Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 01.07.2026
Verfügbar zu: 100%
davon vor Ort: 100%
Top-Skills
GRC
Business Continuity Management
Threat Management
Vulnerability management
Risikomanagement
agiles Projektmanagement
SDLC
Security Operations center
Stakeholdermanagement
IT/OT
ISMS implementation
Audits management
Einsatzorte
Länder
Deutschland, Schweiz, Österreich
Projekte
Rolle
Pentest, Threat & Vulnerability Manager (IT + OT)
Projektinhalte
Designed and implemented a global vulnerability management program across IT & OT business units. Coordinated penetration-testing programs across multiple global divisions. Provided Executive Cyber Threat Briefings to the Group CIO, highlighting risk-informed security investments. Led vulnerability prioritization and remediation coordination with infrastructure and application teams. Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors. Led Risk assessments and vulnerability exception processes for critical systems. Assisted in the development, implementation and maintenance of the organizations BCM framework. Collaborated with business stakeholders to gather requirements, define project goals and manage expectations. Facilitated decision-making processes and conflict resolution among team members & stakeholders. Collaborated with OT Security Architects to implement industrial network segmentation & risk mitigation strategy. Supported internal and external security audits. Developed project plans, sprints roadmaps and release schedules. Managed annual cyber security tooling budget and vendor evaluation for my services.
Produkte
Rapid7
Qualys
Nozomi
ServiceNow
tenable
cyberint
darktrace
cortex
CMDB
Kenntnisse
Burp Suite
Kali Linux
Metasploit
vulnerability management and automation
Rolle
IT-Security Analyst
Projektinhalte
Contributed to the design and implementation of information security governance processes. Developed and implemented enterprise security policies and guidelines. Performed risk assessments to evaluate threats, vulnerabilities and potential business disruptions (BCM) Built a structured vulnerability management framework, including policies and remediation workflows. Conducted security risk assessments across offices in 24 countries. Supported GDPR-related security approvals and incident response processes. Managed Enterprise Email Security Platform & conducted organization-wide phishing awareness training.
Kunde
Kyocera (Meerbusch, Germany)
Rolle
IT-Security Analyst (Vulnerability Management)
Projektinhalte
Managed a vulnerability-scanning infrastructure including distributed scanning engines & credential scanning. Managed automated vulnerability scans, automated ticketing system and risk-based remediation prioritization. Worked closely with infrastructure and patch management teams to improve remediation efficiency. Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors. Manage and integrate SAST /DAST/ IAST findings into CI/CD pipelines and DevSecOps workflows. Consulting & Support for development teams in Application Security & SSDLC. Managed project scope, schedules, resources, risks and deliverables through the project lifecycle. Making different security policies and complete framework of patch management cycle. Supporting SIEM logs, Web Security Appliance, Email Security Appliance, ddos Alarms, DNS Analytics. Investigated phishing incidents and suspicious emails reported by employees.
Kunde
FlatexDegiro AG (Frankfurt, Germany)
Rolle
Information Security Officer
Projektinhalte
Ensured product security compliance for external safety and certification audits. Managed security patch releases for enterprise customers. Responsible for both enterprise and product security assurance. Evaluated secure communication channels between POS terminals and backend servers.
Kunde
Dafuer Gmbh (Darmstadt, Germany)
Rolle
Master Thesis (IT-Security - O.T. & IT- monitoring + prevention)
Projektinhalte
Conducted research & controls mapping on security standards including NIST, BSI, and IEC 62443. Designed a Purdue Model-based OT/IT security laboratory environment. Implemented intrusion detection and prevention using Fortigate firewall and Nozomi OT security platform. Developed and executed three attack scenarios to validate the effectiveness of the monitoring architecture.
Kunde
TüV Rheinland (Gelnhausen & Cologne)
Rolle
Workstudent (Operations Support)
Projektinhalte
Supported real-time sensor data infrastructure during live sporting events. Resolving NTP issues, Implementing firewall rules and system hardening on Linux servers. Configured file integrity monitoring tools to support IT security audit compliance.
Kunde
AGT International (Darmstadt, Germany)
Rolle
Work student (HIWI ? Information Networks Labor)
Projektinhalte
Supported networking and cybersecurity laboratory sessions. Working with Cisco routers, switches, firewall and encryption techniques in the lab. Guide students to a networking and security lab consisting of OSPF, EIGRP, BGP, Nmap, and firewall working. Setting up a firewall (UFW & IP tables) and 2-factor authentication on Raspberry Pi. Developed practical demonstrations of security attacks including DNS spoofing and SSL stripping.
Kunde
Hochschule Darmstadt (Darmstadt, Germany)
Rolle
Internee (Penetration Tester)
Projektinhalte
Conducted security analysis of ZigBee smart home devices. Demonstrated replay attacks on smart home communication protocols. Conducted hardware security testing using UART, JTAG, SPI and I2C interfaces. Developed a proof-of-concept attack environment using Raspberry Pi.
