Senior Azure Security & AI Security Architect | DORA • NIS2 • BSI C5
- Verfügbarkeit einsehen
- 0 Referenzen
- auf Anfrage
- 60306 Frankfurt am Main
- Weltweit
- hr | de | en
- 24.08.2026
- Contract ready
Kurzvorstellung
Senior Azure Security & AI Security Architect | DORA • NIS2 • BSI C5
Geschäftsdaten
Freiberuflich
Steuernummer bekannt
Berufshaftpflichtversicherung aktiv
Qualifikationen
Über mich
Security Governance & Regulatory Compliance
• DORA: ICT Risk Management, Incident Management, Resilience Testing und ICT Third-Party Risk
• NIS2: Governance, Incident Handling, BCM/Krisenmanagement und Supply Chain Security
• BSI C5: Control Mapping, Cloud Security Controls, Kontrollnachweise und Audit Readiness
• ISO 27001, DSGVO, GAP-Analyse, Maßnahmenplanung und Compliance-by-Design
• Regulatorische Anforderungen in Azure Security Controls und auditfähige Evidenzen übersetzen
Azure Security Architecture
• Security Architecture für komplexe Enterprise- und Cloud-Umgebungen
• Microsoft Defender for Cloud: CSPM, CWPP, Security Posture und Workload Protection
• Microsoft Defender XDR: Endpoint, Identity, Office 365 und Cloud Apps
• Microsoft Sentinel: SOC, SIEM/SOAR, KQL, Analytics Rules, Automation Rules, Playbooks
• Detection Engineering, Threat Hunting, Incident Response und Security Monitoring
• Microsoft Entra ID: Conditional Access, PIM, Identity Governance, Access Reviews, B2B
• Microsoft Purview: Information Protection, DLP, Data Governance, Compliance Monitoring
• Azure Policy, Management Groups, Landing Zones und Compliance-by-Design
• Azure Firewall, NSG, Private Link, WAF, DDoS Protection
• Azure Key Vault, Managed HSM, Secrets und Key Management
• Zero Trust, Least Privilege, Identity- und Network-Segmentation
• PowerShell, Terraform und GitHub Advanced Security
AI Security
• Azure OpenAI, Microsoft AI Foundry, Microsoft Copilot, ChatGPT und LLM Security
• Security Architecture für AI-/LLM-Workloads, Identitäten, Daten, Modelle, RAG und Agents
• Threat Modeling für KI-, LLM- und agentische Anwendungen
• Prompt Injection, Indirect Prompt Injection, Data Leakage und RAG Poisoning
• Agent/Tool Abuse, Excessive Agency, Least Privilege und sichere API-/Plugin-Integration
• Schutz von KI-Identitäten, Secrets, Datenzugriffen und externen Datenquellen
• Guardrails, Content Safety, Monitoring und Security Controls
• Integration von Entra ID, Defender, Sentinel und Purview in AI-Security-Architekturen
Projekt- und Branchenerfahrung
• Banking und Finanzsektor, öffentlicher Dienst, Automotive
• Enterprise-Umgebungen mit 10.000 bis 30.000 Benutzern
• Langjährige Erfahrung in hochregulierten und sicherheitskritischen Umgebungen
Ausbildung
• Dipl.-Ing. Informatik (5-jähriges Studium)
Azure Security & AI Security
• Cybersecurity Architect Expert (SC-100)
• Cloud and AI Security Engineer (SC-500)
• Azure Security Engineer (AZ-500)
• Information Security Administrator (SC-401)
• Identity and Access Administrator (SC-300)
• Security Operations Analyst (SC-200)
• Security, Compliance, and Identity Fundamentals (SC-900)
Azure Architecture
• Azure Solutions Architect Expert (AZ-305)
• Azure Administrator (AZ-104)
Azure Networking
• Azure Network Engineer (AZ-700)
DevSecOps
• GitHub Advanced Security (GH-500)
IT Service Management
