Christian Decker
Managing Director and Senior Consultant
Experience
Managing Director and Senior Consultant
business-security (b-sec®) GmbH
- Conceptual consulting for securing business processes
- Consulting for the planning and implementation of IT and IT security projects
- Security and policy checks, process optimizations, emergency planning
- Project management and interim management in the area of IT infrastructure and information security
Overview of relevant projects:
- 2025: Consulting on a DLP concept for Digid GmbH.
- 2025: Consulting for a client after a cybersecurity attack that compromised the IT infrastructure and gave the attacker M365 tenant admin rights. Investigated and restored the IT infrastructure. Developed recommendations to improve IT security.
- 2025: Continued the projects mentioned below for Thyssenkrupp Marine Systems and Norddeutsche Landesbank.
- 2024: Developed a DNS concept including advice on DNS strategy and technology, DNS design, DNS security, load balancing, reverse lookup zones, and automation. Developed a DHCP concept including advice on DHCP design, a central DHCP management system, and automation. Advised on the operation of the mentioned products, on operational processes, and adapted the IT documentation and service description for Thyssenkrupp Marine Systems.
- 2024: Current state analysis and evaluation of the network and security infrastructure established by providers regarding the overall architecture, design, and components. Designed solution proposals to improve current operations for maximum performance and security and to reduce complexity. Presented results at the C-level, explaining causes and possible solutions including decision templates. Developed a SASE concept based on a zero trust architecture for Norddeutsche Landesbank.
- 2024: Continued the projects mentioned below for Atlas GmbH and Deutsche Vermögensberatung AG.
- 2023: Consulting to address findings from an IT security assessment of the IT infrastructure, carried out proof-of-concepts for DDoS protection and digital experience monitoring (DEM) with Zscaler (ZIA, ZPA & ZDX), developed a new security architecture based on zero trust, redesigned a Cisco ISE implementation, and designed a DNS security solution to protect guests and financial advisors for Atlas GmbH / Deutsche Vermögensberatung AG.
- 2023: Continued the projects mentioned below for Digid GmbH, Vaillant Group GmbH (until 09/2023), Federal Institute for Geosciences and Natural Resources (until 05/2023), and Union Investment IT-Services GmbH (until 07/2023).
- 2022: Created and reviewed whitepapers for infrastructure and security architectures, planned new network infrastructures for the German Aerospace Center.
- 2022: Concept development for the technical and procedural modernization of a disaster recovery plan for United Nations Volunteers.
- 2022: Concept development for migrating measurement data to a cloud environment, implementation of network access control, and conducted awareness training for Digid GmbH.
- 2022: Concept development for network segmentation for DZ Hyp AG.
- 2022: Concept development for network segmentation for the Federal Employment Agency.
- 2021: Concept development for a new load balancer architecture for Bundeswehr Fuhrparkservices GmbH.
- 2021: Vulnerability scan and penetration test of a web frontend including analysis and remediation recommendations considering risk and likelihood for ifi GmbH.
- 2021: Consulting, design, and sub-project management for implementing a network access control solution (certificate authentication and MAC address bypass) and macro-segmentation (area and zone concept based on dynamic device assignment) in the office and production IT for Vaillant Group GmbH.
- 2021: Upgrade and optimization of LAN and WLAN infrastructure for United Nations Volunteers.
- 2021: Developed a target concept for modernizing IT security infrastructure including the DMZ (Cisco switches, firewalls, WSA, ESA, SMA), internet connections, admin and management networks, and wireless LAN, and supported the implementation for the Federal Institute for Geosciences and Natural Resources.
- 2021: Developed a micro-segmentation concept based on Cisco DNA, SGT, and zero trust for Union Investment IT-Services GmbH.
- 2021: Reviewed and updated ISMS level 3 policies and created procedural instructions for Software AG.
- 2021: Project management for the global tech refresh project Meraki WLAN 2.0, coordinated outsourcing the LAN/WLAN infrastructure to a managed services provider, and developed a WLAN concept for automated guided vehicles at Heraeus Infosystems GmbH.
- 2021: Project management and technical support for the "Transition of SIEM/SOC Services" project for a client into a shared environment and took on the interim role of Head of Security Operations at Datagroup SE.