Kunde
Verband der Elektrotechnik (VDE) (Offenbach, Germany)
Rolle
IT Security Consultant (Finance Industry Clients)
Projektinhalte
·
Provided support for IT security audits, including preparation of
evidence, documentation review, and facilitation of audit requirements.
Produkte
IBMQradr
Tenable
Kenntnisse
C#
C++
Python
JavaScript
Mehr
Weniger
Aus- und Weiterbildung
Abschluss
Masters of Science (MS), Grade (Good) ? 2.0
Institution, Ort
Hochschule Darmstadt (Darmstadt, Germany)
Mehr anzeigen
Weniger anzeigen
Certification
Certified information Security Manager (CISM) Certified Ethical Hacker (CEH) Metasploit Pro Specialist Certified in Risk and Informations System Control (CRISC) Rapid7 InsightVM (admin) Azure cloud (admin) Computer Hacking Forensic Investigator (CHFI) ISO 27001 Lead Implementer AWS (Associate / Security)
Kompetenzen
Top-Skills
GRC
Business Continuity Management
Threat Management
Vulnerability management
Risikomanagement
agiles Projektmanagement
SDLC
Security Operations center
Stakeholdermanagement
IT/OT
ISMS implementation
Audits management
Produkte / Standards / Erfahrungen / Methoden
Professional Summary
Cybersecurity professional with more than 8+ years of extensive experience leading enterprise security and vulnerability management IT/OT Programs within international organizations. Proven ability to design and implement global vulnerability management & Governance programs, coordinate enterprise penetration testing, and deliver strategic threat intelligence to executive leadership. Experienced in collaborating with SOC teams, security architects, and C-level stakeholders to strengthen cyber resilience across large environments. Strong background in security governance, risk and compliance frameworks. Experienced in Service Provider management and specialized in bridging technical cybersecurity operations with strategic risk management.
Core Expertise
(IT/OT) Vulnerability Management ISMS development Threat Intelligence Threat Hunting Risk Management Governance Compliance Frameworks SOC management (SIEM, EDR/XDR) Security Program Design & Development Project Management Security Audits Support Pentest Support Executive C-Level Reporting Consulting
Sec Tools & Tech
Vulnerability Management: Qualys, Rapid7 (VMinsight), Tenable (Nessus) SOC: IBM QRadar, LogRhythm, Microsoft Sentinal Security Testing: Burp Suite, Kali Linux, Metasploit OT Security: Nozomi Networks Others: Jira ticketing system, SNOW ticketing system, Wireshark / NMAP
Frameworks
NIS 2 ISO 2700-X DORA MaRisk NIST SP-800 IEC 62443-X BSI-X CIS Benchmark NIST CSF KRITIS BCM / ISMS / DR Cyber Resilience Act
Einsatzorte
Länder
Deutschland, Schweiz, Österreich
Projekte
Rolle
Pentest, Threat & Vulnerability Manager (IT + OT)
Projektinhalte
Designed and implemented a global vulnerability management program across IT & OT business units. Coordinated penetration-testing programs across multiple global divisions. Provided Executive Cyber Threat Briefings to the Group CIO, highlighting risk-informed security investments. Led vulnerability prioritization and remediation coordination with infrastructure and application teams. Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors. Led Risk assessments and vulnerability exception processes for critical systems. Assisted in the development, implementation and maintenance of the organizations BCM framework. Collaborated with business stakeholders to gather requirements, define project goals and manage expectations. Facilitated decision-making processes and conflict resolution among team members & stakeholders. Collaborated with OT Security Architects to implement industrial network segmentation & risk mitigation strategy. Supported internal and external security audits. Developed project plans, sprints roadmaps and release schedules. Managed annual cyber security tooling budget and vendor evaluation for my services.
Produkte
Rapid7
Qualys
Nozomi
ServiceNow
tenable
cyberint
darktrace
cortex
CMDB
Kenntnisse
Burp Suite
Kali Linux
Metasploit
vulnerability management and automation
Rolle
IT-Security Analyst
Projektinhalte
Contributed to the design and implementation of information security governance processes. Developed and implemented enterprise security policies and guidelines. Performed risk assessments to evaluate threats, vulnerabilities and potential business disruptions (BCM) Built a structured vulnerability management framework, including policies and remediation workflows. Conducted security risk assessments across offices in 24 countries. Supported GDPR-related security approvals and incident response processes. Managed Enterprise Email Security Platform & conducted organization-wide phishing awareness training.
Kunde
Kyocera (Meerbusch, Germany)
Rolle
IT-Security Analyst (Vulnerability Management)
Projektinhalte
Managed a vulnerability-scanning infrastructure including distributed scanning engines & credential scanning. Managed automated vulnerability scans, automated ticketing system and risk-based remediation prioritization. Worked closely with infrastructure and patch management teams to improve remediation efficiency. Advanced vulnerability prioritization with EPSS, CVSS, CISA KEV and other threat vectors. Manage and integrate SAST /DAST/ IAST findings into CI/CD pipelines and DevSecOps workflows. Consulting & Support for development teams in Application Security & SSDLC. Managed project scope, schedules, resources, risks and deliverables through the project lifecycle. Making different security policies and complete framework of patch management cycle. Supporting SIEM logs, Web Security Appliance, Email Security Appliance, ddos Alarms, DNS Analytics. Investigated phishing incidents and suspicious emails reported by employees.
