Freelance Information Security Architect with 25+ years of experience in designing and implementing enterprise-grade security solutions
Aktualisiert am 29.06.2026
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 01.07.2026
Verfügbar zu: 100%
davon vor Ort: 10%
IT-Sicherheitsarchitektur
Risikomanagement
Solution Architect
Zero Trust
OT Security
IT-Security
Zscaler
GRC
English
Fluent
French
Fluent
Italian
Fluent
Spanish
Intermediate
Czech
Intermediate
Romanian
Muttersprache

Einsatzorte

Einsatzorte

Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

11 months
2025-06 - 2026-04

Risk management, architecture and governance consulting

Global Information Security Consultant Risikomanagement
Global Information Security Consultant

Provided security risk management, architecture and governance consulting within enterprise IT & OT environments, supporting regulatory compliance and risk mitigation strategies.

  • Conducted security risk assessments across enterprise software and infrastructure systems
  • Developed risk mitigation strategies aligned with corporate security policies
  • Supported regulatory compliance and governance activities
  • Delivered security reporting and recommendations to senior stakeholders


Achievements
  • Successfully mitigated every security risk assigned, preventing them from escalating to the Security Board for acceptance
  • Supported adoption of emerging security practices related to AI technologies
Risikomanagement
EVOTEC SE
remote
1 year 3 months
2024-04 - 2025-06

Designed and implemented network security standards

Network Security Service Owner / Network Security Architect IT-Sicherheitsarchitektur
Network Security Service Owner / Network Security Architect

Designed and implemented network security standards, best security practices and Zero Trust.

  • Owned and governed enterprise-wide network security services, ensuring alignment with corporate security standards and Zero Trust principles across IT and OT environments.
  • Reviewed and approved security architectures, firewall changes, external connectivity, and secure remote access solutions (Zscaler ZPA, IPSec VPN), reducing exposure to unauthorized access.
  • Led and contributed to key security transformation initiatives, including FortiGate deployments, firewall segmentation, policy standardization, and iDMZ design.
  • Drove the adoption of Zero Trust architecture by evaluating and integrating modern security solutions, improving overall security posture and access control maturity.
  • Acted as a central decision authority for secure connectivity (suppliers, remote access, privileged access), balancing risk mitigation with business enablement.
  • Collaborated with global stakeholders across IT and OT to enhance plant and enterprise security while supporting digitalization initiatives.


Achievements
  • Strengthened segmentation and access control across IT/OT environments through standardized firewall policies and Zero Trust design.
  • Improved operational efficiency and security governance by streamlining Zscaler policies and remote OT connectivity.
Zscaler Fortinet
IT-Sicherheitsarchitektur
KNAUF INFORMATION SERVICES
remote
8 months
2023-05 - 2023-12

Implemented API-driven automation between Zscaler and ServiceNow

Solutions Specialist ? Zscaler API & Automation Consultant Solution Architect
Solutions Specialist ? Zscaler API & Automation Consultant

Provided consultancy on the secure integration and automation between Zscaler and ServiceNow.

  • Designed and implemented API-driven automation between Zscaler and ServiceNow using Azure API Management, enabling scalable and consistent security workflows.
  • Optimized Zscaler (ZIA/ZPA) configurations by applying best practices, improving performance, policy consistency, and security effectiveness.
  • Produced detailed technical documentation, architecture diagrams, and process flows to support automation and operational handover.
  • Collaborated with cross-functional teams to deliver end-to-end integration and ensure successful testing and deployment.
  • Provided technical guidance and stakeholder presentations, translating complex implementations into business-relevant outcomes.


Achievements
  • Delivered a fully integrated automation solution reducing manual intervention in Zscaler-ServiceNow processes.
  • Enhanced visibility and control over security workflows through structured API integration.
Zscaler ServiceNow
Solution Architect
SANDVIK
remote
1 year 6 months
2021-07 - 2022-12

Implemented cloud-based network security solutions based on Zscaler

Network Security Engineer / Zscaler Design & Implementation Engineer Solution Architect
Network Security Engineer / Zscaler Design & Implementation Engineer

Designed and implemented cloud-based network security solutions based on Zscaler, on a large scale.

