ISO 2700x, KRITIS + Audits Informattionssicherheit/IT+OT-Security, KRITIS/Auditierung Penetration Tests IT-Systemprüfung, Governance + Compliance
Aktualisiert am 16.12.2025
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 15.12.2025
Verfügbar zu: 100%
davon vor Ort: 100%
IT-Sicherheitsarchitektur
Penetrationstest
ISO 27001
Auditor
KRITIS
VPN
Firewall
IEC 62443
OT-Security
Internet of Things
ISMS
IT-Security
Penetrationstest
Informationssicherheit
Infrastruktur
Anforderungsanalyse
Vulnerability
Microsoft
Linux
Cloud
Mac
German
native
English

Einsatzorte

Einsatzorte

Hamburg (+500km) Kiel (+500km) Lübeck (+500km) Heide (+500km) Weltweit (+500km) Berlin (+500km) München (+500km) Koblenz am Rhein (+500km)
Deutschland, Schweiz, Österreich

Remote - weltweit möglich.
Regional aktuell auf Hamburg, Schleswig-Holstein, Niedersachen und Mecklenburg Vorpommern beschränkt, basierend auf Relevanz, Dauer und Aufgabenhorizont.

möglich

Projekte

Projekte

7 Monate
2025-05 - heute

IT security management system

  • Establishing and maintaining a comprehensive IT security management system (ISMS) in accordance with applicable standards (e.g., ISO/IEC 27001, NIST).
  • Ensuring the information security of all IT systems and platforms, especially to sensitive data to members, sections, and partners.
  • Advising the management on all matters relating to information security and emerging technological risks.
  • Ensuring compliance with regulatory requirements and standards for IT security.
  • Responsibility for IT security-related systems, applications, and services such as vulnerability scanning, penetration tests, firewalls, IDS/IPS, patch management, forensics, EDR/XDR/SOAR, SIEM & SOC, PAM, IAM, etc.
  • Establishing an IT security culture within the association at all levels, from full-time staff to volunteer structures
  • Developing and implementing the security strategy in line with the DAV's goals and values.
  • Formulating and maintaining security guidelines, procedures, and standards.
  • Creating emergency plans and conducting regular risk analyses.
  • Monitoring IT systems and networks for security incidents.
  • Management and control of IT security projects.
  • Leadership of incident response teams in the event of security incidents.
  • Conducting training courses for full-time and volunteer employees on IT security issues.
  • Communicating the importance of security measures at all levels of the association.
  • Coordinating with external IT service providers and security consultants.
  • Assisting in the drafting of contracts with service providers to security requirements.
  • Regular reporting to management on security risks, measures, and developments.
  • Preparing audit reports and security assessments.
on request
München
3 Jahre 4 Monate
2022-08 - heute

Found and start a new business with the scope of all IT- and Security services

Founder / CEO
Founder / CEO

on Request
Boostedt
5 Monate
2025-01 - 2025-05

Military project

IT Security Engineer Security Firewall Industrial ...
IT Security Engineer
  • Implementation of measures for hardening systems and application according to DISA STIGs, CIS, FBI, CIA, BSI Grundschutz / BSI Grundschutzkompendium, CERTBw, DEUmilSAA, NATO, NIST, and other guidelines
  • Conduct a comprehensive assessment of the navigation data distributor, focusing on the Operating Systems and Infrastructure components
  • Identify and resolve issues within the network and Linux-based environments through targeted troubleshooting
  • Execute upgrades of operating systems and ensure successful deployment of the application software
  • Set up and perform validation testing using MT-Windows installation notebooks
  • Develop detailed technical documentation outlining system status, procedures, and implemented changes
Security Firewall Industrial Operating System Documentation Management tools Management
Thales Deutschland
Kiel
1 Jahr 3 Monate
2023-12 - 2025-02

Ensuring compliance with the IT security catalog

IT/OT-Manager Security Firewall Industrial ...
IT/OT-Manager
  • Ensuring compliance with the IT security catalog in accordance with Section 11 (1a) of the Energy Industry Act
  • Securing critical infrastructures in accordance with BSIG Section 8a (KRITIS) in general
  • Ensuring the operation of an "attack detection system" (SzA / Systeme zur Angriffserkennung im Bereich OT und IT-Infrastruktur) in accordance with EnWG and BSIG
  • Coordination of services and third-party companies that provide work and services for the operation, maintenance and repair of the LNG terminals
  • responsible for the quality assurance, control and further development of the entire IT/OT and communication infrastructure
  • control and monitoring systems for the gas send-out of the FSRU, the high-pressure loading arms in the jetty pipeline and the gas transfer station, the commercial IT systems with an internet connection for rolling planning
  • responsible of systems for handling LNG cargos and the systems for onward transportation of natural gas as well as the commercial systems are also part of the area of responsibility
  • Managing all internal and external system services
  • Establishing data analytic exchange for external parties
  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements
  • Optimizing the OT environment for operational needs (Siemens SCADA, PLC, HMI and other related systems)
  • Establishing and maintaining a complete Video Surveillance system in IT and OT environments
  • Coordinated cross-functional teams and ensured timely, on-budget project delivery
  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover
  • Designed and implemented IT and OT infrastructure across the client?s operational and administrative environments with high end enterprise needs
  • Deployed Starlink satellite systems to establish connectivity between remote facilities, ports, container office locations and offices
  • Secured all connected sites through the installation and configuration of hardened firewalls and managed switches, ensuring robust perimeter and internal network protection
  • Development and formal documentation of a comprehensive security concept in alignment with the International Ship and Port Facility Security (ISPS) Code, focusing on risk assessment, protective measures, and compliance requirements for maritime and port facility operations
  • Supporting ISMS activities to archive ISO 27001 and ISO 27019 certification for all locations
  • Utilized PI AVEVA for the visualization, analysis, and monitoring of large OT/IT data sets within control centers and operations rooms.
  • Establishing, supporting and maintaining big data analysis from ICS components into PI AVEVA
  • Building specific visualization dashboard for ICS/IT und OT components
Security Firewall Industrial Communications Virtualization Databases Operating System Development Remote Access / VPN Voice/Mobile Management tools Management
LNG / Gas Energy Industry
Wilhelmshaven, Brunsbüttel, Stade, Düssendorf
2 Jahre 2 Monate
2022-11 - 2024-12

Military project

IT Security Engineer Security Firewall Industrial ...
IT Security Engineer
  • Establishment of an analysis of the technical and professional BSI (Federal Office of Information Security) requirements and specification of the military security catalog for ITSecurity
  • Implementation of measures for hardening systems and application according to DISA STIGs, CIS, FBI, CIA, BSI Grundschutz / BSI Grundschutzkompendium, CERTBw, DEUmilSAA, NATO, NIST, and others guidelines
  • Establishment of an analysis of the network and their network requirements
  • Establishment of vulnerability remediation concepts for the network with focus to harden network security components
  • Setting up the virtualized cluster server systems (virtualization platform Microsoft Hyper-V) of new networks on Debian Linux
  • Configuration of Cisco firewalls using Ansible scripts
  • Hardening of Cisco 9xxx Series switches, Genua Genuscreen firewalls according to requirements
  • Execution of system tests and documentation
  • Elimination of errors according to previously created concepts
  • Creation of detailed technical documentation
  • Installation and configuration of Microsoft Windows 10/11 endpoints in Bare-Metal and virtual environments (VMware ESXi & VMware Workstation) with secured hardened profiles based on requirements
  • Installation and configuration of Red Hat Enterprise Linux server and maintainer terminals with secured profiles according to OpenSCAP and DISA STIGs
  • Hardening of Red Hat Enterprise Linux Server and Red Hat Enterprise Linux Workstations based on OpenSCAP and DISA STIGs
  • Maintain and configuration of Red Hat Enterprise Linux Satellite Server, Foreman proxy and Ansible playbooks and roles in a GIT controlled environment
  • Implementation secured configuration for HP switches
  • Configuration of secured profiles for ICS switches, type Belden Hirschmann BOBCAT and MOXA switches
  • Hardening of BIOS / UEFI firmware
  • Ensuring the operation of an "attack detection system" (SzA / Systeme zur
  • Angriffserkennung im Bereich OT und IT-Infrastruktur) in accordance to BSIG
  • Providing multiple Information Security Awareness Trainings based of ISO 27001 and IEC
  • 62443 for different team members and project members
  • Blackbox- & White-box penetration tests (Nessus Pro and Metasploit with own developed scripts and exploits), OWASP TOP 10 checks and vulnerability scans with Nessus Professional/Burp Suite Pro on IT/OT/ICS hardware
  • Security validation and verification (SVV3+4) acc. IEC 62443
  • Deployment of multiple network devices via Zero Touch Provisioning (ZTP)
  • Testing of configuration with Robot-Framework
  • Application management for Linux applications and dependencies
  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements
  • Coordinated cross-functional teams and ensured timely, on-budget project delivery
  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover
VMware ESX Hyper-V Windows 10 Tenable Nessus VMware Workstation Cisco Genua Genuscreen M Cisco 93xx Debian RedHat Redhat Satellite Red Hat Enterprise Linux Ansible Python
Security Firewall Industrial Communications Virtualization Databases Operating System Development Automation Web Servers Documentation Testing Remote Access / VPN Voice/Mobile Scripting Management tools Management
Thales Deutschland
Kiel
6 Monate
2023-10 - 2024-03

