Cybersecurity Innovation Consultant | KI-gestützte Cybersicherheit | IAM & PAM | Security by Design für Cloud & moderne DevSecOps-Umgebungen
Aktualisiert am 20.02.2026
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 05.02.2026
Verfügbar zu: 100%
davon vor Ort: 10%
Cloud
Access Management
AI Security
IAM
DevSecOps
Awareness
Managementberatung
Beratung
Projektmanagement
Stakeholdermanagement
Enterprise Architect
SAFe
Scrum Master
Agile Softwareentwicklung
TISAX
IT-Grundschutz
DSGVO
Security by Design
German
native
English
fluent
Spanish
A1
French
A2

Einsatzorte

Einsatzorte

Deutschland, Schweiz, Österreich
Weltweit einsetzbar
möglich

Projekte

Projekte

8 Monate
2025-08 - heute

Ensuring ISO 27001 and NIS-2 compliance

CISO (external)
CISO (external)
  • Ensured ISO 27001 and NIS-2 compliance while establishing an AI Governance framework and secure SaaS integration within the Microsoft 365 workspace
  • Led enterprise-wide cybersecurity operations and incident management, reducing audit findings to zero.
  • Focus areas: ISO 27001, NIS-2, AI Governance, Information Security Management System (ISMS), Risk Management, SaaS Security, Compliance, Artificial Intelligence
Joint Venture International Insurance, Hamburg
1 Jahr 2 Monate
2025-02 - heute

Teaching assignment

Lecturer on AI in Cybersecurity
Lecturer on AI in Cybersecurity
  • Delivering lectures and hands-on workshops on AI in Cybersecurity, covering AI opportunities, limitations and security implications.
  • Focus on AI risk management and secure AI implementation for corporate environments.
  • Focus areas: Artificial Intelligence, Cybersecurity, AI Governance, Risk Management, Secure AI, Awareness, Compliance, ISO 42001, EU AI Act
bitkom Akademie, Berlin
3 Monate
2025-06 - 2025-08

Cybersecurity

CISO (external)
CISO (external)
  • Assessed enterprise-wide cybersecurity posture and implemented NIS-2?aligned controls and countermeasures.
  • Planned the establishment of a dedicated Cybersecurity Department and ensured the secure deployment of AI technologies.
  • Focus areas: NIS-2, ISO 27001, AI Governance, ISMS, Risk Management, Identity Management, Compliance, Information Security, Artificial Intelligence
Multinational Renewable Energy Supplier, Berlin
1 Jahr 4 Monate
2024-05 - 2025-08

Development and cost modeling of managed cloud solutions

Interim Cybersecurity Architect
Interim Cybersecurity Architect
  • Designed and cost-modelled managed cybersecurity cloud solutions ensuring ISO 27001-compliant architectures and scalable security operations.
  • Defined SIEM/SOC frameworks and network security standards to strengthen risk and identity management.
  • Focus areas: ISO 27001, Cloud Security, ISMS, SIEM, SOC, Risk Management, Identity Management, Compliance, Networks, Cybersecurity
Global Cloud Service Provider, Frankfurt
10 Monate
2024-07 - 2025-04

PMO for E-Invoicing

Programm Lead
Programm Lead
PMO as a technical intermediate layer between development teams and
management.
 
3 Monate
2024-10 - 2024-12

Implementation of cybersecurity policies, controls and processes

ISO (external)
ISO (external)
  • Assessed and implemented cybersecurity policies, controls and processes to ensure NIS-2 compliance and strengthen ISMS maturity.
  • Evaluated company-wide AI usage for security and cost-efficiency to support responsible AI adoption.
  • Focus areas: NIS-2, AI Governance, ISMS, Information Security, Risk Management, Compliance, Artificial Intelligence, Identity Management, Incident Management
Multinational Food Supplier, Berlin
1 Jahr 3 Monate
2023-10 - 2024-12

SECURITY ARCHITECTURE

SUBJECT MATTER EXPERT
SUBJECT MATTER EXPERT

SME for Security Architecture in the SAFe landscape performing analyses of security status on ART level and development of security architecture artefacts on Capability, Large Solution and Platform level including:

