freiberufler Operational Resilience and Delivery Lead (Register of Information, ICT Third-Party Oversight) auf freelance.de

Operational Resilience and Delivery Lead (Register of Information, ICT Third-Party Oversight)

online
  • auf Anfrage
  • München
  • National
  • es  |  en  |  de
  • 04.03.2026
  • Contract ready

Kurzvorstellung

Delivery lead with 15+ years in payments. I lead cross-functional delivery across technology, risk, compliance, and procurement.

Geschäftsdaten

 Freiberuflich
 Steuernummer bekannt
 Berufshaftpflichtversicherung aktiv

Qualifikationen

  • Governance1 J.
  • Operative Resilienz
  • Risikomanagement
  • Cyber-Resilienz-Strategie
  • DORA-Informationsregister
  • DORA-Umsetzung
  • Informationssicherheit4 J.
  • ISO / IEC 27001
  • Pci DSS
  • SWIFT3 J.

Projekt‐ & Berufserfahrung

DORA RoI Health Check: tool development and BaFin submission validation
trigosec, Munich
11/2025 – 2/2026 (4 Monate)
IT & Entwicklung
Tätigkeitszeitraum

11/2025 – 2/2026

Tätigkeitsbeschreibung

- Built a browser-based RoI validation tool covering package structure, XBRL-CSV metadata, referential integrity, and EBA business rules; runs thousands of checks entirely in the browser without data upload (https://www.trigosec.com/dora-roi-health-check)

- Used the tool to identify and fix issues prompting a successful test submission in the BaFin test environment

- Outcome: tool publicly available and free; submission passed BaFin automated validations

Eingesetzte Qualifikationen

Cyber Security, Compliance management

Business continuity and disaster recovery for critical or important functions
Payment Institution (details on request), Munich
4/2025 – 8/2025 (5 Monate)
Finanzdienstleister
Tätigkeitszeitraum

4/2025 – 8/2025

Tätigkeitsbeschreibung

- Designed and operationalised BC/DR for critical or important functions in a DORA context
- Defined recovery and emergency processes with dependencies, escalation mechanisms, and RTO targets derived from Business Impact Analyses
- Coordinated implementation with IT, information security, business owners, and third parties; integrated outcomes into governance, risk, and resilience structures
- Outcome: BC/DR plans defined with clear RTO targets, ownership, and escalation paths for critical or important functions; ready for testing

Eingesetzte Qualifikationen

Cyber Security, Governance, Informationssicherheit

Vulnerability management and KPI framework
Payment Institution (details on request), Munich
3/2025 – 8/2025 (6 Monate)
Finanzdienstleister
Tätigkeitszeitraum

3/2025 – 8/2025

Tätigkeitsbeschreibung

- Defined KPIs to steer remediation speed and backlog evolution, using risk-based prioritisation by system criticality

- Established escalation and reporting processes integrated into ICT risk management governance

- Outcome: remediation backlog made measurable and risk-prioritised; vulnerability posture visible at executive level through decision-ready reporting

Eingesetzte Qualifikationen

Informationssicherheit

DORA RoI implementation and CSSF submission
Payment Institution (details on request), Munich
10/2024 – 4/2025 (7 Monate)
Finanzdienstleister
Tätigkeitszeitraum

10/2024 – 4/2025

Tätigkeitsbeschreibung

- Collected and validated data across 100+ providers and around 10 critical or important functions from distributed sources (Procurement, IT, Risk)
- Built data quality gates to catch inconsistencies early, resolving classification gaps and format issues before submission
- Outcome: BAU operating model with defined ownership and quality gates; successful submission within the first days of the window

Eingesetzte Qualifikationen

Cyber Security, Datenmodelierung, Governance, Informationssicherheit

ICT third-party oversight and resilience assessment for critical providers
Payment Institution (details on request), Munich
9/2024 – 12/2024 (4 Monate)
Finanzdienstleister
Tätigkeitszeitraum