Organization and implementation of the management review

CISO / ext ISB Security Firewall Industrial ...
CISO / ext ISB
  • Organization and implementation of the management review at regular intervals
  • Organization and execution of internal, external and certification audits as well as monitoring and continuation of the audit program, moderation and support
  • Risk management for KRITIS relevant assets
  • Delegation or own execution of activities within the ISMS (after consultation with with management)
  • Document management of the ISMS document collection, e.g. updating and control of new documents
  • Ensuring the operation of an ADS ("attack detection system") (SzA / Systeme zur Angriffserkennung im Bereich OT und IT-Infrastruktur) in accordance with EnWG and BSIG
  • Training of employees regarding information security
  • Implementation of measures (annex, findings, technical requirements according to BSI norms, BSI KritisV, IT-SiKat § 11 Absatz 1b EnWG, ISO 27001, ISO 27019, etc.).
  • Implementation of regulatory requirements
  • Monitoring and consulting of the changing regulatory environment
  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements
  • Coordinated cross-functional teams and ensured timely, on-budget project delivery
  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover
  • Conducting regular Information Security Management meetings with executive leadership in accordance with ISO/IEC 27001 and ISO/IEC 27019, to ensure strategic oversight and continuous improvement of the organization?s information security posture, in line with KRITIS compliance requirements.
Security Firewall Industrial Communications Management tools Management
Veja Mate Offshore Project GmbH
1 Jahr 2 Monate
2021-10 - 2022-11

Professional management

Senior OT Cyber Security Specialist Service Security Firewall Industrial ...
Senior OT Cyber Security Specialist Service
  • Professional management and responsibility for Global Cyber Security of a 4 FTE Cyber Security team in Service, Germany

  • Lead a virtual team and coordinate project activies i.e. ISO 27001 ISMS / IEC 62443

  • Stakeholder management according to compliance requirements and opportunities for improvement

  • Preparation for ISO/IEC recertification and ensure compliance with ISO/IEC standards and other Governmental/Legal regulations

  • Planning, implementation and further development of OT Cyber Security strategies for Security Incident and Event Management, Monitoring, Patch-/Update- and Vulnerability Management

  • Architecture and conception of network zones for implementation acc. IEC 62443 certification

  • Perform security assessment on Windows/Linux operating system, and VMware, Citrix and Microsoft Hyper-V environments

  • Investigate new and emerging security threats against internal/external Network Infrastructure and interconnected systems

  • Coordination, identification and analyses of Cyber Security incidents and development of countermeasures

  • Project management with the scope of different Information Security related Cloud- and Onpremise applications and systems

  • Implementation of ISO 27001/IEC 62443 policies, guidelines and processes

  • Development of processes, methods and tools to detect anomalies

  • Implementation and maintaining infrastructure with Cisco Firewalls, HP Aruba, Fortigate Firewalls/Switches, Sonicwall, Checkpoint and FireEye EX/NX/HX

  • Optimization of network segments and vWAN segments to/from Microsoft Azure into internal infrastructure areas

  • Performing Penetration Tests against IT / OT Infrastructure with the scope of Web application, databases, hardware and mobile devices

  • Blackbox- & White-box penetration tests (Nessus Pro and Metasploit with own developed scripts and exploits), OWASP TOP 10 checks and vulnera

  • Vulnerability scans with Nessus Professional/Burp Suite Pro on IT/OT/ICS hardware

  • Security validation and verification (SVV3+4) acc. IEC 62443

  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements

  • Coordinated cross-functional teams and ensured timely, on-budget project delivery

  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover

  • Application Management & Security Compliance (Application Operations & Administration / Managing and optimizing business-critical applications in cloud and on-premises environments)

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Web Servers Documentation Testing Remote Access / VPN Voice/Mobile Scripting Management tools Management
Nordex Energy SE & Co. KG, Hamburg
2 Jahre 10 Monate
2019-01 - 2021-10

Planning, implementation and further development of IT security systems

IT-Security Specialist & Information Security Officer Security Firewall Industrial ...
IT-Security Specialist & Information Security Officer
  • Planning, implementation and further development of IT security systems and operational mentoring systems (SIEM, SOC monitoring) and improvement of automatic reports

  • Standardization of network schemes/designs in the IT and OT wind energy sector

  • Lead a virtual team and coordinate project activies i.e. ISO 27001 ISMS / IEC 62443

  • Stakeholder management according to compliance requirements and opportunities for improvement

  • Preparation for ISO/IEC recertification and ensure compliance with ISO/IEC standards and other Governmental/Legal regulations

  • Design, modeling, implementation and documentation of information security management systems (ISMS management, guidelines, processes and procedures) according to ISO 27001, KRITIS and BSI Grundschutz

  • Coordination and analysis of incoming security incident reports

  • Establishment of a Computer Emergency Response Team and be first contact to IT related security incidents and Penetration tests

  • Project management with the scope of different Information Security related Cloud- and On-premise applications and systems

  • Implementation and coordination of security recommendations based on non-conformities in the area of LAN/WAN, SCADA, IT & OT Wind turbine systems and encryption

  • Design/modeling of IT security networks zones & systems including automated vulnerability analysis/scans

  • Management and administration of IT security systems to detect malware/ransomware and anomalies in network and web/mail traffic

  • Implementation and maintaining infrastructure with Cisco Firewalls, HP Aruba, Fortigate Firewalls/Switches, Sonicwall, Checkpoint and FireEye EX/NX/HX

  • Optimization of network segments and vWAN segments to/from Microsoft Azure into internal infrastructure areas

  • Establishment and execution of regular audits in the context of ISO 27001

  • Establishment of regular Microsoft Active Directory audits

  • Application Management & Security Compliance (Application Operations & Administration / Managing and optimizing business-critical applications in cloud and on-premises environments)

  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements

  • Coordinated cross-functional teams and ensured timely, on-budget project delivery

  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover


Achievements:

  • Successful company certification according to ISO 27001 in 2019

  • Establishment of an extended security concept within the scope of IT security training courses

  • Project planning and implementation of penetration tests in the energy sector

  • Certification as TÜV Rheinland Information Security Officer (ISO)

  • Additional examination KRITIS topic of "Additional test procedure competence for § 8a BSIG" incl. IT-SIG and BSI-KritisV

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Web Servers Documentation Testing Remote Access / VPN Voice/Mobile Scripting Management tools Management
Nordex SE, Hamburg
1 Jahr 2 Monate
2017-11 - 2018-12

Creation of process documentation

IT System Administrator Security Firewall Industrial ...
IT System Administrator
  • Creation of process documentation and documentation standards in IBM DOORS

  • Coordination of IT systems and their security requirements with internal and external customer projects

  • Administration and management of the VMware ESX server farm

  • Configuration of Juniper switches (EX4300/EX4550) and firewalls (SRX1500)

  • Installation and optimization of the Windows Active Directory DS infrastructure in customer projects

  • Administration and maintenance of existing Linux servers (Ubuntu/CentOS)

  • Administration of virtualization and deployment environment with CI/CD tool chains under the scope of Linux and Windows deployment servers in Enterprise environments

  • Hardening of Windows and Linux servers and application services

  • Implementation, documentation and testing of operating systems, networks, applications on technical equipment in the field of shipping (defense technology)

  • Planning and execution of penetration tests in customer projects

  • Implementation of vulnerability management, IT/live forensics, security information and event management (SIEM) and firewalling in customer projects

  • Creation of developmental product documents, requirements specifications and software documentation


Archievements:

  • Project support with adherence to deadline targets

  • Establish and improve virtualization & deployment processes including hardening parts and solutions in Military Marine projects