• ITIL v3 Foundation (EXIN)
• DORA: ICT Risk Management, Incident Management, Resilience Testing und ICT Third-Party Risk
• NIS2: Governance, Incident Handling, BCM/Krisenmanagement und Supply Chain Security
• BSI C5: Control Mapping, Cloud Security Controls, Kontrollnachweise und Audit Readiness
• ISO 27001, DSGVO, GAP-Analyse, Maßnahmenplanung und Compliance-by-Design
• Regulatorische Anforderungen in Azure Security Controls und auditfähige Evidenzen übersetzen
Azure Security Architecture
• Security Architecture für komplexe Enterprise- und Cloud-Umgebungen
• Microsoft Defender for Cloud: CSPM, CWPP, Security Posture und Workload Protection
• Microsoft Defender XDR: Endpoint, Identity, Office 365 und Cloud Apps
• Microsoft Sentinel: SOC, SIEM/SOAR, KQL, Analytics Rules, Automation Rules, Playbooks
• Detection Engineering, Threat Hunting, Incident Response und Security Monitoring
• Microsoft Entra ID: Conditional Access, PIM, Identity Governance, Access Reviews, B2B
• Microsoft Purview: Information Protection, DLP, Data Governance, Compliance Monitoring
• Azure Policy, Management Groups, Landing Zones und Compliance-by-Design
• Azure Firewall, NSG, Private Link, WAF, DDoS Protection
• Azure Key Vault, Managed HSM, Secrets und Key Management
• Zero Trust, Least Privilege, Identity- und Network-Segmentation
• PowerShell, Terraform und GitHub Advanced Security
AI Security
• Azure OpenAI, Microsoft AI Foundry, Microsoft Copilot, ChatGPT und LLM Security
• Security Architecture für AI-/LLM-Workloads, Identitäten, Daten, Modelle, RAG und Agents
• Threat Modeling für KI-, LLM- und agentische Anwendungen
• Prompt Injection, Indirect Prompt Injection, Data Leakage und RAG Poisoning
• Agent/Tool Abuse, Excessive Agency, Least Privilege und sichere API-/Plugin-Integration
• Schutz von KI-Identitäten, Secrets, Datenzugriffen und externen Datenquellen
• Guardrails, Content Safety, Monitoring und Security Controls
• Integration von Entra ID, Defender, Sentinel und Purview in AI-Security-Architekturen
Projekt- und Branchenerfahrung
• Banking und Finanzsektor, öffentlicher Dienst, Automotive
• Enterprise-Umgebungen mit 10.000 bis 30.000 Benutzern
• Langjährige Erfahrung in hochregulierten und sicherheitskritischen Umgebungen
Ausbildung
• Dipl.-Ing. Informatik (5-jähriges Studium)
Azure Security & AI Security
• Cybersecurity Architect Expert (SC-100)
• Cloud and AI Security Engineer (SC-500)
• Azure Security Engineer (AZ-500)
• Information Security Administrator (SC-401)
• Identity and Access Administrator (SC-300)
• Security Operations Analyst (SC-200)
• Security, Compliance, and Identity Fundamentals (SC-900)
Azure Architecture
• Azure Solutions Architect Expert (AZ-305)
• Azure Administrator (AZ-104)
Azure Networking
• Azure Network Engineer (AZ-700)
DevSecOps
• GitHub Advanced Security (GH-500)
IT Service Management
• ITIL v3 Foundation (EXIN)
Persönliche Daten
Sprache
- Kroatisch (Muttersprache)
- Deutsch (Fließend)
- Englisch (Fließend)
Reisebereitschaft
Weltweit
Arbeitserlaubnis
- Europäische Union
Home-Office
bevorzugt
Profilaufrufe
9238
Berufserfahrung
25 Jahre und 3 Monate
(seit 05/2001)
Projektleitung
12 Jahre
Kontaktdaten
Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.
Jetzt Mitglied werden
