AM Cyber - Independent consultant

Process automation and Cyber Threat Intelligence

I connect your tools, automate your processes and turn threat information into analysis that supports your decisions.

EPITECH graduate in software development (five years of higher education), then a CTI analyst in a CERT and specialist firms.

From tools to a system
Business toolsCRMDataAPIDocumentsApplication services
Connect.
Automate.
An IT foundation that fits
Useful flows. A coherent whole.
01 Automation 02 APIs & integrations 03 IT systems

01 / Areas of work

What I build

Adding a new tool does not always solve the problem. I work where processes, data and software need to function together.

01

Process automation

Reduce duplicate data entry, repetitive tasks and manual steps by turning a business process into a working workflow.

  • Workflows
  • Document generation
  • Synchronisation
  • Generative AI where useful
02

Integrations & APIs

Connect existing tools so information flows between them, reducing manual operations and duplicate data entry.

  • CRM
  • MDM
  • API
  • Third-party services
  • Internal tools
03

IT systems design & deployment

Put the necessary components in place when a simple workflow is no longer enough: services, access, infrastructure, backups and continuity.

  • Self-hosting
  • Access management
  • Virtualisation
  • Backups
  • Business continuity & disaster recovery

Python · Django · n8n · API Tools are chosen to fit the need.

02 / Areas of work

Cyber Threat Intelligence

Threat monitoring, digital exposure analysis and CTI feed integration to inform your security decisions.

CTI analyst at CERT Sopra Steria, then at XMCO and Calypt: vulnerability prioritisation, reports and alerts, EASM / dark web monitoring and OSINT analysis of the digital exposure of sensitive profiles.

  • OpenCTI
  • MISP
  • EASM
  • OSINT
  • Dark web
  • Vulnerability analysis

OpenCTI functional lead at XMCO: collection, API ingestion, CTI feeds and IoCs. At CERT Sopra Steria: Python automation of imports into MISP.

How I can help

  • External attack surface assessment - EASM / OSINT
  • Tailored monitoring and intelligence
  • CTI / OpenCTI feed automation and integration
  • Cybersecurity awareness
Discuss your needs

03 / Projects

Selected projects

Fewer promises, more systems actually built.

Software product

Crisis Input

Media pressure simulation for crisis exercises

Crisis Input is an independently developed tool for simulating media pressure during a crisis exercise.

  • Email
  • News
  • Simulated social network
  • TV / media

An instance was subsequently deployed in a client’s environment. A dedicated integration layer connects the software to their exercise preparation process.

Discover Crisis Input (new tab)

Information system

Redesigning and running a small business’s IT systems

Redesign of self-hosted IT systems with a highly available Proxmox cluster, to improve service continuity and control over data while limiting external dependencies.

  • Self-hosted open source
  • Proxmox HA cluster
  • Replication
  • Independent backups
  • CRM & business applications
  • MDM

Client infrastructure hosted in France; OVH / Scaleway backups.

04 / Kévin Severin

A background in analysis and development

My background on LinkedIn (new tab)
  1. Software development

    2015–2021 · EPITECH (five-year programme)

    Python / Django web application development at IMS Networks (2016), followed by internal applications at the French Ministry of the Armed Forces (2019).

  2. Intelligence

    09/2020–02/2021 · Cellule Renseignement 66

    End-to-end design of a business tool for analysts in a general intelligence unit. A first immersion in intelligence work.

  3. Cyber Threat Intelligence

    2021–2024 · CERT Sopra Steria · XMCO · Calypt

    Vulnerability analysis, EASM, dark web and OSINT. Automated MISP imports and OpenCTI feed ingestion.

  4. Independent consultant

    Since July 2024 · AM Cyber

    Automation, development, integrations and IT systems. Cybersecurity awareness and co-facilitation of crisis exercises.

From April 2025 to August 2026, volunteer IT manager for a national association handling sensitive data: IT systems design and deployment, email, web, internal tools, access, onboarding and automation, with heightened confidentiality requirements.

05 / Working principles

Understand first. Build next.

Needs before tools

I start with the process and constraints before choosing a technology.

Connect before adding

A new application is not always the answer. The first goal is to make existing tools work better.

AI where it helps

Generative AI is integrated when it brings a tangible benefit, not as a marketing claim.

06 / Frequently asked questions

Before we talk

Do you only work on cybersecurity?

My work covers both business process automation and integration, as well as Cyber Threat Intelligence.

Do you always use AI?

No. I use generative AI only when it adds tangible value to the process. Deterministic automation or a conventional API integration is often preferable.

Do we need to replace our existing tools?

Not necessarily. Much of my work is specifically about connecting and automating the tools already in use before considering new ones.

Do you need access to our IT systems?

It depends on the assignment. An EASM/OSINT assessment can be carried out without internal access. An integration or IT systems deployment project requires only the access needed for the work, following the principle of least privilege.

07 / Contact

A process to simplify?
Tools to connect?
A specific CTI need?

Describe the context and the problem to solve. I can quickly tell you whether it falls within my scope of work.

Conversations in French or English.

contact@am-cyber.com

Let’s discuss your needs

Anti-spam verification

Your information is used solely to answer your request. Privacy