freiberufler Cyber Security Consultant auf freelance.de

Cyber Security Consultant

zuletzt online vor wenigen Stunden
  • 120€/Stunde
  • 20459 Hamburg
  • Umkreis (bis 200 km)
  • de  |  en
  • 04.08.2026
  • Contract ready

Kurzvorstellung

Fast 10 Jahre Berufserfahrung in der IT, über 5 Jahre im Security Operations Center einer regulierten Großbank.
Zuletzt als Leitender SOC Analyst und stellv. Teamleiter eines 11-köpfigen Teams.

Geschäftsdaten

 Freiberuflich
 Berufshaftpflichtversicherung aktiv

Qualifikationen

  • Analyst Informationssicherheit
  • Cyber Security
  • Cyber Security Engineer
  • IT-Sicherheitsberater
  • ITIL
  • Projektmanagement (IT)6 J.
  • Prozessoptimierung
  • Security Operations Center (SOC)
  • Sicherheitskonzept
  • Sicherheitsmanagement

Projekt‐ & Berufserfahrung

Lead SOC Analyst & Deputy Head of SOC (Festanstellung)
Kundenname anonymisiert, Berlin
4/2024 – 12/2025 (1 Jahr, 9 Monate)
Banken
Tätigkeitszeitraum

4/2024 – 12/2025

Tätigkeitsbeschreibung

Coordination of SOC Operations (11 Analysts)
Product Owner SIEM
Interviewing / Mentoring new Analysts
Major Incident Response / -Management
Project Management (up to 150k€ budget)
Creating BPMN-Compliant Processes & DORA-Compliant Policies

Took ownership of a company-wide Password Management Solution across all employees: from a structured competitor comparison through budgeting and contract negotiations to resource management during implementation. The entire procurement and implementation process was managed end to end by me.

Eingesetzte Qualifikationen

Projektmanagement (IT), Budgetierung

SOC Analyst (Festanstellung)
Kundenname anonymisiert, Berlin
9/2021 – 3/2024 (2 Jahre, 7 Monate)
Banken
Tätigkeitszeitraum

9/2021 – 3/2024

Tätigkeitsbeschreibung

Incident Response /-Management in accordance with NIST
Conducting Root Cause Analysis
Designing Standard Operating Procedures & Unified Playbooks
Vulnerability Management
Threat Intelligence & Threat Hunting
Onboarding the SOC to AWS

Following a strategic shift toward cloud adoption, the organization migrated all of its on-premises workloads to AWS within a nine-month window. I made strategic decisions around AWS Security Hub and GuardDuty, and their integration into the existing SIEM/SOAR stack. I enhanced the existing SOPs with cloud-native procedures, employing tools such as Crossplane and Terraform to automate and continuously improve the SOCs work.

Eingesetzte Qualifikationen

Projektmanagement (IT)

SecOps Engineer (Festanstellung)
Kundenname anonymisiert, Berlin
9/2020 – 8/2021 (1 Jahr)
Banken
Tätigkeitszeitraum

9/2020 – 8/2021

Tätigkeitsbeschreibung

Roll-Out & Operational responsibility for Endpoint-Security (5k Endpoints)
SIEM Administration / Development
Vulnerability Scanning
XDR Security Center Administration

Orchestrated the replacement of historically grown, inconsistent EDR/AV
tools with Microsoft Defender for Endpoint across more than 5,000 endpoints. Beyond the technical migration, a clean, unified baseline configuration was established, providing a reliable foundation for detection, response, and future hardening measures.

Eingesetzte Qualifikationen

Projektmanagement (IT)

System Administrator (Festanstellung)
Kundenname anonymisiert, Berlin
8/2019 – 8/2020 (1 Jahr, 1 Monat)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

8/2019 – 8/2020

Tätigkeitsbeschreibung

Phishing-Training
Entra (AAD) & Endpoint-Administration (500 Endpoints)
OnPrem to M365 / Entra migration
Vulnerability- / Patch-Management

Migrated 300 user objects and a large number of additional mailboxes from
on-premises to Microsoft Entra ID. Following the successful transition, all on-premises Domain Controllers and Exchange servers were fully
decommissioned. A decisive step that reduced maintenance effort, attack
surface, and operating costs alike.

Eingesetzte Qualifikationen

Projektmanagement (IT)

Junior System Administrator (Festanstellung)
Kundenname anonymisiert, Berlin
2/2019 – 7/2019 (6 Monate)
Hochschulen und Forschungseinrichtungen
Tätigkeitszeitraum

2/2019 – 7/2019

Tätigkeitsbeschreibung

MacOS Management & Automation
Improved Monitoring for Servers / Workloads
Entra Administration

Replaced an organically grown legacy monitoring solution with a modern ELK stack. Using Elastic Beats, infrastructure observability was established across 50 servers - from system metrics to centralized logging. The result: faster troubleshooting and significantly improved visibility across the entire server landscape.

Eingesetzte Qualifikationen

Projektmanagement (IT)

Zertifikate

ITIL4
People Cert
2021

Über mich

DORA/NIS2-Compliant Policy Concepting & Process Design :
- Intelligence-Driven Incident Response
- Threat Intelligence
- Threat Hunting
- Threat-led Detection Engineering
- Vulnerability Management
- Deceptive Security
Incident Response Tabletops
Incident Response as Code
SOC Tooling & Architecture / Threat-Informed Defense

Weitere Kenntnisse

SIEM / SOAR : Splunk Enterprise Security, Cortex XSOAR
Deception : Canary Tokens, Honey-Cluster, Automated Artifact-Extraction (TAXII, STIX)
Endpoint Protection : Microsoft Defender for Endpoint, Cybereason, Symantec Endpoint Protection
Cloud Threat Detection : AWS Security Hub / GuardDuty, XDR Security Center, Sentinel
Vulnerability Scanning : Tenable.sc/.io, Nessus, AWS Inspector, Trivy
Script / Query Languages : Powershell, Python, Bash, KQL, SPL
Logging / Visualization : ELK-Stack, Grafana, Prometheus, AWS SecurityLake, JupyterLab
Secrets Management : OpenBao / Hashicorp Vault
IaC : Terraform, Crossplane, Flux v2, Docker, Kubernetes, Gitlab, Harbor

Persönliche Daten

Sprache
  • Deutsch (Muttersprache)
  • Englisch (Fließend)
Reisebereitschaft
Umkreis (bis 200 km)
Home-Office
bevorzugt
Profilaufrufe
54
Berufserfahrung
10 Jahre und 5 Monate (seit 04/2016)

Kontaktdaten

Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.

Jetzt Mitglied werden