Cyber Security Professional mit mehreren Jahren Erfahrungen speziell in den Bereichen Digitale Forensik, Incident Response und Threat Hunting.
Aktualisiert am 12.03.2026
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 12.03.2026
Verfügbar zu: 100%
davon vor Ort: 100%
Incident Management
IT-Forensik
IT-Security
German
Muttersprache
English
fluent

Einsatzorte

Einsatzorte

Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

3 Monate
2026-01 - heute

Managing a company for digital forensic and incident response investigations

Managing Director
Managing Director
on request Frankfurt, Germany
2 Jahre
2024-01 - 2025-12

Investigation lead of DFIR projects

Manager | Cyber Defense
Manager | Cyber Defense

  • Investigation lead of DFIR projects (e.g. ransomware, data theft, social engineering, malicious insider threat, intellectual property theft) and IT-Security projects (e.g., Incident and Forensic Readiness) 
  • Assessing IT-security risks and improving processes and procedures 
  • C-level advisor for cyber defense strategies 
  • Conference speaker related to cyber security topics 
  • Mentoring team members and supporting their careers 
  • Developing and conducting incident response readiness workshops 


Achievements:

  • Gaining more visibility (e.g., detections, alerts) within the IT-infrastructure of banks, insurance and manufacturing companies by adjusting monitoring tools and IT-security procedures
  • Optimized project margins from 45% up to 65% by implementing self-made project managing template for budget tracking 

Deloitte GmbH WPG Frankfurt, Germany
6 Monate
2023-07 - 2023-12

Detection Engineering

Senior Associate | Incident Response
Senior Associate | Incident Response

  • Detection Engineering for several endpoint solutions to improve alerting mechanisms in SIEM/SOC tools
  • Conducting IR activities within cloud environments Azure, GCP and AWS 


Achievements:

Development of service portfolio for detecting malicious activity related to cyber espionage by implementing use case rules within SIEM software 

PwC LLP UK London, UK
2 Jahre 3 Monate
2021-10 - 2023-12

Investigation work stream lead of several DFIR projects

Senior Associate | Incident Response
Senior Associate | Incident Response

  • Investigation work stream lead of several DFIR projects (e.g. ransomware, data theft, social engineering, malicious insider threat, intellectual property theft) 
  • Conduction of threat hunting and IR activities using several software tools Palo Alto XDR, Cybereason, Tanium, Carbon Black, Windows Defender for Endpoint/Identity 
  • Conducting IR activities within cloud environments Azure, GCP and AWS 
  • Digital forensic data acquisition and data analysis of computer systems (Windows, Linux and macOS) and mobile devices (iOS, Android) 
  • Digital forensic data acquisition and data analysis of log files from different sources (e.g., firewall, proxy, antivirus, NetFlow, DNS, DHCP) 
  • Documentation of investigation findings and preparation of forensic reports (aligning them to standards MITRE and NIST) 
  • Monitoring of the project progress, e.g. project financials, client update meetings 
  • Developing and conducting workshops related to cyber security topics (cyber readiness, social engineering, etc.) 
  • Supporting the clients with remediation and recovery measures after cyber security incidents 
  • Mentoring junior team members in DFIR technologies and career coaching 


Achievements:

Developed and implemented forensic analysis tools in Python for optimizing analysis duration. The duration of analysis process was reduced by half. 

PwC GmbH WPG Frankfurt, Germany
1 Jahr 9 Monate
2020-01 - 2021-09

Digital forensic data acquisition

Associate | Incident Response
Associate | Incident Response

  • Digital forensic data acquisition and data analysis of computer systems (Windows, Linux and macOS) 
  • Digital forensic data acquisition and data analysis of log files from different sources (e.g., firewall, proxy, antivirus, NetFlow) 
  • Documentation of investigation findings and preparation of forensic reports 
  • Review of incident management processes and development of improvement measures 

Ernst & Young GmbH WPG Frankfurt, Germany
8 Monate
2019-03 - 2019-10

Development and implementation of correlation searches

SOC Analyst
SOC Analyst
  • Development and implementation of correlation searches and use cases within the SOC architecture 
  • Development of SOAR and EDR playbooks 
  • Monitoring and responding to security alerts 
Heraeus infosystems GmbH Hanau, Germany

Aus- und Weiterbildung

Aus- und Weiterbildung

2 Jahre 3 Monate
2019-11 - 2022-01

M.Eng. IT-Security & Digital Forensics

Hochschule Wismar
Hochschule Wismar
4 Jahre 1 Monat
2015-10 - 2019-10

B.Sc. Business Information Systems

Technische Hochschule Mittelhessen
Technische Hochschule Mittelhessen

Kompetenzen

Kompetenzen

Top-Skills

Incident Management IT-Forensik IT-Security

Produkte / Standards / Erfahrungen / Methoden

SKILLS

Technology - DF

EnCase, X-Ways, Magnet AXIOM, Cellebrite, Autopsy, KAPE, EZ-Tools, Zeek, Wireshark, Arkime, SIFT, VeraKey/Graykey, FTK-Imager 


Technology ? SOC

TANIUM, Palo Alto XDR, Windows Defender for Endpoint/Identity, Cybereason, Carbon Black, YARA, Loki IoC, Sigma,Velociraptor, Google SecOps, Demisto, Splunk, SOF-ELK, SentinelOne 