  • Execution of automated penetration tests to increase security in projects

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Documentation Testing Management tools Management
Ratheon Anschütz GmbH, Kiel - Engineering
8 Monate
2017-03 - 2017-10

Global IT Infrastructure

System Engineer Security Firewall Industrial ...
System Engineer
  • 2nd/3rd Level Support

  • Infrastructure project management (project planning, design, implementation)

  • Administration and management of Cisco FirePower (IPS SIEM) and IronPort for e-mail security infrastructure (International wide)

  • Planning, preparation and implementation for VDA/TÜV and ISO 27001 certification

  • Administration and maintenance of Linux servers (RedHat, Ubuntu, Debian, Gentoo)

  • Administration and maintenance of the Shopfloor Management System (SFMS)

  • IT Security monitoring with Nagios/OMD - Check_MK

  • Configuration of Cisco routers, firewalls (ASA & IOS) and switches

  • Installation and optimization of the Active Directory environment

  • Administration of the VMware ESX server farm (based on HP Blade Center)

  • Design/administration and maintenance of the Symantec Backup EXE, Commvault and Veeam backup infrastructure (World Wide)

  • Ticket handling through OTRS / RT ticket system

  • Installation and administration of the MobileIron Mobile Device Management (MDM) global wide

  • Installation/administrate of the patch management environment for Operating systems and applications

  • Establish and developments for automated installation based on Windows Deployment System

  • Migration of Windows NT to next generation Windows Server 2008 R2 and 2012 R2

  • Process documentation and establishing documentation standards


Archievements:

  • Implementation of the security concepts, mobile device management system, patch management environment and automation of software and operating systems deployment

  • Accelerate further Cisco-based network structures in the LAN/WAN area

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Documentation Testing Management tools Management
BRUSS Sealing Systems GmbH, Hoisdorf - Automotive supplier
11 Jahre 3 Monate
2006-01 - 2017-03

Technical and professional personnel management

Department Sergeant and System - & Network Engineer Security Firewall Industrial ...
Department Sergeant and System - & Network Engineer
  • Technical and professional personnel management leading employees up to 10-15 FTEs

  • Optimization of IT processes

  • Cost optimization, negotiation of contracts and vendor relationships

  • Reporting of budgeting in a quarterly review

  • Training of civilian, military and military service employees

  • Planning and contributing to hospital internal IT strategies and external sites

  • Main responsible for IT related material, hardware & software

  • Administration and maintenance of Microsoft Windows (NT 4.0 up to 2012 R2) and Linux based operating systems (RedHat, Debian, SuSE)

  • Administration and optimization of Microsoft Windows AD domains

  • Hardening of Windows and Linux server systems and applications according to BSI, CERTBundeswehr, Best Practices and NIST, as well as other internal guidelines to best practices

  • Configuration and maintenance of appliances like Cisco Firewalls (ASA, PIX), routers & switches, Enterasys Networks core switches and Checkpoint firewalls

  • Administration and optimization of Lotus Domino Server from version 4 to 8.5.3

  • Installation and administration of VMware ESX server farms

  • Responsibility to BCM acc. Backup and Recovery ArcServ Backup and IBM TSM

  • Configuration/administration and maintenance of the Symantec security environment, Sophos SafeGuard environment (UTM, Endpoint Protection, SafeGuard Easy)

  • Wi-Fi design and planning, installation and administration of the Cisco WLC environment to secure hospital networks

  • Creation of process documentation and documentation standards

  • Customer site visits (planning, troubleshooting and remediation)


Archievements

  • Implementation of security concepts to state-of-the-art security configurations and systems

  • Implementation of IT-Security training

  • Extensive experience on the Internet provider side (routing, switching) with support from external companies

  • Planning and implementation of the in-house telephone system to VOIP in cooperation with external service providers

  • Implementation of external properties and companies to the VPN network of the Federal Armed Forces Hospital Hamburg

  • Establishment of automation solutions for operating systems and applications

  • Establishment of an internal patch management system

  • Migration of all client systems from Microsoft Windows NT/2000/XP to latest Microsoft Windows 7/10

  • Establishment of a time recording system in cooperation with external service providers

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Documentation Testing Management tools Management
Federal Armed Forces ? Military Hospital, own Datacenter, Hamburg
3 Monate
2001-07 - 2001-09

Design and programming of websites

Training IT system merchant and Information electronics technician
Training IT system merchant and Information electronics technician
  • Sales team member 

  • Design and programming of websites 

  • Installation, configuration of IT supported computer systems 

  • Installation and setup of TV based satellite connections 

  • Support of the in-house IT

Lorenzen Team, Regional specialized dealer for electronics
5 Monate
2001-03 - 2001-07

data order input department

IT-System Administrator
IT-System Administrator
  • Team member in the data order input department 

  • Entry of customer orders/cancellations into the inventory control system 

  • Checking of customer orders based on automated scripts 

  • Supporting in-house IT 


Motivation of change

Direct offer from a recruiting firm to prove yourself in a different role and start an apprenticeship in IT.

Markisen Spettmann GmbH, Neumünster
10 Monate
2000-05 - 2001-02

Military defense service

  • Military defense service for 10-month located in Roth/Bavaria and Kropp/Jagel, SchleswigHolstein, German

Federal Armed Forces, Germany
8 Monate
1999-09 - 2000-04

Sale of hardware and software

IT System Technician & Administrator
IT System Technician & Administrator
  • Up to 09/1999 Company named Comf@ctory, later renamed to Comsystem GmbH, Neumünster, Schleswig-Holstein, Germany 

  • Sale of hardware and software 

  • Setup, configuration and administration of heterogeneous networks 

  • Modifying/Conversion of consumer goods 

  • Installation and modification of electronic components in various devices   


Motivation to change

Federal Republic of Germany drafts me into 10-month military service.

Comf@ctory GmbH
Neumünster

Aus- und Weiterbildung

Aus- und Weiterbildung

2 Jahre 10 Monate
2002-09 - 2005-06

Ausbildung zum Fachinformatiker

Grade: 3, Hard- & Softwarelösungen B. Pommerening, Neumünster und Stadtwerke Kiel AG, Kie
Grade: 3
Hard- & Softwarelösungen B. Pommerening, Neumünster und Stadtwerke Kiel AG, Kie
  • IT Specialist System integration 
  • Focus areas: System analytics / planning / cost optimization 
  • Network Administration for the Energy Control Systems 
  • Planning, Installation and administration of Network-Attached-Storage environments 
  • First- und Second-Level Support Helpdesk 
2 Jahre 10 Monate
2002-09 - 2005-06

Specialized High School ? Economy

Termination due to support my freelancer career, Theodor-Litt-Schule Neumünster
Termination due to support my freelancer career
Theodor-Litt-Schule Neumünster
1 Jahr 11 Monate
1996-08 - 1998-06

Wirtschaft und Sozialwirtschaft

Secondary school diploma in Economy / Grade: 2, Theodor-Litt-Schule Neumünster, Berufliche Schulen Rendsburg
Secondary school diploma in Economy / Grade: 2
Theodor-Litt-Schule Neumünster, Berufliche Schulen Rendsburg

Kompetenzen

Kompetenzen

Top-Skills

IT-Sicherheitsarchitektur Penetrationstest ISO 27001 Auditor KRITIS VPN Firewall IEC 62443 OT-Security Internet of Things ISMS IT-Security Penetrationstest Informationssicherheit Infrastruktur Anforderungsanalyse Vulnerability Microsoft Linux Cloud Mac

Schwerpunkte

Interim CISO / CIO
Information Security Management Systems
Penetration Tests including Vulnerability Management
Strategy and standardization IT infrastructure
IT-Infrastructure architecture
Network architecture
Datacenter architecture
Identity and Access Management
Backup- and Disaster Recovery
Personal- and organizational planning datacenter operations

Produkte / Standards / Erfahrungen / Methoden

Profile:

Technical expert with experience over 20 years in IT/OT/Cyber Security, a comprehensive knowledge of Computer Information System Security, System Administration and Network Operations, and Datacenter Operations. Extensive knowledge in the areas of system security, vulnerability scanning, penetration testing, risk assessment and cyber security analysis. Experienced in leadership management over 10 years with a team up to 25 members, project coordination and system implementation of Government systems, telecommunication and larger computer networks. Security clearance (German Ü2/Ü3) is possible, if needed. Highly organized team player with the ability to effectively manage project milestones and project delivery. International work and leadership experience.


