Alexander S.

Lead Audit Conformity & IT-SiKat

Bayreuth, Germany

Experience

Jan 2025 - Dec 2025
1 year

Lead Audit Conformity & IT-SiKat

DAX Group Energy Supply in the Renewable Energy Sector

  • Support in implementing the requirements of Section 8a of the BSI Act for critical infrastructures.
  • Systematic preparation and management of internal and external audits, addressing previous deviations (HA, NA, VP).
  • Implementation of the specific requirements of the IT security catalog.
  • Development of training, creation of run books, and conducting assessments to ensure operational effectiveness.
Jan 2025 - Dec 2025
1 year

External Information Security Officer

E-commerce and Closed-Loop Provider

  • Conducting risk analyses and vulnerability assessments
  • Supporting the implementation of an information security management system (ISMS) as a basis for meeting the criteria under the Digital Operational Resilience Act (DORA)
  • Preparing software development for the requirements of the Cyber Resilience Act (CRA)
  • Establishing a management system for vulnerabilities and security threats
Jan 2025 - Dec 2025
1 year

Lead of the Log Collection, Extraction & Aggregation Workstream for Enabling a SIEM according to SzA

Critical Infrastructure in International Energy Supply

  • Implementation of a centralized log management system to meet KRITIS requirements in energy supply
  • Responsibility as workstream lead for collecting, extracting, and aggregating log data from selected power plants
  • Installation and configuration of security components such as the genua Cyber-Diode and SYSLOG to ensure logging
Jan 2025 - Dec 2025
1 year

Consulting on the Strategic Implementation of the Cyber Resilience Act

Mechanical Engineering

  • Inventory and gap analysis according to IEC 62443
  • Development of action recommendations to ensure CRA compliance
Jan 2024 - Dec 2025
2 years

Project Consulting in the Field of Innovation

International Mobility Provider

  • Horizon scan: designing a trend analysis for IT emergency management using prelead
Jan 2024 - Dec 2025
2 years

Project consulting on security concept and NIS2 compliance

Water utility

  • Advising on the implementation of NIS2 and network segmentation in a KRITIS-relevant environment
  • Developing a security concept for a technical monitoring system, including early warning logic, considering hybrid IT environments
  • Creating concepts and action plans to meet security requirements under ISO 27001 and BSI IT-Grundschutz
Jan 2023 - Dec 2024
2 years

Project Manager for establishing a cybersecurity program

DAX-listed energy company

  • Taking responsibility for setting up the project and managing delivery through to the finish line
  • Analyzing program and project challenges and risks
  • Defining an effective approach
  • Restructuring and mobilizing colleagues and partner staff
  • Supporting the newly organized cybersecurity department on its path to the next level of operational maturity (e.g., evolving into a customer-focused, standardized, and sustainable organization)
Jan 2022 - Dec 2025
4 years

Lead for standards and regulatory requirements in cybersecurity

DAX-listed machinery and plant engineering group

Lead for a DAX-listed company and the largest industrial manufacturer in Europe. Responsible for certification and vendor self-certification under IEC 62443-4-2 and GDPR.

  • Analyzing, aggregating, and assessing the regulatory impacts of the EU Cyber Resilience Act (CRA), EU AI Act, EU Data Act, and NIS2
  • Developing a preparation and implementation plan and executing the necessary steps to achieve compliance
  • Managing stakeholder relations and coordinating with external auditors
  • Representing the company in industry-specific internal and external committees
Jan 2022 - Dec 2025
4 years

§8a KRITIS audit support

International mobility provider

Audit support for the world's second-largest transport company. Evaluated and completed the information security policies and documentation framework for IDW and BSI audit standards.

  • Supporting the 2nd line of defense in building and operating an information security management system (ISMS) according to ISO 27001
  • Creating and maintaining policies, processes, and other governance documents (e.g., work instructions and manuals)
  • Contributing to the information security strategy
  • Assisting with information security risk management
  • Implementing measures to eliminate/mitigate information security risks and deficiencies
  • Preparing for the next §8a audit cycle (2023)
  • Coordinating with business units to identify KRITIS-relevant assets
  • Creating a scoping document for KRITIS-relevant assets
  • Collecting and preparing evidence
Jan 2022 - Dec 2023
2 years

Project consulting for "ISALIP – Information Security Awareness, Literacy and Privacy"

Research project

The project aimed to improve European citizens' readiness for the digital age. It addressed individual awareness of information security, related skills, and risk management in professional and private contexts.

