Results-driven IT Security Manager providing freelance cybersecurity leadership and hands-on security expertise.
Aktualisiert am 27.06.2026
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 01.07.2026
Verfügbar zu: 100%
davon vor Ort: 100%
GRC
Business Continuity Management
Threat Management
Vulnerability management
Risikomanagement
agiles Projektmanagement
SDLC
Security Operations center
Stakeholdermanagement
IT/OT
ISMS implementation
Audits management
English
Muttersprache
German
Verhandlungssicher

Einsatzorte

Einsatzorte

Berlin (+50km)
Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

2 Jahre 2 Monate
2023-09 - 2025-10

Designed and implemented a global vulnerability management program

Pentest, Threat & Vulnerability Manager (IT + OT) Burp Suite Kali Linux Metasploit ...
Pentest, Threat & Vulnerability Manager (IT + OT)
  • Designed and implemented a global vulnerability management program across IT & OT business units.
  • Coordinated penetration-testing programs across multiple global divisions.
  • Provided Executive Cyber Threat Briefings to the Group CIO, highlighting risk-informed security investments.
  • Led vulnerability prioritization and remediation coordination with infrastructure and application teams.
  • Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors.
  • Led Risk assessments and vulnerability exception processes for critical systems.
  • Assisted in the development, implementation and maintenance of the organizations BCM framework.
  • Collaborated with business stakeholders to gather requirements, define project goals and manage expectations.
  • Facilitated decision-making processes and conflict resolution among team members & stakeholders.
  • Collaborated with OT Security Architects to implement industrial network segmentation & risk mitigation strategy.
  • Supported internal and external security audits.
  • Developed project plans, sprints roadmaps and release schedules.
  • Managed annual cyber security tooling budget and vendor evaluation for my services.

Rapid7 Qualys Nozomi ServiceNow tenable cyberint darktrace cortex CMDB
Burp Suite Kali Linux Metasploit vulnerability management and automation
5 Monate
2023-04 - 2023-08

Developed and implemented enterprise security policies and guidelines

IT-Security Analyst
IT-Security Analyst
  • Contributed to the design and implementation of information security governance processes.
  • Developed and implemented enterprise security policies and guidelines.
  • Performed risk assessments to evaluate threats, vulnerabilities and potential business disruptions (BCM)
  • Built a structured vulnerability management framework, including policies and remediation workflows.
  • Conducted security risk assessments across offices in 24 countries.
  • Supported GDPR-related security approvals and incident response processes.
  • Managed Enterprise Email Security Platform & conducted organization-wide phishing awareness training.
Kyocera (Meerbusch, Germany)
2 Jahre 10 Monate
2020-06 - 2023-03

Managed a vulnerability-scanning infrastructure

IT-Security Analyst (Vulnerability Management)
IT-Security Analyst (Vulnerability Management)
  • Managed a vulnerability-scanning infrastructure including distributed scanning engines & credential scanning.
  • Managed automated vulnerability scans, automated ticketing system and risk-based remediation prioritization.
  • Worked closely with infrastructure and patch management teams to improve remediation efficiency.
  • Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors.
  • Manage and integrate SAST /DAST/ IAST findings into CI/CD pipelines and DevSecOps workflows.
  • Consulting & Support for development teams in Application Security & SSDLC.
  • Managed project scope, schedules, resources, risks and deliverables through the project lifecycle.
  • Making different security policies and complete framework of patch management cycle.
  • Supporting SIEM logs, Web Security Appliance, Email Security Appliance, ddos Alarms, DNS Analytics.
  • Investigated phishing incidents and suspicious emails reported by employees.
FlatexDegiro AG (Frankfurt, Germany)
6 Monate
2019-09 - 2020-02

Ensured product security compliance

Information Security Officer
Information Security Officer
  • Ensured product security compliance for external safety and certification audits.
  • Managed security patch releases for enterprise customers.
  • Responsible for both enterprise and product security assurance.
  • Evaluated secure communication channels between POS terminals and backend servers.
Dafuer Gmbh (Darmstadt, Germany)
5 Monate
2019-02 - 2019-06

Conducted research & controls mapping on security standards

Master Thesis (IT-Security - O.T. & IT- monitoring + prevention)
Master Thesis (IT-Security - O.T. & IT- monitoring + prevention)
  • Conducted research & controls mapping on security standards including NIST, BSI, and IEC 62443.
  • Designed a Purdue Model-based OT/IT security laboratory environment.
  • Implemented intrusion detection and prevention using Fortigate firewall and Nozomi OT security platform.
  • Developed and executed three attack scenarios to validate the effectiveness of the monitoring architecture.
TüV Rheinland (Gelnhausen & Cologne)
6 Monate
2018-09 - 2019-02

