Fachlicher Schwerpunkt dieses Freiberuflers

Fach- und Führungskraft IT-Security-Management, Interim- und Projektmanagement

Available from
Nov 1, 2019
Availability
100 %
on customer site
100 %
Areas

D4

D5

D6

All others

Cities
Köln
150 km
Contact Settings

I prefer getting offers for these sites. However, you may also contact me for interesting projects in other places.

Position

Comment

Interim and project management in the areas of IT, information and cyber security for the entire life cycle of IT infrastructures and applications.

Projects

10/2017 - Today

2 years

various projects

Roles
Head of IT Security Management
Tasks

Projects

  • Definition, initiation and control of the strategic IT Security initiatives as well as ensuring their operational implementation. Initiatives currently under implementation in detail:
    • Secure IT Architectures
    • Secure Software Development Lifecycle
    • Situational Awareness (in particular establishment of an "IT Security Operations Center" as a Managed Service)
  • Initiation and roll-out of a Security Education & Awareness program, including crisis management exercises for senior management.

Responsibilities

  • Establishment and disciplinary management of the IT Security Management team.
  • Definition and implementation of the IT Security Management strategy.
  • Design, implementation and optimization as well as European coordination and harmonization of IT Security Management.

03/2015 - 01/2017

1 year 11 months

various projects

Roles
Head of IT Security Management
Tasks
  • Definition, initiation and control of the strategic IT security initiatives as well as ensuring their operational implementation. Initiatives in detail:
    • Secure IT Architectures
    • Identity Governance & Management
    • Secure Software Development Lifecycle
    • Situational Awareness (in particular establishment of an "IT Security Operations Center" as a Managed Service)
    • IT Supply Chain Management
  • A freely available, rough overview of these initiatives as well as to my person can be found here
  • Establishing international co-operation, including the harmonization and consolidation of relevant IT solution components
  • Definition and establishment of the organizational and procedural interfaces to Information Security functions within RWE.
  • Sub-project management for the topic of "Security Governance, Risk & Compliance" (consisting of data protection, information security and IT security management) as part of the sale of RWE IT’s data centers and the transfer of their operation to an Indian IT service provider
  • Involvement in the preparation of the strategy paper "IT Security for NRW 4.0" within the corresponding work group of the Ministry of Innovation, Science and Research of the State of NRW.

Responsibilities

  • Professional and disciplinary management of the IT Security
    Management team (6 FTEs)
  • Restructuring and further development of the IT Security Management function within the CIO Office of RWE IT GmbH
  • Design, implementation and optimization as well as transnational coordination and harmonization of IT security management
  • Representation of IT Security within RWE IT towards the management and the operational units as well as towards RWE’s Group Security, internal customers and external parties
  • Establishment and support of national and international research and development co-operations with universities located in NRW on the subject of IT Security

04/2006 - 02/2015

8 years 11 months

various projects

Roles
IT Security Manager
Tasks

Projects (Examples)

  • Definition of IT security guidelines and IT architecture requirements as well as their implementation. Examples:
    • Restructuring the RWE Corporate Network to establish IT security domains
    • Use and integration of cloud services (IaaS, PaaS, SaaS)
    • Use and integration of mobile devices
  • Establishment of the Group’s Corporate IT Security Center (process blocks: Incident Prevention & Handling, Technical Monitoring & Reporting, Standardization & Audit)
  • Strategic introduction of vulnerability management and intrusion prevention systems
  • Deputy overall project management for the transfer of all TSO (Amprion GmbH) IT systems and IT services to a new IT service provider to meet legal unbundling requirements as well as sub-project management for IT security, including the specification of a new IT security policy for the TSO
  • Consulting and support of RWE Power in the development and implementation of an IT security strategy for process control systems of lignite-, coal- and gas-fired plants
  • Consulting and support of RWE Power in the implementation of legal and/or official IT security requirements and regulations for nuclear power plants

Responsibilities

  • Responsibility for IT Security within Group IT Governance
  • Representation of IT Governance in the international bodies for IT Architecture Management

Skills

Products / Standards / Experiences

IT Security Consulting

  • Penetration testing

IT Security Management

  • Team Management
  • Transition Management (including overall project management)
  • IT Security Governance
  • Specification of IT security policies, standards, and requirements
  • Specification of IT security architectures
  • Specification and implementation of Group wide IT security management processes
  • Management of the implementation of IT security policies, standards, requirements, and architectures in infrastructure projects
  • Management of IT security assessments and audits
  • Management of IT service providers


IT Security Research

  • Dissertation on intrusion detection for communication networks


IT Security Teaching

  • Lecturing, Talks


IT Security Training

  • Training on penetration testing


Software Development

  • Development of commercial business software
  • Development of research prototypes

Employment History

10/2017 - today

Head of IT Security Management (Europe)

Aioi Nissay Dowa Insurance Europe, Niederlassung Deutschland, Ismaning, Germany

02/2017 - 09/2017
IT Security Manager (in transition)

RWE IT GmbH/innogy SE, Essen, Germany

03/2015 - 01/2017
Head of IT Security Management, CIO Office

RWE IT GmbH, Essen, Germany

06/2008 - 02/2015
“Hauptreferent”/“Referent mit besonderen Aufgaben”, IT Governance

RWE IT GmbH, Essen, Germany

04/2006 - 05/2008
“Hauptreferent”, Group Corporate Information Office

RWE AG, Essen, Germany

10/2001 - 03/2006
Expert/Specialist (national and international), IT Security Networks and Platforms
T-Mobile Deutschland GmbH, Bonn, Germany

07/2000 - 09/2001
IT Security consultant

AixCom e.V., Aachen, Germany

01/1996 - 09/2001 

Research assistant, Chair of Computer Science 4 (Communication and Distributed Systems)

RWTH Aachen University, Germany

11/1995 - 12/1995
Graduate assistant, Chair of Computer Science 4 (Communication and Distributed Systems)

RWTH Aachen University, Aachen, Germany

06/1994 - 04/1995
Student assistant, Chair of Computer Science 4 (Communication and Distributed Systems)

RWTH Aachen University, Aachen, Germany

07/1992 - 09/1995
Student assistant

GPS Prof. Schuh Komplexitätsmanagement GmbH, Herzogenrath, Germany


Language Skills
Dutch
Basic
English
Fluent (oral and written)
German
Native speaker

Comments

Awards and Publications on request


Training History

07/2004 - 04/2008
Member of the executive committee of the special interest group “Security - Intrusion Detection and Response” (SIDAR) of the German Informatics Society (GI)

05/2001

Doctoral degree (“Dr. rer. nat”) in Computer Science

10/1989 - 10/1995
Studies in Computer Science (Informatik)

RWTH Aachen University, Germany, Graduation with the Diploma degree "Dipl.-Inform."

07/1988 - 09/1989
Military service

08/1979 - 05/1988
Liebfrauenschule Mülhausen, Grefrath

Abitur (German university entrance qualification)

Certifications

11/2011

"COBIT Practitioner" Certification

ISACA Germany Chapter e. V., Certificate ID: CP-111111

08/2012

(ISC)2 CISSP Certification

×
×