Virtualization

  • Microsoft Hyper-V and Microsoft Terminal Server solutions
  • VirtualBox
  • VMware ESX
  • VMware Horizen
  • VMware Workstation
  • Parallels Desktop
  • VDI
  • Citrix Hypervisor
  • Proxmox
  • KVM
  • QEMU


LAMP System

  • Linux
  • Apache
  • MySQL/MariaDB
  • PHP


Development

  • Bash Scripting
  • Basic
  • Delphi
  • Pascal
  • C / C++
  • HTML with PHP 
  • JS und CSS
  • JavaScript
  • YAML
  • Python


Cloud

  • Amazon AWS/MWS
  • Google Workspace/GCP
  • Microsoft Azure
  • Hetzner


Scripting

  • Bash
  • Batch
  • Python
  • Ruby
  • AutoIT
  • VBA
  • VBS
  • PowerShell
  • Windows Shell


Mailing

  • sendmail
  • postfix
  • AmaViS
  • SpamAssasin
  • policy-weight
  • sqlgrey
  • Exchange 5.5 / 2000 / 2003 / 2007 / 2010 / 2013 / 2016
  • exim
  • postgrey


Web Servers

  • Apache
  • Nginx
  • Microsoft IIS
  • Varnish
  • Lighttpd
  • Plesk
  • ISPConfig
  • Webmin
  • Caudium


Cryptographic

  • Microsoft PKI
  • easyCA
  • GnuPG
  • PGP
  • easy CA
  • S/MIME
  • Microsoft Bitlocker
  • Sophos SafeGuard Easy
  • FTAPI
  • PGP Whole Disk Encryption
  • DriveLock
  • Utimaco Lancrypt


VPN

  • Cisco VPN Anyconnect
  • OpenVPN
  • WireGuard
  • FortiNet VPN


Else

  • Active Directory, DNS, FileServices, WSUS, WDS, SCCM, SCOM, Radius, RRAS, OpenLDAP
  • IPtables, BIND9, ProFTPd, Nagios (OMD+Check_MK), Squid2+3, TFTP/PXE
  • DHCPd, dnsmasq, Asterisk, Plesk, Shopfloor Management Systems (SFMS), Hospital Information Systems (KIS)
  • Laboratory Information Systems (LIS/LIMS), Radiology Information System (RIS)
  • Mikrotik RouterBoard, nmap, tcpdump, Whireshark, SELinux
  • Graylog, Sysprep, i-doit, cmdb, Docusnap, Secunia CSI, MobileIron MDM, JDisc, Netflow, OwnCloud, and a lot more


Penetration Tester / Ethical Hacker

  • Penetration Test (Art): Networks, Applications, Operating Systems, Mobile, Web & Wireless
  • Vulnerability scanning: automatic or manual triggered
  • Bugs hunting: Reverse engineering & code review
  • Applications: Knowledge about Linux distributions, Open source & commercial applications, Frameworks


Environments:

  • > 1600000 User
  • > 5000 Applications
  • high complexity
  • very high security standards / requirements
  • worldwide connected locations


Architecture:

  • Network LAN and WANs
  • Datacenters
  • Identity and Access Management
  • Cloud Infrastructures (Microsoft Azure, Google Cloud Platform and Amazon AWS/MWS,
  • Strato, Hetzner, Telekom, PlusServer and others local Cloud providers World Wide)
  • ISMS according to ISO/IEC 27001 implementation and maintaining needs 


Security:

  • Network Security based on firewall designs and -implementing for high security needs,
  • SIEM: Splunk Enterprise, LogRythm and IBM QRadar
  • Web Application Firewalls (PaloAlto, Fortinet FortiWeb, Microsoft Azure WAF, Microsoft Azure vWAN)
  • Microsoft Azure Security (Azure E5 Security, Microsoft Defender for Security, Azure
  • Sentinel (SIEM/SOAR), Azure Active Directory (AAD), Conditional Access, MFA/2FA)
  • FireEye EX (E-Mail), NX (Network) and HX (Host) security
  • Cisco, Sonicwall and Checkpoint Firewalls, Squid Proxy (2, 3), FortiGate Proxy, HAproxy, Wireshark, tshark
  • Harden according to NATO Security, DISA STIGs, BSI Grundschutz, BSI Kompendium, FBI, NCSC, NIST, OpenSCAP, best practices various vendors

 

Firewall:

  • Cisco ASA
  • FortiGate
  • CheckPoint
  • WatchGuard
  • SonicWall
  • Ubiquiti Dream Machine
  • Unifi Switches
  • Iptables
  • ufw
  • nftables
  • Genua GenuGate
  • Genua Genuscreen
  • Genua Cyber Diode


Monitoring:

  • Paessler PRTG
  • OMD
  • Nagios
  • Check_MK
  • NetFlow
  • Icinga
  • Zabbix
  • Prometheus
  • Microsoft SCOM


Penetration Testing:

  • Network
  • Applications
  • Operating System
  • Mobile, Web- & Wireless testing plus vulnerability research
  • Development of exploits for the need of IoT, OT hardware and applications


Vulnerability scanning:

  • Greenbone GSA / OpenVAS
  • Tenable Nessus Pro/Expert
  • Burp Suite Pro
  • Metasploit
  • Nmap, Acunetix
  • HCL AppScan
  • Qualys VMDR
  • GFI LanGuard and a lot more tools


Automation:

  • Hudson
  • Jenkins
  • Puppet
  • Chef
  • Ansible
  • Vagrant
  • Chocolate
  • Bash
  • PowerShell
  • Git/Tortoise SVN
  • Microsoft SCCM
  • Microsoft Intune/Autopilot
  • Microsoft Windows Deployment Services
  • Secunia CSI
  • Sysprep
  • WSUS
  • Microsoft SCOM
  • InstallShield


DNS:

  • Microsoft DNS
  • external DNS servers
  • BIND9
  • dnsmasq


Remote Access/VPN:

  • Cisco Anyconnect
  • Forti client
  • OpenVPN/WireGuard
  • NCP Secure VPN GovNet
  • IPsec
  • Microsoft RRAS
  • Secomea SiteManager & GateManager
  • Teamviewer
  • AnyDesk


Voice/Mobile:

  • Asterisk
  • 3CX
  • Fonial
  • Unifi Talk
  • VOIP
  • MobileIron MDM
  • BlackBerry Server
  • Cisco Jabber
  • Microsoft Teams


Documentation:

  • Omnitracker
  • i-Doit
  • CMDB
  • Docusnap
  • Jdisc
  • Git
  • Atlassian Jira
  • Atlassian Bitbucket
  • Atlassian Confluence
  • Microsoft Sharepoint
  • BIC GRC
  • Risk 2 Chance
  • Siemens Teamcenter PLM/PDM
  • ArchiMate


Others:

  • Shopfloor Management Systems (SFMS)
  • Laboratory Information Systems (LIS/LIMS)
  • Radiology Information System (RIS)
  • Hospital Information Systems (KIS)


Testing:

  • Robot-Framework
  • Cisco ZTP (Zero Touch Provisioning)
  • Automation for different vendors
  • Epimetheus
  • Security Validation and Verification acc. IEC 62443


Management tools:

  • Microsoft Office Professional
  • Microsoft Project
  • Microsoft Visio
  • Atlassian Jira
  • Atlassian Confluence
  • SAP
  • IBM DOORS
  • HCL Notes
  • Risk2Chance
  • BIC


Management Soft skills:

  • Team player
  • Assertive
  • Independent
  • Solution-oriented
  • Decisive
  • Empathetic
  • Motivational


Management:

  • Cost to come analysis, effort estimations
  • project management
  • EAC estimations
  • resource planning and management
  • reporting (senior management)
  • introduction / control / specification of processes / methods and tools
  • deployment of test strategies, planning of customer acceptances, coordination with other disciplines, V-model


Praktika

1994 - 1994

Role: Schülerpraktikum

Customer: Ing. Büro, Königs Wusterhausen


Tasks:

  • Learning area Office technology
  • Installation of SAT-Communications facilities
  • Installation and configuration of Office computers with Microsoft Windows 3.x
  • Installation and configuration of Computer networks with Microsoft Windows 3.x

Betriebssysteme

Apple Mac OS X
Experte
Linux
Experte
Microsoft Server
Experte
Microsoft Windows
Experte
Unix
Experte
SELinux variants
Experte
RedHat
Experte

Datenbanken

MySQL
Experte
MariaDB
Fortgeschritten
Microsoft MSSQL
Fortgeschritten
PostgreSQL
Fortgeschritten
IBM Rational DOORS
Fortgeschritten
Graylog
Experte