Supported real-time sensor data infrastructure

Workstudent (Operations Support)
Workstudent (Operations Support)
  • Supported real-time sensor data infrastructure during live sporting events.
  • Resolving NTP issues, Implementing firewall rules and system hardening on Linux servers.
  • Configured file integrity monitoring tools to support IT security audit compliance.
AGT International (Darmstadt, Germany)
1 Jahr 5 Monate
2017-09 - 2019-01

Supported networking and cybersecurity laboratory sessions

Work student (HIWI ? Information Networks Labor)
Work student (HIWI ? Information Networks Labor)
  • Supported networking and cybersecurity laboratory sessions.
  • Working with Cisco routers, switches, firewall and encryption techniques in the lab.
  • Guide students to a networking and security lab consisting of OSPF, EIGRP, BGP, Nmap, and firewall working.
  • Setting up a firewall (UFW & IP tables) and 2-factor authentication on Raspberry Pi.
  • Developed practical demonstrations of security attacks including DNS spoofing and SSL stripping.
Hochschule Darmstadt (Darmstadt, Germany)
6 Monate
2018-03 - 2018-08

Conducted security analysis of ZigBee smart home devices.

Internee (Penetration Tester)
Internee (Penetration Tester)
  • Conducted security analysis of ZigBee smart home devices.
  • Demonstrated replay attacks on smart home communication protocols.
  • Conducted hardware security testing using UART, JTAG, SPI and I2C interfaces.
  • Developed a proof-of-concept attack environment using Raspberry Pi.
Verband der Elektrotechnik (VDE) (Offenbach, Germany)
1 Jahr 9 Monate
2015-01 - 2016-09

IT Security Consultant

IT Security Consultant (Finance Industry Clients) C# C++ Python ...
IT Security Consultant (Finance Industry Clients)

  

  

  

  

  

  

  

  

  

  

  

  

·   Provided support for IT security audits, including preparation of evidence, documentation review, and facilitation of audit requirements.

IBMQradr Tenable
C# C++ Python JavaScript

Aus- und Weiterbildung

Aus- und Weiterbildung

3 Jahre
2016-09 - 2019-08

Electrical Engineering and Information Technology (majors: Communications)

Masters of Science (MS), Grade (Good) ? 2.0, Hochschule Darmstadt (Darmstadt, Germany)
Masters of Science (MS), Grade (Good) ? 2.0
Hochschule Darmstadt (Darmstadt, Germany)

Kompetenzen

Kompetenzen

Top-Skills

GRC Business Continuity Management Threat Management Vulnerability management Risikomanagement agiles Projektmanagement SDLC Security Operations center Stakeholdermanagement IT/OT ISMS implementation Audits management

Produkte / Standards / Erfahrungen / Methoden

Professional Summary

  • Cybersecurity professional with more than 8+ years of extensive experience leading enterprise security and vulnerability management IT/OT Programs within international organizations. Proven ability to design and implement global vulnerability management & Governance programs, coordinate enterprise penetration testing, and deliver strategic threat intelligence to executive leadership. 
  • Experienced in collaborating with SOC teams, security architects, and C-level stakeholders to strengthen cyber resilience across large environments. Strong background in security governance, risk and compliance frameworks. Experienced in Service Provider management and specialized in bridging technical cybersecurity operations with strategic risk management.


Core Expertise

  • (IT/OT) Vulnerability Management 
  • ISMS development 
  • Threat Intelligence 
  • Threat Hunting 
  • Risk Management 
  • Governance 
  • Compliance 
  • Frameworks 
  • SOC management (SIEM, EDR/XDR) 
  • Security Program Design & Development 
  • Project Management 
  • Security Audits Support 
  • Pentest Support 
  • Executive C-Level Reporting 
  • Consulting


Sec Tools & Tech

  • Vulnerability Management: Qualys, Rapid7 (VMinsight), Tenable (Nessus)
  • SOC: IBM QRadar, LogRhythm, Microsoft Sentinal
  • Security Testing: Burp Suite, Kali Linux, Metasploit
  • OT Security: Nozomi Networks
  • Others: Jira ticketing system, SNOW ticketing system, Wireshark / NMAP


