Michaël GBROGO

Michaël GBROGO

Cybersecurity consultant and IT Risk Manager

Practitioner Expert
Biography

Cybersecurity Engineer specialized in Governance, Risk, and Compliance (GRC), Michaël Gbrogo draws on 14 years of experience in IT, including 6 dedicated to cybersecurity, to help organizations manage digital risks and build resilient environments.

Trained at Télécom ParisTech and certified as ISO 27001 Lead Auditor & Lead Implementer, CRISC, and ISO 27005 Risk Manager, he combines methodological expertise, strategic vision, and operational understanding of complex systems.

Throughout his assignments with international groups such as TotalEnergies, Orange, Bouygues Télécom, and SFR, he has developed proven expertise in risk assessment and treatment, advanced vulnerability management, supplier cyber-evaluation, and steering security indicators within executive security committees (COSEC).

His role has involved drafting and reviewing cybersecurity requirements, embedding security into projects, monitoring compliance with standards and regulations (NIS2, DORA, GDPR), and actively contributing to the continuous improvement of ISO 27001 ISMS.

Michaël is also proficient in cloud environments (Azure, AWS) and security solutions such as Microsoft Defender, Purview DLP, and Rapid7, enabling him to combine a mature GRC approach with precise technical insight into operational environments.

Recognized for his ability to rigorously analyze, structure effective governance processes, and support teams in achieving tangible risk reduction, he also excels in producing decision-making dashboards and leading awareness campaigns.

His pragmatic vision, coupled with strong pedagogical skills, makes him an expert capable of bridging compliance requirements, business challenges, and operational imperatives.

Professional Experience· 7
  • Cybersecurity consultant and IT Risk Manager

    Total Energies-Courbevoie

    2021-Present

    Responsible for qualifying, monitoring, and verifying vulnerability remediation with regular reporting to the IT Department. He also manages bidder evaluations, drafts and reviews cybersecurity requirements in contracts, leads security committees, and contributes to the continuous improvement of the ISMS (ISO 27001), risk management (ISO 27005), and compliance with NIS2, DORA, and GDPR regulations.

  • Cybersecurity Consultant

    Total Energies-Nanterre

    March 2020-March 2021

    Responsible for identifying, analyzing, and assessing cyber risks, proposing and monitoring action plans. Ensures that risk mapping is updated, dashboards are developed, and security committees are led. Oversees audits, non-compliance issues, and exemptions to ensure compliance and continuous improvement.

  • Cybersecurity Consultant

    Orange-Villejuif

    April-october 2021

    Responsible for application and infrastructure risk analysis, providing recommendations and monitoring action plans. Accountable for vulnerability management, supplier relations, and maintaining security conditions. He produces and presents activity reports, updates the flow matrix, integrates security into projects (ISP), and validates the opening/closing of flows in accordance with filtering rules

  • Network and Security Engineer

    Bouygues Télécom6-Meudon

    January 2018-February 2020

    Responsible for designing and documenting engineering solutions for new services, supporting prototypes and tests. Manages incident reporting to suppliers and coordinates resolution to ensure service reliability.

  • Security Engineer

    Bouygues Telecom-Meudon

    January 2026-February 2017

    Responsible for correcting vulnerabilities identified during security audits of the B2B environment, validating the relevance of auditors' recommendations, and monitoring their implementation. Development and presentation of monitoring indicators, while ensuring that configurations comply with the group's security policy.

  • Network and Security Engineer

    SFR- Saint Denis

    April-december 2017

    Conducted vulnerability scans and configuration audits of network equipment, proposed hardening measures, and ensured follow‑up with reporting on implemented corrections.

  • Network Engineer

    Alcatel Lucent-Villarceaux

    February 2012-November 2015

    Coordination of deployment activities : Production and presentation of activity reports • Drafting of engineering files for deployment, equipment replacement, Support for operators during deployment phases

Education· 7
  • ISO 27001 Lead Auditor

    2025

  • ISO 27001 Lead Implementer

    2025

  • CRISC (Certified in Risk and Information Systems Control)

    2021

  • ISO 27005 Risk Manager

    2019

  • CISCO CCNP Routing&Switching

    2018

  • Master's Degree in Telecom Network Design and Architecture

    Télécom Paristech

    October 2010 - January 2012

  • Telecommunications Engineer

    Institut national des télécoms-Oran-Algérie

    September 2008 - June 2010

Biography

Cybersecurity Engineer specialized in Governance, Risk, and Compliance (GRC), Michaël Gbrogo draws on 14 years of experience in IT, including 6 dedicated to cybersecurity, to help organizations manage digital risks and build resilient environments.

