Christine Schmitt
Lead OT Security | Industrial Cybersecurity | Cyber Program Manager | CISO Advisor
Experience
OT Security Architect and Technical Consultant
Sweet Tec
Provided strategic and technical support for implementing the NIS2 Directive (§30 BSIG) in a classic ICS/SCADA environment with production lines, packaging machines, conveyor systems, PLC/SCADA infrastructure, historian servers, and a partially segmented OT network.
Focus areas:
- Leading and conducting the NIS2 gap analysis (alignment of the 10 measures per §30 BSIG)
- Developing an NIS2-compliant OT target architecture for 2026 (DMZ design, jump host concept, logging, user/password policy, MFA rollout, cryptography)
- Revising and preparing OT security policies for management approval
- Planning and coordinating further project phases: OT asset inventory, network mapping, criticality assessment, risk analysis, action prioritization, pilot line implementation, and rollout
The focus was on practical, production-friendly solutions considering availability requirements, safety aspects, and legacy systems. Work followed IEC 62443, ISO 27001, and BSI ICS guidelines, including OT zones/conduit modeling, secure remote maintenance, logging concepts, network segmentation, and compensating controls for non-patchable systems.
The project laid the foundation for audit-ready NIS2 compliance by mid-2026 and served as a pilot within the group.
NIS2 compliance strategy & implementation, OT gap analysis per §30 BSIG, OT target architecture (IEC 62443 zones/conduits), DMZ design & IT/OT segmentation, jump host & secure remote maintenance, OT logging concepts & analysis, OT asset inventory & criticality, action prioritization (quick wins), OT security policies & management approval, compensating controls for legacy PLCs
IEC 62443 (SL-1 to SL-3), ISO 27001 / ISMS (ConSense), NIS2 Directive (§30 BSIG – 10 measures), BSI ICS security compendium, SCADA systems, historian servers, OT network components, OT firewalls, jump host solutions, logging tools
Development and Technical Consultant for Implementation of an OT Security Framework (IEC 62443, NIS2)
Felleskjøpet Agri SA
Felleskjøpet Agri SA commissioned the development and rollout of a tailored OT security framework to raise the cybersecurity maturity level at prioritized operational and production sites. The project aimed to better protect industrial control environments from cyberattacks, meet regulatory requirements (including IEC 62443, NIS2), and establish a sustainable governance structure for OT security.
Tasks & Responsibilities:
- Defining OT security requirements and contributing to architectural design initiatives according to IEC 62443 and NIST CSF
- Conducting site maturity assessments, risk analyses, and evaluating existing governance structures
- Setting up governance, processes, and control frameworks for OT security measures across multiple sites
- Promoting collaboration between central IT, local operations, and third parties to ensure consistent implementation
- Creating security documentation, system mappings, and network topology analyses to improve visibility and risk management
- Supporting the introduction and standardization of OT security measures in ongoing operations
Project Outcome:
- Established a company-wide OT security framework based on international standards
- Consistent, cross-site implementation of OT security measures
- Increased cybersecurity maturity and resilience against attacks on industrial control environments
- Strengthened governance, transparency, and risk management in the OT domain
Skills: OT cybersecurity (industrial control systems), development of OT security frameworks, NIS2 and IEC 62443 compliance, cyber risk management in OT environments, protection against cyberattacks on production facilities, establishing sustainable OT security governance, maturity improvement in OT security (assessment & implementation), security concepts for critical infrastructure operators (agriculture), industrial network security (SCADA, PLC)
IEC 62443 (OT security standard), NIS2 Directive (EU cybersecurity), OT security framework, Industrial Control Systems (ICS) security, Purdue Enterprise Reference Architecture (PERA), cybersecurity maturity models, risk assessment tools for OT environments
Technical Specialist for ISMS and IAM | Cybersecurity Director
Felleskjøpet Agri SA
Felleskjøpet Agri SA, a leading Norwegian agricultural service provider, commissioned the implementation of an ISMS to meet regulatory requirements and sustainably strengthen security and compliance structures.
The project included designing, implementing, and operationalizing a fully auditable ISMS, integrating automated security processes, and preparing for external audits by regulators.
- Building an enterprise-wide ISMS framework based on ISO 27001, NIST CSF, and NIS2 requirements, defining roles, responsibilities, and governance structures
- Creating and harmonizing core ISMS policies, security processes, risk management policies, and reporting structures
- Ensuring audit readiness through complete, audit-proof documentation and defining control mechanisms
- Integrating tools to automate key ISMS processes (e.g., risk management, incident management, change requests), and building a dashboard for real-time security monitoring
- Collaborating closely with management, IT security officers, operations managers, and external auditors to align requirements and ensure successful implementation
- Conducting structured risk analyses, assessing protection needs, and deriving technical and organizational measures to reduce risks
- Supporting the development of a security culture through training and awareness campaigns for business units and executives
Project Outcome:
- Established a robust, auditable ISMS that meets all NIS2 Directive requirements
- Reduced security risks through structured processes, automated workflows, and clearly defined responsibilities
- Improved audit and reporting capabilities, as well as real-time transparency of security and compliance status
- Embedded information security sustainably into the corporate organization
Skills: NIS2, Purdue Model, IAM, ISMS, ISO 27001
Tools Used: ServiceNow (GRC & SecOps), Microsoft 365, Confluence, Jira
Project Manager IT Governance, Risk & Compliance (GRC) Program – Audit Alignment & DORA Readiness
Volkswagen (VW) Møller Bilfinans
Project Description Volkswagen Møller Bilfinans commissioned the introduction and optimization of IT governance, risk, and compliance (GRC) processes to address identified audit findings and ensure alignment with Volkswagen Group policies as well as Norwegian and European regulatory requirements.
A key focus was preparing for the EU Digital Operational Resilience Act (DORA) and integrating ISO/IEC 20022 standards to harmonize payment and reporting processes with regulatory guidelines. The goal was to sustainably strengthen IT resilience, compliance, and audit readiness.
Tasks & Responsibilities:
- Coordinating group-wide alignment between compliance, IT, and security teams to close audit findings and meet corporate and legal requirements
- Developing and updating central GRC documentation to close audit gaps and comply with policy and regulatory standards, including ISO/IEC 20022 for reporting and payment processes
- Adapting local IT governance structures to Volkswagen Group requirements with a focus on risk management, internal controls, and regulatory compliance
- Planning and implementing measures to meet DORA requirements, strengthen operational resilience, optimize incident response management, and improve reporting capabilities
- Integrating ISO/IEC 20022 processes: embedding technical and regulatory aspects of ISO/IEC 20022 into the governance and compliance architecture to support future-proof financial processes
- Coordinating all stakeholders, scheduling, progress reporting, and on-time implementation in line with audit and compliance requirements
Project Outcome:
- Addressed major audit findings and established a robust, auditable GRC framework
- Enhanced regulatory preparedness for DORA and ISO/IEC 20022-based reporting and payment processes
- Harmonized local IT governance with group and EU requirements
- Improved transparency, resilience, and compliance in key IT and financial processes
- Future-proofed reporting and financial infrastructure through ISO/IEC 20022 standards
Skills: DORA, Digital Operational Resilience Act, ISO 27001, IAM, GRC, NIS2, NIST Cybersecurity Framework (CSF) 2.0, ISO 20022, NIST CSF, ISO 20022, Volkswagen Group Governance Frameworks, GRC framework design, audit remediation, compliance management, risk management, ISO/IEC 20022 integration, governance & reporting
Tools Used: Microsoft 365, Confluence, Jira, internal GRC systems
OT Security Specialist | Cybersecurity Director
Nye Veier / Norwegen
Project Description As part of a prioritized internal audit initiative, the maturity and effectiveness of OT security measures at Nye Veier AS are being assessed. The context is the growing threat landscape for critical infrastructures and the resulting need to significantly increase the company's cyber resilience. The goal is to identify vulnerabilities, derive concrete improvement opportunities, and strengthen organizational and technical security structures.
Tasks & Responsibilities:
- Providing expert support for internal audit processes focusing on OT security governance, risk management, and control environments
- Advising on best practices and international security standards (IEC 62443) to ensure a comprehensive and technically sound assessment
- Identifying risks related to organizational structures, access management, system dependencies, and process responsibilities
- Developing practical, risk-based recommendations in line with business requirements, regulatory guidelines, and current security maturity
- Ensuring technical accuracy and feasibility of audit findings to support sustainable security improvements
Project Outcome:
- Delivered a data-driven assessment of OT security maturity, highlighting key weaknesses in governance and operational controls
- Developed targeted improvement measures and clearly defined roles and responsibilities
- Reduced reliance on external service providers by strengthening internal competencies and processes
- Enhanced capabilities for detection, response, and recovery after cyber incidents
- Increased resilience and protection of critical infrastructures
Skills: ISO/IEC 62443, OT security, endpoint encryption, endpoint security, public road infrastructure, traffic management systems, telematics, supply chain security, OT security governance, risk analysis, audit support, security maturity assessment, risk-based recommendations
Compliance & Cybersecurity Advisor
Löwenstein Medical
Project Description The goal of the project was to develop and implement a global PKI strategy (Public Key Infrastructure) to secure medical devices, enterprise IT systems, and R&D environments. The focus was on building a scalable digital trust infrastructure that meets regulatory requirements while ensuring security throughout the entire device lifecycle. This included securing IoT-enabled medical devices, authenticating and encrypting sensitive data streams, and supporting international compliance requirements (MDR, ISO 27001, GDPR, NIS2, CRA, FDA).