  • Designed and implemented Zscaler-based cloud security architecture across multiple countries, supporting the organization?s transition to a Zero Trust model.
  • Led large-scale deployment of Zscaler Client Connector to 7,000+ users across 10 countries, enabling secure, cloud-based internet access.
  • Migrated traffic from legacy on-premise proxy infrastructure (Blue Coat) to cloud-native security solutions, improving scalability and user experience.
  • Developed PAC files, deployment strategies, and migration plans ensuring minimal disruption during rollout.
  • Provided post-deployment support and continuous optimization, ensuring service stability and user adoption.
  • Worked within Agile/Scrum teams to deliver iterative improvements aligned with business and security goals.


Achievements
  • Successfully executed a multi-country rollout impacting thousands of users with minimal disruption.
  • Accelerated Zero Trust adoption and improved user experience through cloud-first security architecture.
Zscaler
Solution Architect
Nationale-Nederlanden
remote
1 year
2020-03 - 2021-02

Implementation of cloud-based proxy security architecture

Network Security Engineer Solution Architect
Network Security Engineer

Delivered global implementation of cloud-based proxy security architecture following a major cyber incident.

  • Implemented Zscaler SaaS proxy solution across global infrastructure
  • Configured URL filtering, SSL inspection and malware protection
  • Produced operational documentation (SOPs, FAQs)
  • Supported incident resolution and user onboarding


Achievements
  • Successfully deployed secure proxy solution to 35,000+ devices globally
  • Contributed to enterprise security recovery following cyber incident
  • Trained SOC teams on how to deal with specific incidents
  • Improved global visibility into web traffic and threat activity
Zscaler
Solution Architect
EUROFINS
remote
1 year 9 months
2017-10 - 2019-06

Risk management

Security Problem Manager Risikomanagement
Security Problem Manager

Provided security risk management for DB, as part of the CISO team.

  • Led proactive security problem management within the CISO function, focusing on root cause analysis and long-term remediation of security issues.
  • Drove the identification and mitigation of systemic vulnerabilities, reducing recurrence of incidents across the IT environment.
  • Managed and tracked security issues (SIIs) in alignment with Operational Risk Management frameworks, ensuring regulatory and internal compliance.
  • Coordinated cross-functional efforts with Threat Intelligence, Incident Response, Red Team, and business units to address complex security challenges.
  • Delivered reporting and insights to stakeholders, improving visibility into security risks and remediation progress.


Achievements
  • Reduced repeat security incidents by enforcing structured root cause analysis and remediation processes.
  • Strengthened collaboration between security, risk, and business teams, improving overall risk posture and governance.
Risikomanagement
Deutsche Bank
Eschborn, Taunus
1 year 1 month
2016-03 - 2017-03

Migrations and security architecture design

Security Architect IT-Sicherheitsarchitektur
Security Architect
Delivered Fortinet migrations and security architecture design for global enterprise customers; performed SD-WAN hub and spoke configurations.
Fortinet Cisco ASA
IT-Sicherheitsarchitektur
Orange Cyberdefense
Brussels
7 months
2015-06 - 2015-12

Implemented enterprise security governance and incident management

Security Architect IT-Sicherheitsarchitektur
Security Architect

IT-Sicherheitsarchitektur
Adecco
Lyon
1 year 4 months
2013-07 - 2014-10

FortiGate firewalls

Security Consultant Solution Architect
Security Consultant
Deployed 80+ FortiGate firewalls across production environments to secure the Airbus A350 aircraft production plants.
Fortinet Check Point
Solution Architect
Airbus
Toulouse

Aus- und Weiterbildung

Aus- und Weiterbildung

11 years 11 months
2014-08 - now

CISSP (Certified Information Systems Security Professional)

ISC2
ISC2
Information Security
13 years 2 months
2013-05 - now

FCNSP (Fortinet Certified Network Security Professional)

Fortinet
Fortinet
Fortinet products
15 years 2 months
2011-05 - now

ITIL Foundation

PeopleCert
PeopleCert
IT Service Management
16 years 1 month
2010-06 - now

CWNA (Certified Wireless Network Administrator)

CWNP
CWNP
Wireless networking
6 years 1 month
2009-04 - 2015-04

CCNP (Cisco Certified Network Professional)

Cisco
Cisco
Cisco routing and switching, security

Position

Position

Senior Security Architect (IT/OT) | Zero Trust | Risk Management Specialist | Security Consultant

Kompetenzen

Kompetenzen

Top-Skills

IT-Sicherheitsarchitektur Risikomanagement Solution Architect Zero Trust OT Security IT-Security Zscaler GRC

Schwerpunkte

security architecture
Experte
zero trust
Experte
risk management
Experte
IT security
Experte
OT security
Fortgeschritten
cloud security
Fortgeschritten

