Jérémie
Kassianoff
DevSecOps Consultant: Cybersecurity, Compliance & Cloud
I reduce the attack surface of information systems and align organizations with ISO 27001, NIS2 and SecNumCloud, from audit to remediation.

Profile
An independent consultant since 2020 and founder of Cybernetics, I work across the whole defensive chain: asset mapping, risk measurement, vulnerability remediation and regulatory compliance.
My scope spans legacy infrastructure (Windows, Linux, hypervisors, network) as much as modern environments (AWS, Azure, Kubernetes, IaC). I translate framework requirements - GDPR, ISO 27001, NIS2, SecNumCloud - into actionable remediation roadmaps, prioritized by real severity and business exposure.
I have worked on international projects (EMEA, APISA, APAC) at Ingenico, Virbac and Energy-Pool, while designing a Cyber Asset Attack Surface Management platform since 2021.
Skills
The technical foundation I bring to engagements.
Network & perimeter security
Microsoft 365 & identity
Detection, vulnerabilities & secrets
Cloud, IaC & containers
Standards & frameworks
Experience
Twelve roles since 2012, from field support to multi-cloud compliance.
STORMSHIELDCurrent
May 2026 - present- Designed and drove vulnerability remediation programmes across multi-cloud infrastructures, prioritizing risk based on CVE severity and business exposure.
- Extended security coverage to Kubernetes compliance posture through policy-as-code enforcement (Kyverno) and continuous misconfiguration scanning against CIS, NSA and MITRE frameworks (Kubescape).
- Ensured continuous alignment with ISO 27001 and NIS2, translating regulatory requirements into actionable remediation roadmaps.
INGENICO
Nov. 2025 - May 2026- Security & compliance strategy: managed vulnerability remediation based on CVE analysis, ensuring adherence to ISO 27001 and PCI DSS.
- Led end-to-end patch cycles across multi-environment infrastructure: Windows, Linux, VMware hypervisors, network and storage devices.
- Controlled operational impact together with business stakeholders, with strict adherence to maintenance windows.
- Tooling: Qualys Enterprise TruRisk Platform (VMDR), Trend Vision One, Cisco Meraki, FortiGate.
VIRBAC
Dec. 2024 - Dec. 2025- Led the rollout of backup data security best practices across the group's subsidiaries: kick-off with all stakeholders, assessment grid for pilot countries, validation of the support & operations RACI catalogue.
- Backup policies validated by headquarters; authored integration prerequisites, standard operating procedures and the security & compliance best practices audit matrix.
- Audited the German, South African, Uruguayan and US sites, then deployed the new data security architecture.
- Veeam Backup Enterprise Manager, Backup & Replication, Veeam One; AWS IAM, Secrets Manager, KMS, SSM, EC2, S3. ISO 27001:2022 compliance.
ENERGY-POOL
June 2022 - Dec. 2024- Led the transformation of the industrial equipment VPN architecture: solution deployed and provisioned as IaC on AWS (CloudFormation, cloud-init, Terraform, Ansible).
- Resources: EC2, EBS, S3, ASG, Secrets Manager, KMS, SSM, SQS, SES, Lambda. Production incident resolution alongside the DevOps team.
- Change management and ISO 27001:2022, ISO 9001 and GDPR recommendations.
- Additional engagement (July - Dec. 2024): Microsoft Azure architect - Defender XDR, Intune, SharePoint; review of Stormshield/Fortinet rules and Entra ID conditional access.
COMPTE R
Apr. 2021 - Apr. 2022- Modernized the infrastructure and authored the group's security policy: 180 workstations, 25 servers. Operational and security maintenance, systems/network administration, L1 to L3 support.
- LAN/WLAN integration across two sites (Stormshield, Juniper Networks), IPsec interconnection between three sites, Ansible application deployment on Windows 10 and GPO overhaul at headquarters.
XEFI
Sept. 2020 - Apr. 2021- Built a firewall on Arch Linux: network and security service integration (DNS, DHCP, OpenVPN, PAM, iptables, Exim4, syslog), service hardening and kernel security.
