freiberufler Cybersecurity & AI Governance Consultant (ISO 27001, NIS-2, TISAX, ISO 42001) auf freelance.de

Cybersecurity & AI Governance Consultant (ISO 27001, NIS-2, TISAX, ISO 42001)

offline
  • 125€/Stunde
  • Dittweiler, Pfalz
  • Weltweit
  • de  |  en  |  es  |  fr
  • 03.02.2026

Kurzvorstellung

Freiberuflicher Experte für Cybersecurity & KI-Governance. Ich helfe Unternehmen, Security, Compliance und KI sicher zu integrieren, pragmatisch, modern und businessorientiert.

Auszug Referenzen (1)

"Herr E. hat verantwortlich gezeichnet für die administrative Betreuung der PAM Infrastruktur eines Kunden."
PAM Consultant
Andreas Hartje
Tätigkeitszeitraum

3/2021 – 10/2021

Tätigkeitsbeschreibung

Implementation and adaptation of the CyberArk solution to the existing infrastructure to secure privileged access (PAM) including:
• Creation and management of all accounts, safes & platforms of the acceptance environment via PVWA as well as Rest API
• Administration of CyberArk servers on infrastructure & OS level
• Execution of technical acceptance tests
• Monitoring of infrastructure components
• Documentation of processes, components & platforms

Eingesetzte Qualifikationen

Access Management, Benutzerverwaltung, Berechtigungskonzept, Identitätsmanagement

Geschäftsdaten

 Steuernummer bekannt
 Berufshaftpflichtversicherung aktiv

Qualifikationen

  • Access Management1 J.
  • Certified Information Systems Security Professional (CISSP)1 J.
  • CISO
  • Cloud (allg.)2 J.
  • Cyber Security4 J.
  • DIN EN ISO 27001
  • Enterprise Architect (EA)3 J.
  • Information Systems Manager
  • Informationssicherheit1 J.
  • Ingenieurwissenschaft4 J.
  • ISO / IEC 27001
  • Management-Informationssysteme3 J.
  • NIS-2
  • Projektmanagement (IT)
  • Wirtschaftsinformatik3 J.

Projekt‐ & Berufserfahrung

CISO (external)
Joint Venture aus Versicherern, Hamburg
9/2025 – offen (10 Monate)
Versicherungen
Tätigkeitszeitraum

9/2025 – offen

Tätigkeitsbeschreibung

Establishment of a security governance framework, implementation of ISO 27001-aligned controls, development of risk, incident, and third-party management processes, and strategic guidance for secure cloud and AI adoption across the organization.

Eingesetzte Qualifikationen

Informationssicherheit, Information Systems Manager, ISO / IEC 27001

CISO (external)
Internationales Energieunternehmen, Berlin
6/2025 – 9/2025 (4 Monate)
High-Tech- und Elektroindustrie
Tätigkeitszeitraum

6/2025 – 9/2025

Tätigkeitsbeschreibung

Analysis of the company's overall cybersecurity posture, implementation and countermeasures, planning for the establishment of a dedicated Cybersecurity department, and ensuring the secure deployment of AI technologies

Eingesetzte Qualifikationen

Cyber Security, DIN EN ISO 27001, It-Governance

Trainer für sicheren Einsatz von KI
bitkom Akademie, Berlin
2/2025 – offen (1 Jahr, 5 Monate)
Dienstleistungsbranchen (Service)
Tätigkeitszeitraum

2/2025 – offen

Tätigkeitsbeschreibung

Trainer für den sicheren EInsatz von KI

Eingesetzte Qualifikationen

Cyber Security, Certified Information Systems Security Professional (CISSP)

Subject matter expert for security architecture
Kundenname anonymisiert, Stuttgart
10/2023 – 12/2023 (3 Monate)
Automobilindustrie
Tätigkeitszeitraum

10/2023 – 12/2023

Tätigkeitsbeschreibung

SME for Security Architecture in the SAFE landscape performing analyses of security status on ART level and development of security architecture artefacts on Capability, Large Solution and Platform level including:
Analysis of the DevSecOps process in all ARTs of a digitalization department
Identification of decision points for security issues in the DevSecOps process
Analysis of the decision levels in the SAFe framework (products, ARTs, solution, portfolio)
Analysis of decision-making bodies and participants
Alignment of architecture and security artefacts on all levels
Analysis of overlaps between architecture and security artefacts
Identification of decision points for Architecture topics
Analysis of decision levels in the SAFe framework (products, ARTs, solution, portfolio).
Analysis and linking to the Domain Model / Architecture Target Landscape
Depiction of the dependencies between architecture and IT security
Development of security guidelines for architecture, etc.
Creation of result and management presentations

