Provide intermediate consulting in an ongoing IT security architecture project
Document the project progress so far and plan the next steps
Apply and implement the BSI IT Baseline Protection
Develop and maintain security management systems
Apply the ISO 27001 standard series
Integrate ITIL processes into security architectures
Collaborate with government clients, regulatory authorities, and internal and external service providers
Document the status
Jul 2024 - Dec 2024
6 months
Security Consultant
Provide security consulting, planning, review, and documentation for a large Europe-wide network (VS-NfD, KRITIS)
Provide technical advice in the network area, migration planning, segmentation, IP harmonization
Support the regular operation of the security infrastructure based on BSI C5 / BSI 200-2
Focus on SIEM/SOC platform with creation of use cases and playbooks
Identify, plan, and independently implement projects to update or improve the security infrastructure
Active technical project management and leadership of internal teams
Ensure compliance with VS-NfD, VSA (classified information directive), and VSV requirements
Jan 2023 - Apr 2024
1 year 4 months
Security PM/Consultant
Provide consulting, planning, and hands-on project management for a closed on-premises high-security network (BSI, VS-NfD, VSA)
ITSCM focusing on SOC, SIEM, ISMS/KRITIS in the OT/IoT area
Provide technical advice in the network and data center areas, supporting the regular operation of security infrastructure and LAN/WAN
Develop use cases and playbooks in Splunk
Independently implement data center security infrastructure projects
Perform architecture and development work in Windows and Linux environments; RHEL OpenShift updates
Plan and review network segmentation and extend LAN/WLAN environments
Review and update HPE/Aruba switching platforms and gateways, implement and troubleshoot
Roll out EDR, encrypt removable media with DriveLock; handle email security (DLP), introduce/update Proofpoint
Update Splunk, manage SharePoint projects, report to C-level and board of directors
Plan budgets, propose improvements or new security measures
Lead the entire IT security department, all teams, vendors, and service providers
Ensure compliance with VS-NfD, VSA, VSV; BSI C5; develop and continuously update Genua VPN architecture
Client name protected
Sep 2022 - Jan 2023
5 months
Senior Network IT Security Engineer
Advise on the architecture of an on-premises hospital network
Renew the network according to the B3S security standard
Plan and secure infrastructure services (DNS, DHCP, RDP)
Advise on security regulations in the healthcare sector
Deploy a SIEM and SOC platform
Provide consulting for tendering and implementation
Plan and actively manage a closed high-security network
Jan 2022 - Aug 2022
8 months
Project Manager Network Architecture
On-premises network: design, concept, and implementation of a complete rebuild of a third-party connection platform and data diode for several thousand users (VS-NfD, up to NATO security level)
Integrate Deep Security Enterprise solutions (Opswat, Infodas SDoT)
Document IoT/OT and perform vulnerability analysis
Deploy IAM/PAM/LDAP in the government network under BSI KRITIS requirements
Integrate thin clients, SINA, terminal services, ReCoBS in a VS-NfD environment
Gather requirements and run PoC/PoV for data diode and connections; evaluate and consolidate requirements, and prepare cost estimates
Conduct Splunk SOC requirements gathering, create use cases and playbooks
Develop scripts (PowerShell, VBS, Batch), use Ansible
Design architecture in a government environment according to ISMS – BSI 200-2; BCM-GRC with HiScout Suite
Ensure compliance with VSA, EU/NATO/MISSION requirements; BSI C5
Technically implement solutions for over 2000 users
Provide audited project documentation and training workshops
Preparation of a new blockchain-based security platform (PAM/IAM/SIEM/SOC/SOAR) with Wazuh as a complete package for internal and external entities in Singapore/Southeast Asia
Leading the sales team, technical training, and pitch development
Acquisition of potential customers outside the company group
Commercial and technical support; head of technical pre-sales team
Architecture and custom concepts; proposal creation tailored to customer infrastructures
Support for rollout, commissioning, and operations phase
Creating full documentation and handing it over to internal sales
Technologies: IAM/IDM/PAM on blockchain technology, SOC, SIEM
Apr 2020 - Oct 2020
7 months
Cloud Management Platform Architect/Head of Development
SecureScrypt Pte. Ltd.