Frameworks

  • NIS 2
  • ISO 2700-X
  • DORA
  • MaRisk
  • NIST SP-800
  • IEC 62443-X
  • BSI-X
  • CIS Benchmark
  • NIST CSF
  • KRITIS
  • BCM / ISMS / DR
  • Cyber Resilience Act

Einsatzorte

Einsatzorte

Berlin (+50km)
Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

2 Jahre 2 Monate
2023-09 - 2025-10

Designed and implemented a global vulnerability management program

Pentest, Threat & Vulnerability Manager (IT + OT) Burp Suite Kali Linux Metasploit ...
Pentest, Threat & Vulnerability Manager (IT + OT)
  • Designed and implemented a global vulnerability management program across IT & OT business units.
  • Coordinated penetration-testing programs across multiple global divisions.
  • Provided Executive Cyber Threat Briefings to the Group CIO, highlighting risk-informed security investments.
  • Led vulnerability prioritization and remediation coordination with infrastructure and application teams.
  • Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors.
  • Led Risk assessments and vulnerability exception processes for critical systems.
  • Assisted in the development, implementation and maintenance of the organizations BCM framework.
  • Collaborated with business stakeholders to gather requirements, define project goals and manage expectations.
  • Facilitated decision-making processes and conflict resolution among team members & stakeholders.
  • Collaborated with OT Security Architects to implement industrial network segmentation & risk mitigation strategy.
  • Supported internal and external security audits.
  • Developed project plans, sprints roadmaps and release schedules.
  • Managed annual cyber security tooling budget and vendor evaluation for my services.

Rapid7 Qualys Nozomi ServiceNow tenable cyberint darktrace cortex CMDB
Burp Suite Kali Linux Metasploit vulnerability management and automation
5 Monate
2023-04 - 2023-08

Developed and implemented enterprise security policies and guidelines

IT-Security Analyst
IT-Security Analyst
  • Contributed to the design and implementation of information security governance processes.
  • Developed and implemented enterprise security policies and guidelines.
  • Performed risk assessments to evaluate threats, vulnerabilities and potential business disruptions (BCM)
  • Built a structured vulnerability management framework, including policies and remediation workflows.
  • Conducted security risk assessments across offices in 24 countries.
  • Supported GDPR-related security approvals and incident response processes.
  • Managed Enterprise Email Security Platform & conducted organization-wide phishing awareness training.
Kyocera (Meerbusch, Germany)
2 Jahre 10 Monate
2020-06 - 2023-03

Managed a vulnerability-scanning infrastructure

IT-Security Analyst (Vulnerability Management)
IT-Security Analyst (Vulnerability Management)
  • Managed a vulnerability-scanning infrastructure including distributed scanning engines & credential scanning.
  • Managed automated vulnerability scans, automated ticketing system and risk-based remediation prioritization.
  • Worked closely with infrastructure and patch management teams to improve remediation efficiency.
  • Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors.
  • Manage and integrate SAST /DAST/ IAST findings into CI/CD pipelines and DevSecOps workflows.
  • Consulting & Support for development teams in Application Security & SSDLC.
  • Managed project scope, schedules, resources, risks and deliverables through the project lifecycle.
  • Making different security policies and complete framework of patch management cycle.
  • Supporting SIEM logs, Web Security Appliance, Email Security Appliance, ddos Alarms, DNS Analytics.
  • Investigated phishing incidents and suspicious emails reported by employees.
FlatexDegiro AG (Frankfurt, Germany)
6 Monate
2019-09 - 2020-02

Ensured product security compliance

Information Security Officer
Information Security Officer
  • Ensured product security compliance for external safety and certification audits.
  • Managed security patch releases for enterprise customers.
  • Responsible for both enterprise and product security assurance.
  • Evaluated secure communication channels between POS terminals and backend servers.
Dafuer Gmbh (Darmstadt, Germany)
5 Monate
2019-02 - 2019-06

Conducted research & controls mapping on security standards

Master Thesis (IT-Security - O.T. & IT- monitoring + prevention)
Master Thesis (IT-Security - O.T. & IT- monitoring + prevention)
  • Conducted research & controls mapping on security standards including NIST, BSI, and IEC 62443.
  • Designed a Purdue Model-based OT/IT security laboratory environment.
  • Implemented intrusion detection and prevention using Fortigate firewall and Nozomi OT security platform.
  • Developed and executed three attack scenarios to validate the effectiveness of the monitoring architecture.
TüV Rheinland (Gelnhausen & Cologne)
6 Monate
2018-09 - 2019-02