9/2024 – 12/2024

Tätigkeitsbeschreibung

- Conducted cyber security assessments and Business Impact Analyses for providers supporting critical or important functions, covering technical and organisational security measures, dependencies, and recovery time objectives

- Structured and maintained third-party and dependency data as input to ICT risk management and the Register of Information; coordinated with Procurement, IT, Information Security, and business units

- Outcome: assessment and BIA results captured for critical or important functions; third-party and dependency data integrated into ICT risk management and the Register of Information

Eingesetzte Qualifikationen

Cyber Security, Governance, Informationssicherheit, ISO / IEC 27001

DORA implementation and cyber resilience strategy
Payment Institution (details on request), Munich
4/2024 – 12/2024 (9 Monate)
Finanzdienstleister
Tätigkeitszeitraum

4/2024 – 12/2024

Tätigkeitsbeschreibung

- Designed and led a 6-workstream DORA programme across Risk, Technology, Legal, Compliance, and Procurement

- Translated DORA requirements into a working operating model: defined ownership, decision rights, escalation paths, and a reporting cadence from weekly PMO to quarterly board (including Luxembourg Authorised Managers)

- Outcome: governance framework adopted into BAU; passed internal audit without significant findings

Eingesetzte Qualifikationen

Cyber Security, Governance, Informationssicherheit, Projektleitung / Teamleitung, Risikomanagement

Interim CISO
Payment Institution (details on request), Munich
1/2024 – 4/2024 (4 Monate)
Finanzdienstleister
Tätigkeitszeitraum

1/2024 – 4/2024

Tätigkeitsbeschreibung

- Led PCI DSS recertification and ISO/IEC 27001 activities (evidence, remediation tracking, audit readiness)

- Managed incident response, SOC focus (signal-to-noise), and executive reporting

- Outcome: certifications on track; security governance handed over to permanent leadership without continuity gap

Eingesetzte Qualifikationen

Informationssicherheit, Pci DSS, Security Operations Center (SOC), Incident-Management, ISO / IEC 27001

Key management transformation
Payment Institution (details on request), Munich
1/2023 – 12/2023 (1 Jahr)
Finanzdienstleister
Tätigkeitszeitraum

1/2023 – 12/2023

Tätigkeitsbeschreibung

- Migrated from a custom key management solution to AWS KMS, establishing durable governance for cryptographic assets

- Built a key inventory and dependency map across applications, coordinating platform and engineering teams for a safe migration

- Implemented rotation, monitoring, and access control processes with audit-ready evidence for each

- Outcome: migration completed without service disruption; full cryptographic asset inventory established, replacing a bespoke solution with governed, auditable controls

Eingesetzte Qualifikationen

Cyber Security Engineer, Digitale Transformation

SWIFT MT to ISO 20022 migration
Payment Institution (details on request), Munich
1/2022 – 12/2022 (1 Jahr)
Finanzdienstleister
Tätigkeitszeitraum

1/2022 – 12/2022

Tätigkeitsbeschreibung

- Co-owned delivery with Treasury: target architecture, transition approach, and risk control

- Coordinated Engineering and Operations to maintain regulatory and operational continuity through cutover

- Outcome: migration delivered without service disruption or customer interface impact

Eingesetzte Qualifikationen

SWIFT

Certificates and PKI governance programme
Payment Institution (details on request), Munich
1/2022 – 12/2022 (1 Jahr)
Finanzdienstleister
Tätigkeitszeitraum

1/2022 – 12/2022

Tätigkeitsbeschreibung

- Identified and inventoried production certificates and keys, eliminating "shadow certificates" and unclear lifecycle ownership

- Defined lifecycle processes for issuance, renewal, rotation, and decommissioning with clear roles, approvals, and evidence requirements

- Aligned governance to regulated-environment expectations (including PCI DSS)

- Outcome: shadow certificates eliminated; structured lifecycle governance established with clear accountability and PCI DSS-aligned evidence, reducing risk of unplanned expirations

