SAMIR KADI IT Risk Analyst & Cybersecurity Specialist Relocating to London, UK — 2026 Email sab.11149@protonmail.com Phone +33 6 19 58 07 89 (WhatsApp / Signal) LinkedIn https://linkedin.com/in/samir-kadi-1947tb1949 X https://x.com/Sab11149 GitHub https://github.com/samyvenom69 PROFILE ------- Junior IT Risk Analyst specialising in RCSA, GRC, DORA and business continuity. Proven delivery of measurable risk reduction in regulated banking. I combine a banking background in factoring, fraud and compliance with hands-on cybersecurity and IT risk. At BNP Paribas I design permanent controls, run RCSA campaigns and strengthen operational resilience under DORA and French regulation. Stats: 2.5 years IT risk · 3.5 years insurance · 9-node Raspberry Pi cluster EXPERIENCE ---------- IT Risk Analyst — BNP Paribas Bank, Montreuil Jun 2024 — Present - Permanent Control & RCSA: spearheaded the permanent IT control framework (2nd line) for the Asset Management (OPC) entity, driving the RCSA cycle to map risks and evaluate control effectiveness. - Incident & remediation: root-cause analysis on historical IT incidents and end-to-end ownership of corrective action plans with technical teams. - Compliance & strategy: continuous alignment with banking regulation (EBA, ACPR) and strategic plans for emerging technology risk. - Third-party risk: vendor evaluations and recommendations to protect the supply chain. - Resilience & InfoSec: contribution to BCPs and cross-departmental work on disaster recovery and security posture. - Risk culture: designed IT risk training that raised employee awareness and operational efficiency. Cybersecurity Mission Manager — BNP Paribas Bank, Montreuil May 2023 — May 2024 - Directed end-to-end cybersecurity missions and delivered post-mission reports covering findings, lessons and recommendations. - Reduced operational risk through assessments, mitigation strategies and adherence to security policy. - Kept stakeholders informed with transparent reporting and regular progress updates. - Led teams under pressure toward a solutions-oriented, continuous-improvement culture. IT Security Administrator (Intern) — Easy Former, Cergy Sep 2022 — Apr 2023 - Wrote project security plans aligned with compliance standards and monitored the threat landscape. - Evaluated, implemented and tuned security tooling with vendors. - Strengthened IAM through password policy, reducing unauthorised-access incidents. - Supported BCP and disaster-recovery design. Factoring Sales Manager — BNP Paribas Factor, Paris Jun 2016 — Apr 2022 - Built sales strategies that grew factoring revenue and expanded the client portfolio. - Tracked market and client-finance needs to capture new business. - Maintained long-term partnerships through service quality and rapid issue resolution. EARLIER CAREER -------------- Store Manager — KADI SERVICES (1997—1999) Stock & Sales Assistant — MANGO (2003—2005) Debt Collection Officer — GDF (2005—2008) Factoring Operations Officer — EDF (2008—2009) Insurance Underwriting Assistant — MMA IARD (2009—2012) Premium Collection Officer — Bpifrance (2013—2014) Compliance Officer — CréditPar (2015) Card Fraud Operations Analyst — Boursorama (2015—2016) SELECTED PROJECTS ----------------- ICT Risk & Permanent Control (OPC LoD1 — Factor France) — 2024—Present End-to-end ownership of the IT permanent-control framework, application testing and bi-annual RCSA campaigns. ServiceNow, RISK360, DORA, Power BI. Metrics: 2× / year RCSA campaigns · 100% core-app scope Frameworks: COBIT · DORA & NIS2 · French ACPR Decree 2014 · GDPR Akamai Anti-DDoS Deployment — 2024 Production rollout of Akamai Kona Site Defender. 1.2 Tbps DDoS mitigated. CAR Light — Business Continuity (Factor France) — 2024 Annual BCP exercise with 80+ participants. Recovery time reduced by 40%. GAP 05 Participation — 2023 Regulatory and security gap analysis with a tracked remediation roadmap. Secure Infrastructure Lab — 2022 PfSense, Snort IDS/IPS, Squid/SquidGuard, captive portal. HOME LABORATORY --------------- 9× Raspberry Pi 4 cluster (24/7): Pi-hole, Wazuh SIEM, Suricata, WireGuard zero-trust VPN, Cowrie honeypot, OpenVAS, Nextcloud, k3s, Kali attack sim. Personal labs: Home SOC, secure file sharing, honeypot, vulnerability management, banking-system risk modelling, digital forensics. EDUCATION --------- 2022 Master's in Cybersecurity & Information Systems University — Graduated with Distinction Network security, risk-management frameworks, security auditing, vulnerability analysis, incident response, GRC and SOC practice. 2016 MSc Economics & Finance University — Master of Science Corporate and market finance, quantitative methods, strategic analysis. CERTIFICATIONS -------------- ISO 27001 Lead Implementer — 2024 CompTIA Security+ — 2023 Certified Ethical Hacker (CEH) — 2023 Certificate of Competence: Cybersecurity Analyst (network admin, IS security, operational risk, threat detection) PLATFORM PROGRESS ----------------- TryHackMe Top 5% · 420+ points · 207 rooms · 472-day streak HackTheBox Pro Hacker · 1,850+ points · 45+ machines · 120+ challenges PortSwigger 100% Web Security OverTheWire Bandit + Natas Root-Me Top 10% France