Senior Azure Security & Compliance Architect | Defender•Sentinel•Purview•Entra•AI | DORA•NIS2•BSI C5
- Verfügbarkeit einsehen
- 0 Referenzen
- auf Anfrage
- 60306 Frankfurt am Main
- Weltweit
- hr | de | en
- 12.08.2026
- Contract ready
Kurzvorstellung
Senior Azure Security und Compliance Architect mit über 20 Jahren Projekterfahrung im Finanzsektor und öffentlichen Dienst.
Geschäftsdaten
Freiberuflich
Steuernummer bekannt
Berufshaftpflichtversicherung aktiv
Qualifikationen
Über mich
Azure Security & Compliance – Fähigkeiten
• Regulatorische Compliance: DORA, NIS2, BSI C5, ISO 27001 und DSGVO
• Überführung regulatorischer Anforderungen in technische Security Controls
• Azure Security Architecture, Security Governance und Zero Trust
• Azure- und AI-Security-Architektur für Azure OpenAI, AI Foundry und Microsoft Copilot
• Absicherung von AI-Workloads, Identitäten, Daten, Modellen und Schnittstellen
• Bedrohungsmodellierung für AI-Anwendungen: Prompt Injection, Datenabfluss, unsichere Modellausgaben und AI Supply Chain Risks
• Security Controls für RAG, AI Agents, Plugins und externe Datenquellen
• Microsoft Security Copilot für Threat Analysis, Incident Response und Security Operations
• Microsoft Sentinel: SIEM/SOAR, Analytics Rules, Automation Rules und Playbooks
• Microsoft Defender XDR und Defender for Cloud
• Detection Engineering, Security Use Cases und KQL-basiertes Threat Hunting
• Microsoft Entra ID: Identity & Access Management, Conditional Access, PIM und Zero Trust
• Microsoft 365 Security: Exchange Online, SharePoint Online, OneDrive und Teams Security
• Microsoft Purview: Information Protection, Data Loss Prevention und Data Governance
• Azure Policy, Management Groups, Landing Zones und Compliance Monitoring
• Network Security: Azure Firewall, NSG, Private Link, WAF und DDoS Protection
• Incident Response, Security Monitoring und Cyber Resilience
• Backup, Business Continuity und Disaster Recovery
• PowerShell, Terraform und GitHub Advanced Security
Branchenerfahrung
• Finanzsektor und internationale Banken
• Öffentlicher Dienst und hochregulierte Enterprise-Umgebungen
• Komplexe IT-Landschaften mit 10.000 bis 30.000 Benutzern
Projektschwerpunkte
• Azure Security, Microsoft 365 Security, AI Security und Compliance
• Security Architecture, Security Governance und Zero-Trust-Transformation
• Compliance Assessments, Gap-Analysen und technische Kontrollkonzeption
• Entwicklung und Implementierung nachvollziehbarer Security Controls
• Absicherung von Cloud- und AI-Workloads
• Security Monitoring, Detection Engineering und Incident-Response-Automatisierung
• Audit Readiness und revisionssichere Security-Dokumentation
Ausbildung
• Dipl.-Ing. Informatik (5-jähriges Studium)
Azure Security & Compliance
• Cybersecurity Architect Expert (SC-100)
• Cloud and AI Security Engineer (SC-500)
• Azure Security Engineer (AZ-500)
• Information Security Administrator (SC-401)
• Identity and Access Administrator (SC-300)
• Security Operations Analyst (SC-200)
• Security, Compliance, and Identity Fundamentals (SC-900)
Azure Architecture
• Azure Solutions Architect Expert (AZ-305)
• Azure Administrator (AZ-104)
• Azure Network Engineer (AZ-700)
Azure Virtual Desktop
• Azure Virtual Desktop Specialty (AZ-140)
DevSecOps
• GitHub Advanced Security (GH-500)
Microsoft Legacy-Zertifizierungen
