IT-Forensiker ISO/IEC 17024 (Dekra) & ISO 27001 Auditor | Microsoft Security Advisor
- Verfügbarkeit einsehen
- 0 Referenzen
- auf Anfrage
- 86156 Augsburg
- Europa
- de | en
- 12.08.2026
- Contract ready
Kurzvorstellung
Geschäftsdaten
Qualifikationen
Projekt‐ & Berufserfahrung
1/2026 – 3/2026
Tätigkeitsbeschreibung
Retained as a specialized IT Forensics and Incident Response expert to investigate a complex corporate data breach and executive identity fraud attempt.
Conducted advanced forensic preservation of digital evidence and created legally admissible, court-ready documentation using cryptographic chain-of-custody standards.
Developed proactive defensive frameworks against synthetic media, including AI Penetration Testing and Deepfake Defense protocols to mitigate CEO-fraud vulnerabilities.
Outcome: Successfully identified the breach vector, secured data integrity, and hardened the client’s identity infrastructure against next-gen AI attack vectors.
IT-Sicherheitsberater
2/2025 – 8/2025
Tätigkeitsbeschreibung
Architecture Advisory: Acted as the lead strategic advisor during a major global ERP migration to Microsoft Dynamics 365 Business Central, ensuring "Security & Compliance by Design."
Zero-Trust Strategy & Governance: Designed a comprehensive Zero-Trust framework and identity governance strategy, mapping complex corporate access structures into Microsoft Entra ID, Defender, and Purview.
Cross-Functional Process Mapping: Bridged the gap between procurement, IT infrastructure, and legal departments to translate strict global regulatory mandates (REACH, RoHS, CBAM) into automated ERP data models and tamper-proof logging processes.
Risk & Vendor Management: Advised C-level management on risk mitigation regarding data loss prevention (DLP) and structured secure tenant isolation rules for third-party supplier integrations.
Outcome: Successfully aligned the global cloud infrastructure with international compliance standards, securing all critical enterprise ERP touchpoints across five global subsidiaries without disrupting operational workflows.
Certified Information Security Manager
2/2024 – 12/2024
Tätigkeitsbeschreibung
Strategic Advisory & GTM: Acted as the lead external consultant for a premier Swiss Managed Auditing & SOC provider, driving their enterprise security consulting architecture across the DACH region.
SIEM/SOAR Architecture Consulting: Advised enterprise clients on migrating to and optimizing Microsoft Sentinel, designing advanced detection rules, and automating incident response workflows (SOAR) to reduce Mean Time to Detect (MTTD).
Cross-Platform Security Integration: Formulated strategic Blue-Teaming concepts by aligning Microsoft Security stacks (Defender for Endpoint/Cloud, Entra ID) with the provider's centralized SOC monitoring infrastructure.
Compliance & Framework Mapping: Guided corporate security teams in structuring their SOC logging and retention policies to meet strict European regulatory mandates (such as NIS2, DORA, and Swiss DPA).
Outcome: Enabled the Swiss provider to successfully onboard four multi-national enterprise clients in Germany and Austria by delivering high-end, audit-ready Microsoft Sentinel architectures.
Cyber Security, Security Operations Center (SOC)
3/2023 – 12/2023
Tätigkeitsbeschreibung
Conducted a comprehensive GAP analysis and full ISMS Review based on ISO/IEC 27001 and ISO 19011 standards ahead of an official certification audit.
Designed and aligned internal security policies at the intersection of IT, procurement, and legal management to achieve full regulatory compliance (GDPR/NIS2 readiness).
Mapped out risk assessment matrices and established incident response escalation workflows.
Outcome: Successfully navigated the client through the formal ISO 27001 certification process with zero major non-conformities.
Certified Information Security Manager
Zertifikate
DEKRA
ICO
ICO
mITSM GmbH
TEDIC GmbH
Ausbildung
Dekra
Über mich
Core Freelance Specializations:
Digital Forensics & Evidence Authentication: Performing court-admissible investigations into manipulated PDFs, forged emails, altered chat logs, and cloud security breaches—delivering ISO/IEC 27037-compliant forensic expert reports for litigation and M&A due diligence (in partnership with a DEKRA-certified forensic laboratory).
Information Security Management (ISO 27001): Serving as an external/interim Information Security Officer (CISO/ISO 27001), establishing ISMS frameworks, managing risk, and preparing organizations for official certification and regulatory compliance (NIS2, DORA, GDPR).
Microsoft Ecosystem Specialization: Architecting Zero-Trust environments and high-security cloud infrastructures leveraging Microsoft Security, Identity & Compliance (Entra ID, Purview, Defender, Sentinel).
Weitere Kenntnisse
Forensic analysis, incident response, preservation of evidence, and legal admissibility of digital footprints
Microsoft Cloud Security: * Microsoft Security, Identity & Compliance Expert (Specialist for Defender, Sentinel, Entra ID, Purview, and M365 Copilot Compliance)
Strategic Advisory: * Architecture of security frameworks at the intersection of procurement, IT infrastructure, and C-level management
Governance & Audits: * Certified Information Security Officer (ISO/IEC 27001)
Certified Auditor according to ISO 19011 (Planning, execution, and validation of internal/external audits)
Audit Readiness: GAP analyses and design/implementation of Information Security Management Systems (ISMS) ahead of official ISO 27001 certifications.
Emergency & Forensics: Post-incident analysis following cyberattacks, data breach investigations, and the creation of legally admissible, court-ready documentation.
AI & Deepfake Defense: Conducting AI penetration testing and implementing defense strategies against synthetic media and identity fraud (e.g., CEO fraud).
Persönliche Daten
- Deutsch (Muttersprache)
- Englisch (Fließend)
- Europäische Union
- Schweiz
- Vereinigte Staaten von Amerika
Kontaktdaten
Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.
Jetzt Mitglied werden
