I am a cybersecurity project director with over two decades of international experience in IT and OT security, risk management, and regulatory compliance (PCI DSS, DORA, LPM). I have led both captive and outsourced security programs across Europe, including large-scale SOC implementations, data center migrations, and governance initiatives for banking, healthcare, and industrial sectors. My expertise spans security strategy, program delivery, and cross-functional leadership in complex, multi-stakeholder environments. I thrive on translating risk into pragmatic security controls, building high-performing teams, and delivering secure, compliant solutions on time and within budget. I communicate fluently in English and French, with working knowledge of Japanese, and enjoy collaborating with stakeholders and vendors across borders to align security with business goals while maintaining a friendly, collaborative approach.

William Sanhaj

I am a cybersecurity project director with over two decades of international experience in IT and OT security, risk management, and regulatory compliance (PCI DSS, DORA, LPM). I have led both captive and outsourced security programs across Europe, including large-scale SOC implementations, data center migrations, and governance initiatives for banking, healthcare, and industrial sectors. My expertise spans security strategy, program delivery, and cross-functional leadership in complex, multi-stakeholder environments. I thrive on translating risk into pragmatic security controls, building high-performing teams, and delivering secure, compliant solutions on time and within budget. I communicate fluently in English and French, with working knowledge of Japanese, and enjoy collaborating with stakeholders and vendors across borders to align security with business goals while maintaining a friendly, collaborative approach.

Available to hire

I am a cybersecurity project director with over two decades of international experience in IT and OT security, risk management, and regulatory compliance (PCI DSS, DORA, LPM). I have led both captive and outsourced security programs across Europe, including large-scale SOC implementations, data center migrations, and governance initiatives for banking, healthcare, and industrial sectors. My expertise spans security strategy, program delivery, and cross-functional leadership in complex, multi-stakeholder environments.

I thrive on translating risk into pragmatic security controls, building high-performing teams, and delivering secure, compliant solutions on time and within budget. I communicate fluently in English and French, with working knowledge of Japanese, and enjoy collaborating with stakeholders and vendors across borders to align security with business goals while maintaining a friendly, collaborative approach.

See more

Experience Level

Expert
Expert
Expert
Expert
Expert
Intermediate
Intermediate
Intermediate
Intermediate
See more