Datenkommunikation

Ethernet
Starlink Network
3G, 4G, 5G
Fiber channel

Branchen

Branchen

  • Government
  • Military
  • Energy
  • Automotive
  • Healthcare
  • Music / Record label
  • Finance

Einsatzorte

Einsatzorte

Hamburg (+500km) Kiel (+500km) Lübeck (+500km) Heide (+500km) Weltweit (+500km) Berlin (+500km) München (+500km) Koblenz am Rhein (+500km)
Deutschland, Schweiz, Österreich

Remote - weltweit möglich.
Regional aktuell auf Hamburg, Schleswig-Holstein, Niedersachen und Mecklenburg Vorpommern beschränkt, basierend auf Relevanz, Dauer und Aufgabenhorizont.

möglich

Projekte

Projekte

7 Monate
2025-05 - heute

IT security management system

  • Establishing and maintaining a comprehensive IT security management system (ISMS) in accordance with applicable standards (e.g., ISO/IEC 27001, NIST).
  • Ensuring the information security of all IT systems and platforms, especially to sensitive data to members, sections, and partners.
  • Advising the management on all matters relating to information security and emerging technological risks.
  • Ensuring compliance with regulatory requirements and standards for IT security.
  • Responsibility for IT security-related systems, applications, and services such as vulnerability scanning, penetration tests, firewalls, IDS/IPS, patch management, forensics, EDR/XDR/SOAR, SIEM & SOC, PAM, IAM, etc.
  • Establishing an IT security culture within the association at all levels, from full-time staff to volunteer structures
  • Developing and implementing the security strategy in line with the DAV's goals and values.
  • Formulating and maintaining security guidelines, procedures, and standards.
  • Creating emergency plans and conducting regular risk analyses.
  • Monitoring IT systems and networks for security incidents.
  • Management and control of IT security projects.
  • Leadership of incident response teams in the event of security incidents.
  • Conducting training courses for full-time and volunteer employees on IT security issues.
  • Communicating the importance of security measures at all levels of the association.
  • Coordinating with external IT service providers and security consultants.
  • Assisting in the drafting of contracts with service providers to security requirements.
  • Regular reporting to management on security risks, measures, and developments.
  • Preparing audit reports and security assessments.
on request
München
3 Jahre 4 Monate
2022-08 - heute

Found and start a new business with the scope of all IT- and Security services

Founder / CEO
Founder / CEO

on Request
Boostedt
5 Monate
2025-01 - 2025-05

Military project

IT Security Engineer Security Firewall Industrial ...
IT Security Engineer
  • Implementation of measures for hardening systems and application according to DISA STIGs, CIS, FBI, CIA, BSI Grundschutz / BSI Grundschutzkompendium, CERTBw, DEUmilSAA, NATO, NIST, and other guidelines
  • Conduct a comprehensive assessment of the navigation data distributor, focusing on the Operating Systems and Infrastructure components
  • Identify and resolve issues within the network and Linux-based environments through targeted troubleshooting
  • Execute upgrades of operating systems and ensure successful deployment of the application software
  • Set up and perform validation testing using MT-Windows installation notebooks
  • Develop detailed technical documentation outlining system status, procedures, and implemented changes
Security Firewall Industrial Operating System Documentation Management tools Management
Thales Deutschland
Kiel
1 Jahr 3 Monate
2023-12 - 2025-02

Ensuring compliance with the IT security catalog

IT/OT-Manager Security Firewall Industrial ...
IT/OT-Manager
  • Ensuring compliance with the IT security catalog in accordance with Section 11 (1a) of the Energy Industry Act
  • Securing critical infrastructures in accordance with BSIG Section 8a (KRITIS) in general
  • Ensuring the operation of an "attack detection system" (SzA / Systeme zur Angriffserkennung im Bereich OT und IT-Infrastruktur) in accordance with EnWG and BSIG
  • Coordination of services and third-party companies that provide work and services for the operation, maintenance and repair of the LNG terminals
  • responsible for the quality assurance, control and further development of the entire IT/OT and communication infrastructure
  • control and monitoring systems for the gas send-out of the FSRU, the high-pressure loading arms in the jetty pipeline and the gas transfer station, the commercial IT systems with an internet connection for rolling planning
  • responsible of systems for handling LNG cargos and the systems for onward transportation of natural gas as well as the commercial systems are also part of the area of responsibility
  • Managing all internal and external system services
  • Establishing data analytic exchange for external parties
  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements
  • Optimizing the OT environment for operational needs (Siemens SCADA, PLC, HMI and other related systems)
  • Establishing and maintaining a complete Video Surveillance system in IT and OT environments
  • Coordinated cross-functional teams and ensured timely, on-budget project delivery
  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover
  • Designed and implemented IT and OT infrastructure across the client?s operational and administrative environments with high end enterprise needs
  • Deployed Starlink satellite systems to establish connectivity between remote facilities, ports, container office locations and offices
  • Secured all connected sites through the installation and configuration of hardened firewalls and managed switches, ensuring robust perimeter and internal network protection
  • Development and formal documentation of a comprehensive security concept in alignment with the International Ship and Port Facility Security (ISPS) Code, focusing on risk assessment, protective measures, and compliance requirements for maritime and port facility operations
  • Supporting ISMS activities to archive ISO 27001 and ISO 27019 certification for all locations
  • Utilized PI AVEVA for the visualization, analysis, and monitoring of large OT/IT data sets within control centers and operations rooms.
  • Establishing, supporting and maintaining big data analysis from ICS components into PI AVEVA
  • Building specific visualization dashboard for ICS/IT und OT components
Security Firewall Industrial Communications Virtualization Databases Operating System Development Remote Access / VPN Voice/Mobile Management tools Management
LNG / Gas Energy Industry
Wilhelmshaven, Brunsbüttel, Stade, Düssendorf
2 Jahre 2 Monate
2022-11 - 2024-12

Military project

IT Security Engineer Security Firewall Industrial ...
IT Security Engineer
  • Establishment of an analysis of the technical and professional BSI (Federal Office of Information Security) requirements and specification of the military security catalog for ITSecurity
  • Implementation of measures for hardening systems and application according to DISA STIGs, CIS, FBI, CIA, BSI Grundschutz / BSI Grundschutzkompendium, CERTBw, DEUmilSAA, NATO, NIST, and others guidelines
  • Establishment of an analysis of the network and their network requirements
  • Establishment of vulnerability remediation concepts for the network with focus to harden network security components
  • Setting up the virtualized cluster server systems (virtualization platform Microsoft Hyper-V) of new networks on Debian Linux
  • Configuration of Cisco firewalls using Ansible scripts
  • Hardening of Cisco 9xxx Series switches, Genua Genuscreen firewalls according to requirements
  • Execution of system tests and documentation
  • Elimination of errors according to previously created concepts
  • Creation of detailed technical documentation
  • Installation and configuration of Microsoft Windows 10/11 endpoints in Bare-Metal and virtual environments (VMware ESXi & VMware Workstation) with secured hardened profiles based on requirements
  • Installation and configuration of Red Hat Enterprise Linux server and maintainer terminals with secured profiles according to OpenSCAP and DISA STIGs
  • Hardening of Red Hat Enterprise Linux Server and Red Hat Enterprise Linux Workstations based on OpenSCAP and DISA STIGs
  • Maintain and configuration of Red Hat Enterprise Linux Satellite Server, Foreman proxy and Ansible playbooks and roles in a GIT controlled environment
  • Implementation secured configuration for HP switches
  • Configuration of secured profiles for ICS switches, type Belden Hirschmann BOBCAT and MOXA switches
  • Hardening of BIOS / UEFI firmware
  • Ensuring the operation of an "attack detection system" (SzA / Systeme zur
  • Angriffserkennung im Bereich OT und IT-Infrastruktur) in accordance to BSIG
  • Providing multiple Information Security Awareness Trainings based of ISO 27001 and IEC
  • 62443 for different team members and project members
  • Blackbox- & White-box penetration tests (Nessus Pro and Metasploit with own developed scripts and exploits), OWASP TOP 10 checks and vulnerability scans with Nessus Professional/Burp Suite Pro on IT/OT/ICS hardware
  • Security validation and verification (SVV3+4) acc. IEC 62443
  • Deployment of multiple network devices via Zero Touch Provisioning (ZTP)
  • Testing of configuration with Robot-Framework
  • Application management for Linux applications and dependencies
  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements
  • Coordinated cross-functional teams and ensured timely, on-budget project delivery
  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover
VMware ESX Hyper-V Windows 10 Tenable Nessus VMware Workstation Cisco Genua Genuscreen M Cisco 93xx Debian RedHat Redhat Satellite Red Hat Enterprise Linux Ansible Python
Security Firewall Industrial Communications Virtualization Databases Operating System Development Automation Web Servers Documentation Testing Remote Access / VPN Voice/Mobile Scripting Management tools Management
Thales Deutschland
Kiel
6 Monate
2023-10 - 2024-03