Eingesetzte Qualifikationen

Enterprise Architect (EA), Solution Architektur

Security Coordinator in an ISO/ISA supporting role
Kundenname anonymisiert, Stuttgart
4/2023 – 12/2023 (9 Monate)
Automobilindustrie
Tätigkeitszeitraum

4/2023 – 12/2023

Tätigkeitsbeschreibung

Creation and implementation of processes including:
• Analysis of existing policies, security standards and blueprints
• Interviews with different stakeholders to evaluate security status in products to adapt project plan
• Gap analysis
• Adapting of project plan based on risk assessment and gap analysis. Priorizitation by using OWASP Top 10 Cybersecurity risks as a reference
• Support with moving legacy application to cloud (AWS)
• Development of secure coding guidelines, static code analysis and dynamic code analysis by using different tools (SonarQube, BlackDuck, Prisma, …)
• Communication interface between development teams and central cybersecurity (business- and operations side)
• Conducting of workshop to raise awareness on team level and sharpen understanding of responsibilities
• Development of shared responsibilities and RACI-matrix
• Improvement of security standards and blueprints including feedback loops from development teams and central cybersecurity
• Plan and implementation of suitable knowledge management
• Roll-out of new standards, processes and blueprints and enabling of development teams for following topics (excerpt):
o User Access Management
o Vulnerability Management
o Incident Management
o Asset Management
o Hardening
o Backup & Recovery
o Patch Management
o Logging and Monitoring
o Data protection
• Presentation of results on management level to raise awareness about security status

Eingesetzte Qualifikationen

Access Management, Amazon Web Services (AWS), Back up / Recovery, Benutzerverwaltung, Berechtigungskonzept, Cloud (allg.), Cyber Security, Incident-Management, Projektleitung / Teamleitung (IT), Prozessmanagement

Lead GDPR Taskforce (Datenschutz)
Kundenname anonymisiert, Stuttgart
10/2022 – 6/2023 (9 Monate)
Automobilindustrie
Tätigkeitszeitraum

10/2022 – 6/2023

Tätigkeitsbeschreibung

Lead GDPR taskforce including coordinating teams, preparing and conducting workshops, preparing management decisions and providing checklists and best practices to teams including:
• Analysis of existing material and guidelines from central security
• Gap analysis
• Design and conduction of management workshops to raise awareness for GDPR
• Set up of a roadmap to be compliant with GDPR requirements before Go-Live
• Design and conduction of workshops on product level to asses GDPR status, clarify open questions, definition of next steps and clarification of (shared) responsibilities
• Creation of documentation blueprints and steps to perform to be able to fulfill:
o RoPA
o TOM
o Retention periods
o Technical requirements
o Data Subject Rights
o Deletion concept
• Analysis of created documentation from products, processing of results, support with steering team discussions and escalation processes

Eingesetzte Qualifikationen

Datenschutz, Projektleitung / Teamleitung (IT)

Lecturer and scientific contact for IT-Security
DHWB Mannheim, Mannheim
9/2022 – offen (3 Jahre, 10 Monate)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

9/2022 – offen

Tätigkeitsbeschreibung

Reading lectures on specific security topics. Contact person for scientific questions. Proofreader for scientific papers

Eingesetzte Qualifikationen

Cyber Security, Management-Informationssysteme, Enterprise Architect (EA), Ingenieurwissenschaft, Wirtschaftsinformatik

TISAX Implementer
Kundenname anonymisiert, Hamburg
3/2022 – 11/2022 (9 Monate)
Dienstleistungsbranche
Tätigkeitszeitraum

3/2022 – 11/2022

Tätigkeitsbeschreibung

Development and implementation of an ISMS in accordance with TISAX requirements including:
• Assessment of security status and documentation
• Gap analysis
• Processing of TISAX requirements and derivation of necessary steps
• Analysis and editing of security policies
• Implementation of an ISMS in organization
• Creation of processes and documentation
• Readiness assessment
• Audit support

Eingesetzte Qualifikationen

Informationssicherheit

Project Manager for Science
Kundenname anonymisiert, Darmstadt
3/2022 – 7/2022 (5 Monate)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

