Operational Resilience and Delivery Lead (Register of Information, ICT Third-Party Oversight)
- Verfügbarkeit einsehen
- 0 Referenzen
- auf Anfrage
- München
- National
- es | en | de
- 04.03.2026
- Contract ready
Kurzvorstellung
Geschäftsdaten
Qualifikationen
Projekt‐ & Berufserfahrung
11/2025 – 2/2026
Tätigkeitsbeschreibung
- Built a browser-based RoI validation tool covering package structure, XBRL-CSV metadata, referential integrity, and EBA business rules; runs thousands of checks entirely in the browser without data upload (https://www.trigosec.com/dora-roi-health-check)
- Used the tool to identify and fix issues prompting a successful test submission in the BaFin test environment
- Outcome: tool publicly available and free; submission passed BaFin automated validations
Cyber Security, Compliance management
4/2025 – 8/2025
Tätigkeitsbeschreibung
- Designed and operationalised BC/DR for critical or important functions in a DORA context
- Defined recovery and emergency processes with dependencies, escalation mechanisms, and RTO targets derived from Business Impact Analyses
- Coordinated implementation with IT, information security, business owners, and third parties; integrated outcomes into governance, risk, and resilience structures
- Outcome: BC/DR plans defined with clear RTO targets, ownership, and escalation paths for critical or important functions; ready for testing
Cyber Security, Governance, Informationssicherheit
3/2025 – 8/2025
Tätigkeitsbeschreibung
- Defined KPIs to steer remediation speed and backlog evolution, using risk-based prioritisation by system criticality
- Established escalation and reporting processes integrated into ICT risk management governance
- Outcome: remediation backlog made measurable and risk-prioritised; vulnerability posture visible at executive level through decision-ready reporting
Informationssicherheit
10/2024 – 4/2025
Tätigkeitsbeschreibung
- Collected and validated data across 100+ providers and around 10 critical or important functions from distributed sources (Procurement, IT, Risk)
- Built data quality gates to catch inconsistencies early, resolving classification gaps and format issues before submission
- Outcome: BAU operating model with defined ownership and quality gates; successful submission within the first days of the window
Cyber Security, Datenmodelierung, Governance, Informationssicherheit
9/2024 – 12/2024
Tätigkeitsbeschreibung
- Conducted cyber security assessments and Business Impact Analyses for providers supporting critical or important functions, covering technical and organisational security measures, dependencies, and recovery time objectives
- Structured and maintained third-party and dependency data as input to ICT risk management and the Register of Information; coordinated with Procurement, IT, Information Security, and business units
- Outcome: assessment and BIA results captured for critical or important functions; third-party and dependency data integrated into ICT risk management and the Register of Information
Cyber Security, Governance, Informationssicherheit, ISO / IEC 27001
4/2024 – 12/2024
Tätigkeitsbeschreibung
- Designed and led a 6-workstream DORA programme across Risk, Technology, Legal, Compliance, and Procurement
- Translated DORA requirements into a working operating model: defined ownership, decision rights, escalation paths, and a reporting cadence from weekly PMO to quarterly board (including Luxembourg Authorised Managers)
- Outcome: governance framework adopted into BAU; passed internal audit without significant findings
Cyber Security, Governance, Informationssicherheit, Projektleitung / Teamleitung, Risikomanagement
1/2024 – 4/2024
Tätigkeitsbeschreibung
- Led PCI DSS recertification and ISO/IEC 27001 activities (evidence, remediation tracking, audit readiness)
- Managed incident response, SOC focus (signal-to-noise), and executive reporting
- Outcome: certifications on track; security governance handed over to permanent leadership without continuity gap
Informationssicherheit, Pci DSS, Security Operations Center (SOC), Incident-Management, ISO / IEC 27001
1/2023 – 12/2023
Tätigkeitsbeschreibung
- Migrated from a custom key management solution to AWS KMS, establishing durable governance for cryptographic assets