Produkte / Standards / Erfahrungen / Methoden

Profile

  • Senior Information Security Architect (IT/OT) | CISSP | Zero Trust & Risk Management Specialist | SC Cleared
  • Freelance Information Security Architect with 25+ years of experience in designing and implementing enterprise-grade security solutions across banking, aerospace, manufacturing, pharmaceutical and technology sectors. Proven track record delivering Zero Trust architectures, OT security segmentation, and large-scale cloud security transformations for multinational organizations.
  • Extensive experience in security risk management, IT/OT architecture, secure remote access, and Zero Trust, with strong stakeholder engagement at technical and executive levels.
  • Successfully delivered global security programs including Zscaler deployments to 35,000+ endpoints, OT network segmentation using the Purdue Model, and enterprise security modernization initiatives.
  • Available for remote contract roles (across Germany and Nordic regions mainly).


Key Achievements

  • Conducted enterprise-wide risk assessments and mitigation programs
  • Led global Zscaler deployment to 35,000+ endpoints across multinational enterprise environments
  • Designed and implemented Zero Trust architecture across multi-country environments
  • Delivered OT segmentation architectures aligned to Purdue Model standards
  • Implemented secure remote access solutions for multi-site OT environments
  • Supported security modernization programs following major cyber incident recovery


Core Competencies

  • Information Security Architecture (IT & OT)
  • Zero Trust Architecture (ZTNA)
  • Security Risk Management
  • Threat Modeling
  • Security Governance & Compliance
  • Cloud Security (Azure / AWS)
  • Network Security Architecture
  • Secure Remote Access
  • API Security & Automation
  • OT Security & Industrial Networks


Technology Stack

Security Platforms:

  • Zscaler (ZIA, ZPA, ZDX)
  • Fortinet
  • Cisco ASA
  • Check Point


Cloud & Identity:

  • Azure
  • AWS
  • Microsoft Entra ID
  • OAuth 2.0


Governance & Compliance:

  • ISO 27001
  • NIST
  • PCI-DSS
  • GDPR
  • NIS2


Architecture:

  • Zero Trust
  • Purdue Model
  • IT/OT Security

Datenkommunikation

VPN
SD-WAN
Segmentation

Branchen

Branchen

  • Banking
  • Financial Services
  • Pharmaceutical
  • Aerospace
  • Manufacturing
  • Human Resources
  • Technology and Communications
  • Network Security
  • Cybersecurity
  • IT Consulting

Einsatzorte

Einsatzorte

Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

11 months
2025-06 - 2026-04

Risk management, architecture and governance consulting

Global Information Security Consultant Risikomanagement
Global Information Security Consultant

Provided security risk management, architecture and governance consulting within enterprise IT & OT environments, supporting regulatory compliance and risk mitigation strategies.

  • Conducted security risk assessments across enterprise software and infrastructure systems
  • Developed risk mitigation strategies aligned with corporate security policies
  • Supported regulatory compliance and governance activities
  • Delivered security reporting and recommendations to senior stakeholders


Achievements
  • Successfully mitigated every security risk assigned, preventing them from escalating to the Security Board for acceptance
  • Supported adoption of emerging security practices related to AI technologies
Risikomanagement
EVOTEC SE
remote
1 year 3 months
2024-04 - 2025-06

Designed and implemented network security standards

Network Security Service Owner / Network Security Architect IT-Sicherheitsarchitektur
Network Security Service Owner / Network Security Architect

Designed and implemented network security standards, best security practices and Zero Trust.

  • Owned and governed enterprise-wide network security services, ensuring alignment with corporate security standards and Zero Trust principles across IT and OT environments.
  • Reviewed and approved security architectures, firewall changes, external connectivity, and secure remote access solutions (Zscaler ZPA, IPSec VPN), reducing exposure to unauthorized access.
  • Led and contributed to key security transformation initiatives, including FortiGate deployments, firewall segmentation, policy standardization, and iDMZ design.
  • Drove the adoption of Zero Trust architecture by evaluating and integrating modern security solutions, improving overall security posture and access control maturity.
  • Acted as a central decision authority for secure connectivity (suppliers, remote access, privileged access), balancing risk mitigation with business enablement.
  • Collaborated with global stakeholders across IT and OT to enhance plant and enterprise security while supporting digitalization initiatives.