3/2022 – 7/2022

Tätigkeitsbeschreibung

Scrum project manager in science for following projects:
• Smart city project to detect traffic jams and accidents automatically with AI
• Smart railway project to improve time forecast for trains
• Internal railway infrastructure project to replace old and hardcoded codebase with object-oriented programming language and dynamic frontend

Eingesetzte Qualifikationen

Ingenieurwissenschaft, Projektleitung / Teamleitung (IT), Projektmanagement (IT)

Security Program Manager
Kundenname anonymisiert, Stuttgart
1/2022 – 6/2023 (1 Jahr, 6 Monate)
Automobilindustrie
Tätigkeitszeitraum

1/2022 – 6/2023

Tätigkeitsbeschreibung

Design and implementation of a security strategy as part of a sales process redesign program involving 1.200 employees including:
• Definition of KPI’s and OKR’s
• Implementation and optimization of Quality Gates on platform level
• Recurring awareness sessions for different stakeholders (management, PO’s, security responsibles, …)
• Preparation and conduction of workshops for different purposes and audiences
• Analysis of existing security tools and AWS services
• Alignment of an appropriate security toolchain (BlackDuck, SecHub, Habor, AWS Services, …)
• Central cybersecurity communication and presentation support
• Development of central documentation strategy
• Creation of central documentation for everyone who wants to onboard on platform
• Moderation of regular security guild meeting including management of topics and guest speakers

Eingesetzte Qualifikationen

Cloud (allg.), Amazon Web Services (AWS), Cyber Security, DevOps (allg.), Incident-Management, Programm-Management

PAM Consultant
Kundenname anonymisiert, Frankfurt
3/2021 – 10/2021 (8 Monate)
Banken
Tätigkeitszeitraum

3/2021 – 10/2021

Tätigkeitsbeschreibung

Implementation and adaptation of the CyberArk solution to the existing infrastructure to secure privileged access (PAM) including:
• Creation and management of all accounts, safes & platforms of the acceptance environment via PVWA as well as Rest API
• Administration of CyberArk servers on infrastructure & OS level
• Execution of technical acceptance tests
• Monitoring of infrastructure components
• Documentation of processes, components & platforms

Eingesetzte Qualifikationen

Access Management, Benutzerverwaltung, Berechtigungskonzept, Identitätsmanagement

IAM Consultant
Kundenname anonymisiert, Düsseldorf
4/2020 – 10/2020 (7 Monate)
Konsumgüterindustrie
Tätigkeitszeitraum

4/2020 – 10/2020

Tätigkeitsbeschreibung

Line support and consulting for Identity & Access implementation requests

Eingesetzte Qualifikationen

Identitätsmanagement

Ausbildung

Informatik
M.Sc.
TU Darmstadt
2022
Darmstadt
Praktische Informatik
B.Sc.
HTW des Saarlandes
2019
Saarbrücken

Über mich

Üblicherweise in folgenden Rollen:
- Interim CISO
- Interim ISO
- Security Champion
- Trainer in Workshops

Top Qualifikationen:
ISMS nach ISO 27001, TISAX, NIS-2 | ISO 42001 | Sicherer Einsatz von KI | Cybersecurity Awareness | Risikoabwägungen

Dafür bin ich genau der Richtige:
- Planung und Implementierung eines ISMS (ISO 27001, TISAX, NIS-2) und AIMS (ISO 42001)
- Effiziente Implementierung von Cybersecurity in Anlehnung an Business Anforderungen
- Schnittstelle zwischen technischen und business-orientierten Stakeholdern
- Sparringspartner mit dem Management zur Erarbeitung von Lösungen und Diskussion von Risikobewältigungsstrategien
- Big Picture: Wie kann Cybersecurity das Business absichern ohne es zu bremsen?
- Schulungen von Mitarbeitern in Unternehmen
- Konzeption und Durchführung von Workshops z.B. sicherer Einsatz von KI, Security Awareness, ...
- Wie kann KI sicher im Unternehmen eingesetzt werden?

Persönliche Daten

Sprache
  • Deutsch (Muttersprache)
  • Englisch (Fließend)
  • Spanisch (Grundkenntnisse)
  • Französisch (Grundkenntnisse)
Reisebereitschaft
Weltweit
Arbeitserlaubnis
  • Europäische Union
Home-Office
bevorzugt
Profilaufrufe
773
Alter
30
Berufserfahrung
7 Jahre und 5 Monate (seit 01/2019)
Projektleitung
4 Jahre

Kontaktdaten

Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.

Jetzt Mitglied werden