- 2021: Workshop for future implementation of mobile device management at Allgeier Experts Go GmbH.
- 2021: Sub-project management to introduce a firewall rule management tool and recertification of NAC endpoints based on 802.1x and MAB at Union Investment IT-Services GmbH.
- 2020: Developed a network segmentation concept for two data centers based on Cisco and VMware for Aareon AG.
- Conducted current state analysis and initiated the project.
- Developed a micro-segmentation concept for the data center and access network.
- 2020: Infrastructure and security architecture audit for Stuttgarter Versicherung AG.
- Analyzed the IT infrastructure and security architecture regarding network and security component configurations. Also reviewed contracts, process descriptions, and manuals for completeness. Developed recommendations to improve stability and operations of the infrastructure. Created a network segmentation concept and managed the implementation of the measures from the analysis project.
- 2020: Consulting on building an ISMS light for Josera foodforplanet GmbH & Co. KG.
- 2020: Security architecture consulting at Datagroup SE.
- Developed a future IT infrastructure and security architecture.
- Assessed the current IT architecture of all 23 companies.
- Made recommendations to optimize IT infrastructure and prepared a comparison of classic perimeter security concept versus zero trust model.
- Created a security zone concept.
- Developed an IT infrastructure architecture in coordination with all companies.
- 2018 - 2019: Stream lead in the cybersecurity program at Deutsche Lufthansa AG.
- Responsible for conceptualizing and implementing 9 projects in IT security infrastructure and user access management and for managing project managers and experts.
- Project areas: network segmentation and access control; security architecture; privileged, identity & access management; simplified user authentication (MFA); mobile & endpoint security; OT security; e-enabled aircraft.
- 2018: Security architecture consulting at Deutsche Lufthansa AG.
- Project management for developing, evaluating, and managing the enterprise-wide information security architecture.
- Developed a security strategy and roadmap for aligning the security architecture with the zero trust model.
- Evaluated market security solutions, services, and tools.
- Defined requirements for RFPs and assessed offers.
- Developed, maintained, and monitored security architecture artifacts.
- Conducted security assessments of existing and new IT systems and security services.
- 2018: ISMS consulting at GLS IT Services GmbH.
- Advised on the introduction and initial operation of an ISMS based on ISO 27001.
- Audited IT environments of GLS country organizations.
- Analyzed and assessed IT security risks and derived necessary measures.
- Developed solution proposals in coordination with relevant stakeholders.
- Managed the project and handed over the ISMS to operational teams.
- 2016 - 2018: Security pre-sales consultant for Cisco Systems GmbH.
- Provided strategic and conceptual consulting nationwide to major enterprise and financial services customers on Cisco and Meraki security products and services such as Firepower, WSA, ESA, Stealthwatch, and ISE.
- 2017 - 2018: Conceptualized and implemented an ISMS for Verivox GmbH.
- Conducted various BIAs and gap analyses.
- Developed security policies based on ISO 2700x.
- Took on the interim role of Information Security Officer.
- 2017: Developed an emergency plan for VPV Lebensversicherungs-AG.
- Reviewed and updated the IT emergency manual.
- 2016: Consulting and project management for cloud & hosting service design at Vodafone Group Services GmbH.
- Analyzed and optimized the sell-build-run process.
- Created detailed-level designs for cloud products.
Freelance IT Infrastructure and IT Security Consultant
christiandecker.net
- 2015 - 2016: Consulting and project management to set up IT security demand management for corporate security at Vodafone Deutschland GmbH.
- Supported the Information Security Officer.
- Proof of concept for a WAF integrated with SIEM.
- Security check of the top 10 applications.
- Security review of a cloud solution for an internal DMS.
- Security audit of a data center interconnection.
- Migration of the SOC from Kabel Deutschland to Vodafone.
- Defined security parameters for a VDI environment.
- 2015: Developed a telephone system security concept for VPV Lebensversicherungs-AG.
- 2014 - 2015: Consulting and various IT security project management for group security at Kabel Deutschland Vertrieb und Service GmbH.
- Implemented NAC in the corporate network with 4000 endpoints based on Cisco ISE and 802.1x in preparation for TrustSec microsegmentation.