- Built a key inventory and dependency map across applications, coordinating platform and engineering teams for a safe migration
- Implemented rotation, monitoring, and access control processes with audit-ready evidence for each
- Outcome: migration completed without service disruption; full cryptographic asset inventory established, replacing a bespoke solution with governed, auditable controls
Cyber Security Engineer, Digitale Transformation
1/2022 – 12/2022
Tätigkeitsbeschreibung
- Co-owned delivery with Treasury: target architecture, transition approach, and risk control
- Coordinated Engineering and Operations to maintain regulatory and operational continuity through cutover
- Outcome: migration delivered without service disruption or customer interface impact
SWIFT
1/2022 – 12/2022
Tätigkeitsbeschreibung
- Identified and inventoried production certificates and keys, eliminating "shadow certificates" and unclear lifecycle ownership
- Defined lifecycle processes for issuance, renewal, rotation, and decommissioning with clear roles, approvals, and evidence requirements
- Aligned governance to regulated-environment expectations (including PCI DSS)
- Outcome: shadow certificates eliminated; structured lifecycle governance established with clear accountability and PCI DSS-aligned evidence, reducing risk of unplanned expirations
Informationssicherheit
6/2020 – 12/2020
Tätigkeitsbeschreibung
- Co-owned delivery with Treasury to identify and onboard new partner banks and migrate payment and settlement workflows to work with them, driven by Brexit regulatory changes
- Defined target state options and decision material; coordinated Treasury, Engineering, Operations, and external partners
- Outcome: new partner banks onboarded and payment and settlement workflows migrated without service disruption
SWIFT, Systemmigration
4/2020 – 12/2021
Tätigkeitsbeschreibung
- Led engineering, infrastructure, and platform architecture; later took additional Interim CTO responsibility
- Migrated critical systems from data centre to AWS-based cloud architecture
- Restructured engineering ways of working to reduce silos and improve delivery speed, reliability, and root cause discipline
- Outcome: stabilisation and scaling of a globally operating payments platform
Cloud Computing, Systemmigration, Amazon Web Services (AWS)
1/2018 – 3/2020
Tätigkeitsbeschreibung
- Led the build and operation of banking and payments infrastructure including SWIFT connectivity
- Implemented and operated SWIFT Alliance Lite2 and integrated SWIFT messaging into a microservice architecture
- Drove hardening and operational controls aligned to SWIFT CSP; coordinated internal teams and external infrastructure and security providers
- Outcome: stable operation of a regulated BaaS payments infrastructure under CSSF supervision, with SWIFT CSP controls embedded
Informationssicherheit, SWIFT
Ausbildung
Valladolid
Über mich
Most experienced in Luxembourg and UK regulated environments (CSSF, FCA) with additional BaFin exposure. Comfortable leading multi-stream delivery with executive cadence and board-level reporting.
Weitere Kenntnisse
Critical services, dependency mapping (internal and third-party), measurable risk signals, and recoverability tested.
Security governance and assurance:
KRIs and thresholds tied to decisions, drills and simulations, audit readiness (PCI DSS, ISO 27001), incident governance and executive reporting.
ICT third-party oversight:
Criticality and dependency intelligence, concentration risk visibility, external risk signals beyond questionnaires, proportionate oversight and evidence.
Cross-functional transformation:
Multi-stream execution across Risk, Compliance, Technology, Legal and Procurement, with governance cadence, escalation paths, and steering-level reporting.
Digital Operational Resilience Act delivery (including RoI):
DORA workstreams translated into BAU operating models, RoI as a governed dataset (XBRL-CSV, validation-first), and submission readiness.
Resilience engineering:
Point-of-change guardrails (DevSecOps) that keep delivery fast and generate continuous evidence for governance and assurance.
Persönliche Daten
- Spanisch (Muttersprache)
- Deutsch (Gut)
- Englisch (Fließend)
- Europäische Union
Kontaktdaten
Nur registrierte PREMIUM-Mitglieder von freelance.de können Kontaktdaten einsehen.
Jetzt Mitglied werden
