 25 servers. Operational and security maintenance, systems/network administration, L1 to L3 support.
  • LAN/WLAN integration across two sites (Stormshield, Juniper Networks), IPsec interconnection between three sites, Ansible application deployment on Windows 10 and GPO overhaul at headquarters.
StormshieldJuniperIPsecAnsiblePSSI

XEFI

Sept. 2020 - Apr. 2021
Linux R&D Consultant (security)
  • Built a firewall on Arch Linux: network and security service integration (DNS, DHCP, OpenVPN, PAM, iptables, Exim4, syslog), service hardening and kernel security.
  • Built from scratch both the ISO build system for firmware releases and the management system that distributes updates to the firewall. GitLab CI, SCRUM, NodeJS, Jest, Shell.
Arch LinuxHardeningGitLab CINodeJS

ABICOM

Apr. 2019 - Aug. 2020
Infrastructure & IS Security Consultant
  • Integration, migration, documentation and knowledge-transfer projects. IS operational maintenance, systems/network administration and L2 support, on-call duty, security audits and remediation.
IntégrationMCOAudit

MICHELIN

Jan. - Apr. 2019
DevSecOps training programme
Institut de la PME for Michelin · Clermont-Ferrand, France
  • Development, security and systems operations: Java development (Spring Boot), continuous integration, Linux, Docker, Kubernetes, networking and cryptography fundamentals.
  • Received a Michelin contract offer at the end of the programme.
Java Spring BootCI/CDDockerKubernetesCryptographie

THALES

Sept. - Nov. 2018
Operations Consultant
  • Thales Services Build team: migrated an Active Directory 2003 R2 to a hardened 2012 R2 core for Thales Alenia Space; Ansible automation of Windows installation sources within continuous integration. ISO/ITIL standards.
Active DirectoryAnsibleITIL

DELL

Feb. 2016
Infrastructure Consultant
DIRISI - French forces in Djibouti
  • Brought a new vCenter infrastructure into production: deployed 4 Dell R720 servers and an EqualLogic SAN array.
VMware vCenterDell R720SAN EqualLogicDéfense

IOR-SYSTEM

Aug. 2015 - Aug. 2018
Network & Systems Administrator
  • Managed around 40 clients under preventive maintenance across some 90 production servers.
  • Remote support for Paris-based users, corrective maintenance from L1 to L3.
  • Hardening of workstations, servers and networks.
MCOSupport N1-N3Durcissement

ES2COM

Aug. 2012 - Aug. 2015
Network & Systems Technician
  • On-site technician and administrator of a 3-host vCenter platform hosted at OVH.
  • Built the complete infrastructure for client CAN SAS: Juniper Networks, VMware, HP SAN and Windows Server 2012 R2.
  • Configured network security (VLANs, IDS/IPS, MAC filtering) on JunOS, and client VPN links.
  • P2V migrations, modernization of client firewall routers (VyOS, Endian), GPO-based deployment and workstation hardening with ESET.
VMwareJuniper JunOSHP SANVyOSP2VGPO

Beyond the CV

CYBERNETICS - Founder · Aug. 2020 to date

My CV highlights my most significant engagements. It does not, however, reflect all of my contributions - here are other achievements, sometimes quieter, but no less formative.

2021

External cybersecurity expert, CPME Auvergne-Rhône-Alpes

Admitted to assess companies' resilience to cyber threats. I supported Surgar, CoAudit Group and MGA Distribution, delivering audit reports with recommended improvements ranked by criticality.

2022

Strengthening information system security

Hair Design Group and EAS SEAPORT reached out through my personal blog. I audited their infrastructure, trained their teams and implemented concrete improvements to secure their IS perimeter.

2023

Training Enedis CERT teams

One year of training within the Cyber Defence department on the Cyberbit attack/defence platform. The same year, I helped a French municipal community secure its entire IT estate under the ANSSI programme.

2024

Consolidating and validating skills

A year devoted to training and deepening my knowledge: reading on management and information technology, consolidating the skills acquired since 2020. That period let me structure my vision, enrich my practices and strengthen my posture in a fast-moving technological environment.

2020 → today

A risk measurement platform

I designed a Cyber Asset Attack Surface Management (CAASM) platform that keeps an information system's asset inventory up to date dynamically, without agents and without human intervention. The goal: measure risk in order to assess compliance with cybersecurity best practices. Built on security-by-design principles from the outset, our solution meets OWASP, GDPR and ISO 27001 requirements. It was IP-protected, validated, then released commercially in beta; since July 2025 the platform has been stable and in production, and keeps improving as user feedback and regulatory or technological changes come in.

Since founding my company in 2020 I have integrated and operated an advanced toolset to keep my own information system both secure and performant: Secrets Manager, EASM, WAF, SAST/DAST/IAST, SCA, ASM, SIEM, APM, XDR, MDM, IdP, among others. That expertise let me build a strong defensive (Blue Team) capability, and respond to threats with rigour and anticipation.

Contact

Let's talk about your security, compliance or cloud needs.