- Introduced a firewall policy tool based on Tufin.
- Optimized processes and SIEM integrations based on ArcSight.
- Introduced a vulnerability scanner based on Tripwire.
- Introduced mobile device management based on SAP Afaria.
- Reviewed and aligned security policies of both companies.
Head of Infrastructure & Security and Service Desk / Information Security Officer
Commerz Real AG
- Upgraded Windows Server 2003 to 2008.
- Implemented a new employee evaluation system.
- Project management for project leader levels 1 to 4.
- Visualization and presentations.
Head of Technology
Com-Sys Gesellschaft für Netzwerktechnik mbH
- Compared IT security criteria (ITIL, BS2700x).
- Managed Realtech Network Management and Funkwerk UTM appliance.
Senior Support Engineer
Com-Sys Gesellschaft für Netzwerktechnik mbH
- Avaya advanced 1st and 3rd level support.
- Experience with Enterasys PEN, IDS, and IDS Advanced.
- Experience with Kobil SmartKey, SmartToken, SecOvid, and mIDentity.
- Varysys Packetalarm administrator.
- Experience with Enterasys routing, VPN, UPN, and IDS.
Team Lead IP Network Management
Deutsche Telekom AG
- Led a team in IP network management using Cisco technologies (ICND, BSCN, BCMSN, BCRAN, CVOICE, CIT, CID, CATM, AOSPF, ABGP, SNAM, CCIE-VB).
Network Planning and Design Staff
Fraport AG
- Airport management.
- Cisco router configurations on IOS.
- Conflict management, moderating and presenting.
Network Operation Center Staff
Fraport AG
- NOC operation center trainee.
- UNIX, switched to Solaris.
- Federal Data Protection Act.
- Basics of Ethernet / Token Ring / ATM.
- Sniffer Network Analyzer.
Network Installation Service Staff
Fraport AG
Apprenticeship as communications electronics technician specializing in telecommunications
Fraport AG
- Bosch Integral 22x/E.
Industries Experience
See where this freelancer has spent most of their professional time. Longer bars indicate deeper hands-on experience, while shorter ones reflect targeted or project-based work.
Experienced in Information Technology (17 years), Professional Services (10 years), Telecommunication (7 years), Banking and Finance (6 years), Real Estate (6 years), and Transportation (5 years).
Business Areas Experience
The graph below provides a cumulative view of the freelancer's experience across multiple business areas, calculated from completed and active engagements. It highlights the areas where the freelancer has most frequently contributed to planning, execution, and delivery of business outcomes.
Experienced in Information Technology (33 years), Project Management (18 years), Customer Service (5 years), and Operations (3 years).
Summary
- Conceptual consulting for securing business processes
- Consulting for the planning and implementation of IT and IT security projects
- Security and policy checks, process optimizations, emergency planning
- Project management and interim management in the area of IT infrastructure and information security
Skills
Operating Systems
- Macos, Ios, Windows, Linux, Unix
Software
- Ms Office Product Family Including Outlook, Project, Visio And Jira
Vendors
- Cisco, Meraki, Prtg, Zscaler, Netskope, Aruba, Cyberark, Arcsight, Ping, Beta Systems, Okta, Rsa, Apiida, Duo, Extreme Networks, Juniper, Kobil, Astaro, Mobileiron, Airwatch, Fortinet, Dell, Hp, Radware
Domains
- Security Architecture, Secure Access Service Edge (Sase), Data Loss Prevention (Dlp), Privileged Access Management (Pam), Identity Management (Idm), Identity And Access Management (Iam), Multi-factor Authentication (Mfa, 2fa), Single Sign-on (Sso), Web Application Firewall (Waf), Mobile Device Management (Mdm), Enterprise Mobility Management (Emm), Ddos Protection, Endpoint Security, Network Security, Dns Security, Security Information And Event Management (Siem), Security Operations Center (Soc), Cyber Defence Center (Cdc), Computer Emergency Response Team (Cert), Network Operations Center (Noc), Network Access Control (Nac), Operational Technology (Ot), Internet Of Things (Iot), Macro And Micro-segmentation, Cloud Security, Access Management (Aaa), Vulnerability Management, Patch Management, Information Security Management Systems (Isms), Intrusion Detection And Prevention (Ids/ips), Network Security Monitoring (Nsm), Bsi, Gdpr, Itil, Iso2700x, Critical Infrastructure (Kritis), Rfi, Rfp, Vendor Evaluation, Market Analysis, Anti-virus, Advanced Threat Protection, Advanced Malware Protection (Amp), Governance Risk And Compliance (Grc), Audits And Certifications, Cryptography, Penetration Testing, Configuration Management, Change Management, Incident Management, Business Continuity Management (Bcm), Public Key Infrastructure (Pki)