  • Analysis of the DevSecOps process in all ARTs of a digitalization department
  • Identification of decision points for security issues in the DevSecOps process
  • Analysis of the decision levels in the SAFe framework (products, ARTs, solution, portfolio)
  • Analysis of decision-making bodies and participants
  • Alignment of architecture and security artefacts on all levels
  • Analysis of overlaps between architecture and security artefacts
  • Identification of decision points for Architecture topics
  • Analysis of decision levels in the SAFe framework (products, ARTs, solution, portfolio).
  • Analysis and linking to the Domain Model / Architecture Target Landscape
  • Depiction of the dependencies between architecture and IT security
  • Development of security guidelines for architecture, etc.
  • Creation of result and management presentations

GLOBAL AUTOMOTIVE MANUFACTURER
STUTTGART
7 Monate
2024-01 - 2024-07

Identity & Access Management

Project Manager for IAM & PAM
Project Manager for IAM & PAM
  • Managed implementation of advanced Identity & Access Management (IAM, PAM) solutions with MFA and SSO integration to strengthen enterprise access security.
  • Aligned access governance and ISMS controls to ensure compliance and reduce identity-related risks.
  • Focus areas: IAM, PAM, SSO, MFA, Access Management, Identity Management, ISMS, Risk Management, Cybersecurity, Compliance
Global Automotive Supplier, Lausanne
1 Jahr 4 Monate
2023-04 - 2024-07

Coordinated cybersecurity initiatives

ISO (external) Access Management Vulnerability Incident Management ...
ISO (external)
  • Coordinated cybersecurity initiatives for cloud-based products, performing risk assessments and enforcing secure coding practices (OWASP) across development teams.
  • Supported ISO 27001 compliance and improved vulnerability and incident management integration within the ISMS.
  • Focus areas: ISO 27001, ISMS, OWASP, Risk Management, Vulnerability Management, Incident Management, Compliance, Secure Development, Cybersecurity
Access Management Vulnerability Incident Management Patchmanagement Stakeholdermanagement Solution Enabler OWASP Secure coding Atlassian JIRA Atlassian Confluence Git
Global Automotive Manufacturer, Stuttgart
10 Monate
2022-09 - 2023-06

GDPR Taskforce Lead

GDPR TASKFORCE LEAD
GDPR TASKFORCE LEAD

Lead GDPR taskforce by coordinating teams, preparing and conducting workshops, preparing management decisions and providing checklists and best practices to teams including:

  • Analysis of existing material and guidelines from central security
  • Gap analysis
  • Design and conduction of management workshops to raise awareness for GDPR
  • Set up of a roadmap to be compliant with GDPR requirements before Go-Live
  • Design and conduction of workshops on product level to asses GDPR status, clarify open questions, definition of next steps and clarification of (shared) responsibilities
  • Creation of documentation blueprints and steps to perform to be able to fulfill:
    • RoPA
    • TOM
    • Retention periods
    • Technical requirements
    • Data Subject Rights
    • ?Deletion ?concept
  • Analysis of created documentation from products, processing of results, support with steering team discussions and escalation processes

GLOBAL AUTOMOTIVE MANUFACTURER
Stuttgart
1 Jahr 6 Monate
2022-01 - 2023-06

Design and implementation of a security strategy

Cybersecurity Program Manager
Cybersecurity Program Manager
  • Implemented an enterprise-wide cybersecurity strategy and security guardrails for a large-scale digital transformation project.
  • Drove stakeholder engagement and aligned security controls to ensure program-wide compliance and secure development.
  • Focus areas: Cybersecurity Strategy, ISMS, Security Guardrails, Risk Management, Compliance, Vulnerability Management, Incident Management, SSDLC, Stakeholder Management
Global Automotive Manufacturer, Stuttgart
9 Monate
2022-03 - 2022-11

Development and implementation of an ISMS

TISAX IMPLEMENTER ISO 27001
TISAX IMPLEMENTER

Development and implementation of an ISMS in accordance with TISAX requirements including:

  • Assessment of security Status and documentation
  • Gapanalysis
  • Processing of TISAX requirements and derivation of necessary Steps
  • Analysis and editing of security policies
  • Implementation of an ISMS in Organization
  • Creation of processes and documentation
  • Readiness assessment
  • Audit support