Technology ? Other

Python, Java, Windows PowerShell, SQL, Linux, VMware ESXI


Project Management

Budgeting, Roling Forecasts, Margin Optimizations

Einsatzorte

Einsatzorte

Deutschland, Schweiz, Österreich
möglich

Projekte

Projekte

3 Monate
2026-01 - heute

Managing a company for digital forensic and incident response investigations

Managing Director
Managing Director
on request Frankfurt, Germany
2 Jahre
2024-01 - 2025-12

Investigation lead of DFIR projects

Manager | Cyber Defense
Manager | Cyber Defense

  • Investigation lead of DFIR projects (e.g. ransomware, data theft, social engineering, malicious insider threat, intellectual property theft) and IT-Security projects (e.g., Incident and Forensic Readiness) 
  • Assessing IT-security risks and improving processes and procedures 
  • C-level advisor for cyber defense strategies 
  • Conference speaker related to cyber security topics 
  • Mentoring team members and supporting their careers 
  • Developing and conducting incident response readiness workshops 


Achievements:

  • Gaining more visibility (e.g., detections, alerts) within the IT-infrastructure of banks, insurance and manufacturing companies by adjusting monitoring tools and IT-security procedures
  • Optimized project margins from 45% up to 65% by implementing self-made project managing template for budget tracking 

Deloitte GmbH WPG Frankfurt, Germany
6 Monate
2023-07 - 2023-12

Detection Engineering

Senior Associate | Incident Response
Senior Associate | Incident Response

  • Detection Engineering for several endpoint solutions to improve alerting mechanisms in SIEM/SOC tools
  • Conducting IR activities within cloud environments Azure, GCP and AWS 


Achievements:

Development of service portfolio for detecting malicious activity related to cyber espionage by implementing use case rules within SIEM software 

PwC LLP UK London, UK
2 Jahre 3 Monate
2021-10 - 2023-12

Investigation work stream lead of several DFIR projects

Senior Associate | Incident Response
Senior Associate | Incident Response

  • Investigation work stream lead of several DFIR projects (e.g. ransomware, data theft, social engineering, malicious insider threat, intellectual property theft) 
  • Conduction of threat hunting and IR activities using several software tools Palo Alto XDR, Cybereason, Tanium, Carbon Black, Windows Defender for Endpoint/Identity 
  • Conducting IR activities within cloud environments Azure, GCP and AWS 
  • Digital forensic data acquisition and data analysis of computer systems (Windows, Linux and macOS) and mobile devices (iOS, Android) 
  • Digital forensic data acquisition and data analysis of log files from different sources (e.g., firewall, proxy, antivirus, NetFlow, DNS, DHCP) 
  • Documentation of investigation findings and preparation of forensic reports (aligning them to standards MITRE and NIST) 
  • Monitoring of the project progress, e.g. project financials, client update meetings 
  • Developing and conducting workshops related to cyber security topics (cyber readiness, social engineering, etc.) 
  • Supporting the clients with remediation and recovery measures after cyber security incidents 
  • Mentoring junior team members in DFIR technologies and career coaching 


Achievements:

Developed and implemented forensic analysis tools in Python for optimizing analysis duration. The duration of analysis process was reduced by half. 

PwC GmbH WPG Frankfurt, Germany
1 Jahr 9 Monate
2020-01 - 2021-09

Digital forensic data acquisition

Associate | Incident Response
Associate | Incident Response

  • Digital forensic data acquisition and data analysis of computer systems (Windows, Linux and macOS) 
  • Digital forensic data acquisition and data analysis of log files from different sources (e.g., firewall, proxy, antivirus, NetFlow) 
  • Documentation of investigation findings and preparation of forensic reports 
  • Review of incident management processes and development of improvement measures 

Ernst & Young GmbH WPG Frankfurt, Germany
8 Monate
2019-03 - 2019-10

Development and implementation of correlation searches

SOC Analyst
SOC Analyst
  • Development and implementation of correlation searches and use cases within the SOC architecture 
  • Development of SOAR and EDR playbooks 
  • Monitoring and responding to security alerts 
Heraeus infosystems GmbH Hanau, Germany

Aus- und Weiterbildung

Aus- und Weiterbildung

2 Jahre 3 Monate
2019-11 - 2022-01

M.Eng. IT-Security & Digital Forensics

Hochschule Wismar
Hochschule Wismar
4 Jahre 1 Monat
2015-10 - 2019-10

B.Sc. Business Information Systems

Technische Hochschule Mittelhessen
Technische Hochschule Mittelhessen

Kompetenzen

Kompetenzen

Top-Skills

Incident Management IT-Forensik IT-Security

Produkte / Standards / Erfahrungen / Methoden

SKILLS

Technology - DF

EnCase, X-Ways, Magnet AXIOM, Cellebrite, Autopsy, KAPE, EZ-Tools, Zeek, Wireshark, Arkime, SIFT, VeraKey/Graykey, FTK-Imager 


Technology ? SOC

TANIUM, Palo Alto XDR, Windows Defender for Endpoint/Identity, Cybereason, Carbon Black, YARA, Loki IoC, Sigma,Velociraptor, Google SecOps, Demisto, Splunk, SOF-ELK, SentinelOne 


Technology ? Other

Python, Java, Windows PowerShell, SQL, Linux, VMware ESXI


Project Management

Budgeting, Roling Forecasts, Margin Optimizations

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.