- Built from scratch both the ISO build system for firmware releases and the management system that distributes updates to the firewall. GitLab CI, SCRUM, NodeJS, Jest, Shell.
ABICOM
Apr. 2019 - Aug. 2020- Integration, migration, documentation and knowledge-transfer projects. IS operational maintenance, systems/network administration and L2 support, on-call duty, security audits and remediation.
MICHELIN
Jan. - Apr. 2019- Development, security and systems operations: Java development (Spring Boot), continuous integration, Linux, Docker, Kubernetes, networking and cryptography fundamentals.
- Received a Michelin contract offer at the end of the programme.
THALES
Sept. - Nov. 2018- Thales Services Build team: migrated an Active Directory 2003 R2 to a hardened 2012 R2 core for Thales Alenia Space; Ansible automation of Windows installation sources within continuous integration. ISO/ITIL standards.
DELL
Feb. 2016- Brought a new vCenter infrastructure into production: deployed 4 Dell R720 servers and an EqualLogic SAN array.
IOR-SYSTEM
Aug. 2015 - Aug. 2018- Managed around 40 clients under preventive maintenance across some 90 production servers.
- Remote support for Paris-based users, corrective maintenance from L1 to L3.
- Hardening of workstations, servers and networks.
ES2COM
Aug. 2012 - Aug. 2015- On-site technician and administrator of a 3-host vCenter platform hosted at OVH.
- Built the complete infrastructure for client CAN SAS: Juniper Networks, VMware, HP SAN and Windows Server 2012 R2.
- Configured network security (VLANs, IDS/IPS, MAC filtering) on JunOS, and client VPN links.
- P2V migrations, modernization of client firewall routers (VyOS, Endian), GPO-based deployment and workstation hardening with ESET.
Certifications
Skills validated by vendors and accredited certification bodies.
Beyond the CV
My CV highlights my most significant engagements. It does not, however, reflect all of my contributions - here are other achievements, sometimes quieter, but no less formative.
External cybersecurity expert, CPME Auvergne-Rhône-Alpes
Admitted to assess companies' resilience to cyber threats. I supported Surgar, CoAudit Group and MGA Distribution, delivering audit reports with recommended improvements ranked by criticality.
Strengthening information system security
Hair Design Group and EAS SEAPORT reached out through my personal blog. I audited their infrastructure, trained their teams and implemented concrete improvements to secure their IS perimeter.
Training Enedis CERT teams
One year of training within the Cyber Defence department on the Cyberbit attack/defence platform. The same year, I helped a French municipal community secure its entire IT estate under the ANSSI programme.
Consolidating and validating skills
A year devoted to training and deepening my knowledge: reading on management and information technology, consolidating the skills acquired since 2020. That period let me structure my vision, enrich my practices and strengthen my posture in a fast-moving technological environment.
A risk measurement platform
I designed a Cyber Asset Attack Surface Management (CAASM) platform that keeps an information system's asset inventory up to date dynamically, without agents and without human intervention. The goal: measure risk in order to assess compliance with cybersecurity best practices. Built on security-by-design principles from the outset, our solution meets OWASP, GDPR and ISO 27001 requirements. It was IP-protected, validated, then released commercially in beta; since July 2025 the platform has been stable and in production, and keeps improving as user feedback and regulatory or technological changes come in.
Since founding my company in 2020 I have integrated and operated an advanced toolset to keep my own information system both secure and performant: Secrets Manager, EASM, WAF, SAST/DAST/IAST, SCA, ASM, SIEM, APM, XDR, MDM, IdP, among others. That expertise let me build a strong defensive (Blue Team) capability, and respond to threats with rigour and anticipation.
Contact
Let's talk about your security, compliance or cloud needs.
- Phone+33 4 44 44 95 44
- Address12 rue de la Part-Dieu, 69003 Lyon, France
- Websitecybernetics.fr