Supporting transition from ISO 27001:2017 to ISO 27001:2022
Security analyses and controls
Developing security concepts
Conducting internal audits
Apr 2023 - Present
2 years 4 months
Lead Auditor
Würth IT GmbH und PÜG Prüf- und Überwachungsgesellschaft mbH
Conducting external audits
Audits at energy providers
Audits in the banking sector
Audits in software development
Jan 2023 - Present
2 years 7 months
Bietigheim-Bissingen, Germany
Data Protection Officer
Automotive Supplier
Data protection consulting
Creating data protection impact assessments
Maintaining and updating processing records
Revising privacy statements
Handling data protection incidents
Conducting data protection training
Mar 2021 - Oct 2021
8 months
Stuttgart, Germany
Consultant
Automaker
IT security management / IT compliance
Security and compliance requirements in the digital workplace product development process
IT security management
Security analyses and controls
Identifying and minimizing security and compliance risks
Developing security concepts
Jul 2020 - Jun 2024
4 years
Berlin, Germany
Consultant
Telecommunications Company
Implementing NIS 2 Directive (01/24 – 06/24)
Applying NIS 2 Directive
Implementing measures to prevent and contain cybersecurity incidents
Responding to security incidents
Adjusting risk management for AI systems, cybersecurity
Documentation and containment strategies
Incident reporting
Risk analysis and security for information systems
Maintaining and restoring backup and crisis management
IT security, BSI IT baseline protection (07/20 – 12/23)
Conducting baseline protection checks
Performing risk analyses
Documenting security processes
Participating in training management (training and awareness)
Supporting digital radio BOS / BDBOS subprojects
Assessing information security for digital radio BOS
Developing and maintaining security concepts for digital radio BOS
Creating information security policies for digital radio BOS
Feb 2020 - Dec 2020
11 months
Munich, Germany
Consultant
Munich Re
Data protection consultant
Processor contracts (reviewing existing contracts, checking if a processor agreement is needed for departments, drafting processor agreements, negotiating with partners, etc.)
Advising on data protection issues
Creating and reviewing processing records
Conducting data protection impact assessments
Data protection review for launching a knowledge platform