KILIAN PICHARD
Cybersecurity Engineer, passionate about network security, SOC analysis, and Linux.
I am always on the lookout for new opportunities in cybersecurity. Feel free to contact me!
About

Kilian PICHARD | Cybersecurity Engineer
Hello! I am a cybersecurity engineer, passionate about network security, SOC analysis, and Linux. I am constantly looking for new challenges to combine my passion with my expertise. In short: a passionate individual ready to tackle any challenge!
- Age: 25 years old
- Address: Brest (France)
- Email: contact-pro@kilianpichard.com
- Root Me: 1435 points
- Experience
- Education
- Projets
-
Freelance - Brest (France)
(Mar 2025 - Today)Independant Cybersecurity Engineer
Currently working for a client with high standards in terms of security and data protection, I specialize in hardening network and server infrastructures, ensuring optimal protection for Windows Server and Linux environments. My expertise includes verifying the configuration of firewalls and switching solutions to enhance network security.
My services also cover:
🔹 Compliance and standards: support in complying with II901, ISO 27001, and other security standards.
🔹 Risk analysis: identifying and assessing risks to propose appropriate mitigation strategies.
🔹 Technology watch: continuous monitoring of developments and threats in cybersecurity to anticipate risks.
🔹 Hardening and log reporting: strengthening system security and integrating logs into a SIEM for centralized monitoring and analysis.
🔹 Document package validation: verification and validation of security documents to ensure their compliance and completeness.
-
Astek / Naval defense company - Brest (France)
(Oct 2023 - Mar 2025)Cybersecurity Engineer
During my current mission, I actively participate in managing the security of projects within a naval defense company, with a particular focus on network and server infrastructure, as well as compliance with security standards.
🔹 Project security monitoring: I am the security point of contact for the various projects entrusted to me, with a particular focus on network and server infrastructure.
🔹 Checking compliance with security requirements: I ensure that projects follow strict security standards, such as II 901, as well as recommendations from ANSSI, CIS and solution providers. This ensures both compliance with regulations and secure systems and equipment.
🔹 Equipment hardening: I ensure the hardening of network equipment (such as firewalls, switches, encryptors), operating systems (Linux, Windows), as well as servers (NAS, hypervisors, etc.), enforcing good security practices to minimize vulnerability risks and reinforce infrastructure resilience.
🔹 Log analysis: I check the equipment syslog server configuration to ensure that logs are correctly fed back into the SIEM. I also analyze the content of the logs to ensure the consistency of the logs that are brought up, guaranteeing continuous monitoring of equipment security.
🔹 Raising teams’ awareness of good security practices: As the project’s security referent, I pass on good advice and best practices to the teams. I’m also available to answer their questions, ensuring that they understand and apply the appropriate safety measures to guarantee project safety.
-
Continental Digital Services France - Toulouse (France)
(Sept 2022 - Sept 2023)Work-study Cybersecurity Engineer
During my work-study, I participated in various initiatives related to security management and project compliance, working with the SOC team and other departments, while strengthening my cybersecurity and risk management skills.
🔹 Design and implementation of an alert management process: Working with the SOC team, I helped create a process to improve the efficiency of the internal Security Operations Center. This process has significantly reduced the time taken to escalate alerts to project teams.
🔹 Risk analysis: I actively participated in the risk analysis for a project that was already ISO 27001 certified. The risk analysis method used was based on the EBIOS RM method.
🔹 Maintenance and implementation of ISO 27001 certification: A significant part of my work-study period was dedicated to the maintenance of ISO 27001 certification for an already certified ISMS and to the preparation for ISO 27001 certification of another ISMS.
🔹 Follow-up of the renewal audit: I actively participated in monitoring the renewal audit for ISO 27001 certification already in place on an ISMS, ensuring that security practices were maintained at a high level.
-
Universidad de Jaén - Jaén (Spain)
(Apr 2022 - Jul 2022)Full Stack Developer Internship - 4 months
During my 4-month internship at the University of Jaén in Andalusia (Spain), I participated in the design and development of a website for a cultural project aimed at highlighting the pioneering women in computer science.
🔹 Website design and development: I designed and developed an interactive website for this project, focusing on showcasing pioneering women in the field of computer science.
🔹 Frontend with ReactJS: The frontend was developed using ReactJS, which allowed me to create a dynamic and responsive user interface. I also used HTML, CSS, and the Tailwind CSS framework to ensure a modern and responsive design.