Kunde
FlatexDegiro AG (Frankfurt, Germany)
Rolle
Information Security Officer
Projektinhalte
Ensured product security compliance for external safety and certification audits. Managed security patch releases for enterprise customers. Responsible for both enterprise and product security assurance. Evaluated secure communication channels between POS terminals and backend servers.
Kunde
Dafuer Gmbh (Darmstadt, Germany)
Rolle
Master Thesis (IT-Security - O.T. & IT- monitoring + prevention)
Projektinhalte
Conducted research & controls mapping on security standards including NIST, BSI, and IEC 62443. Designed a Purdue Model-based OT/IT security laboratory environment. Implemented intrusion detection and prevention using Fortigate firewall and Nozomi OT security platform. Developed and executed three attack scenarios to validate the effectiveness of the monitoring architecture.
Kunde
TüV Rheinland (Gelnhausen & Cologne)
Rolle
Workstudent (Operations Support)
Projektinhalte
Supported real-time sensor data infrastructure during live sporting events. Resolving NTP issues, Implementing firewall rules and system hardening on Linux servers. Configured file integrity monitoring tools to support IT security audit compliance.
Kunde
AGT International (Darmstadt, Germany)
Rolle
Work student (HIWI ? Information Networks Labor)
Projektinhalte
Supported networking and cybersecurity laboratory sessions. Working with Cisco routers, switches, firewall and encryption techniques in the lab. Guide students to a networking and security lab consisting of OSPF, EIGRP, BGP, Nmap, and firewall working. Setting up a firewall (UFW & IP tables) and 2-factor authentication on Raspberry Pi. Developed practical demonstrations of security attacks including DNS spoofing and SSL stripping.
Kunde
Hochschule Darmstadt (Darmstadt, Germany)
Rolle
Internee (Penetration Tester)
Projektinhalte
Conducted security analysis of ZigBee smart home devices. Demonstrated replay attacks on smart home communication protocols. Conducted hardware security testing using UART, JTAG, SPI and I2C interfaces. Developed a proof-of-concept attack environment using Raspberry Pi.
Kunde
Verband der Elektrotechnik (VDE) (Offenbach, Germany)
Rolle
IT Security Consultant (Finance Industry Clients)
Projektinhalte
·
Provided support for IT security audits, including preparation of
evidence, documentation review, and facilitation of audit requirements.
Produkte
IBMQradr
Tenable
Kenntnisse
C#
C++
Python
JavaScript
Mehr
Weniger
Aus- und Weiterbildung
Abschluss
Masters of Science (MS), Grade (Good) ? 2.0
Institution, Ort
Hochschule Darmstadt (Darmstadt, Germany)
Mehr anzeigen
Weniger anzeigen
Certification
Certified information Security Manager (CISM) Certified Ethical Hacker (CEH) Metasploit Pro Specialist Certified in Risk and Informations System Control (CRISC) Rapid7 InsightVM (admin) Azure cloud (admin) Computer Hacking Forensic Investigator (CHFI) ISO 27001 Lead Implementer AWS (Associate / Security)
Kompetenzen
Top-Skills
GRC
Business Continuity Management
Threat Management
Vulnerability management
Risikomanagement
agiles Projektmanagement
SDLC
Security Operations center
Stakeholdermanagement
IT/OT
ISMS implementation
Audits management
Produkte / Standards / Erfahrungen / Methoden
Professional Summary
Cybersecurity professional with more than 8+ years of extensive experience leading enterprise security and vulnerability management IT/OT Programs within international organizations. Proven ability to design and implement global vulnerability management & Governance programs, coordinate enterprise penetration testing, and deliver strategic threat intelligence to executive leadership. Experienced in collaborating with SOC teams, security architects, and C-level stakeholders to strengthen cyber resilience across large environments. Strong background in security governance, risk and compliance frameworks. Experienced in Service Provider management and specialized in bridging technical cybersecurity operations with strategic risk management.
Core Expertise
(IT/OT) Vulnerability Management ISMS development Threat Intelligence Threat Hunting Risk Management Governance Compliance Frameworks SOC management (SIEM, EDR/XDR) Security Program Design & Development Project Management Security Audits Support Pentest Support Executive C-Level Reporting Consulting
Sec Tools & Tech
Vulnerability Management: Qualys, Rapid7 (VMinsight), Tenable (Nessus) SOC: IBM QRadar, LogRhythm, Microsoft Sentinal Security Testing: Burp Suite, Kali Linux, Metasploit OT Security: Nozomi Networks Others: Jira ticketing system, SNOW ticketing system, Wireshark / NMAP
Frameworks
NIS 2 ISO 2700-X DORA MaRisk NIST SP-800 IEC 62443-X BSI-X CIS Benchmark NIST CSF KRITIS BCM / ISMS / DR Cyber Resilience Act
Das Freelancer-Portal
Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.
Jetzt bei GULP Direkt registrieren