Language

English
Fluent
French
Fluent
Japanese
Intermediate

Work Experience

Security Program Manager (Freelance) at Various international clients (Bank of France, Bundesbank, Banca d'Italia, Bank of Spain, Transdev, WorldLine/Ingenico, Manutan, APHP, STIME/Les Mousquetaires, Eramet, HSBC, Expedia, Al Ahli Bank (Saudi Arabia), Saudi Telecom Company, Accenture, Natixis-B
January 1, 2005 - November 28, 2025
Lead and manage cybersecurity projects including establishing European SOCs and OT-SOCs, governance and risk management, network/security transformation, PCI DSS initiatives, data-center relocation, and incident response planning. Implemented MITRE ATT&CK/TTP, NIST, and DORA frameworks; deployed SIEM, IDS/IPS, EDR, IAM/PAM, MFA; managed cross-border teams up to 60 people and budgets up to €30M; led RFP/RFQ processes and governance forums; ensured ISO27001/NIS2/PPCI DSS compliance.
LAN/WAN Network Engineer & International Security Deployment at Coface (1988-2004) and various employers (ING Ferri BBL Bank, Kodak Pathe, Indosuez Carr Futures, Council of Europe SDF, Paris Stock Exchange, TDT FranCom)
December 31, 2004 - December 31, 2004
Security management and network engineering across multiple sites and international deployments; conducted LAN/WAN redesigns, VPN integrations, and security rule optimization; implemented data-loss protection, EDR, and training for admins; supported mergers and international operations.
Establishment of a European SOC in the financial environment at Bank of France (European SOC Initiative with ECBs)
January 1, 2005 - January 1, 2025
Led the setup of a European SOC across multiple central banks, established common Tier1/Tier2/DFIR/CTI processes, aligned with MITRE ATT&CK, TIBER EU and NIST, recruited analysts and conducted cyber crisis scenarios; implemented DORA compliance.
Setting up an OT SOC in an industrial environment at Transdev
January 1, 2005 - January 1, 2025
Managed a SOC-OT project for the transport fleet, defined OT scoping, inventory, obsolescence management, remediation coordination with manufacturers, patching/deployment planning and English RFP writing.
Security deployment at Worldline / Ingenico
January 1, 2005 - January 1, 2025
Global security project management; deployment of encryption, strong authentication and hardening; geographic zoning reporting.
Setting up an IT / OT SOC at Manutan
January 1, 2005 - January 1, 2025
Implemented a centralized global SOC; led RFP/RFQ processes, recruited internal/external experts, contractor negotiation and budget management.
Network and security transformation at APHP
January 1, 2005 - January 1, 2025
LAN/WAN project management for the APHP hospital group; implemented IPAM, Checkpoint/Cisco firewall, DLP and EDR; ongoing support and maintenance.
Security governance at Stime / Les Mousquetaires
January 1, 2005 - January 1, 2025
Audit and remediation across the retail group; established governance and comitology processes.
Network transformation at Eramet
January 1, 2005 - January 1, 2025
Global cloud proxy solution deployment (Zscaler) with continental rollout; scope definition and POC documentation.
Data center relocation at HSBC
January 1, 2005 - January 1, 2025
Security management for HQ and subsidiaries; datacenter relocations; firewall rule optimization; proxy management and L3 ITIL support.
PCI DSS certification at Expedia Group Corp.
January 1, 2005 - January 1, 2025
Managed PCI DSS certification project; coordinated network and security teams; documented flows and optimized data center redundancy.
Anti-terrorism CCTV deployment at Saudi Telecom Company
January 1, 2005 - January 1, 2025
Provided technical security guidance; managed vendor tendering; national CCTV deployment for anti-terrorism efforts.
National network and security deployment at Accenture
January 1, 2005 - January 1, 2025
LAN/WAN project management; international VPN deployment; office Wi-Fi rollout across multiple sites.
Obsolescence management / carve-in carve-out at Natexis Bleichroeder
January 1, 2005 - January 1, 2025
Security management for HQ and subsidiaries; HAC/HV integration; preparation for merger activities involving financial flows.
International security deployment at Bouygues Construction
January 1, 2005 - January 1, 2025
Security consultation; firewall optimization and global deployment across 75 countries; site-to-site VPN implementations.
Network and security audit at Terrasys
January 1, 2005 - January 1, 2025
Security consulting for Terrasys customers; vulnerability patching; VPN interconnections; DRP design.
LAN / WAN redesign and international security deployment at Coface
January 1, 1988 - December 31, 2004
Security management for HQ and subsidiaries; branch relocations; RFP/RFQ writing; multinational VPN design.
LAN / MAN carve-in redesign and operation trading room network at ING Ferri BBL Bank
January 1, 1988 - December 31, 2004
Managed trading room network with inter-city WAN; merger/preparation for new offices; interoffice scalability.
Industrialization / hardening of workstations and servers at Kodak Pathe
January 1, 1988 - December 31, 2004
Industrialization of workstation images; L3 support; system hardening.
LAN / WAN network engineering at Indosuez Carr Futures
January 1, 1988 - December 31, 2004
LAN/WAN network engineering for Banque Indosuez; ongoing network management.