🔹 Backend with Strapi and SQLite: For the backend, I used the Headless CMS Strapi, as well as JavaScript. I worked with an SQL database using the SQLite library for data storage.
🔹 Deployment on Nginx HTTP server: Once the site was complete, I deployed it on an Nginx HTTP server, ensuring its online availability.
🔹 Technologies used: JavaScript (ReactJS), HTML, CSS, Tailwind CSS, SQLite, WebStorm, Git, and GitHub.
-
Sigma Consulting - Pau (France)
(May 2022 - Jul 2022)Full Stack Developer Internship - 3 months
During my 3-month internship at Sigma Consulting, I participated in the development of a SaaS software called Airphoning. This project allowed me to work on the complete development of a web application, from front-end to back-end.
🔹 SaaS Software Development: I developed Airphoning from scratch, integrating all the necessary features to provide a smooth and complete user experience.
🔹 Installation and use of the Symfony framework: I installed and configured the Symfony framework, using it for the development of the application’s back-end features.
🔹 Database and programming in PHP and SQL: I worked on implementing the complete database in SQL, using PHP for server-side logic and integrating the features required for the proper functioning of the SaaS.
🔹 Front-end and back-end development: My role also included developing the front-end (user interface) in HTML5, CSS3, and JavaScript, as well as developing the back-end to handle interactions with the database.
🔹 Technologies used: PHP, HTML5, CSS3, JavaScript, SQL, Git, GitHub.
-
Marine Nationale - Brittany (France)
(Jul 2018 - Jul 2021)Reservist in the French Navy
During my experience as a semaphore lookout for the French Navy, I underwent a 2-week training at the Naval Academy in Brest and carried out various missions monitoring maritime approaches.
🔹 Training at the Naval Academy in Brest: I underwent a 2-week training at the Naval Academy, where I acquired the fundamental skills necessary to monitor maritime areas, while becoming familiar with the specific equipment used by the French Navy.
🔹 Maritime and air surveillance missions: I was responsible for monitoring maritime and air approaches along the French coastline, using sophisticated detection and communication means.
🔹 Identification and control of vessels: One of my key missions was identifying and controlling vessels operating near the French coast to ensure the safety and compliance of maritime activities.
🔹 Fighting marine pollution and illicit trafficking: I participated in monitoring maritime activities aimed at combating marine pollution and detecting illicit trafficking, contributing to the preservation of the marine environment.
🔹 Assistance at sea: I also contributed to sea rescue operations with the SNSM (French Sea Rescue Service), intervening to provide quick help in the event of an incident or need for assistance, ensuring the safety of people at sea.
-
La Web Factory - Anglet (Francia)
(Mayo 2020 - Julio 2020)Pasantía de Desarrollador Back-end - 3 meses
Durante mi pasantía de 3 meses en La Web Factory, contribuí al desarrollo y la actualización de una plataforma CRM utilizando PHP. Esta pasantía me permitió adquirir habilidades sólidas en automatización de procesos, gestión de datos y creación de interfaces dinámicas.
🔹 Desarrollo y actualización de una plataforma CRM: Participé en la mejora y enriquecimiento de las funcionalidades de una plataforma CRM, trabajando principalmente en la implementación de nuevas características y la optimización del sistema existente.
🔹 Automatización de tareas: Instalé y creé tareas de automatización que permitieron almacenar datos JSON en una base de datos SQL de manera óptima. Esto facilitó la gestión de los datos en el CRM y mejoró la eficiencia de los procesos.
🔹 Creación de un panel de control interactivo: Diseñé un panel de control para permitir a los usuarios visualizar los datos de manera clara e interactiva usando Chart.js, facilitando así la toma de decisiones basadas en los datos.
🔹 Tecnologías utilizadas: PHP, JavaScript, Chart.js, HTML5, CSS3, SQL, Git, GitHub.
-
TryHackMe - Online
(2024 - 2025)Career Path - SOC Level 1 & Level 2
These trainings allowed me to acquire in-depth expertise in monitoring and defending information systems within a Security Operations Center (SOC). They cover the entire cycle of detection, analysis, and response to cybersecurity incidents:
🔹 SOC Level 1 – Threat Detection and Analysis
-
Monitoring security events via SIEM (Splunk, Wazuh, etc.).
-
Detecting and investigating alerts (log analysis, correlation rules).
-
Identifying common threats (malware, phishing, network attacks).