Trained at Télécom ParisTech and certified as ISO 27001 Lead Auditor & Lead Implementer, CRISC, and ISO 27005 Risk Manager, he combines methodological expertise, strategic vision, and operational understanding of complex systems.

Throughout his assignments with international groups such as TotalEnergies, Orange, Bouygues Télécom, and SFR, he has developed proven expertise in risk assessment and treatment, advanced vulnerability management, supplier cyber-evaluation, and steering security indicators within executive security committees (COSEC).

His role has involved drafting and reviewing cybersecurity requirements, embedding security into projects, monitoring compliance with standards and regulations (NIS2, DORA, GDPR), and actively contributing to the continuous improvement of ISO 27001 ISMS.

Michaël is also proficient in cloud environments (Azure, AWS) and security solutions such as Microsoft Defender, Purview DLP, and Rapid7, enabling him to combine a mature GRC approach with precise technical insight into operational environments.

Recognized for his ability to rigorously analyze, structure effective governance processes, and support teams in achieving tangible risk reduction, he also excels in producing decision-making dashboards and leading awareness campaigns.

His pragmatic vision, coupled with strong pedagogical skills, makes him an expert capable of bridging compliance requirements, business challenges, and operational imperatives.

Professional Experience
  • Cybersecurity consultant and IT Risk Manager

    Total Energies-Courbevoie

    2021-Present

    Responsible for qualifying, monitoring, and verifying vulnerability remediation with regular reporting to the IT Department. He also manages bidder evaluations, drafts and reviews cybersecurity requirements in contracts, leads security committees, and contributes to the continuous improvement of the ISMS (ISO 27001), risk management (ISO 27005), and compliance with NIS2, DORA, and GDPR regulations.

  • Cybersecurity Consultant

    Total Energies-Nanterre

    March 2020-March 2021

    Responsible for identifying, analyzing, and assessing cyber risks, proposing and monitoring action plans. Ensures that risk mapping is updated, dashboards are developed, and security committees are led. Oversees audits, non-compliance issues, and exemptions to ensure compliance and continuous improvement.

  • Cybersecurity Consultant

    Orange-Villejuif

    April-october 2021

    Responsible for application and infrastructure risk analysis, providing recommendations and monitoring action plans. Accountable for vulnerability management, supplier relations, and maintaining security conditions. He produces and presents activity reports, updates the flow matrix, integrates security into projects (ISP), and validates the opening/closing of flows in accordance with filtering rules

  • Network and Security Engineer

    Bouygues Télécom6-Meudon

    January 2018-February 2020

    Responsible for designing and documenting engineering solutions for new services, supporting prototypes and tests. Manages incident reporting to suppliers and coordinates resolution to ensure service reliability.

  • Security Engineer

    Bouygues Telecom-Meudon

    January 2026-February 2017

    Responsible for correcting vulnerabilities identified during security audits of the B2B environment, validating the relevance of auditors' recommendations, and monitoring their implementation. Development and presentation of monitoring indicators, while ensuring that configurations comply with the group's security policy.

  • Network and Security Engineer

    SFR- Saint Denis

    April-december 2017

    Conducted vulnerability scans and configuration audits of network equipment, proposed hardening measures, and ensured follow‑up with reporting on implemented corrections.

  • Network Engineer

    Alcatel Lucent-Villarceaux

    February 2012-November 2015

    Coordination of deployment activities : Production and presentation of activity reports • Drafting of engineering files for deployment, equipment replacement, Support for operators during deployment phases

Education
  • ISO 27001 Lead Auditor

    2025

  • ISO 27001 Lead Implementer

    2025

  • CRISC (Certified in Risk and Information Systems Control)

    2021

  • ISO 27005 Risk Manager

    2019

  • CISCO CCNP Routing&Switching

    2018

  • Master's Degree in Telecom Network Design and Architecture

    Télécom Paristech

    October 2010 - January 2012

  • Telecommunications Engineer

    Institut national des télécoms-Oran-Algérie

    September 2008 - June 2010