Achievements
  • Strengthened segmentation and access control across IT/OT environments through standardized firewall policies and Zero Trust design.
  • Improved operational efficiency and security governance by streamlining Zscaler policies and remote OT connectivity.
Zscaler Fortinet
IT-Sicherheitsarchitektur
KNAUF INFORMATION SERVICES
remote
8 months
2023-05 - 2023-12

Implemented API-driven automation between Zscaler and ServiceNow

Solutions Specialist ? Zscaler API & Automation Consultant Solution Architect
Solutions Specialist ? Zscaler API & Automation Consultant

Provided consultancy on the secure integration and automation between Zscaler and ServiceNow.

  • Designed and implemented API-driven automation between Zscaler and ServiceNow using Azure API Management, enabling scalable and consistent security workflows.
  • Optimized Zscaler (ZIA/ZPA) configurations by applying best practices, improving performance, policy consistency, and security effectiveness.
  • Produced detailed technical documentation, architecture diagrams, and process flows to support automation and operational handover.
  • Collaborated with cross-functional teams to deliver end-to-end integration and ensure successful testing and deployment.
  • Provided technical guidance and stakeholder presentations, translating complex implementations into business-relevant outcomes.


Achievements
  • Delivered a fully integrated automation solution reducing manual intervention in Zscaler-ServiceNow processes.
  • Enhanced visibility and control over security workflows through structured API integration.
Zscaler ServiceNow
Solution Architect
SANDVIK
remote
1 year 6 months
2021-07 - 2022-12

Implemented cloud-based network security solutions based on Zscaler

Network Security Engineer / Zscaler Design & Implementation Engineer Solution Architect
Network Security Engineer / Zscaler Design & Implementation Engineer

Designed and implemented cloud-based network security solutions based on Zscaler, on a large scale.

  • Designed and implemented Zscaler-based cloud security architecture across multiple countries, supporting the organization?s transition to a Zero Trust model.
  • Led large-scale deployment of Zscaler Client Connector to 7,000+ users across 10 countries, enabling secure, cloud-based internet access.
  • Migrated traffic from legacy on-premise proxy infrastructure (Blue Coat) to cloud-native security solutions, improving scalability and user experience.
  • Developed PAC files, deployment strategies, and migration plans ensuring minimal disruption during rollout.
  • Provided post-deployment support and continuous optimization, ensuring service stability and user adoption.
  • Worked within Agile/Scrum teams to deliver iterative improvements aligned with business and security goals.


Achievements
  • Successfully executed a multi-country rollout impacting thousands of users with minimal disruption.
  • Accelerated Zero Trust adoption and improved user experience through cloud-first security architecture.
Zscaler
Solution Architect
Nationale-Nederlanden
remote
1 year
2020-03 - 2021-02

Implementation of cloud-based proxy security architecture

Network Security Engineer Solution Architect
Network Security Engineer

Delivered global implementation of cloud-based proxy security architecture following a major cyber incident.

  • Implemented Zscaler SaaS proxy solution across global infrastructure
  • Configured URL filtering, SSL inspection and malware protection
  • Produced operational documentation (SOPs, FAQs)
  • Supported incident resolution and user onboarding


Achievements
  • Successfully deployed secure proxy solution to 35,000+ devices globally
  • Contributed to enterprise security recovery following cyber incident
  • Trained SOC teams on how to deal with specific incidents
  • Improved global visibility into web traffic and threat activity
Zscaler
Solution Architect
EUROFINS
remote
1 year 9 months
2017-10 - 2019-06

Risk management

Security Problem Manager Risikomanagement
Security Problem Manager

Provided security risk management for DB, as part of the CISO team.

  • Led proactive security problem management within the CISO function, focusing on root cause analysis and long-term remediation of security issues.
  • Drove the identification and mitigation of systemic vulnerabilities, reducing recurrence of incidents across the IT environment.
  • Managed and tracked security issues (SIIs) in alignment with Operational Risk Management frameworks, ensuring regulatory and internal compliance.
  • Coordinated cross-functional efforts with Threat Intelligence, Incident Response, Red Team, and business units to address complex security challenges.
  • Delivered reporting and insights to stakeholders, improving visibility into security risks and remediation progress.