Supported real-time sensor data infrastructure

Workstudent (Operations Support)
Workstudent (Operations Support)
  • Supported real-time sensor data infrastructure during live sporting events.
  • Resolving NTP issues, Implementing firewall rules and system hardening on Linux servers.
  • Configured file integrity monitoring tools to support IT security audit compliance.
AGT International (Darmstadt, Germany)
1 Jahr 5 Monate
2017-09 - 2019-01

Supported networking and cybersecurity laboratory sessions

Work student (HIWI ? Information Networks Labor)
Work student (HIWI ? Information Networks Labor)
  • Supported networking and cybersecurity laboratory sessions.
  • Working with Cisco routers, switches, firewall and encryption techniques in the lab.
  • Guide students to a networking and security lab consisting of OSPF, EIGRP, BGP, Nmap, and firewall working.
  • Setting up a firewall (UFW & IP tables) and 2-factor authentication on Raspberry Pi.
  • Developed practical demonstrations of security attacks including DNS spoofing and SSL stripping.
Hochschule Darmstadt (Darmstadt, Germany)
6 Monate
2018-03 - 2018-08

Conducted security analysis of ZigBee smart home devices.

Internee (Penetration Tester)
Internee (Penetration Tester)
  • Conducted security analysis of ZigBee smart home devices.
  • Demonstrated replay attacks on smart home communication protocols.
  • Conducted hardware security testing using UART, JTAG, SPI and I2C interfaces.
  • Developed a proof-of-concept attack environment using Raspberry Pi.
Verband der Elektrotechnik (VDE) (Offenbach, Germany)
1 Jahr 9 Monate
2015-01 - 2016-09

IT Security Consultant

IT Security Consultant (Finance Industry Clients) C# C++ Python ...
IT Security Consultant (Finance Industry Clients)

  

  

  

  

  

  

  

  

  

  

  

  

·   Provided support for IT security audits, including preparation of evidence, documentation review, and facilitation of audit requirements.

IBMQradr Tenable
C# C++ Python JavaScript

Aus- und Weiterbildung

Aus- und Weiterbildung

3 Jahre
2016-09 - 2019-08

Electrical Engineering and Information Technology (majors: Communications)

Masters of Science (MS), Grade (Good) ? 2.0, Hochschule Darmstadt (Darmstadt, Germany)
Masters of Science (MS), Grade (Good) ? 2.0
Hochschule Darmstadt (Darmstadt, Germany)

Kompetenzen

Kompetenzen

Top-Skills

GRC Business Continuity Management Threat Management Vulnerability management Risikomanagement agiles Projektmanagement SDLC Security Operations center Stakeholdermanagement IT/OT ISMS implementation Audits management

Produkte / Standards / Erfahrungen / Methoden

Professional Summary

  • Cybersecurity professional with more than 8+ years of extensive experience leading enterprise security and vulnerability management IT/OT Programs within international organizations. Proven ability to design and implement global vulnerability management & Governance programs, coordinate enterprise penetration testing, and deliver strategic threat intelligence to executive leadership. 
  • Experienced in collaborating with SOC teams, security architects, and C-level stakeholders to strengthen cyber resilience across large environments. Strong background in security governance, risk and compliance frameworks. Experienced in Service Provider management and specialized in bridging technical cybersecurity operations with strategic risk management.


Core Expertise

  • (IT/OT) Vulnerability Management 
  • ISMS development 
  • Threat Intelligence 
  • Threat Hunting 
  • Risk Management 
  • Governance 
  • Compliance 
  • Frameworks 
  • SOC management (SIEM, EDR/XDR) 
  • Security Program Design & Development 
  • Project Management 
  • Security Audits Support 
  • Pentest Support 
  • Executive C-Level Reporting 
  • Consulting


Sec Tools & Tech

  • Vulnerability Management: Qualys, Rapid7 (VMinsight), Tenable (Nessus)
  • SOC: IBM QRadar, LogRhythm, Microsoft Sentinal
  • Security Testing: Burp Suite, Kali Linux, Metasploit
  • OT Security: Nozomi Networks
  • Others: Jira ticketing system, SNOW ticketing system, Wireshark / NMAP


Frameworks

  • NIS 2
  • ISO 2700-X
  • DORA
  • MaRisk
  • NIST SP-800
  • IEC 62443-X
  • BSI-X
  • CIS Benchmark
  • NIST CSF
  • KRITIS
  • BCM / ISMS / DR
  • Cyber Resilience Act

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.