Eingesetzte Qualifikationen

Informationssicherheit

Brexit-driven payments and settlement migration
Payment Institution (details on request), Munich
6/2020 – 12/2020 (7 Monate)
Finanzdienstleister
Tätigkeitszeitraum

6/2020 – 12/2020

Tätigkeitsbeschreibung

- Co-owned delivery with Treasury to identify and onboard new partner banks and migrate payment and settlement workflows to work with them, driven by Brexit regulatory changes

- Defined target state options and decision material; coordinated Treasury, Engineering, Operations, and external partners

- Outcome: new partner banks onboarded and payment and settlement workflows migrated without service disruption

Eingesetzte Qualifikationen

SWIFT, Systemmigration

Infrastructure and platform transformation
Payment Institution (details on request), Munich
4/2020 – 12/2021 (1 Jahr, 9 Monate)
Finanzdienstleister
Tätigkeitszeitraum

4/2020 – 12/2021

Tätigkeitsbeschreibung

- Led engineering, infrastructure, and platform architecture; later took additional Interim CTO responsibility

- Migrated critical systems from data centre to AWS-based cloud architecture

- Restructured engineering ways of working to reduce silos and improve delivery speed, reliability, and root cause discipline

- Outcome: stabilisation and scaling of a globally operating payments platform

Eingesetzte Qualifikationen

Cloud Computing, Systemmigration, Amazon Web Services (AWS)

Banking infrastructure and SWIFT connectivity, build and operations
Payment Institution (details on request), Munich
1/2018 – 3/2020 (2 Jahre, 3 Monate)
Finanzdienstleister
Tätigkeitszeitraum

1/2018 – 3/2020

Tätigkeitsbeschreibung

- Led the build and operation of banking and payments infrastructure including SWIFT connectivity

- Implemented and operated SWIFT Alliance Lite2 and integrated SWIFT messaging into a microservice architecture

- Drove hardening and operational controls aligned to SWIFT CSP; coordinated internal teams and external infrastructure and security providers

- Outcome: stable operation of a regulated BaaS payments infrastructure under CSSF supervision, with SWIFT CSP controls embedded

Eingesetzte Qualifikationen

Informationssicherheit, SWIFT

Ausbildung

Universität Valladolid
B.Sc. & Ing. Informatik

Valladolid

Über mich

Operational and cyber resilience practitioner with 15+ years in payments and financial services. I translate regulatory and risk requirements (DORA, ICT risk governance, third-party oversight) into operating models, and deliver end-to-end outcomes with engineering teams, risk, compliance, legal, and procurement.
Most experienced in Luxembourg and UK regulated environments (CSSF, FCA) with additional BaFin exposure. Comfortable leading multi-stream delivery with executive cadence and board-level reporting.

Weitere Kenntnisse

Resilience operating model design:
Critical services, dependency mapping (internal and third-party), measurable risk signals, and recoverability tested.

Security governance and assurance:
KRIs and thresholds tied to decisions, drills and simulations, audit readiness (PCI DSS, ISO 27001), incident governance and executive reporting.

ICT third-party oversight:
Criticality and dependency intelligence, concentration risk visibility, external risk signals beyond questionnaires, proportionate oversight and evidence.

Cross-functional transformation:
Multi-stream execution across Risk, Compliance, Technology, Legal and Procurement, with governance cadence, escalation paths, and steering-level reporting.

Digital Operational Resilience Act delivery (including RoI):
DORA workstreams translated into BAU operating models, RoI as a governed dataset (XBRL-CSV, validation-first), and submission readiness.

Resilience engineering:
Point-of-change guardrails (DevSecOps) that keep delivery fast and generate continuous evidence for governance and assurance.

Persönliche Daten

Sprache
  • Spanisch (Muttersprache)
  • Deutsch (Gut)
  • Englisch (Fließend)
Reisebereitschaft
National
Arbeitserlaubnis
  • Europäische Union
Profilaufrufe
58
Berufserfahrung
2 Jahre und 2 Monate (seit 01/2024)

Kontaktdaten

Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.

Jetzt Mitglied werden