Contact

Cybersecurity · Risk Management · IT Audit · Data · Resilience · IA

Edmond Song

Independent consultant and interim manager — helping financial-market institutions strengthen cybersecurity, operational resilience, and risk governance.

Track record

12+ yrs

in cybersecurity, risk management and IT audit — from Big Four to exchanges.

12 countries

where engagements were delivered, beyond France — UK, CH, NL, LU, BE, SG, MA, DZ, PT, IT, DK, NO.

2· certs

professional certifications: CISSP (security) and CISA (audit).

Professional experience

Twelve years keeping financial infrastructure secure.

2012 — present
2023 — Present
ES Consulting
Independent Consultant, Interim Manager · Paris, FR
detail

AI & Automation

  • Architected and developed a proof-of-concept AI audit assistant using local LLM and RAG architecture, enabling secure, on-device document analysis to reduce manual review time.
  • Engineered intelligent AI agents to automate structured information extraction from unstructured documents, optimizing accuracy and processing speed for high-volume datasets.
  • Developping RiskAssistant AI, an AI-driven tool for Risk, Compliance, and Audit professionals to enhance operational efficiency.

Strategic Advisory & GRC

  • Advised as a strategic consultant on Cybersecurity, Risk Management, and IT Audit, guiding initiatives to automate and optimize existing business processes.
LCH SA (London Stock Exchange Group)
Chief Operational Resilience Officer

Operational Resilience & Regulation

  • Architected and implemented a comprehensive operational resilience strategy for the First Line of Defence (1LoD), strengthening risk posture and regulatory compliance.
  • Unified the Digital Operational Resilience strategy and testing programme into a consolidated compliance framework.
  • Led critical remediation activities to secure alignment with the Digital Operational Resilience Act (DORA) within strict regulatory deadlines.
  • Orchestrated periodic Business Impact Analysis (BIA) and Business Continuity Plan (BCP) exercises across business lines.

Risk Governance & Reporting

  • Oversaw all risk and control activities for the 1LoD, driving completion of mitigation measures, periodic reviews, and remediation plans.
  • Re-engineered the risk reporting framework, consolidating 1st and 2nd Line of Defence reports into a single source of truth for the Board.
  • Automated reporting dashboards (Power BI, Excel), eliminating manual data entry to ensure consistent metrics.

Technology Innovation

  • Initiated the evaluation of AI-driven solutions to modernize and optimize risk management processes.
2021 — 2023
Euronext
Head of Risk and Practices · Paris, La Défense, FR · PT, NL, IT, DK, NO
detail

Management & Operational Excellence

  • Managed and mentored three cross-border teams (32 members in France and Portugal) to promote operational efficiency and collaboration.
  • Directed operational risk management for the 1LoD, ensuring robust threat identification and mitigation.
  • Streamlined IT Service Management (ITSM) processes and optimized tool configurations to improve service delivery.

Risk Management & Governance

  • Designed and deployed a group-wide risk management framework and taxonomy, establishing a standardized risk language.
  • Led the development of an automated operational risk dashboard, leveraging quantitative analysis for real-time C-level insights.
  • Cultivated a proactive risk-aware culture across the organization.

Internal Control, Audit & Reporting

  • Engineered an Internal Control framework covering IT and cyber risks to systematically close control gaps.
  • Reported critical risk metrics to C-level executives and the Managing Board.
  • Managed high-stakes external audits as primary liaison with regulators and statutory auditors.
2019 — 2021
Euronext
IT Audit Manager · Paris, La Défense, FR · PT, NL, DK, NO
detail

Audit Governance & Methodology

  • Developed the annual IT audit plan based on risk assessment and mapping (risk-based approach).
  • Authored comprehensive audit reports and advised as SME on follow-up of open issues and remediation plans.

