Your security is our priority+1 438 799 4154info@obkoni.comFrançais

Your security is our priority

Securing the cloud, identities and the projects that matter.

obKoni helps banks, public bodies and growing companies assess cyber risk, design their access architecture and deliver critical IT projects. You work directly with senior consultants.

Expertise

Seven practices, one standard of rigour.

Every mandate ends with a concrete deliverable: an assessment report, a target architecture, a roadmap or a delivered project.

Cloud security and governance

Assessment of your AWS, Azure and GCP environments under the shared responsibility model. Maturity scoring, target operating model (TOM) and a prioritized roadmap.

  • AWS
  • Azure
  • GCP
  • NIST
  • CIS
  • TOM

Application security and penetration testing

Web and API penetration testing, threat modelling and attack trees. Risk-rated reports with remediation your teams can act on.

  • OWASP Top 10
  • ASVS
  • SAMM
  • NIST SSDF
  • DevSecOps

Identity and access (IAM / CIAM)

Design and rollout of workforce and customer identity platforms: federation, strong authentication, provisioning. Experience with journeys serving over a million users.

  • Okta
  • SAML
  • OIDC
  • Entra ID
  • Oracle IAM

Security operations

SIEM and SOAR architecture, security data pipelines and forensic environments on AWS. Detect earlier, respond faster.

  • SIEM
  • SOAR
  • Splunk ES
  • Cribl
  • Forensics

AI system security

Risk assessment specific to artificial intelligence systems: data, models, integrations and governance, aligned with your compliance obligations.

  • NIST AI RMF
  • ISO/IEC 42001
  • Governance
  • AI in SDLC

Cloud-native development and platforms

Design and development of web applications and APIs, containerization and Kubernetes orchestration, CI/CD pipelines with security built in from the start.

  • Kubernetes
  • Docker
  • Node.js
  • Java
  • CI/CD

IT project management and PMO

Leading migrations, infrastructure modernization and project portfolios: schedules, budgets, RAID logs, cutovers and governance, in Agile or waterfall.

  • PMO
  • Cutover
  • RAID
  • Scrum
  • MS Project
  • Jira

A security challenge or an IT project to deliver?

Contact us
  • 2020Delivering consulting mandates since
  • 7Practices across security, cloud and IT projects
  • 1M+Users served by identity platforms we designed
  • 3Continents served: America, Europe and Africa

Industries

Hands-on knowledge of your industry.

Mandates delivered by our consultants, directly or through partners.

Financial services and insurance

Banks and insurers: cloud security, IAM and regulatory compliance.

Public sector

Ministries and agencies: Agile IT projects and governance.

Transportation and logistics

National-scale infrastructure migration and modernization.

Telecommunications

Project portfolios, budget tracking and dashboards.

Technology and SaaS

Application security, SOC 2 and ISO for software vendors.

Agrifood

Structuring operations and performance management tools.

Organizations that trusted us.

  • Banque Nationale du Canada
  • Vidéotron
  • iA Groupe financier
  • Diot-SIACI
  • In Fidem
  • TEKsystems
  • SourceEvolution

Approach

Four steps, every mandate.

  1. Scoping

    Business goals, scope, regulatory constraints and stakeholders.

  2. Assessment

    Gap analysis in the field, grounded in recognized frameworks.

  3. Roadmap

    Target architecture and an action plan prioritized by risk and cost.

  4. Delivery

    Hands-on support for your teams through go-live and handover.

Frameworks we apply

  • NIST CSF 2.0
  • NIST SP 800-218 (SSDF)
  • NIST AI RMF
  • ISO/IEC 27002
  • ISO/IEC 42001
  • CIS Controls v8
  • SOC 2
  • OWASP Top 10
  • OWASP ASVS
  • OWASP SAMM
  • PMBOK
  • Scrum

Profiles

Senior profiles, staffed to fit your mandate.

We build each team from these profiles, from strategic advice to technical delivery.

Expert · 20+ years in IT

Principal advisor, cloud and AI security

Maturity assessments, cloud architectures and AI systems, target operating models and roadmaps for IT and security leadership.

  • CCSP
  • AWS Solutions Architect
  • NIST
  • ISO 27002

Senior · AI governance and security

Senior artificial intelligence advisor

AI governance, security of AI systems, AI for defenders and AI in the software development lifecycle (SDLC).

  • NIST AI RMF
  • ISO/IEC 42001
  • AI Security
  • AI for defenders
  • AI in SDLC

Senior · large-scale platforms

Identity and access architect (IAM / CIAM)

Design and rollout of workforce and customer identity platforms, federation and provisioning, on journeys serving over a million users.

  • Okta certified
  • SAML
  • OIDC
  • Entra ID

Senior · Web and API

Penetration testing and application security specialist

Penetration testing, threat modelling and DevSecOps support, with risk-rated reports.

  • OWASP
  • Burp Suite
  • Threat modeling

Senior · cloud-native

Full stack developer and Kubernetes platforms

Design and development of web applications and APIs, containerization and deployment on Kubernetes, secure CI/CD pipelines.

  • Kubernetes
  • Docker
  • Node.js
  • Java
  • CI/CD

Senior · 15+ years

IT project manager and PMO

Infrastructure migrations and modernization, cutovers, RAID logs, governance and budget tracking, in Agile or waterfall.

  • PSM I
  • MS Project
  • Jira
  • SAP

Senior · Europe

IT project manager

Leading information systems projects for clients in France, from study to go-live.

  • Project management
  • Acceptance testing
  • Vendor management

Looking for another profile?

Let’s talk

A security challenge or an IT project to deliver?

Talk it through with a senior consultant. First conversation, no commitment.

Contact us

Contact

Let’s talk about your next mandate.

Tell us about your context in a few lines. We reply within two business days.