freiberufler TISAX / ISO 27000 ISMS Consultant auf freelance.de

TISAX / ISO 27000 ISMS Consultant

offline
  • 40€/Stunde
  • 550248 Sibiu / Hermannstadt
  • Weltweit
  • en  |  ro  |  de
  • 19.10.2023

Kurzvorstellung

Zurzeit bin ich als Berater für ISMS und TISAX tätig. Meine Erfahrung besteht aus mehr als 10 TISAX-Zertifizierungs-, Re-Zertifizierungs- und Label-Upgrade-Audits in Deutschland, als ISMS Consultant für Dassault Systemes GmbH und sensified GmbH.

Qualifikationen

  • BSI-Standards
  • DIN EN ISO 27001
  • DIN ISO/IEC 27002
  • ITIL
  • Projektleitung / Teamleitung (IT)
  • Risikoanalyse
  • Risikomanagement
  • tisax

Projekt‐ & Berufserfahrung

ISMS Consultant for TISAX/ ISO 27001
sensified Solutions GmbH, Pfüllingen
9/2022 – 9/2023 (1 Jahr, 1 Monat)
IT & Entwicklung
Tätigkeitszeitraum

9/2022 – 9/2023

Tätigkeitsbeschreibung

• Managing the internal ISO 27001/TISAX certification program
• Supporting the IT department with the infrastructural design of the company
• Supervising, directing, and planning the activities related to information security.
• Implement Role Based Access Management frameworks and user data anonymization solutions.
• Conducting the yearly awareness training session
• Managing the tasks and activities aimed at achieving information security.
• Developing and implementing information security policies, objectives, and strategies.
• Ensuring the availability of necessary resources for information security management.
• Monitoring and reviewing the performance of the security process.
• Making decisions regarding improvements to the security process.
• Assessing and managing risks associated with information security.
• Reviewing and optimizing security safeguards for their efficiency.
• Enhancing the practical feasibility of technical safeguards and organizational procedures.
• Ensuring compliance with information security standards and regulations.
• Maintaining and improving the level of security in the long run.
• Documenting and reporting on the design and operation of the ISMS.

Eingesetzte Qualifikationen

Certified Information Systems Security Professional (CISSP)

ISMS Consultant for TISAX
Dassault Systemes GmbH, München
3/2022 – 9/2023 (1 Jahr, 7 Monate)
Automobilindustrie
Tätigkeitszeitraum

3/2022 – 9/2023

Tätigkeitsbeschreibung

Responsibilities:

● Clarify priorities to develop an ISMS
● Assess and analyze the organization's existing information security policies, procedures, and controls.
● Conduct the risk management process to identify potential vulnerabilities and threats to the organization's information assets, while creating the internal methodology and reports.
● Develop and implement an ISMS framework based on industry standards such as ISO 27001, TISAX, ISO 27017, TPISR, and BSI-Grundschutz
● Advise and assist in the development of information security policies, procedures, and guidelines.
● Conduct gap analysis to identify areas where the organization's current practices deviate from the desired security standards.
● Collaborate with stakeholders to establish information security objectives and develop a roadmap for achieving them.
● Perform regular audits and assessments to evaluate the effectiveness of the ISMS implementation and identify areas for improvement.
● Provide guidance and support to IT and security teams in implementing security controls, best practices and technical documentation.
● Offer training and awareness programs to educate employees on information security risks and their responsibilities, as well as designing the cybersecurity awareness program.
● Stay updated with emerging security threats and trends to ensure the ISMS remains relevant and effective.
● Create supplier relationships policies and conduct vendor assessments to evaluate the security posture of third-party providers and assess potential risks to the organization, creating also the remediation plans.
● Assist in incident response and management, including investigating security incidents and recommending corrective actions.
● Prepare reports and presentations for management, highlighting the status of the ISMS implementation, identified risks, and proposed solutions.
● Liaise with external auditors and regulatory bodies to ensure compliance with relevant information security standards and regulations.
● Provide ongoing support and guidance to maintain the ISMS and address any security-related concerns or incidents.
● Operate the declared security controls and manage the control measurement procedure.

Eingesetzte Qualifikationen

ITIL, Projektleitung / Teamleitung (IT), Projektmanagement (IT), DIN ISO/IEC 27002, Risikomanagement, Risikoanalyse, DIN EN ISO 27001

Über mich

Experienced Security Consultant with a demonstrated history of working in the management consulting industry. Skilled in Information Security, TISAX/ISO27001, ITIL, IT Service Management, and Risk Management.

At the moment, I am working as a consultant on ISMS and TISAX. My experience consists both of working for one of the biggest software companies in the automotive industry, having participated in more than 10 TISAX certification, re-certification and label upgrade audits in Germany, but also supporting a German tech start-up with the ISO 27001/TISAX certification, as well as helping building their infrastructure.
I am always interested in new challenges and acquiring knowledge.

Persönliche Daten

Sprache
  • Englisch (Muttersprache)
  • Rumänisch (Muttersprache)
  • Deutsch (Fließend)
Reisebereitschaft
Weltweit
Arbeitserlaubnis
  • Europäische Union
Home-Office
bevorzugt
Profilaufrufe
118
Alter
26
Berufserfahrung
2 Jahre und 1 Monat (seit 03/2022)
Projektleitung
2 Jahre

Kontaktdaten

Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.

Jetzt Mitglied werden