Achievements
  • Reduced repeat security incidents by enforcing structured root cause analysis and remediation processes.
  • Strengthened collaboration between security, risk, and business teams, improving overall risk posture and governance.
Risikomanagement
Deutsche Bank
Eschborn, Taunus
1 year 1 month
2016-03 - 2017-03

Migrations and security architecture design

Security Architect IT-Sicherheitsarchitektur
Security Architect
Delivered Fortinet migrations and security architecture design for global enterprise customers; performed SD-WAN hub and spoke configurations.
Fortinet Cisco ASA
IT-Sicherheitsarchitektur
Orange Cyberdefense
Brussels
7 months
2015-06 - 2015-12

Implemented enterprise security governance and incident management

Security Architect IT-Sicherheitsarchitektur
Security Architect

IT-Sicherheitsarchitektur
Adecco
Lyon
1 year 4 months
2013-07 - 2014-10

FortiGate firewalls

Security Consultant Solution Architect
Security Consultant
Deployed 80+ FortiGate firewalls across production environments to secure the Airbus A350 aircraft production plants.
Fortinet Check Point
Solution Architect
Airbus
Toulouse

Aus- und Weiterbildung

Aus- und Weiterbildung

11 years 11 months
2014-08 - now

CISSP (Certified Information Systems Security Professional)

ISC2
ISC2
Information Security
13 years 2 months
2013-05 - now

FCNSP (Fortinet Certified Network Security Professional)

Fortinet
Fortinet
Fortinet products
15 years 2 months
2011-05 - now

ITIL Foundation

PeopleCert
PeopleCert
IT Service Management
16 years 1 month
2010-06 - now

CWNA (Certified Wireless Network Administrator)

CWNP
CWNP
Wireless networking
6 years 1 month
2009-04 - 2015-04

CCNP (Cisco Certified Network Professional)

Cisco
Cisco
Cisco routing and switching, security

Position

Position

Senior Security Architect (IT/OT) | Zero Trust | Risk Management Specialist | Security Consultant

Kompetenzen

Kompetenzen

Top-Skills

IT-Sicherheitsarchitektur Risikomanagement Solution Architect Zero Trust OT Security IT-Security Zscaler GRC

Schwerpunkte

security architecture
Experte
zero trust
Experte
risk management
Experte
IT security
Experte
OT security
Fortgeschritten
cloud security
Fortgeschritten

Produkte / Standards / Erfahrungen / Methoden

Profile

  • Senior Information Security Architect (IT/OT) | CISSP | Zero Trust & Risk Management Specialist | SC Cleared
  • Freelance Information Security Architect with 25+ years of experience in designing and implementing enterprise-grade security solutions across banking, aerospace, manufacturing, pharmaceutical and technology sectors. Proven track record delivering Zero Trust architectures, OT security segmentation, and large-scale cloud security transformations for multinational organizations.
  • Extensive experience in security risk management, IT/OT architecture, secure remote access, and Zero Trust, with strong stakeholder engagement at technical and executive levels.
  • Successfully delivered global security programs including Zscaler deployments to 35,000+ endpoints, OT network segmentation using the Purdue Model, and enterprise security modernization initiatives.
  • Available for remote contract roles (across Germany and Nordic regions mainly).


Key Achievements

  • Conducted enterprise-wide risk assessments and mitigation programs
  • Led global Zscaler deployment to 35,000+ endpoints across multinational enterprise environments
  • Designed and implemented Zero Trust architecture across multi-country environments
  • Delivered OT segmentation architectures aligned to Purdue Model standards
  • Implemented secure remote access solutions for multi-site OT environments
  • Supported security modernization programs following major cyber incident recovery


Core Competencies

  • Information Security Architecture (IT & OT)
  • Zero Trust Architecture (ZTNA)
  • Security Risk Management
  • Threat Modeling
  • Security Governance & Compliance
  • Cloud Security (Azure / AWS)
  • Network Security Architecture
  • Secure Remote Access
  • API Security & Automation
  • OT Security & Industrial Networks


Technology Stack

Security Platforms:

  • Zscaler (ZIA, ZPA, ZDX)
  • Fortinet
  • Cisco ASA
  • Check Point


Cloud & Identity:

  • Azure
  • AWS
  • Microsoft Entra ID
  • OAuth 2.0


Governance & Compliance:

  • ISO 27001
  • NIST
  • PCI-DSS
  • GDPR
  • NIS2


Architecture:

  • Zero Trust
  • Purdue Model
  • IT/OT Security

Datenkommunikation

VPN
SD-WAN
Segmentation

Branchen

Branchen

  • Banking
  • Financial Services
  • Pharmaceutical
  • Aerospace
  • Manufacturing
  • Human Resources
  • Technology and Communications
  • Network Security
  • Cybersecurity
  • IT Consulting

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.