Organization and implementation of the management review

CISO / ext ISB Security Firewall Industrial ...
CISO / ext ISB
  • Organization and implementation of the management review at regular intervals
  • Organization and execution of internal, external and certification audits as well as monitoring and continuation of the audit program, moderation and support
  • Risk management for KRITIS relevant assets
  • Delegation or own execution of activities within the ISMS (after consultation with with management)
  • Document management of the ISMS document collection, e.g. updating and control of new documents
  • Ensuring the operation of an ADS ("attack detection system") (SzA / Systeme zur Angriffserkennung im Bereich OT und IT-Infrastruktur) in accordance with EnWG and BSIG
  • Training of employees regarding information security
  • Implementation of measures (annex, findings, technical requirements according to BSI norms, BSI KritisV, IT-SiKat § 11 Absatz 1b EnWG, ISO 27001, ISO 27019, etc.).
  • Implementation of regulatory requirements
  • Monitoring and consulting of the changing regulatory environment
  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements
  • Coordinated cross-functional teams and ensured timely, on-budget project delivery
  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover
  • Conducting regular Information Security Management meetings with executive leadership in accordance with ISO/IEC 27001 and ISO/IEC 27019, to ensure strategic oversight and continuous improvement of the organization?s information security posture, in line with KRITIS compliance requirements.
Security Firewall Industrial Communications Management tools Management
Veja Mate Offshore Project GmbH
1 Jahr 2 Monate
2021-10 - 2022-11

Professional management

Senior OT Cyber Security Specialist Service Security Firewall Industrial ...
Senior OT Cyber Security Specialist Service
  • Professional management and responsibility for Global Cyber Security of a 4 FTE Cyber Security team in Service, Germany

  • Lead a virtual team and coordinate project activies i.e. ISO 27001 ISMS / IEC 62443

  • Stakeholder management according to compliance requirements and opportunities for improvement

  • Preparation for ISO/IEC recertification and ensure compliance with ISO/IEC standards and other Governmental/Legal regulations

  • Planning, implementation and further development of OT Cyber Security strategies for Security Incident and Event Management, Monitoring, Patch-/Update- and Vulnerability Management

  • Architecture and conception of network zones for implementation acc. IEC 62443 certification

  • Perform security assessment on Windows/Linux operating system, and VMware, Citrix and Microsoft Hyper-V environments

  • Investigate new and emerging security threats against internal/external Network Infrastructure and interconnected systems

  • Coordination, identification and analyses of Cyber Security incidents and development of countermeasures

  • Project management with the scope of different Information Security related Cloud- and Onpremise applications and systems

  • Implementation of ISO 27001/IEC 62443 policies, guidelines and processes

  • Development of processes, methods and tools to detect anomalies

  • Implementation and maintaining infrastructure with Cisco Firewalls, HP Aruba, Fortigate Firewalls/Switches, Sonicwall, Checkpoint and FireEye EX/NX/HX

  • Optimization of network segments and vWAN segments to/from Microsoft Azure into internal infrastructure areas

  • Performing Penetration Tests against IT / OT Infrastructure with the scope of Web application, databases, hardware and mobile devices

  • Blackbox- & White-box penetration tests (Nessus Pro and Metasploit with own developed scripts and exploits), OWASP TOP 10 checks and vulnera

  • Vulnerability scans with Nessus Professional/Burp Suite Pro on IT/OT/ICS hardware

  • Security validation and verification (SVV3+4) acc. IEC 62443

  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements

  • Coordinated cross-functional teams and ensured timely, on-budget project delivery

  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover

  • Application Management & Security Compliance (Application Operations & Administration / Managing and optimizing business-critical applications in cloud and on-premises environments)

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Web Servers Documentation Testing Remote Access / VPN Voice/Mobile Scripting Management tools Management
Nordex Energy SE & Co. KG, Hamburg
2 Jahre 10 Monate
2019-01 - 2021-10

Planning, implementation and further development of IT security systems

IT-Security Specialist & Information Security Officer Security Firewall Industrial ...
IT-Security Specialist & Information Security Officer
  • Planning, implementation and further development of IT security systems and operational mentoring systems (SIEM, SOC monitoring) and improvement of automatic reports

  • Standardization of network schemes/designs in the IT and OT wind energy sector

  • Lead a virtual team and coordinate project activies i.e. ISO 27001 ISMS / IEC 62443

  • Stakeholder management according to compliance requirements and opportunities for improvement

  • Preparation for ISO/IEC recertification and ensure compliance with ISO/IEC standards and other Governmental/Legal regulations

  • Design, modeling, implementation and documentation of information security management systems (ISMS management, guidelines, processes and procedures) according to ISO 27001, KRITIS and BSI Grundschutz

  • Coordination and analysis of incoming security incident reports

  • Establishment of a Computer Emergency Response Team and be first contact to IT related security incidents and Penetration tests

  • Project management with the scope of different Information Security related Cloud- and On-premise applications and systems

  • Implementation and coordination of security recommendations based on non-conformities in the area of LAN/WAN, SCADA, IT & OT Wind turbine systems and encryption

  • Design/modeling of IT security networks zones & systems including automated vulnerability analysis/scans

  • Management and administration of IT security systems to detect malware/ransomware and anomalies in network and web/mail traffic

  • Implementation and maintaining infrastructure with Cisco Firewalls, HP Aruba, Fortigate Firewalls/Switches, Sonicwall, Checkpoint and FireEye EX/NX/HX

  • Optimization of network segments and vWAN segments to/from Microsoft Azure into internal infrastructure areas

  • Establishment and execution of regular audits in the context of ISO 27001

  • Establishment of regular Microsoft Active Directory audits

  • Application Management & Security Compliance (Application Operations & Administration / Managing and optimizing business-critical applications in cloud and on-premises environments)

  • Led complex IT/OT projects in critical infrastructure (KRITIS) with a focus on stringent security and compliance requirements

  • Coordinated cross-functional teams and ensured timely, on-budget project delivery

  • Managed external providers through KPI-based performance tracking, clear contract expectations, and oversight from planning to final handover


Achievements:

  • Successful company certification according to ISO 27001 in 2019

  • Establishment of an extended security concept within the scope of IT security training courses

  • Project planning and implementation of penetration tests in the energy sector

  • Certification as TÜV Rheinland Information Security Officer (ISO)

  • Additional examination KRITIS topic of "Additional test procedure competence for § 8a BSIG" incl. IT-SIG and BSI-KritisV

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Web Servers Documentation Testing Remote Access / VPN Voice/Mobile Scripting Management tools Management
Nordex SE, Hamburg
1 Jahr 2 Monate
2017-11 - 2018-12

Creation of process documentation

IT System Administrator Security Firewall Industrial ...
IT System Administrator
  • Creation of process documentation and documentation standards in IBM DOORS

  • Coordination of IT systems and their security requirements with internal and external customer projects

  • Administration and management of the VMware ESX server farm

  • Configuration of Juniper switches (EX4300/EX4550) and firewalls (SRX1500)

  • Installation and optimization of the Windows Active Directory DS infrastructure in customer projects

  • Administration and maintenance of existing Linux servers (Ubuntu/CentOS)

  • Administration of virtualization and deployment environment with CI/CD tool chains under the scope of Linux and Windows deployment servers in Enterprise environments

  • Hardening of Windows and Linux servers and application services

  • Implementation, documentation and testing of operating systems, networks, applications on technical equipment in the field of shipping (defense technology)

  • Planning and execution of penetration tests in customer projects

  • Implementation of vulnerability management, IT/live forensics, security information and event management (SIEM) and firewalling in customer projects

  • Creation of developmental product documents, requirements specifications and software documentation


Archievements:

  • Project support with adherence to deadline targets

  • Establish and improve virtualization & deployment processes including hardening parts and solutions in Military Marine projects

  • Execution of automated penetration tests to increase security in projects

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Documentation Testing Management tools Management
Ratheon Anschütz GmbH, Kiel - Engineering
8 Monate
2017-03 - 2017-10

Global IT Infrastructure

System Engineer Security Firewall Industrial ...
System Engineer
  • 2nd/3rd Level Support

  • Infrastructure project management (project planning, design, implementation)