ISO 27001
Internal
Hamburg
7 Monate
2021-10 - 2022-04

Projectmanagement

PROJECT MANAGER IN SCIENCE
PROJECT MANAGER IN SCIENCE

Scrum project manager in science for following projects:

  • Smart city project to detect traffic jams and accidents automatically with AI
  • Smart railway project to improve time forecast for trains
  • Internal railway infrastructure project to replace old and hardcoded codebase with object-oriented programming language and dynamic frontend

TU Darmstadt
11 Monate
2020-12 - 2021-10

Implementation of Cyberark as PAM solution software

Technical consultant Privileged Access Management
Technical consultant

Implementation and adaptation of the CyberArk solution tothe existing infrastructure to secure privileged access (PAM) including:

  • Creation and management of all accounts, safes & platforms of the acceptance environment via PVWA as well as Rest API
  • Administration of CyberArk servers on infrastructure & OS level
  • Execution of technical acceptance tests
  • Monitoring of infrastructure components
  • Documentation of processes, components & platforms
  • PAM integration in existing SIEM solution

cyberark
Privileged Access Management
GLOBAL COMMERICAL BANK
Frankfurt

Aus- und Weiterbildung

Aus- und Weiterbildung

2 Jahre 10 Monate
2019-10 - 2022-07

Study - Computer Science/ Cybersecurity

M.Sc., TU Darmstadt
M.Sc.
TU Darmstadt

Master thesis on request

3 Jahre 2 Monate
2016-10 - 2019-11

Applied Computer Science

Bachelor of Science, HTW des Saarlandes
Bachelor of Science
HTW des Saarlandes

Bachelor thesis: on request

Position

Position

CYBERSECURITY & AI GOVERNANCE CONSULTANT

Kompetenzen

Kompetenzen

Top-Skills

Cloud Access Management AI Security IAM DevSecOps Awareness Managementberatung Beratung Projektmanagement Stakeholdermanagement Enterprise Architect SAFe Scrum Master Agile Softwareentwicklung TISAX IT-Grundschutz DSGVO Security by Design

Schwerpunkte

Security Strategy & Goverance
Awareness & Communication
Identity & Trust
Cloud Security
Leadership & Project Management

Produkte / Standards / Erfahrungen / Methoden

Profile

Cybersecurity & AI Governance Consultant with 8+ years of experience bridging technology and business. Former software developer, now designing and implementing ISO 27001, NIS-2 and AI Governance frameworks for enterprise clients that want to build security rather than paper tigers.

WHY WORK WITH ME
With me, you get an independent cybersecurity advisor focused on building secure, compliant and pragmatic solutions always aligned with your business goals.


TECHNOLOGIES

  • Microsoft PowerPoint
  • Microsoft Excel
  • AWS
  • SharePoint
  • Confluence
  • CyberArk
  • SailPoint
  • Jira
  • Docker
  • Angular
  • CitHub
  • Maven
  • Java
  • Python
  • XML
  • Azure ADDS/AAD
  • Typescript
  • BlackDuck
  • SecHub
  • SonarOube
  • Prisma
  • Harbor
  • Backstage. io
  • Okta

SKILLS
  • Governance & Compliance
    • ISO 27001, NIS2, TISAX, ISMS, AIMS, Cybersecurity & AI Governance, Risk Management, Compliance, Data Privacy (GDPR)
  • Cloud & Architecture
    • Cloud Security, SaaS Security, DevSecOps, Security by Design, SSDLC, OWASP, SIEM/SOC
  • Awareness & Processes
    • Cybersecurity Awareness, Incident Management, Asset Management, Identity & Access Management (IAM, PAM)
  • Methods & Soft Skills
    • Agile Project Management (Scrum, SAFe), Leadership, Trusted Advisor, Innovation

