Process automation
Reduce duplicate data entry, repetitive tasks and manual steps by turning a business process into a working workflow.
AM Cyber - Independent consultant
I connect your tools, automate your processes and turn threat information into analysis that supports your decisions.
EPITECH graduate in software development (five years of higher education), then a CTI analyst in a CERT and specialist firms.
01 / Areas of work
Adding a new tool does not always solve the problem. I work where processes, data and software need to function together.
Reduce duplicate data entry, repetitive tasks and manual steps by turning a business process into a working workflow.
Connect existing tools so information flows between them, reducing manual operations and duplicate data entry.
Put the necessary components in place when a simple workflow is no longer enough: services, access, infrastructure, backups and continuity.
Python · Django · n8n · API Tools are chosen to fit the need.
02 / Areas of work
Threat monitoring, digital exposure analysis and CTI feed integration to inform your security decisions.
CTI analyst at CERT Sopra Steria, then at XMCO and Calypt: vulnerability prioritisation, reports and alerts, EASM / dark web monitoring and OSINT analysis of the digital exposure of sensitive profiles.
OpenCTI functional lead at XMCO: collection, API ingestion, CTI feeds and IoCs. At CERT Sopra Steria: Python automation of imports into MISP.
03 / Projects
Fewer promises, more systems actually built.
Process automation
For a company specialising in crisis exercises: a web application connects client information collection, document generation, the scenario and the exercise timeline with the CRM and mobile device management (MDM).
API integrations and generative AI at selected relevant steps automate much of the preparation.
Preparing an exercise
≈ 30 min
Preparation can be completed in around 30 minutes under the intended conditions, compared with several hours previously.
Software product
Crisis Input
Crisis Input is an independently developed tool for simulating media pressure during a crisis exercise.
An instance was subsequently deployed in a client’s environment. A dedicated integration layer connects the software to their exercise preparation process.
Discover Crisis Input (new tab)Information system
Redesign of self-hosted IT systems with a highly available Proxmox cluster, to improve service continuity and control over data while limiting external dependencies.
Client infrastructure hosted in France; OVH / Scaleway backups.
04 / Kévin Severin
2015–2021 · EPITECH (five-year programme)
Python / Django web application development at IMS Networks (2016), followed by internal applications at the French Ministry of the Armed Forces (2019).
09/2020–02/2021 · Cellule Renseignement 66
End-to-end design of a business tool for analysts in a general intelligence unit. A first immersion in intelligence work.
2021–2024 · CERT Sopra Steria · XMCO · Calypt
Vulnerability analysis, EASM, dark web and OSINT. Automated MISP imports and OpenCTI feed ingestion.
Since July 2024 · AM Cyber
Automation, development, integrations and IT systems. Cybersecurity awareness and co-facilitation of crisis exercises.
From April 2025 to August 2026, volunteer IT manager for a national association handling sensitive data: IT systems design and deployment, email, web, internal tools, access, onboarding and automation, with heightened confidentiality requirements.
05 / Working principles
I start with the process and constraints before choosing a technology.
A new application is not always the answer. The first goal is to make existing tools work better.
Generative AI is integrated when it brings a tangible benefit, not as a marketing claim.
06 / Frequently asked questions
My work covers both business process automation and integration, as well as Cyber Threat Intelligence.
No. I use generative AI only when it adds tangible value to the process. Deterministic automation or a conventional API integration is often preferable.
Not necessarily. Much of my work is specifically about connecting and automating the tools already in use before considering new ones.
It depends on the assignment. An EASM/OSINT assessment can be carried out without internal access. An integration or IT systems deployment project requires only the access needed for the work, following the principle of least privilege.
07 / Contact
Describe the context and the problem to solve. I can quickly tell you whether it falls within my scope of work.
Conversations in French or English.
contact@am-cyber.com