Development of a cloud management platform with a payment gateway for SaaS sales; government project in Asia with the SecureScrypt team
Architecture of a private cloud with no connection to public cloud services
Development of the payment gateway SentosaXchange for marketplace transactions
Using an ERP/SCM platform to provide cloud services; SEPA-enabled gateway
Preparing for future blockchain services
Introduction of Splunk as a security platform (SOC use cases and playbooks)
Consideration of Magnet, Nuix, Griffeye, X-Ways
Integration of IAM and PAM (SaaS) on the platform
Requirements: NIST, Docker, Linux, Red Hat, ISO17789, IAM, PAM, SaaS, cloud systems, cloud management, regional catalogs
Cloud security in enterprise networks; staff training; documentation
Public sector: PM and technical consultant for on-premises network, integrator of a complete EPM/IAM/PAM/PSM/Vault system with onboarding of about 64 AWS units (military environment)
Building a new system with security gateways, HSM, DDI, IAM, PKI, ITSCM; implementation of BSI/BMWi requirements, NATO level
Integration of the existing SOC with customization of use cases and playbooks; rollout of DriveLock Endpoint Security
Design of BTU structure in data centers
Migration from BeyondTrust to CyberArk REST API; RHEL OpenShift installation/integration/administration
Migration of CyberArk 10.x to 11.x in test/dev/production environments without downtime; redundant architecture; onboarding/migration of 64 business units
Developer and interface review, support with scripting; full documentation
Jan 2020 - Dec 2023
4 years
Blockchain Security Engineer/Architect
SecureScrypt Pte. Ltd.
Development of a blockchain security framework with encryption using QKD (Quantum Key Distribution) over fiber between two data centers
High-security development for financial applications in Asia
Teamwork within SecureScrypt; project under high confidentiality
Apr 2019 - Oct 2019
7 months
Lead Project Manager/Consultant – Cyber Security (Automotive)
Led three subprojects on cybersecurity in embedded automotive platforms (VWFS environment)
Design, development and implementation of a Europe-wide security system for the ECB in the 4CB network (Deutsche Bundesbank, Central Banks of Italy, Spain, France) with central SIEM/SOC integration
Integration/adjustment to BAIT and MaRisk; HiScout GRC within the BSI baseline protection framework
Set up test system with sandbox (Cuckoo); build 4-region network with ECB integration
Certifications according to BSI 200-2, ISO 27001/27002; preparation for cloud migration (Azure/AWS); PoC, governance, readiness, strategy, onboarding; technical implementation; final documentation
Nov 2017 - Oct 2018
1 year
Global Project Manager (Telco Industry)
Led three subprojects in the telco industry: audit of all systems/services; architecture, planning and integration of a global DLP, ATP, EDR, anti-DDoS system across networks/clouds
Implementation of ISMS, SIEM with SOC; preparation for cloud migration; agile approach; Splunk for all subprojects/platforms
O365 cloud DLP, EDR, anti-DDoS; GDPR/EUGDPR, ISO 27001/27002-compliant security concept
Implementation of OMADA IAM for cloud; pen tests in enterprise environment; HLD governance; new risk management framework
Maintenance/implementation of new tools (Symantec, Check Point); SOC use cases and playbooks; reports; training internal resources; vendor/system integrator management
System updates to the latest security technology; presentations on risk management/cybersecurity
Marketing management; customer consulting/analysis; solution proposals for sales/marketing
Jan 2005 - Jan 2009
4 years 1 month
Hong Kong
Telecommunications and IT Networks – Support and Services
PIC Pte. Ltd.
