freiberufler Senior Security Architect, CISSP auf freelance.de

Senior Security Architect, CISSP

zuletzt online vor wenigen Stunden
  • auf Anfrage
  • 1050 Wien
  • Weltweit
  • de  |  en  |  fr  |  es
  • 08.09.2026
  • Contract ready

Kurzvorstellung

I'm an IT professional with 20+ years of solid experience. My combined expertise of Cloud Security Architecture, Cloud Solution Architecture and Development Lead allows me to support my customers in a holistic manner when building secure solutions.

Geschäftsdaten

 Gewerbetreibend
 Steuernummer bekannt
 Berufshaftpflichtversicherung aktiv

Qualifikationen

  • Cloud Architect
  • Cyber Security13 J.
  • Security Architect
  • Certified Information Systems Security Professional (CISSP)13 J.
  • Enterprise Architect
  • IAM
  • IT-Sicherheitsberater13 J.
  • Microsoft Azure13 J.

Projekt‐ & Berufserfahrung

Cyber Trust Austria Silver Certification
Kundenname anonymisiert, Wien
6/2026 – 8/2026 (3 Monate)
IT & Entwicklung
Tätigkeitszeitraum

6/2026 – 8/2026

Tätigkeitsbeschreibung

* Led application and implementation of the Cyber Trust Austria Silver label (KSV1870 Cyber Risk A-Rating; 25 validated controls)

* Mapped and fulfilled requirements covering risk management, incident response, access control, vulnerability and penetration testing, BCM, and supply-chain security, aligned with ISO/IEC 27001/27002 control themes and NIS 2 / NISG 2026 expectations

* Coordinated stakeholders, compiled audit evidence, and completed KSV1870 validation

Eingesetzte Qualifikationen

IT-Sicherheitsberater, Certified Information Systems Security Professional (CISSP), Cyber Security, Governance

Carve Out - Security Architecture
Kundenname anonymisiert, Toulouse
1/2026 – 9/2026 (9 Monate)
Life Sciences
Tätigkeitszeitraum

1/2026 – 9/2026

Tätigkeitsbeschreibung

* Strategic carve-out coordination, finalization, and governance-ready handover of a full-site security landscape including privileged access management, Defender XDR, Microsoft Sentinel, Entra ID, Active Directory, and Azure

* Cross-functional coordination with internal stakeholders, counterparty teams, and implementation functions

* Target architecture definition and design decisions for key security components with risk-based prioritization

Eingesetzte Qualifikationen

Cloud Spezialist, Cyber Security, Enterprise Architect, Certified Information Systems Security Professional (CISSP), IT-Sicherheitsberater, Microsoft Azure

Security Audit
Kundenname anonymisiert, Wien
12/2025 – 1/2026 (2 Monate)
Versicherungen
Tätigkeitszeitraum

12/2025 – 1/2026

Tätigkeitsbeschreibung

* Security audit of a cloud-first Azure Databricks environment against Microsoft Cloud Security Benchmark & Azure Policy.

* EntraID attack-path analysis and network assessment (Azure Firewall, NSG rules)

Eingesetzte Qualifikationen

Certified Information Systems Security Professional (CISSP), Databricks, IT-Sicherheitsberater, IT Sicherheit (allg.), Microsoft Azure

Security Architecture for Laboratories
Kundenname anonymisiert, Hamburg
10/2025 – 3/2026 (6 Monate)
Life Sciences
Tätigkeitszeitraum

10/2025 – 3/2026

Tätigkeitsbeschreibung

* Lead architecture position

* Designing lab security architecture from scratch

* Adaptation and application of the Purdue model

* Topics: network architecture, remote access, IAM, secure file exchange, user provisioning, PIM/PAM, Citrix, lab workstations, network detection and response (Vectra AI), and application gateways.

Eingesetzte Qualifikationen

Certified Information Systems Security Professional (CISSP), Cyber Security, IT-Sicherheitsberater, Microsoft Azure, Sicherheitsexperte

Interim Head of Cyber Defense Unit
Kundenname anonymisiert, Hamburg
7/2025 – 9/2026 (1 Jahr, 3 Monate)
Life Sciences
Tätigkeitszeitraum

7/2025 – 9/2026

Tätigkeitsbeschreibung

• Interim position as Head of the Cyber Defense Unit for a international biotech corporation
• Management of Security Architecture, Security Engineering, and Securrity Operations Center (SOC)
• Communication and expectation management with C-level upper management
• Member of the security board