• MCSE, MCSA, MCITP, MCTS, MCP
IT Service Management
• ITIL v3 Foundation (EXIN)
• Regulatorische Compliance: DORA, NIS2, BSI C5, ISO 27001 und DSGVO
• Überführung regulatorischer Anforderungen in technische Security Controls
• Azure Security Architecture, Security Governance und Zero Trust
• Azure- und AI-Security-Architektur für Azure OpenAI, AI Foundry und Microsoft Copilot
• Absicherung von AI-Workloads, Identitäten, Daten, Modellen und Schnittstellen
• Bedrohungsmodellierung für AI-Anwendungen: Prompt Injection, Datenabfluss, unsichere Modellausgaben und AI Supply Chain Risks
• Security Controls für RAG, AI Agents, Plugins und externe Datenquellen
• Microsoft Security Copilot für Threat Analysis, Incident Response und Security Operations
• Microsoft Sentinel: SIEM/SOAR, Analytics Rules, Automation Rules und Playbooks
• Microsoft Defender XDR und Defender for Cloud
• Detection Engineering, Security Use Cases und KQL-basiertes Threat Hunting
• Microsoft Entra ID: Identity & Access Management, Conditional Access, PIM und Zero Trust
• Microsoft 365 Security: Exchange Online, SharePoint Online, OneDrive und Teams Security
• Microsoft Purview: Information Protection, Data Loss Prevention und Data Governance
• Azure Policy, Management Groups, Landing Zones und Compliance Monitoring
• Network Security: Azure Firewall, NSG, Private Link, WAF und DDoS Protection
• Incident Response, Security Monitoring und Cyber Resilience
• Backup, Business Continuity und Disaster Recovery
• PowerShell, Terraform und GitHub Advanced Security
Branchenerfahrung
• Finanzsektor und internationale Banken
• Öffentlicher Dienst und hochregulierte Enterprise-Umgebungen
• Komplexe IT-Landschaften mit 10.000 bis 30.000 Benutzern
Projektschwerpunkte
• Azure Security, Microsoft 365 Security, AI Security und Compliance
• Security Architecture, Security Governance und Zero-Trust-Transformation
• Compliance Assessments, Gap-Analysen und technische Kontrollkonzeption
• Entwicklung und Implementierung nachvollziehbarer Security Controls
• Absicherung von Cloud- und AI-Workloads
• Security Monitoring, Detection Engineering und Incident-Response-Automatisierung
• Audit Readiness und revisionssichere Security-Dokumentation
Ausbildung
• Dipl.-Ing. Informatik (5-jähriges Studium)
Azure Security & Compliance
• Cybersecurity Architect Expert (SC-100)
• Cloud and AI Security Engineer (SC-500)
• Azure Security Engineer (AZ-500)
• Information Security Administrator (SC-401)
• Identity and Access Administrator (SC-300)
• Security Operations Analyst (SC-200)
• Security, Compliance, and Identity Fundamentals (SC-900)
Azure Architecture
• Azure Solutions Architect Expert (AZ-305)
• Azure Administrator (AZ-104)
• Azure Network Engineer (AZ-700)
Azure Virtual Desktop
• Azure Virtual Desktop Specialty (AZ-140)
DevSecOps
• GitHub Advanced Security (GH-500)
Microsoft Legacy-Zertifizierungen
• MCSE, MCSA, MCITP, MCTS, MCP
IT Service Management
• ITIL v3 Foundation (EXIN)
Persönliche Daten
Sprache
- Kroatisch (Muttersprache)
- Deutsch (Fließend)
- Englisch (Fließend)
Reisebereitschaft
Weltweit
Arbeitserlaubnis
- Europäische Union
Home-Office
bevorzugt
Profilaufrufe
9156
Berufserfahrung
25 Jahre und 3 Monate
(seit 05/2001)
Projektleitung
12 Jahre
Kontaktdaten
Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.
Jetzt Mitglied werden