Leadership of 200 technical staff in Hong Kong, China, South America
Management of branches and contractors; staff training/instruction
Designing new IT security and network solutions; design/implementation of complex IP/VoIP systems for service providers and enterprises
Frequent travel; IT risk management, analysis, presentations, training
Special training for investment bank IT staff (risk management, 4 months)
Interim CTO Electronic Developments – Lintux Hong Kong Ltd.: acquiring new customers, coordination with Chinese factories, staff training, development of IP systems
SVP Goldtron Group Singapore Pte. Ltd.: leading the development team in Singapore; coordination with Hong Kong; design of MXI platform (mobile/VoIP services); installation of the first VoIP network in Malaysia; portfolio management software
Developer Taitoma Group – Taipei – Taiwan: software/hardware development and design; project management methods; IT security and risk mitigation; quality control for large projects in APAC/Greater China; technologies: Java, SQL, Python, Cobol, C++
Jan 2000 - Dec 2000
1 year
Hong Kong
VP/IT – Head of Asia-Pacific Group
Credit Suisse First Boston
Member of the Hong Kong Global Engineering and Infrastructure Support Team
Responsible for communication between technical teams and helpdesk groups worldwide
Analysis of existing networks and identification of security risks; development of new risk solutions
Developing solutions for existing networks; migrating legacy systems to Windows
Technologies: Microsoft Windows
Electrical Customer Service / Office Administration / Team Leadership
Professional internship after graduation: electrical customer service, office administration, team leadership
Education: TU Darmstadt (electrical engineering, electronics, mathematics, physics); Dipl.-Ing. – Philipp Reitz Polytechnic Frankfurt; leadership, business studies, marketing
Master Electrician certificate: apprenticeship, journeyman, master exam in Wiesbaden
High school diploma from Humanistisches Gymnasium Wiesbaden (GPA 1.1): mathematics, English
Distance learning in USA – PhD Telecommunication
Senior Systems Engineer (Engineering – 5G Radio Networks)
Network planning and implementation for clients including Bank of America, Deutsche Bank, BSI Machinery Germany, Indonesian Government, Thai Farmers Bank, Hoechst Chemicals Taiwan/Thailand, Anderson Singapore, SAP Germany
Experience in the financial sector, chemical industry, and other fields
Planning of 5G mobile networks and security aspects according to 3GPP; billing systems for Inmarsat; uplink/downlink interfaces to LANs
Planning/installation of terminal server networks for a Swiss banking group to improve slow connections and reduce costs; upgrading older PCs/laptops to NT/W2000/XP
Experience with packet protocol (basis of later GSM mobile phone systems); installation/implementation
Special projects: sales/installation of nationwide UHF communication networks (precursors of today's mobile communication) in the Middle East and Asia
Development/manufacture of UHF components; development of the first 'cell phones' (ETACS, AMPS)
Experience with A-network car phones; development of the first satellite phone in a briefcase; encryption of mobile devices
Hong Kong
Senior Consultant
Merrill Lynch International Inc.
Network migrations and setup of IP network
Development of investment applications for stock market monitoring
Complete systems: installation and implementation
Migration from Novell to Windows and Transaction Server
Service, training of local engineers; system analysis; telecom connectivity; routers (3Com, Transcend, Cisco)
TCP/IP, DHCP, WINS, Ethernet; trusted relationships with networks in the USA and Europe
Integration of NT 4 with BLITZ (SQL/Excel-based pricing model and trend manager for portfolio trading)
Development of new applications (position calculator, IROS, Pagepool) for equities, bonds and portfolio trading
Creating numerous Excel macros with live feeds (Reuters, Bloomberg, exchange channel) and custom applications; pioneer of IP-based TV
Installation of applications for buying/selling, messaging/notification for individual stocks/bonds/portfolios (RAM Excel, RAM Add-Ins, Newport, Loan Manager, Bond Manager, IORS, K-Tek, PDD, DDE)
Implementation of initial security regulations for banks in the investment business
Contract Engineer
PIC International Hong Kong
Development and design of software and hardware as outsourced services from Asian manufacturers
Long-term deployment for project implementations in Iraq, Lebanon, Syria, Saudi Arabia and other countries (installation of complete radio communication networks)
Complete systems: installation and implementation
Development of the first encrypted satellite phone for a German group, later used in public service and on ships
Distance learning at Princeton University, USA, earning a PhD
Pathcom Inc. / Minthorne International Inc. / Pathcom Ltd.
Development of CB and UHF radio systems; worldwide customer support
Monitoring manufacturing in the USA and Japan
Development of the first open CB radio system; first FTZ approval in Darmstadt; established CB radio standards
Technology development for new data communication products in the USA and Yokohama, Japan; manufacturing control and instruction
Development of the first Asian-made radio synthesizer, VHF/UHF transceiver and bundle mobile phone; system development and manufacturing of Pathcom communication products
Summary
More than 30 years working as a technical PM/IT Engineer, Analyst, Architect.
Languages
German
Native
English
Native
Spanish
Elementary
Chinese
Elementary
Education
Lorem ipsum dolor sit amet
Master in Electrical Engineering · Electrical Engineering