  • Building a network of experts from partner countries and at the European level
  • Providing project consulting to define requirements, training and qualification profiles, and content topics in the field of cybersecurity
Jan 2021 - Dec 2022
2 years
Germany

Development and implementation of BSI IT-Grundschutz projects

State Administration

Development and implementation of multiple BSI IT-Grundschutz projects for state ministries in North Rhine-Westphalia and for federal agencies.

Jan 2021 - Dec 2022
2 years

Implementation of the BSI IT-Grundschutz

Public Sector

Implementation of the BSI IT-Grundschutz within a joint, coordinated maritime security control center.

Jan 2020 - Dec 2022
3 years

Manager with signatory authority

Big4 Consulting

  • Project manager for the introduction and maintenance of a quality management system according to ISO 9001 for consulting, auditing, and training in information security, risk management, data protection, and BCM
  • Transition manager for the transition of a 120-person team
  • Key expert for OT security and general advisor on technical aspects of cybersecurity in the energy sector and other industries
Jan 2020 - Dec 2022
3 years

Project manager for the technical implementation of a cybersecurity program in the OT area

DAX-Listed Chemical Industry Group

Technical implementation of a cybersecurity program for OT environments at the company's global sites.

  • Network scanning
  • Vulnerability management
  • Access management
  • Endpoint protection
  • Asset management
  • Awareness and tactical alignment of further measures to develop the cybersecurity maturity level
Jan 2020 - Dec 2022
3 years

Lead for data protection assessments as part of the Microsoft Supplier Security and Privacy Assurance (SSPA) program

Digital Company

Jan 2020 - Dec 2022
3 years

Technical Lead for the Implementation of ISO 27001

Mechanical Engineering

Technical Lead for the implementation of ISO 27001 at a former DAX-listed company in precision mechanical engineering and a global leading manufacturer of sheet-fed offset printing presses.

Jan 2017 - Dec 2020
4 years

Information Security Officer (ISO)

International TSO

  • Support in requirements engineering and the technical implementation for the document management system OneDMS
  • Management of organizational change to develop a cybersecurity interface (policy development, implementation of technical requirements, awareness training, ticket management, support for business projects regarding cybersecurity aspects and requirements)
  • Management of internal and external audits as well as supplier audits according to ISO 27001, ISO 27002 and ISO 27019 (based on the IT security catalog)
  • Support of the CISO, assessing protection needs and monitoring cybersecurity aspects for IT and OT
Jan 2017 - Dec 2018
2 years

Senior Consultant

Consulting Firm

  • Implementation of ISMS and GDPR-based PMS in subsidiaries of a consulting firm (500+ employees), consultant for ISO 27001-based ISMS and GDPR
Jan 2017 - Dec 2018
2 years

Project Lead

Research & Development

  • Study on 'ISMS in the Energy Sector 2018'
  • In-house implementation of GDPR and ITIL-oriented services
Jan 2017 - Dec 2018
2 years

Senior Consultant

Real Estate Startup

  • Implementation of an ISMS according to ISO 27001 in a real estate management company
Jan 2017 - Dec 2018
2 years

Senior Consultant

Municipal Utility and Transport Company

  • Supported the Group CISO in the areas of governance, processes and awareness, incident management, strategic management, and technical issues in the energy sector
Jan 2015 - Dec 2017
3 years
Bayreuth, Germany

Postdoc

University of Bayreuth, Chair of Innovation & Marketing

  • Industry study on "ISMS in the energy sector" with Energieforen Leipzig
  • Public study on the EU regulation for digital content consumer protection (Bavarian State Ministry for the Environment and Consumer Protection)
Jan 2009 - Dec 2017
9 years
Cottbus, Germany

PhD Candidate

Brandenburg University of Technology Cottbus, Chair of Marketing and Innovation Management

  • Study on location management to close vacancies in industrial parks in the Lusatia energy region, commissioned by Vattenfall Europe Generation AG and the Lusatia-Spreewald Energy Region
  • Market analysis of the Bavarian, Brandenburg, and Saxon tourism markets to derive suitable market entry strategies
  • Fundraising for the event marking 20 years of Brandenburg University of Technology Cottbus
  • Lectures on eBusiness, International Marketing, and market-oriented product development
Jan 2009 - Dec 2015
7 years

