Cybersecurity · Risk Management · IT Audit · Data · Resilience · IA
Edmond Song
Independent consultant and interim manager — helping financial-market institutions strengthen cybersecurity, operational resilience, and risk governance.
Track record
in cybersecurity, risk management and IT audit — from Big Four to exchanges.
where engagements were delivered, beyond France — UK, CH, NL, LU, BE, SG, MA, DZ, PT, IT, DK, NO.
professional certifications: CISSP (security) and CISA (audit).
Professional experience
Twelve years keeping financial infrastructure secure.
ES Consulting
Independent Consultant, Interim Manager · Paris, FR
detail
AI & Automation
- Architected and developed a proof-of-concept AI audit assistant using local LLM and RAG architecture, enabling secure, on-device document analysis to reduce manual review time.
- Engineered intelligent AI agents to automate structured information extraction from unstructured documents, optimizing accuracy and processing speed for high-volume datasets.
- Developping RiskAssistant AI, an AI-driven tool for Risk, Compliance, and Audit professionals to enhance operational efficiency.
Strategic Advisory & GRC
- Advised as a strategic consultant on Cybersecurity, Risk Management, and IT Audit, guiding initiatives to automate and optimize existing business processes.
Operational Resilience & Regulation
- Architected and implemented a comprehensive operational resilience strategy for the First Line of Defence (1LoD), strengthening risk posture and regulatory compliance.
- Unified the Digital Operational Resilience strategy and testing programme into a consolidated compliance framework.
- Led critical remediation activities to secure alignment with the Digital Operational Resilience Act (DORA) within strict regulatory deadlines.
- Orchestrated periodic Business Impact Analysis (BIA) and Business Continuity Plan (BCP) exercises across business lines.
Risk Governance & Reporting
- Oversaw all risk and control activities for the 1LoD, driving completion of mitigation measures, periodic reviews, and remediation plans.
- Re-engineered the risk reporting framework, consolidating 1st and 2nd Line of Defence reports into a single source of truth for the Board.
- Automated reporting dashboards (Power BI, Excel), eliminating manual data entry to ensure consistent metrics.
Technology Innovation
- Initiated the evaluation of AI-driven solutions to modernize and optimize risk management processes.
Euronext
Head of Risk and Practices · Paris, La Défense, FR · PT, NL, IT, DK, NO
detail
Management & Operational Excellence
- Managed and mentored three cross-border teams (32 members in France and Portugal) to promote operational efficiency and collaboration.
- Directed operational risk management for the 1LoD, ensuring robust threat identification and mitigation.
- Streamlined IT Service Management (ITSM) processes and optimized tool configurations to improve service delivery.
Risk Management & Governance
- Designed and deployed a group-wide risk management framework and taxonomy, establishing a standardized risk language.
- Led the development of an automated operational risk dashboard, leveraging quantitative analysis for real-time C-level insights.
- Cultivated a proactive risk-aware culture across the organization.
Internal Control, Audit & Reporting
- Engineered an Internal Control framework covering IT and cyber risks to systematically close control gaps.
- Reported critical risk metrics to C-level executives and the Managing Board.
- Managed high-stakes external audits as primary liaison with regulators and statutory auditors.
Euronext
IT Audit Manager · Paris, La Défense, FR · PT, NL, DK, NO
detail
Audit Governance & Methodology
- Developed the annual IT audit plan based on risk assessment and mapping (risk-based approach).
- Authored comprehensive audit reports and advised as SME on follow-up of open issues and remediation plans.
Technical Audits & Risk Assessment
- Conducted technical audits in Cybersecurity, Cloud security, identity and access management (IAM), and incident/problem management.
- Assessed design and operating effectiveness of controls; identified and mapped IT-related risks for key stakeholders.
KPMG France
IT / Cyber Security Auditor — Manager · Paris, La Défense, FR · UK, CH, NL, LU, BE, SG, MA, DZ
detail
Risk & Internal Audit Governance
- Established and scaled Risk Management and Internal Audit departments, defining governance structures and methodologies (IIA standards).
Information Systems Security (ISS) Audit
- Executed high-impact IT security engagements globally: cyber risk assessment (ISO 27005, NIST 800-37), control environment audits (ISO 27001/27002), DLP reviews, ISSP alignment, CIS benchmark configuration analysis, and Red Team exercise supervision.
Third-Party Compliance (SOC)
- Led SOC 1 and SOC 2 (Type I & II) engagements for major banks and cloud providers.
Internal Controls & ITGC
- Reviewed IT General Controls (ITGC) and Entity Level Controls (ELC) for financial reporting compliance (SOX / LSF).
Forensic Investigation & OFAC Compliance
- Designed a scalable Big Data architecture to process hundreds of millions of SWIFT messages (dozens of terabytes), achieving 100% data coverage.
- Developed complex fuzzy-matching algorithms against OFAC sanctions lists with high precision, plus SWIFT parsing and transaction reconstruction modules.
- Implemented transaction linking and clustering, reducing manual case review time; built automated reporting protecting audit trail integrity.
Other Engagements
- Validated asset data quality for regulatory stress tests (ECB / EBA — Asset Quality Review).
- Analyzed IT business plans for M&A due diligence; designed and deployed an accounting information system (General Ledger and Reporting).
Aviva France
IT Security Internal Control · Bois-Colombes, FR
detail
SOX Compliance & Internal Control
- Designed and tested the operating effectiveness of IT General Controls (ITGC) and application controls to ensure SOX compliance.
- Contributed to IT committees as SME for information security, risk management, and governance topics.
Selected projects
Where regulation meets engineering.
RiskAssistant AI
An AI-driven assistant built for Risk, Compliance, and Audit professionals — structured extraction from unstructured documents using local LLM and RAG architecture, keeping sensitive analysis on-device.
OFAC sanctions screening at scale
A Big Data forensic platform processing hundreds of millions of SWIFT messages — fuzzy matching against sanctions lists, transaction chaining and clustering, and automated exception handling with full audit-trail integrity.
DORA compliance programme
A consolidated operational resilience framework for LCH's First Line of Defence — unified strategy and testing programme, critical remediation, and Board-level reporting delivered within strict regulatory deadlines.
Skills & tools
Frameworks in the morning, data pipelines by lunch.
Frameworks, Standards & Regulations
Cybersecurity
Data Analysis & Management
Cloud & Systems
Languages
Interpersonal
Education & certifications
Credentials.
MSc in Computer Science
Ecole Supérieure d'Informatique de Paris
Baccalaureat Scientifique, Sciences de l'ingénieur
Lycée Martin Luther King
CISSP
Certified Information Systems Security Professional — (ISC)²
CISA
Certified Information Systems Auditor — ISACA
Let's talk risk, resilience, or AI.
Open to consulting and interim management engagements across financial services and regulated industries.