Languages
Education
Fraport AG
Vocational training as a communications electronics technician, specialization in telecommunications · Communications electronics technician, specialization in telecommunications · Frankfurt, Germany
Certifications & licenses
Cisco AMP And Threat Grid Integration With Cisco Email Security
business-security GmbH
Cisco AMP For Endpoints Fundamentals
business-security GmbH
Cisco Advanced Threat Security Domain Fire Jumper Academy
business-security GmbH
Cisco CSS Stealthwatch And SOVA
business-security GmbH
Cisco Cloud, Web And Email Security Domain Fire Jumper Academy
business-security GmbH
Cisco Cyber Security Specialist Stage I Exam
business-security GmbH
Cisco Network Security Domain Fire Jumper Academy
business-security GmbH
Cisco Ransomware Defense Solution
business-security GmbH
Cisco Sales Compliance Phase 2- Compliant Alternatives To Off-book Funds Assessment
business-security GmbH
Cisco Threat Grid Fundamentals
business-security GmbH
Cisco Umbrella Security Sales Training
business-security GmbH
Cisco Umbrella Security Technical Training
business-security GmbH
Cisco Understanding The Umbrella Proposition - Distributor Assessment
business-security GmbH
Cisco Visibility And Enforcement Security Domain Fire Jumper Academy
business-security GmbH
Cisco CMNA Meraki Training with Certification
christiandecker.net
Cisco Cisco Talos - The Team That Keeps Us Cybersafe
christiandecker.net
Cisco Cisco Tetration Analytics
christiandecker.net
Cisco Compliance: Risk Assessment
christiandecker.net
Cisco Get Some Cisco Spark In Your Life!
christiandecker.net
Cisco My Business Reports Test 1
christiandecker.net
Cisco Power Update - Data And Analytics
christiandecker.net
Cisco Safety Induction Training V2
christiandecker.net
Cisco Sales Compliance Training Assessment
christiandecker.net
Cisco Security Baseline Assessment
christiandecker.net
Cisco The Road To Success With Cloud Networking
christiandecker.net
CISSP training with certification
Commerz Real AG
Astaro Certified Administrator, Engineer, Expert and Sales Expert V7
Com-Sys Gesellschaft für Netzwerktechnik mbH
Enterasys PEN, IDS, IDS Advanced with Certification
Com-Sys Gesellschaft für Netzwerktechnik mbH
Enterasys Routing, VPN, UPN and IDS with Certification
Com-Sys Gesellschaft für Netzwerktechnik mbH
Kobil SmartKey, SmartToken, SecOvid and mIDentity with Certification
Com-Sys Gesellschaft für Netzwerktechnik mbH
Varysys Packetalarm-Administrator
Com-Sys Gesellschaft für Netzwerktechnik mbH
CISCO: ICND, BSCN, BCMSN, BCRAN, CVOICE, CIT, CID, CATM, AOSPF, ABGP, SNAM and CCIE-VB with Certification
Deutsche Telekom AG
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Christian based?
What languages does Christian speak?
How many years of experience does Christian have?
What roles would Christian be best suited for?
What is Christian's latest experience?
What companies has Christian worked for in recent years?
Which industries is Christian most experienced in?
Which business areas is Christian most experienced in?
Which industries has Christian worked in recently?
Which business areas has Christian worked in recently?
What is Christian's education?
Does Christian have any certificates?
What is the availability of Christian?
What is the rate of Christian?
How to hire Christian?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Managing Director and Senior Consultant
Nearby freelancers
Professionals working in or nearby Groß-Umstadt, Germany