-
Initial response actions and escalation.
🔹 SOC Level 2 – Incident Response and Advanced Threat Management
-
In-depth analysis of cyberattacks and forensic investigation.
-
Detection of complex attacks (APT, ransomware, advanced exploitation).
-
Implementing SOC detection rules and automation (SOAR).
-
Coordination with security teams for remediation and infrastructure hardening.
Through these trainings, I developed solid skills in SI monitoring, threat investigation, and incident response, enabling me to provide effective defense against cyberattacks.
-
-
TryHackMe - Online
(2024)Career Path - Jr Penetration Tester
This immersive training allowed me to gain a solid understanding of the fundamentals of penetration testing and offensive security techniques, even though this is not my main field. It covers several key aspects of cybersecurity:
🔹 Reconnaissance & Scanning: Using tools like Nmap and Gobuster to identify services, open ports, and potential vulnerabilities on a network.
🔹 Exploiting Vulnerabilities: Discovering and exploiting common flaws (OWASP Top 10, network and system vulnerabilities) with Metasploit and other tools.
🔹 Privilege Escalation: Techniques for obtaining administrator rights on Linux and Windows systems.
🔹 Post-Exploitation & Persistence: Analyzing logs, lateral movements, and maintaining access to a compromised system.
🔹 Penetration Test Reporting: Writing a structured report on the vulnerabilities found and recommendations for remediation.
Although penetration testing is not something I practice daily, this course gave me a better understanding of attack techniques, allowing me to anticipate and strengthen the defensive security of the systems I protect.
-
CY Tech (formerly EISTI) - Pau/Cergy (France)
(Sept 2020 - Sept 2023)Engineering Degree in Computer Science - Specialization in Cybersecurity
This program allowed me to acquire in-depth expertise in computer science and cybersecurity, covering both technical and strategic aspects of information system protection.
🔹 Development & Algorithms: Design and optimization of algorithms, data structures, Design Patterns.
🔹 Networks & System Programming: Network architecture, low-level programming (processes, IPC, sockets, TCP).
🔹 Cybersecurity & Information System Security:
-
Cryptography (symmetric, asymmetric).
-
Web security (OWASP, XSS, CSRF, SQLi).
-
Penetration testing & forensics, reverse engineering, malware analysis.
-
Governance and compliance (ISO/IEC 2700x), crisis management & incident response.
-
Network security, Linux hardening, hardware and software security.
-
Industrial system security (SCADA).
🔹 Web & Software Programming: Development in HTML5, CSS3, JavaScript, PHP, Spring, Hibernate, SQL/MySQL.
🔹 Operating Systems: Administration and management of Linux/Windows, advanced Unix commands.
🔹 Artificial Intelligence & Machine Learning:
-
Neural networks, Deep Learning, NLP (Python, Keras, TensorFlow).
-
Reinforcement learning.
🔹 Testing & Advanced Programming:
-
Unit tests (JUnit).
-
Parallel programming (OpenMPI, MPI).
-
Languages mastered: HTML5, CSS3, JavaScript, PHP, Python, C, C++, Java, Prolog, Scala, R.
Thanks to this program, I developed a comprehensive view of cybersecurity, programming, and systems administration, enabling me to effectively intervene in the protection of IT infrastructures and the securing of applications.
-
-
Bayonne and Basque Country Institute of Technology - Anglet (France)
(Sept 2018 - Sept 2020)DUT in Computer Science
This degree allowed me to develop solid skills in computer science, covering a wide range of fields from programming to project management, with a particular focus on databases and networks. Below is a summary of the skills acquired:
🔹 Development & Algorithms: Mastery of algorithms, data structures, and Design Patterns for optimizing software design.
🔹 Networks & System Programming: Network programming with sockets, protocols (TCP/IP, OSI model), and C programming for developing network applications.
🔹 Web Programming & Databases: Development of web applications using HTML5, CSS3, JavaScript, PHP (Symfony). Design and management of relational databases with SQL, PL/SQL (Oracle), creating triggers, and implementing DAO/ADO models.
🔹 Object-Oriented Analysis & Design: Use of UML and MERISE methods for software system design.
🔹 Law & Cyber Law: Understanding the legal framework related to the Internet, cybercrime, system security, intellectual property, and copyright.
🔹 Business Management: Project management skills, as well as creating and taking over businesses in the field of computer science.