WORKING EXPERIENCE
09/2022 - today
EXTERNAL LECTURER AND SCIENTIFIC CONTACT
DHBW MANNHEIM

01/2022 - 07/2024
SENIOR CYBERSECURITY CONSULTANT
ERANEOS CYBERSECURITY GMBH, HAMBURG

11/2020 - 11/2021
CYBERSECURITY CONSULTANT
GCON GMBH, MUNICH

11/2020 - 11/2021
Identity Management Administrator
KOGIT GmbH, Darmstadt

Branchen

Branchen

  • Automotive
  • Financial Services

Einsatzorte

Einsatzorte

Deutschland, Schweiz, Österreich
Weltweit einsetzbar
möglich

Projekte

Projekte

8 Monate
2025-08 - heute

Ensuring ISO 27001 and NIS-2 compliance

CISO (external)
CISO (external)
  • Ensured ISO 27001 and NIS-2 compliance while establishing an AI Governance framework and secure SaaS integration within the Microsoft 365 workspace
  • Led enterprise-wide cybersecurity operations and incident management, reducing audit findings to zero.
  • Focus areas: ISO 27001, NIS-2, AI Governance, Information Security Management System (ISMS), Risk Management, SaaS Security, Compliance, Artificial Intelligence
Joint Venture International Insurance, Hamburg
1 Jahr 2 Monate
2025-02 - heute

Teaching assignment

Lecturer on AI in Cybersecurity
Lecturer on AI in Cybersecurity
  • Delivering lectures and hands-on workshops on AI in Cybersecurity, covering AI opportunities, limitations and security implications.
  • Focus on AI risk management and secure AI implementation for corporate environments.
  • Focus areas: Artificial Intelligence, Cybersecurity, AI Governance, Risk Management, Secure AI, Awareness, Compliance, ISO 42001, EU AI Act
bitkom Akademie, Berlin
3 Monate
2025-06 - 2025-08

Cybersecurity

CISO (external)
CISO (external)
  • Assessed enterprise-wide cybersecurity posture and implemented NIS-2?aligned controls and countermeasures.
  • Planned the establishment of a dedicated Cybersecurity Department and ensured the secure deployment of AI technologies.
  • Focus areas: NIS-2, ISO 27001, AI Governance, ISMS, Risk Management, Identity Management, Compliance, Information Security, Artificial Intelligence
Multinational Renewable Energy Supplier, Berlin
1 Jahr 4 Monate
2024-05 - 2025-08

Development and cost modeling of managed cloud solutions

Interim Cybersecurity Architect
Interim Cybersecurity Architect
  • Designed and cost-modelled managed cybersecurity cloud solutions ensuring ISO 27001-compliant architectures and scalable security operations.
  • Defined SIEM/SOC frameworks and network security standards to strengthen risk and identity management.
  • Focus areas: ISO 27001, Cloud Security, ISMS, SIEM, SOC, Risk Management, Identity Management, Compliance, Networks, Cybersecurity
Global Cloud Service Provider, Frankfurt
10 Monate
2024-07 - 2025-04

PMO for E-Invoicing

Programm Lead
Programm Lead
PMO as a technical intermediate layer between development teams and
management.
 
3 Monate
2024-10 - 2024-12

Implementation of cybersecurity policies, controls and processes

ISO (external)
ISO (external)
  • Assessed and implemented cybersecurity policies, controls and processes to ensure NIS-2 compliance and strengthen ISMS maturity.
  • Evaluated company-wide AI usage for security and cost-efficiency to support responsible AI adoption.
  • Focus areas: NIS-2, AI Governance, ISMS, Information Security, Risk Management, Compliance, Artificial Intelligence, Identity Management, Incident Management
Multinational Food Supplier, Berlin
1 Jahr 3 Monate
2023-10 - 2024-12

SECURITY ARCHITECTURE

SUBJECT MATTER EXPERT
SUBJECT MATTER EXPERT

SME for Security Architecture in the SAFe landscape performing analyses of security status on ART level and development of security architecture artefacts on Capability, Large Solution and Platform level including:

  • Analysis of the DevSecOps process in all ARTs of a digitalization department
  • Identification of decision points for security issues in the DevSecOps process
  • Analysis of the decision levels in the SAFe framework (products, ARTs, solution, portfolio)
  • Analysis of decision-making bodies and participants
  • Alignment of architecture and security artefacts on all levels
  • Analysis of overlaps between architecture and security artefacts
  • Identification of decision points for Architecture topics
  • Analysis of decision levels in the SAFe framework (products, ARTs, solution, portfolio).
  • Analysis and linking to the Domain Model / Architecture Target Landscape
  • Depiction of the dependencies between architecture and IT security
  • Development of security guidelines for architecture, etc.
  • Creation of result and management presentations

GLOBAL AUTOMOTIVE MANUFACTURER
STUTTGART
7 Monate
2024-01 - 2024-07

Identity & Access Management

Project Manager for IAM & PAM
Project Manager for IAM & PAM
  • Managed implementation of advanced Identity & Access Management (IAM, PAM) solutions with MFA and SSO integration to strengthen enterprise access security.
  • Aligned access governance and ISMS controls to ensure compliance and reduce identity-related risks.
  • Focus areas: IAM, PAM, SSO, MFA, Access Management, Identity Management, ISMS, Risk Management, Cybersecurity, Compliance
Global Automotive Supplier, Lausanne
1 Jahr 4 Monate
2023-04 - 2024-07

Coordinated cybersecurity initiatives

ISO (external) Access Management Vulnerability Incident Management ...
ISO (external)
  • Coordinated cybersecurity initiatives for cloud-based products, performing risk assessments and enforcing secure coding practices (OWASP) across development teams.
  • Supported ISO 27001 compliance and improved vulnerability and incident management integration within the ISMS.
  • Focus areas: ISO 27001, ISMS, OWASP, Risk Management, Vulnerability Management, Incident Management, Compliance, Secure Development, Cybersecurity
Access Management Vulnerability Incident Management Patchmanagement Stakeholdermanagement Solution Enabler OWASP Secure coding Atlassian JIRA Atlassian Confluence Git
Global Automotive Manufacturer, Stuttgart
10 Monate
2022-09 - 2023-06

GDPR Taskforce Lead

GDPR TASKFORCE LEAD
GDPR TASKFORCE LEAD

Lead GDPR taskforce by coordinating teams, preparing and conducting workshops, preparing management decisions and providing checklists and best practices to teams including:

  • Analysis of existing material and guidelines from central security
  • Gap analysis
  • Design and conduction of management workshops to raise awareness for GDPR
  • Set up of a roadmap to be compliant with GDPR requirements before Go-Live
  • Design and conduction of workshops on product level to asses GDPR status, clarify open questions, definition of next steps and clarification of (shared) responsibilities
  • Creation of documentation blueprints and steps to perform to be able to fulfill:
    • RoPA
    • TOM
    • Retention periods
    • Technical requirements
    • Data Subject Rights
    • ?Deletion ?concept
  • Analysis of created documentation from products, processing of results, support with steering team discussions and escalation processes

GLOBAL AUTOMOTIVE MANUFACTURER
Stuttgart
1 Jahr 6 Monate
2022-01 - 2023-06

Design and implementation of a security strategy

Cybersecurity Program Manager
Cybersecurity Program Manager
  • Implemented an enterprise-wide cybersecurity strategy and security guardrails for a large-scale digital transformation project.
  • Drove stakeholder engagement and aligned security controls to ensure program-wide compliance and secure development.
  • Focus areas: Cybersecurity Strategy, ISMS, Security Guardrails, Risk Management, Compliance, Vulnerability Management, Incident Management, SSDLC, Stakeholder Management
Global Automotive Manufacturer, Stuttgart
9 Monate
2022-03 - 2022-11

Development and implementation of an ISMS

TISAX IMPLEMENTER ISO 27001
TISAX IMPLEMENTER

Development and implementation of an ISMS in accordance with TISAX requirements including:

  • Assessment of security Status and documentation
  • Gapanalysis
  • Processing of TISAX requirements and derivation of necessary Steps
  • Analysis and editing of security policies
  • Implementation of an ISMS in Organization
  • Creation of processes and documentation
  • Readiness assessment
  • Audit support

ISO 27001
Internal
Hamburg
7 Monate
2021-10 - 2022-04

Projectmanagement

PROJECT MANAGER IN SCIENCE
PROJECT MANAGER IN SCIENCE

Scrum project manager in science for following projects:

  • Smart city project to detect traffic jams and accidents automatically with AI
  • Smart railway project to improve time forecast for trains
  • Internal railway infrastructure project to replace old and hardcoded codebase with object-oriented programming language and dynamic frontend

TU Darmstadt
11 Monate
2020-12 - 2021-10

Implementation of Cyberark as PAM solution software

Technical consultant Privileged Access Management
Technical consultant

Implementation and adaptation of the CyberArk solution tothe existing infrastructure to secure privileged access (PAM) including:

  • Creation and management of all accounts, safes & platforms of the acceptance environment via PVWA as well as Rest API
  • Administration of CyberArk servers on infrastructure & OS level
  • Execution of technical acceptance tests
  • Monitoring of infrastructure components
  • Documentation of processes, components & platforms
  • PAM integration in existing SIEM solution

cyberark
Privileged Access Management
GLOBAL COMMERICAL BANK
Frankfurt

Aus- und Weiterbildung

Aus- und Weiterbildung

2 Jahre 10 Monate
2019-10 - 2022-07

Study - Computer Science/ Cybersecurity

M.Sc., TU Darmstadt
M.Sc.
TU Darmstadt

Master thesis on request

3 Jahre 2 Monate
2016-10 - 2019-11

Applied Computer Science

Bachelor of Science, HTW des Saarlandes
Bachelor of Science
HTW des Saarlandes

Bachelor thesis: on request

Position

Position

CYBERSECURITY & AI GOVERNANCE CONSULTANT

Kompetenzen

Kompetenzen

Top-Skills

Cloud Access Management AI Security IAM DevSecOps Awareness Managementberatung Beratung Projektmanagement Stakeholdermanagement Enterprise Architect SAFe Scrum Master Agile Softwareentwicklung TISAX IT-Grundschutz DSGVO Security by Design

Schwerpunkte

Security Strategy & Goverance
Awareness & Communication
Identity & Trust
Cloud Security
Leadership & Project Management

Produkte / Standards / Erfahrungen / Methoden

Profile

Cybersecurity & AI Governance Consultant with 8+ years of experience bridging technology and business. Former software developer, now designing and implementing ISO 27001, NIS-2 and AI Governance frameworks for enterprise clients that want to build security rather than paper tigers.

WHY WORK WITH ME
With me, you get an independent cybersecurity advisor focused on building secure, compliant and pragmatic solutions always aligned with your business goals.


TECHNOLOGIES

  • Microsoft PowerPoint
  • Microsoft Excel
  • AWS
  • SharePoint
  • Confluence
  • CyberArk
  • SailPoint
  • Jira
  • Docker
  • Angular
  • CitHub
  • Maven
  • Java
  • Python
  • XML
  • Azure ADDS/AAD
  • Typescript
  • BlackDuck
  • SecHub
  • SonarOube
  • Prisma
  • Harbor
  • Backstage. io
  • Okta

SKILLS
  • Governance & Compliance
    • ISO 27001, NIS2, TISAX, ISMS, AIMS, Cybersecurity & AI Governance, Risk Management, Compliance, Data Privacy (GDPR)
  • Cloud & Architecture
    • Cloud Security, SaaS Security, DevSecOps, Security by Design, SSDLC, OWASP, SIEM/SOC
  • Awareness & Processes
    • Cybersecurity Awareness, Incident Management, Asset Management, Identity & Access Management (IAM, PAM)
  • Methods & Soft Skills
    • Agile Project Management (Scrum, SAFe), Leadership, Trusted Advisor, Innovation

WORKING EXPERIENCE
09/2022 - today
EXTERNAL LECTURER AND SCIENTIFIC CONTACT
DHBW MANNHEIM

01/2022 - 07/2024
SENIOR CYBERSECURITY CONSULTANT
ERANEOS CYBERSECURITY GMBH, HAMBURG

11/2020 - 11/2021
CYBERSECURITY CONSULTANT
GCON GMBH, MUNICH

11/2020 - 11/2021
Identity Management Administrator
KOGIT GmbH, Darmstadt

Branchen

Branchen

  • Automotive
  • Financial Services

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.