Eingesetzte Qualifikationen

Certified Information Systems Security Professional (CISSP), Cyber Security, IT-Berater, IT Architekt Informationssicherheit, Microsoft Azure

Enterprise Security Architect
Kundenname anonymisiert, Hamburg
3/2024 – 6/2025 (1 Jahr, 4 Monate)
Gesundheitswesen
Tätigkeitszeitraum

3/2024 – 6/2025

Tätigkeitsbeschreibung

* Enterprise Security Architecture consulting for multinational corporation in a regulated field

* Assessment of complex IT security infrastructures on enterprise level including capability transparency, dependencies, and maturity status

* Security solution architecture covering all levels from OT, on-premise server and network infrastructure, cloud in-frastructure with strong focus on Azure Cloud, big-data pipelines, endpoint protection, IAM, as well as global moni-toring and SIEM

* Architecting of Microsoft tiering concept covering on-premise Active Directory (AD), and Entra ID in a complex multi-forest and multi-tenant environment

* Architecture of privileged access, PIM/PAM and JIT strategy for an environment with hybrid identities

* Application-level security architecture including threat modeling, residual risk assessment, and formal architecture/design reviews

* Security training workshops for developers and IT staff with documented control handover and governance alignment

Eingesetzte Qualifikationen

Certified Information Systems Security Professional (CISSP), Cloud (allg.), Cyber Security, IT-Berater, IT-Sicherheitsberater, Microsoft Azure

SW Development & Cyber Security Lead (Festanstellung)
EMTensor GmbH, Wien
12/2019 – 3/2024 (4 Jahre, 4 Monate)
Gesundheitswesen
Tätigkeitszeitraum

12/2019 – 3/2024

Tätigkeitsbeschreibung

EMTensor is developing a novel portable brain scanning device for early stroke detection, where the image reconstruction and centralized monitoring and control of the scanner devices happens in the cloud.

My responsabilities:
* Lead architect and development lead of the entire IoT solution
* Detailed design of the cloud platform
* Design and implementation of the security architecture and the security controls (in the cloud and the IoT devices)
* Security assessment and reporting for FDA submission
* DevOps (setting up pipelines for automatic build, static code analysis and unit tests)
* Global Office 365 admin
* Design and Implementation of company-wide backup concept

Eingesetzte Qualifikationen

IT-Sicherheitsberater, Amazon Web Services (AWS), Certified Information Systems Security Professional (CISSP), Cloud Computing, Cyber Security, DevOps (allg.), Google Cloud, IT Sicherheit (allg.), Microsoft Azure, Microsoft Office 365, Requirement Analyse

Senior Project Manager / Solution Architect / Technical Lead (Festanstellung)
AVL List GmbH, Graz
1/2013 – 12/2019 (7 Jahre)
Automobilindustrie
Tätigkeitszeitraum

1/2013 – 12/2019

Tätigkeitsbeschreibung

Senior Project Manager & Solution Architect in the field of Safety-Critical Systems, Data Integration & Data Management, Big Data and Cloud Computing

At AVL I was leading the development of a Secure Big Data Management and Analytics Cloud Platform in the AVL ADAS (Advanced Driver Assistance Systems) Project House.

Between 2013 and 2016, my key role at AVL List GmbH, was the Global Technical and Strategic Coordinator of the EU CRYSTAL research project; a European research project with a budget of over 82M Euro and 70 international partners with the focus on interoperability standards for safety-critical systems.

-Hyperlink entfernt-

Eingesetzte Qualifikationen

IT-Sicherheitsberater, Automotive functional safety expert (AFSE), Certified Information Systems Security Professional (CISSP), Cyber Security, Microsoft Azure, Projektleitung / Teamleitung (IT), Solution Architektur

Project Manager (Festanstellung)
Vienna University of Technology, Wien
6/2010 – 12/2013 (3 Jahre, 7 Monate)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

6/2010 – 12/2013

Tätigkeitsbeschreibung

Global Project Coordinator of the ARTEMIS ACROSS project (16M€ Budget, 16 Partners)

-Hyperlink entfernt-

Eingesetzte Qualifikationen

Projektmanagement (IT), Solution Architektur

Assistant Professor (Festanstellung)
Vienna University of Technology, Wien
12/2008 – 1/2012 (3 Jahre, 2 Monate)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

12/2008 – 1/2012

Tätigkeitsbeschreibung

- Coordination and research activities in many national and international industry-oriented projects
- Solution architect in several project at the institute
- Coordination, preparation, and submission of project proposals
- Supervision of master and PhD students, lecturing and other teaching activities in the field of embedded systems
- Consulting on a regular basis for industrial partners

