Contract & freelance · open via agencies & direct

Davide Guglielmi

Cybersecurity Consultant · Security Culture, Awareness & Human Risk

Security culture, awareness and phishing programs for regulated environments, aligned with ISO 27001 and NIS2.

Background

Recent role

Security Awareness & Communications Manager, BNP Paribas Fortis · Feb 2025 – Oct 2025

Certification

SANS SSAP badge

SANS Security Awareness Professional (SSAP) · GIAC, Oct 2024 · SANS LDR433 Managing Human Risk

Languages

Dutch (native)
English (professional)
French (conversational)
Italian (fluent)

What I bring

Phishing program ownership

Built and ran end-to-end phishing programs for 19,000+ employees across 27 entities: risk-based segmentation, scenario design, campaign operations, and knowledge transfer.

Security culture strategy

Contributed to cyber culture planning at BNP Paribas Fortis: translated maturity data into a 12-month awareness roadmap with target groups, priorities, KPIs, and management reporting.

Multi-client delivery

Delivered 8 concurrent client awareness programs in one year, from government agencies to 1,500+ employee organisations, on KnowBe4 and Phished.io.

KPIs & reporting

Produced maturity KPIs, management dashboards, and repeat-clicker trends, with SOC-aligned data quality that auditors can use.

Compliance alignment

Built audit-ready awareness artefacts for regulated environments: ISO 27001, NIS2, and internal controls.

Handover & process

Documented handover packs and process guides so phishing and awareness operations continue after the contract ends.

Stakeholder communication

Partnered with SOC, HR, Communications, CISOs, and DPOs, including a multi-month password manager rollout with measurable adoption.

Role-based awareness

Designed awareness and training for different audiences — executives, managers, engineers, operators — with content, risk, and reporting aligned to each group.

Role fit

Skills

Platforms

KnowBe4 Phished.io Microsoft 365 SharePoint Teams Exchange Online Microsoft Defender (AST) LMS / SCORM

Program & culture

Human Risk Management Security Culture Role-Based Awareness KPI Design Behavioral Change Audit Evidence

Frameworks

ISO 27001 NIS2 GDPR Internal control mapping

Working on a role in this space?

I can share a full CV and am available for a short call.