  • Administration and management of Cisco FirePower (IPS SIEM) and IronPort for e-mail security infrastructure (International wide)

  • Planning, preparation and implementation for VDA/TÜV and ISO 27001 certification

  • Administration and maintenance of Linux servers (RedHat, Ubuntu, Debian, Gentoo)

  • Administration and maintenance of the Shopfloor Management System (SFMS)

  • IT Security monitoring with Nagios/OMD - Check_MK

  • Configuration of Cisco routers, firewalls (ASA & IOS) and switches

  • Installation and optimization of the Active Directory environment

  • Administration of the VMware ESX server farm (based on HP Blade Center)

  • Design/administration and maintenance of the Symantec Backup EXE, Commvault and Veeam backup infrastructure (World Wide)

  • Ticket handling through OTRS / RT ticket system

  • Installation and administration of the MobileIron Mobile Device Management (MDM) global wide

  • Installation/administrate of the patch management environment for Operating systems and applications

  • Establish and developments for automated installation based on Windows Deployment System

  • Migration of Windows NT to next generation Windows Server 2008 R2 and 2012 R2

  • Process documentation and establishing documentation standards


Archievements:

  • Implementation of the security concepts, mobile device management system, patch management environment and automation of software and operating systems deployment

  • Accelerate further Cisco-based network structures in the LAN/WAN area

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Documentation Testing Management tools Management
BRUSS Sealing Systems GmbH, Hoisdorf - Automotive supplier
11 Jahre 3 Monate
2006-01 - 2017-03

Technical and professional personnel management

Department Sergeant and System - & Network Engineer Security Firewall Industrial ...
Department Sergeant and System - & Network Engineer
  • Technical and professional personnel management leading employees up to 10-15 FTEs

  • Optimization of IT processes

  • Cost optimization, negotiation of contracts and vendor relationships

  • Reporting of budgeting in a quarterly review

  • Training of civilian, military and military service employees

  • Planning and contributing to hospital internal IT strategies and external sites

  • Main responsible for IT related material, hardware & software

  • Administration and maintenance of Microsoft Windows (NT 4.0 up to 2012 R2) and Linux based operating systems (RedHat, Debian, SuSE)

  • Administration and optimization of Microsoft Windows AD domains

  • Hardening of Windows and Linux server systems and applications according to BSI, CERTBundeswehr, Best Practices and NIST, as well as other internal guidelines to best practices

  • Configuration and maintenance of appliances like Cisco Firewalls (ASA, PIX), routers & switches, Enterasys Networks core switches and Checkpoint firewalls

  • Administration and optimization of Lotus Domino Server from version 4 to 8.5.3

  • Installation and administration of VMware ESX server farms

  • Responsibility to BCM acc. Backup and Recovery ArcServ Backup and IBM TSM

  • Configuration/administration and maintenance of the Symantec security environment, Sophos SafeGuard environment (UTM, Endpoint Protection, SafeGuard Easy)

  • Wi-Fi design and planning, installation and administration of the Cisco WLC environment to secure hospital networks

  • Creation of process documentation and documentation standards

  • Customer site visits (planning, troubleshooting and remediation)


Archievements

  • Implementation of security concepts to state-of-the-art security configurations and systems

  • Implementation of IT-Security training

  • Extensive experience on the Internet provider side (routing, switching) with support from external companies

  • Planning and implementation of the in-house telephone system to VOIP in cooperation with external service providers

  • Implementation of external properties and companies to the VPN network of the Federal Armed Forces Hospital Hamburg

  • Establishment of automation solutions for operating systems and applications

  • Establishment of an internal patch management system

  • Migration of all client systems from Microsoft Windows NT/2000/XP to latest Microsoft Windows 7/10

  • Establishment of a time recording system in cooperation with external service providers

Security Firewall Industrial Communications Virtualization Databases Operating System Penetration Testing Vulnerability management Cryptography Development Automation Documentation Testing Management tools Management
Federal Armed Forces ? Military Hospital, own Datacenter, Hamburg
3 Monate
2001-07 - 2001-09

Design and programming of websites

Training IT system merchant and Information electronics technician
Training IT system merchant and Information electronics technician
  • Sales team member 

  • Design and programming of websites 

  • Installation, configuration of IT supported computer systems 

  • Installation and setup of TV based satellite connections 

  • Support of the in-house IT

Lorenzen Team, Regional specialized dealer for electronics
5 Monate
2001-03 - 2001-07

data order input department

IT-System Administrator
IT-System Administrator
  • Team member in the data order input department 

  • Entry of customer orders/cancellations into the inventory control system 

  • Checking of customer orders based on automated scripts 

  • Supporting in-house IT 


Motivation of change

Direct offer from a recruiting firm to prove yourself in a different role and start an apprenticeship in IT.

Markisen Spettmann GmbH, Neumünster
10 Monate
2000-05 - 2001-02

Military defense service

  • Military defense service for 10-month located in Roth/Bavaria and Kropp/Jagel, SchleswigHolstein, German

Federal Armed Forces, Germany
8 Monate
1999-09 - 2000-04

Sale of hardware and software

IT System Technician & Administrator
IT System Technician & Administrator
  • Up to 09/1999 Company named Comf@ctory, later renamed to Comsystem GmbH, Neumünster, Schleswig-Holstein, Germany 

  • Sale of hardware and software 

  • Setup, configuration and administration of heterogeneous networks 

  • Modifying/Conversion of consumer goods 

  • Installation and modification of electronic components in various devices   


Motivation to change

Federal Republic of Germany drafts me into 10-month military service.

Comf@ctory GmbH
Neumünster

Aus- und Weiterbildung

Aus- und Weiterbildung

2 Jahre 10 Monate
2002-09 - 2005-06

Ausbildung zum Fachinformatiker

Grade: 3, Hard- & Softwarelösungen B. Pommerening, Neumünster und Stadtwerke Kiel AG, Kie
Grade: 3
Hard- & Softwarelösungen B. Pommerening, Neumünster und Stadtwerke Kiel AG, Kie
  • IT Specialist System integration 
  • Focus areas: System analytics / planning / cost optimization 
  • Network Administration for the Energy Control Systems 
  • Planning, Installation and administration of Network-Attached-Storage environments 
  • First- und Second-Level Support Helpdesk 
2 Jahre 10 Monate
2002-09 - 2005-06

Specialized High School ? Economy

Termination due to support my freelancer career, Theodor-Litt-Schule Neumünster
Termination due to support my freelancer career
Theodor-Litt-Schule Neumünster
1 Jahr 11 Monate
1996-08 - 1998-06

Wirtschaft und Sozialwirtschaft

Secondary school diploma in Economy / Grade: 2, Theodor-Litt-Schule Neumünster, Berufliche Schulen Rendsburg
Secondary school diploma in Economy / Grade: 2
Theodor-Litt-Schule Neumünster, Berufliche Schulen Rendsburg

Kompetenzen

Kompetenzen

Top-Skills

IT-Sicherheitsarchitektur Penetrationstest ISO 27001 Auditor KRITIS VPN Firewall IEC 62443 OT-Security Internet of Things ISMS IT-Security Penetrationstest Informationssicherheit Infrastruktur Anforderungsanalyse Vulnerability Microsoft Linux Cloud Mac

Schwerpunkte

Interim CISO / CIO
Information Security Management Systems
Penetration Tests including Vulnerability Management
Strategy and standardization IT infrastructure
IT-Infrastructure architecture
Network architecture
Datacenter architecture
Identity and Access Management
Backup- and Disaster Recovery
Personal- and organizational planning datacenter operations

Produkte / Standards / Erfahrungen / Methoden

Profile:

Technical expert with experience over 20 years in IT/OT/Cyber Security, a comprehensive knowledge of Computer Information System Security, System Administration and Network Operations, and Datacenter Operations. Extensive knowledge in the areas of system security, vulnerability scanning, penetration testing, risk assessment and cyber security analysis. Experienced in leadership management over 10 years with a team up to 25 members, project coordination and system implementation of Government systems, telecommunication and larger computer networks. Security clearance (German Ü2/Ü3) is possible, if needed. Highly organized team player with the ability to effectively manage project milestones and project delivery. International work and leadership experience.