Innovation Lead

IHP GmbH – Innovation for High-Performance Microelectronics

  • Innovation management in the project "Enhanced Security for Critical Infrastructures" and project lead for research and development in information security in critical infrastructures (KRITIS) for "Security in Sensor Networks"
  • Requirements engineering with IC-104, PROFINET, Profibus, and other fieldbus communications to prepare for implementation in IDS/IPS
  • Drafted several research proposals on 5G for tactile internet applications, information security architecture in future automotive developments, communication protocols and real-time requirements for information security in industrial applications
  • Various workshops with BSI, BMI, BBK on UP-KRITIS, LÜKEX, and KRITIS
Jan 2007 - Dec 2009
3 years

Technical Associate

Fraunhofer Application Center for Logistics Management ALI and Information Systems

Part of the Fraunhofer Institute for Material Flow and Logistics IML.

  • Implementation of real-time location systems in complex industrial environments with ubisense
  • Assessment of physical security at Sheremetyevo Cargo Airport, Moscow, Russia
  • User support for the Fraunhofer Public Key Infrastructure
  • Application development for a digital patient history for online and offline use by emergency services using .NET/C#/HTML and PRINCE2 (ADAC)
  • Development and promotion of an EU-wide injury database (IDB)
  • Event management for the "Night of Creative Minds" – a science roadshow
  • Organizational and technical assistance at the related Chair of Industrial IT
Jan 2005 - Dec 2009
5 years
Cottbus, Germany

Founder

PC Help Cottbus

  • Various office IT projects for clients: websites, marketing and web design projects
  • Installation and maintenance of infrastructure and IT solutions in the tourism sector, e.g. implementation of Amadeus (Sabre) and Bistro Portal
  • Custom software development in the insurance sector
  • Various services in the field of information security

Summary

ad2b-solutions GmbH protects companies in the critical infrastructure supply chain from cyber security incidents, production outages, and personal liability cases. For this purpose, we develop, certify, and continuously improve organization-appropriate management systems based on established standards. This covers information security, handling of artificial intelligence (AI), and IT project management in general.

Under the brand prelead, innovation management in information security is methodically combined. This leads to the introduction and maintenance of information security while ensuring user-friendliness.

"Cyber Security as an Enabler" helps develop processes, optimize the overall organization, and align new projects from the start with regulatory requirements, market standards, and customer needs.

Examples of requirements for using a management system come from fields such as:

  • Cyber security according to ISO 27001, IEC 62443, and BSI IT-Grundschutz, data protection according to ISO 27001, quality management according to ISO 9001, business continuity management according to ISO 22301, risk management according to ISO 27005 and ISO 31000.
  • Project management according to PRINCE2, SCRUM, agile Stage Gate, lead user, and open innovation, as well as taking into account established ITIL processes.

By applying the practical prelead method, the right customer requirements are implemented. This avoids costly rework and missing compliance in target markets.

Languages

German
Native
English
Advanced

Education

Oct 2009 - Jun 2017

Brandenburg University of Technology Cottbus

Dr. rer. pol., The Preference-Driven Lead User Method for New Product Development · Economics, Marketing, and Innovation Management · Cottbus, Germany

Brandenburg University of Technology Cottbus

Degree Program in eBusiness, Specialization: Application and Operation of eBusiness Systems · eBusiness · Cottbus, Germany

Certifications & licenses

BSI Certified IT Basic Protection Consultant

Certified Cyber Security Auditor ISA/IEC 62443

Certified Cyber Security Professional IEC 62443 (pwc Certification Services) (CCSP) (UL)

Certified Ethical Hacking And Countermeasures (CEH) Candidate (PMMI)

Certified IT-Service Management (ITIL) (CCSA) (UL)

Certified ITIL IT-Service Management Expert

Certified Information Security Manager (CISM)

Certified Information System Security Professional (pwc Certification Services) (CISSP) (ISC2)

Certified Program Management Professional (PgMP)

Leadership at a Distance (Quadriga) and in Projects and Project Management ISO 21500 (TiBa)

Leading Across a Distance (quadriga)

Prince2 And Itil-Related Project Management (maxpert)

Quality Systems Manager By German Society For Quality (DGQ)

Certified Data Protection Officer

Certified Scrum Master (ISMF)

Certified Senior Lead Auditor ISO 27001 (PECB)

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions