Experience
Feb 2024 - Present
1 year 7 months
- Adapting the organizational structure and revising policy documents.
- (Re-)designing processes.
- Implementing ICT risk management, information network, third-party ICT providers, and information registry.
- Vulnerability, patch, and change management.
- SBOMs and incident management.
Apr 2023 - Present
2 years 5 months
- Achieved Achilles certification.
- Established an ISMS according to ISO 27001.
Jan 2022 - Dec 2023
2 years
- Deputy technical lead of information security management with a 10-member team.
- Worked in a highly regulated environment (DORA, VAIT, BAIT).
- Direct reporting lines to the CIO and management of Gothaer Solutions.
- Managed and coordinated information security processes.
- Led task forces to handle information security incidents.
- Contributed to IT emergency and business continuity management.
Sep 2021 - Dec 2022
1 year 4 months
- Responsible for strategic direction and operational business activities.
- Managed and coordinated software development in AI and cryptography.
- Experience with massively parallel processing in distributed systems at about 1.5 petaflops.
Mar 2021 - Dec 2023
2 years 10 months
- Responsible for the “nora emergency call app”.
- Established an ISMS based on BSI IT-Grundschutz.
Jan 2020 - Dec 2021
2 years
- Helped build a certified information security management system according to ISO 27001.
- Created guidelines and policies, and designed processes and controls.
- Advised IT projects on information security.
- Analyzed and assessed technical issues.
Jun 2018 - Oct 2023
5 years 5 monthsJun 2018 - Mar 2023
4 years 10 months
- Established an ISMS according to ISO 27001.
Jun 2017 - Present
8 years 3 months
- Delivered various projects focused on information security, data protection, and enterprise IT architecture in a partner network.
- Built and operated vulnerability management solutions in partnership with Tenable and Rapid7.
- Designed vulnerability and patch management, defined governance and technical concepts, and implemented on-premise, cloud, or managed services.
Jan 2017 - Dec 2019
3 years
- Led audits in a highly regulated environment (BAIT, MaRisk, ZAG, KRITIS).
- Conducted various audits in information security and IT.
- Covered topics like information security management, payment systems, PKI, and data center security.
- Reviewed audit results, developed remediation measures, and presented to management.
Nov 2015 - Dec 2016
1 year 2 months
- Led projects to build information security management systems according to ISO 27001 for critical infrastructure companies.
- Focused on public sector clients at the municipal level in energy, water, transport, and traffic.
- Managed audits for information security reviews under TÜV TRUST IT standards.
Nov 2014 - Oct 2015
1 year
- Technical project lead for Gematik/Telematics Infrastructure.
- Focused on requirements analysis, testing, and implementing PKI components.
- Worked with software and hardware like Hardware Security Modules (HSM).
- Developed security concepts.
Feb 2011 - Oct 2014
3 years 9 months
- Designed, developed, and operated directory services and PKI.
- Coordinated data synchronization across about 15 subsystems.
- Specialized in disk encryption and smartcard authentication.
- Responsible for identity and access management and building service portfolio management.
Jun 2007 - Jan 2011
3 years 8 months
- Developed scripts.
- Supported service level management.
- Designed and developed in SharePoint Designer.
- Led small projects.
- Provided VIP support and VIP helpdesk for top management.