🔹 Operating Systems: Administration and use of Linux and Unix commands for working on Unix-based systems.
🔹 Programming Languages: Proficiency in a wide range of programming languages, including HTML5, CSS3, JavaScript, PHP, Java, Python, C, C++, Java, Assembly, R.
This DUT laid the solid foundation for my career in computer science, with a focus on practical applications, project management, and cybersecurity, allowing me to be versatile in various technical fields.
-
Léonce Vieljeux High School - La Rochelle (France)
(Sept 2015 - Jun 2018)Scientific Baccalaureate, specializing in Computer Science and Digital Sciences
🔹 Development & Algorithms: Mastery of algorithms, data structures, and Design Patterns for optimizing software design.
🔹 Algorithms
🔹 Networks: TCP/IP, protocols, addressing, OSI model.
🔹 Web Programming: HTML5, CSS3, JavaScript, PHP.
🔹 Engineering Sciences: Arduino, 3D printing, design of an energy recovery module for bicycles.
🔹 Databases: SQL/MySQL.
-
CY Tech (formerly EISTI) - Pau/Cergy (France)
(March 2023 - May 2023)University Project - Implementation of a Virtual Core
🔹 Designed and developed a virtual core in C, utilizing a 64-bit architecture. This virtual core was capable of managing a set of 16 64-bit registers, which was essential for low-level operations related to cybersecurity.
🔹 Created a compiler in Python, allowing translation of an assembly file into a binary file understandable by the virtual core. This step was crucial to enable the programming of the virtual core using an assembly language tailored to cybersecurity needs.
🔹 Implemented a mechanism to retrieve instructions from the binary file generated by the compiler. These instructions were then decoded and executed by the virtual core, which was essential for security analysis and experimentation.
🔹 Throughout the project, we ensured the security and reliability of the virtual core, ensuring that it could execute instructions in a secure and reproducible manner.
🔹 Project link: Kilian-Pichard/virtual_core
-
CY Tech (formerly EISTI) - Pau/Cergy (France)
(Sept 2021 - Dec 2021)University Project - Development of a Web Application
🔹 Design and development of a web application to help students revise before exams.
🔹 Development using IntelliJ with Java and the Spring framework to utilize Spring Boot and Spring Data JPA.
🔹 Technologies: Java, HTML, CSS, JavaScript, IntelliJ, Spring Boot, Spring Data JPA, Git, GitHub.
-
Bayonne and Basque Country Institute of Technology - Anglet (France)
(Sept 2019 - May 2020)University Project - Development of an Android Application
🔹 Design and development of a music learning application for Android, called Zic’All.
🔹 Development using Android Studio with Java for the logic part and XML for the graphical part.
🔹 Technologies: Java, XML, Android Studio, Git, GitHub.
Skills
🛡️ Cybersecurity & Networks
🔹 Network Security: Firewalling (Stormshield, Palo Alto, Fortinet), network segmentation, VPN (IPsec, TLS, WireGuard), NAT, ACL
🔹 Hardening of Equipment: Securing and advanced configuration of firewalls, switches (Cisco, Brocade), and encryption devices
🔹 Log Analysis & Monitoring: Configuration and management of syslog servers, anomaly detection, SIEM (Splunk, Wazuh)
🔹 Security Audits & Testing: Network compliance verification, traffic analysis (Nmap, Wireshark)
⚙️ DevSecOps & Automation
🔹 Security in CI/CD Pipelines: Integration of security best practices into DevOps processes.
🔹 Infrastructure as Code & Automation: Use of Ansible, Docker, Docker Compose, Portainer, and Proxmox to manage and automate infrastructures, with Python/Bash script development.
🔹 PKI Certificate Management: Configuration and management of certificates to secure communications.
📜 Standards & Compliance
🔹 Frameworks & Standards: Implementation of ANSSI best practices, CIS Benchmarks and vendors
🔹 Compliance & Infrastructure Security: Ensuring compliance with security standards (ISO 27001, II 901, ANSSI RGS, NIS 2)
🔹 System Audits & Hardening: Enhancing the security of equipment and systems in sensitive environments
🛠️ Tools & Technologies
🔹 SIEM & Log Analysis: Splunk, ELK, Wazuh, managing and utilizing system and network logs
🔹 System Security: Windows Server, Linux (Debian, Red Hat, Ubuntu), access control and permission auditing
🔹 Testing & Analysis Tools: Wireshark (packet analysis), Nmap (network mapping)