Eingesetzte Qualifikationen

Aus- / Weiterbildung, Angewandte Forschung

Research Assistant (Festanstellung)
Vienna University of Technology, Wien
9/2003 – 9/2008 (5 Jahre, 1 Monat)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

9/2003 – 9/2008

Tätigkeitsbeschreibung

Research activities in the DECOS (Dependable Embedded Components and Systems) project (integrated EU project)

Consulting and know‑how transfer between the Robert Bosch GmbH and the Vienna University of Technology in the
field of fault tolerant systems in the automotive sector

Eingesetzte Qualifikationen

Angewandte Forschung

Zertifikate

Microsoft Certified: Azure Security Engineer Associate (Expired November 2024)
Microsoft
2023
Certified Information Systems Security Professional (CISSP)
ISC2
2019

Ausbildung

Dr. techn.
Computer Science (completed with distinction)
Vienna University of Technology
2008
Wien
Dipl. Ing.
Computer Science (completed with distinction)
Vienna University of Technology
2003
Wien

Über mich

I am a solution and security architect with 20+ years of experience in enterprise IT and cybersecurity. During my career, I have built strong expertise in cybersecurity strategy, roadmap and target architecture definition, stakeholder coordination, and translation of technical topics into management-ready recommendations.

I am specialized in Cyber Security, Cloud Computing, AI Security, and Safety-Critical Systems.

I co-founded PrimeFaktor IT Solutions GmbH, a cybersecurity consulting firm focused on securing cloud-native and hybrid enterprise environments.

Weitere Kenntnisse

* Bridge building and senior stakeholder management across strategy, architecture, implementation, and governance functions

* Analytical thinking

* Ability to see the big picture in complex enterprise transformation and cybersecurity initiatives

* Strong stakeholder management across cybersecurity, IT, compliance, legal, procurement, vendor management, and business functions

* Ability to establish and maintain trusted collaboration with culturally diverse teams, senior executives, and external partners

* Excellent communication and presentation skills demonstrated in international conferences, steering boards, and management briefings

* Problem-solving attitude with strong prioritization and decision support capabilities

* Ability to create alignment, motivation, and ownership across cross-functional teams

* Strategic cybersecurity architecture for enterprise environments, including roadmap and target architecture definition

* Translation of business, compliance, and risk requirements into enforceable security controls, governance models, and architecture guardrails

* Security Architecture for AI on enterprise level, as well as on solution level

* Microsoft security stack expertise: Defender family, Microsoft Sentinel, Microsoft Purview, Microsoft Entra, and Copilot

*Identity Security with Entra ID: Identity Governance, Conditional Access, MFA, Passwordless Authentication, RBAC, and Privileged Access Management (PAM/PIM)

* Hands-on experience with Microsoft 365 licensing and capability mapping: E5, E3, F3, F5 security, and Microsoft 365 Business Premium

* Governance, KPI, reporting, and maturity-oriented security management frameworks for enterprise programs

* Security frameworks and standards (e.g., BSI-Grundschutz, NIST, ISO 27001, CIS, OWASP Top 10, HIPAA, GDPR, NIS2)

* Threat modeling and security risk assessment, including residual risk and AI-related security risk evaluation

* Definition of logging, monitoring, and detection requirements with SIEM/SOC integration (Microsoft Sentinel)

* Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP)

* Embedded Systems and Internet-of-Things

* Safety-Critical Systems & Hard Real-Time Systems

* Big Data Architectures & Scalable Execution Platforms (Hadoop, Spark, Kafka, Elastic Search, Kubernetes, AKS, Docker, Databricks)

* Management of critical cloud resources via Infrastructure-as-Code with Terraform

* Hands on development experience in multiple programming languages and frameworks (C#, .NET, Python, React, C, C++, Android, iOS, JavaScript, Java, SQL, …)

Persönliche Daten

Sprache
  • Deutsch (Muttersprache)
  • Englisch (Fließend)
  • Französisch (Grundkenntnisse)
  • Spanisch (Grundkenntnisse)
Reisebereitschaft
Weltweit
Arbeitserlaubnis
  • Europäische Union
  • Schweiz
Home-Office
bevorzugt
Profilaufrufe
1153
Alter
50
Berufserfahrung
23 Jahre und 8 Monate (seit 01/2003)
Projektleitung
15 Jahre

Kontaktdaten

Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.

Jetzt Mitglied werden