Virtualization

  • Microsoft Hyper-V and Microsoft Terminal Server solutions
  • VirtualBox
  • VMware ESX
  • VMware Horizen
  • VMware Workstation
  • Parallels Desktop
  • VDI
  • Citrix Hypervisor
  • Proxmox
  • KVM
  • QEMU


LAMP System

  • Linux
  • Apache
  • MySQL/MariaDB
  • PHP


Development

  • Bash Scripting
  • Basic
  • Delphi
  • Pascal
  • C / C++
  • HTML with PHP 
  • JS und CSS
  • JavaScript
  • YAML
  • Python


Cloud

  • Amazon AWS/MWS
  • Google Workspace/GCP
  • Microsoft Azure
  • Hetzner


Scripting

  • Bash
  • Batch
  • Python
  • Ruby
  • AutoIT
  • VBA
  • VBS
  • PowerShell
  • Windows Shell


Mailing

  • sendmail
  • postfix
  • AmaViS
  • SpamAssasin
  • policy-weight
  • sqlgrey
  • Exchange 5.5 / 2000 / 2003 / 2007 / 2010 / 2013 / 2016
  • exim
  • postgrey


Web Servers

  • Apache
  • Nginx
  • Microsoft IIS
  • Varnish
  • Lighttpd
  • Plesk
  • ISPConfig
  • Webmin
  • Caudium


Cryptographic

  • Microsoft PKI
  • easyCA
  • GnuPG
  • PGP
  • easy CA
  • S/MIME
  • Microsoft Bitlocker
  • Sophos SafeGuard Easy
  • FTAPI
  • PGP Whole Disk Encryption
  • DriveLock
  • Utimaco Lancrypt


VPN

  • Cisco VPN Anyconnect
  • OpenVPN
  • WireGuard
  • FortiNet VPN


Else

  • Active Directory, DNS, FileServices, WSUS, WDS, SCCM, SCOM, Radius, RRAS, OpenLDAP
  • IPtables, BIND9, ProFTPd, Nagios (OMD+Check_MK), Squid2+3, TFTP/PXE
  • DHCPd, dnsmasq, Asterisk, Plesk, Shopfloor Management Systems (SFMS), Hospital Information Systems (KIS)
  • Laboratory Information Systems (LIS/LIMS), Radiology Information System (RIS)
  • Mikrotik RouterBoard, nmap, tcpdump, Whireshark, SELinux
  • Graylog, Sysprep, i-doit, cmdb, Docusnap, Secunia CSI, MobileIron MDM, JDisc, Netflow, OwnCloud, and a lot more


Penetration Tester / Ethical Hacker

  • Penetration Test (Art): Networks, Applications, Operating Systems, Mobile, Web & Wireless
  • Vulnerability scanning: automatic or manual triggered
  • Bugs hunting: Reverse engineering & code review
  • Applications: Knowledge about Linux distributions, Open source & commercial applications, Frameworks


Environments:

  • > 1600000 User
  • > 5000 Applications
  • high complexity
  • very high security standards / requirements
  • worldwide connected locations


Architecture:

  • Network LAN and WANs
  • Datacenters
  • Identity and Access Management
  • Cloud Infrastructures (Microsoft Azure, Google Cloud Platform and Amazon AWS/MWS,
  • Strato, Hetzner, Telekom, PlusServer and others local Cloud providers World Wide)
  • ISMS according to ISO/IEC 27001 implementation and maintaining needs 


Security:

  • Network Security based on firewall designs and -implementing for high security needs,
  • SIEM: Splunk Enterprise, LogRythm and IBM QRadar
  • Web Application Firewalls (PaloAlto, Fortinet FortiWeb, Microsoft Azure WAF, Microsoft Azure vWAN)
  • Microsoft Azure Security (Azure E5 Security, Microsoft Defender for Security, Azure
  • Sentinel (SIEM/SOAR), Azure Active Directory (AAD), Conditional Access, MFA/2FA)
  • FireEye EX (E-Mail), NX (Network) and HX (Host) security
  • Cisco, Sonicwall and Checkpoint Firewalls, Squid Proxy (2, 3), FortiGate Proxy, HAproxy, Wireshark, tshark
  • Harden according to NATO Security, DISA STIGs, BSI Grundschutz, BSI Kompendium, FBI, NCSC, NIST, OpenSCAP, best practices various vendors

 

Firewall:

  • Cisco ASA
  • FortiGate
  • CheckPoint
  • WatchGuard
  • SonicWall
  • Ubiquiti Dream Machine
  • Unifi Switches
  • Iptables
  • ufw
  • nftables
  • Genua GenuGate
  • Genua Genuscreen
  • Genua Cyber Diode


Monitoring:

  • Paessler PRTG
  • OMD
  • Nagios
  • Check_MK
  • NetFlow
  • Icinga
  • Zabbix
  • Prometheus
  • Microsoft SCOM


Penetration Testing:

  • Network
  • Applications
  • Operating System
  • Mobile, Web- & Wireless testing plus vulnerability research
  • Development of exploits for the need of IoT, OT hardware and applications


Vulnerability scanning:

  • Greenbone GSA / OpenVAS
  • Tenable Nessus Pro/Expert
  • Burp Suite Pro
  • Metasploit
  • Nmap, Acunetix
  • HCL AppScan
  • Qualys VMDR
  • GFI LanGuard and a lot more tools


Automation:

  • Hudson
  • Jenkins
  • Puppet
  • Chef
  • Ansible
  • Vagrant
  • Chocolate
  • Bash
  • PowerShell
  • Git/Tortoise SVN
  • Microsoft SCCM
  • Microsoft Intune/Autopilot
  • Microsoft Windows Deployment Services
  • Secunia CSI
  • Sysprep
  • WSUS
  • Microsoft SCOM
  • InstallShield


DNS:

  • Microsoft DNS
  • external DNS servers
  • BIND9
  • dnsmasq


Remote Access/VPN:

  • Cisco Anyconnect
  • Forti client
  • OpenVPN/WireGuard
  • NCP Secure VPN GovNet
  • IPsec
  • Microsoft RRAS
  • Secomea SiteManager & GateManager
  • Teamviewer
  • AnyDesk


Voice/Mobile:

  • Asterisk
  • 3CX
  • Fonial
  • Unifi Talk
  • VOIP
  • MobileIron MDM
  • BlackBerry Server
  • Cisco Jabber
  • Microsoft Teams


Documentation:

  • Omnitracker
  • i-Doit
  • CMDB
  • Docusnap
  • Jdisc
  • Git
  • Atlassian Jira
  • Atlassian Bitbucket
  • Atlassian Confluence
  • Microsoft Sharepoint
  • BIC GRC
  • Risk 2 Chance
  • Siemens Teamcenter PLM/PDM
  • ArchiMate


Others:

  • Shopfloor Management Systems (SFMS)
  • Laboratory Information Systems (LIS/LIMS)
  • Radiology Information System (RIS)
  • Hospital Information Systems (KIS)


Testing:

  • Robot-Framework
  • Cisco ZTP (Zero Touch Provisioning)
  • Automation for different vendors
  • Epimetheus
  • Security Validation and Verification acc. IEC 62443


Management tools:

  • Microsoft Office Professional
  • Microsoft Project
  • Microsoft Visio
  • Atlassian Jira
  • Atlassian Confluence
  • SAP
  • IBM DOORS
  • HCL Notes
  • Risk2Chance
  • BIC


Management Soft skills:

  • Team player
  • Assertive
  • Independent
  • Solution-oriented
  • Decisive
  • Empathetic
  • Motivational


Management:

  • Cost to come analysis, effort estimations
  • project management
  • EAC estimations
  • resource planning and management
  • reporting (senior management)
  • introduction / control / specification of processes / methods and tools
  • deployment of test strategies, planning of customer acceptances, coordination with other disciplines, V-model


Praktika

1994 - 1994

Role: Schülerpraktikum

Customer: Ing. Büro, Königs Wusterhausen


Tasks:

  • Learning area Office technology
  • Installation of SAT-Communications facilities
  • Installation and configuration of Office computers with Microsoft Windows 3.x
  • Installation and configuration of Computer networks with Microsoft Windows 3.x

Betriebssysteme

Apple Mac OS X
Experte
Linux
Experte
Microsoft Server
Experte
Microsoft Windows
Experte
Unix
Experte
SELinux variants
Experte
RedHat
Experte

Datenbanken

MySQL
Experte
MariaDB
Fortgeschritten
Microsoft MSSQL
Fortgeschritten
PostgreSQL
Fortgeschritten
IBM Rational DOORS
Fortgeschritten
Graylog
Experte

Datenkommunikation

Ethernet
Starlink Network
3G, 4G, 5G
Fiber channel

Branchen

Branchen

  • Government
  • Military
  • Energy
  • Automotive
  • Healthcare
  • Music / Record label
  • Finance

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.