Technical Audits & Risk Assessment

  • Conducted technical audits in Cybersecurity, Cloud security, identity and access management (IAM), and incident/problem management.
  • Assessed design and operating effectiveness of controls; identified and mapped IT-related risks for key stakeholders.
2013 — 2019
KPMG France
IT / Cyber Security Auditor — Manager · Paris, La Défense, FR · UK, CH, NL, LU, BE, SG, MA, DZ
detail

Risk & Internal Audit Governance

  • Established and scaled Risk Management and Internal Audit departments, defining governance structures and methodologies (IIA standards).

Information Systems Security (ISS) Audit

  • Executed high-impact IT security engagements globally: cyber risk assessment (ISO 27005, NIST 800-37), control environment audits (ISO 27001/27002), DLP reviews, ISSP alignment, CIS benchmark configuration analysis, and Red Team exercise supervision.

Third-Party Compliance (SOC)

  • Led SOC 1 and SOC 2 (Type I & II) engagements for major banks and cloud providers.

Internal Controls & ITGC

  • Reviewed IT General Controls (ITGC) and Entity Level Controls (ELC) for financial reporting compliance (SOX / LSF).

Forensic Investigation & OFAC Compliance

  • Designed a scalable Big Data architecture to process hundreds of millions of SWIFT messages (dozens of terabytes), achieving 100% data coverage.
  • Developed complex fuzzy-matching algorithms against OFAC sanctions lists with high precision, plus SWIFT parsing and transaction reconstruction modules.
  • Implemented transaction linking and clustering, reducing manual case review time; built automated reporting protecting audit trail integrity.

Other Engagements

  • Validated asset data quality for regulatory stress tests (ECB / EBA — Asset Quality Review).
  • Analyzed IT business plans for M&A due diligence; designed and deployed an accounting information system (General Ledger and Reporting).
2012 — 2013
Aviva France
IT Security Internal Control · Bois-Colombes, FR
detail

SOX Compliance & Internal Control

  • Designed and tested the operating effectiveness of IT General Controls (ITGC) and application controls to ensure SOX compliance.
  • Contributed to IT committees as SME for information security, risk management, and governance topics.

Selected projects

Where regulation meets engineering.

01 · AI

RiskAssistant AI

An AI-driven assistant built for Risk, Compliance, and Audit professionals — structured extraction from unstructured documents using local LLM and RAG architecture, keeping sensitive analysis on-device.

02 · FORENSICS

OFAC sanctions screening at scale

A Big Data forensic platform processing hundreds of millions of SWIFT messages — fuzzy matching against sanctions lists, transaction chaining and clustering, and automated exception handling with full audit-trail integrity.

03 · RESILIENCE

DORA compliance programme

A consolidated operational resilience framework for LCH's First Line of Defence — unified strategy and testing programme, critical remediation, and Board-level reporting delivered within strict regulatory deadlines.

Skills & tools

Frameworks in the morning, data pipelines by lunch.

Frameworks, Standards & Regulations

ISO 27000 seriesNIST CSFDORAGDPRPCI-DSSSOXCOSOCOBITITIL

Cybersecurity

Governance & OrganizationSecurity Assessment & TestingIAMSOCNetwork SecurityAsset ManagementBCP

Data Analysis & Management

PythonPower BISQL ServerPostgreSQLMySQLOracleSAP Business ObjectsData GovernanceData QualityData LineageTalend

Cloud & Systems

Amazon AWSMicrosoft AzureWindows ServerUnix / Linux

Languages

French — nativeEnglish — proficient (TOEIC 990)Spanish — elementaryPortuguese — elementary

Interpersonal

Problem solverFast learnerDiplomacyAutonomousTeam player

Education & certifications

Credentials.

2007 — 2012

MSc in Computer Science

Ecole Supérieure d'Informatique de Paris

Paris, FR
2007

Baccalaureat Scientifique, Sciences de l'ingénieur

Lycée Martin Luther King

Bussy-St-Georges, FR
CERT

CISSP

Certified Information Systems Security Professional — (ISC)²

Security
CERT

CISA

Certified Information Systems Auditor — ISACA

Audit

Let's talk risk, resilience, or AI.

Open to consulting and interim management engagements across financial services and regulated industries.