Network audit and training at Council of Europe Social Development Fund
January 1, 1988 - December 31, 2004
Novell Netware expert; admins training; remastered office workstations; installation training.
LAN / MAN network engineering at Paris Stock Exchange
January 1, 1988 - December 31, 2004
MONEP network management; EPFS European price feed server; real-time links with banks and brokers.
Network engineering at TDT Francom
January 1, 1988 - December 31, 2004
Interconnection network equipment; test lab; RFP/RFQ responses; after-sales support.
DIRECTEUR DE PROJET CYBERSÉCURITÉ at BANQUE DE FRANCE - ACPR
January 1, 2022 - December 31, 2025
Gestion d’un SOC IT Européen, définition et pilotage du SOC Tier1/2/DFIR/CTI, recrutement d’analysts, conformité DORA et scénarios de cybercrise; campagnes de pentesting et actions de remédiation.
DIRECTEUR DE PROJET CYBERSÉCURITÉ at TRANSDEV
January 1, 2021 - December 31, 2021
Mise en place d’un SOC OT en environnement industriel, scope OT et parc de transports, gestion de l’obsolescence et de la segmentation, rédaction d’RFP et négociation multi-pays.
DIRECTEUR DE PROJET CYBERSÉCURITÉ at WORLDLINE / INGENICO
January 1, 2020 - December 31, 2020
Gestion de projets de sécurité pour la conformité et le chiffrement, authentification forte et durcissement, reporting par zone géographique.
DIRECTEUR DE PROJET CYBERSÉCURITÉ at MANUTAN
January 1, 2019 - December 31, 2019
Mise en place d’un SOC IT/OT global centralisé, RFP/RFQ, recrutement et sélection d’intégrateurs, négociation des contrats et gestion des budgets.
CHEF DE PROJET RÉSEAU ET SÉCURITÉ at APHP
January 1, 2018 - December 31, 2018
Transformation réseau LAN/WAN et sécurité (IPAM, Checkpoint, DLP, EDR), maintien opérationnel et support across l’ensemble de l’infrastructure.
CONSULTANT GOUVERNANCE SECURITE at STIME / LES MOUSQUETAIRES
January 1, 2017 - December 31, 2017
Audit sécurité et remédiation, mise en place de process de gouvernance et comitologie, amélioration des pratiques sécurité.
CHEF DE PROJET RÉSEAU at ERAMET
January 1, 2016 - December 31, 2016
Transformation réseau et déploiement proxy cloud Zscaler par continent, définition du scope et POC.
CHEF DE PROJET RÉSEAU ET SÉCURITÉ at HSBC
January 1, 2014 - December 31, 2015
Déménagements de Datacenters et sécurisation du siège et filiales; installation et optimisation des règles de sécurité; gestion des proxys.
CONSULTANT SÉCURITÉ at EXPEDIA GROUP CORP.
January 1, 2012 - December 31, 2013
Gestion de projet PCI DSS, rédaction d’architectures, optimisation des datacenters et redondance opérationnelle.
CHEF DE PROJET SÉCURITÉ / ASSISTANT RSSI at BANQUE ALAHLI – ARABIE SAOUDITE
January 1, 2011 - December 31, 2011
Mise en œuvre des exigences PCI DSS, déploiement EDR/MFA/IAM-PAM et durcissement de l’infrastructure.
CHEF DE PROJET RÉSEAU ET SÉCURITÉ at SAUDI TELECOM COMPANY
January 1, 2010 - December 31, 2010
Conseil sécurité et déploiement CCTV, étude des solutions, gestion des appels d’offres et déploiement national.
CHEF DE PROJET RÉSEAU ET SÉCURITÉ at ACCENTURE
January 1, 2009 - December 31, 2009
Déploiement réseau et sécurité à l’échelle nationale; VPN international et déploiement Wi-Fi dans plusieurs sites.
CHEF DE PROJET RÉSEAU ET SÉCURITÉ at NATEXIS BLEICHROEDER
January 1, 2007 - December 31, 2008
Gestion des obsolescences / carve-in carve-out; architecture haute disponibilité et préparation de fusion (Natexis + Ixis CIB).
CONSULTANT SÉCURITÉ at BOUYGUES CONSTRUCTION
January 1, 2005 - December 31, 2006
Consultation sécurité internationale; analyse des flux, cleansing de firewall et déploiement mondial (75 pays).
DIRECTEUR DE PROJET RÉSEAU ET SÉCURITÉ at COFACE
January 1, 2000 - December 31, 2004
Refonte LAN/WAN et déploiement sécurité international; migration VPN site à site vers 64 pays; RFP/RFQ.
RESPONSABLE RÉSEAU ET TÉLÉCOMS at BANQUE ING FERRI BBL
January 1, 1998 - December 31, 1999
Refonte LAN/MAN, Carve-In et MCO; réseaux de salle des marchés et interconnexions internationales.
INGÉNIEUR SYSTÈME ET RÉSEAU at KODAK PATHE
January 1, 1997 - December 31, 1997
Industrialisation et durcissement des postes de travail; support N3 sur l’infrastructure
INGÉNIEUR RÉSEAU at INDOSUEZ CARR FUTURES
January 1, 1996 - December 31, 1996
Ingénierie réseau LAN/WAN et gestion des flux financiers sur les salles des marchés.
CONSULTANT RÉSEAU at FONDS DE DÉVELOPPEMENT SOCIAL DU CONSEIL DE L’EUROPE
January 1, 1995 - December 31, 1995
Audit réseau Novell Netware et formation des admins; rationalisation des postes.
INGÉNIEUR RÉSEAU at BOURSE DE PARIS
January 1, 1990 - December 31, 1994
Réseau LAN/MAN et liaison VPN site à site dans le cadre des marchés financiers.
INGÉNIEUR RÉSEAU at TDT FRANCOM
January 1, 1988 - December 31, 1989
Installation d’équipements réseaux et laboratoire POC; support technique.

Education

Master's degree at EPITA
January 7, 1985 - December 23, 1987

Qualifications

CCNA/CCNP/CEH v7
January 1, 2012 - December 31, 2013
ITIL/PRINCE2/CISSP
January 1, 2014 - December 31, 2015

Industry Experience

Financial Services, Government, Manufacturing, Transportation & Logistics, Professional Services, Software & Internet, Telecommunications, Media & Entertainment, Retail

Experience Level

Expert
Expert
Expert
Expert
Expert
Intermediate
Intermediate
Intermediate
Intermediate
See more

Hire a Project Manager

We have the best project manager experts on Twine. Hire a project manager in Paris today.