Tasks & Responsibilities
- Managed the end-to-end RFP process for PKI solution providers, including technical evaluation, commercial analysis, and contract negotiations
- Conducted a comprehensive PKI readiness and gap analysis across international markets with a focus on IoT device security and lifecycle management (provisioning, certificate management, revocation)
- Developed a strategic PKI roadmap to ensure long-term cyber resilience and support ISO 27001 certifications
- Advised top management on regulatory requirements: MDR, GDPR, NIS2, CRA, FDA
- Designed a PKI architecture that supports secure device connectivity, end-to-end encryption, and identity management for IoT ecosystems
- Ensured audit readiness and integrated the PKI into global IT, OT, and R&D system landscapes
Project Outcome
- Built a global PKI infrastructure that secures the entire lifecycle of connected medical devices, from production to safe operation
- Strengthened IoT security through standardized certificate management, authentication, and encryption in production and clinical environments
- Harmonized international regulatory requirements (MDR, GDPR, NIS2, CRA, FDA) with a future-proof security architecture
- Improved audit and compliance capabilities and reduced regulatory risks
- Created a scalable trust infrastructure as a basis for innovation, secure product development, and global market approval
Skills: PKI, encryption, endpoint encryption, medical devices, MDR, NIS2, GDPR, ISO 27001, IT baseline protection, GDPR, CRA, FDA, PKI best practices, IoT security policies, PKI strategy development, IoT security architecture, lifecycle protection, gap analysis, compliance management, audit readiness, vendor selection (RFP)
Tools Used: Microsoft 365, Jira, Confluence, PKI management solutions, HSM, CA, lifecycle management systems
Project Manager & Lead Consultant
SSI Schäfer
Project Description SSI Schäfer aimed to strategically consolidate its global system landscapes through a hybrid iPaaS architecture (Integration Platform as a Service).
As part of the project, an integration platform was planned and tested in a PoC, connecting about 250 systems and over 5,000 interfaces across 69 international sites. By combining SAP Integration Suite (SAP IS) for core SAP processes and MuleSoft for non-SAP, cloud, and external partner integrations, the goal was to create a scalable, secure, and future-proof integration landscape that significantly improves governance, interoperability, and efficiency.
Tasks & Responsibilities
- Managed the vendor selection and PoC process for SAP CPI and MuleSoft; defined technical, business, and security evaluation criteria
- Developed strategic decision frameworks and oversaw collaboration with partners like NTT DATA, Salesforce, and SAP
- Led enterprise-wide integration governance and cross-platform delivery, aligned with global IT strategy and compliance requirements
- Applied a PI-based agile delivery approach to manage complex integration dependencies and accelerate rollouts across business units
- Coordinated stakeholder management, risk management, and process standardization to ensure long-term interoperability and performance
- Supported the setup of a central framework for security, compliance, and monitoring as part of the global integration strategy
Project Outcome
- Built a standardized, modular integration framework that enables fast partner onboarding, cloud adoption, and scalability for international business units
- Strengthened integration governance, security, and compliance
- Calculated total cost of ownership (TCO) reduction through consolidation and standardization of the integration landscape
- Improved interoperability, operational efficiency, and resilience of the global IT infrastructure
- Designed a future-proof integration architecture as the foundation for digital transformation and new business models
Skills: API-first architecture, enterprise integration patterns, security & compliance standards, ISO 27001, enterprise integration governance, vendor evaluation, agile delivery (PI-based), process standardization, risk management
Tools Used: SAP Integration Suite (CPI), MuleSoft, Salesforce, Microsoft 365, Confluence, Jira
IT Project Manager, Regulations & Security Requirements Analyst
BMW Bank
- Managed infrastructure development, file transfer implementation, and Go Live planning for core banking systems migration.
- Oversaw critical compliance needs including SEPA migration and national financial authority connections.
- Developed and deployed over 300 security requirements, coordinating system architecture and interface development.
- Utilized Azure cloud platform, ForgeRock integration, IAM integration (Keycloak, SAML 2.0, AD Adapter), VPN for SEPA, encryption across data lifecycle, and audit-grade security documentation.
Cyber Security Manager
Thales GTS
- Led cybersecurity risk assessments and compliance reviews following IEC 62443 standards for a railway signalling digitisation pilot in Stuttgart 21.
- Created security policies under Cybersecurity by Design principles and maintained comprehensive audit documentation.
- Employed IEC 62443, CENELEC 50128, CENELEC 50129, compliance tools, pen testing planning, and IBM Rational DOORS.
Product Owner (AI in Circular Economy); Requirements Analyst (eGov); AWS Cloud Migration Trainer
Agile project manager and architect for AI technologies.
Led workshops to define requirements and enterprise architecture for AI tools.
Developed and managed epic and user story backlog using test-driven development.
Requirements analyst and IT consultant for digitalisation of German railway insurance company.
Agile Project Manager (eRetail); Product Owner (Manufacturing); Solution Architect (B2B Supply Chain)
- Managed functional requirements and project planning for cloud migration and headless eCommerce development using Frontastic.
- Defined business strategy and technical requirements for predictive maintenance platforms in mining and heavy machinery industries.
- Architected IBM Blockchain and BigCommerce solutions, conducted design sprints, risk assessments, and produced technical documentation.
Product Owner (Automotive); Agile Coach (Insurance); Agile Coach (XING / Social Media)
- Agile coaching and project management for digitalisation and omnichannel journeys in luxury automotive experiences.
- Supported digital claims reporting app development and Kubernetes platform analytics for insurance.
- Introduced agile methods across social media platform teams, coached Scrum Masters and Product Owners, and structured agile project documentation.
Agile Project Manager (Media); Program Manager Interim (Energy); Project Manager (Supply Chain)
- Intake and requirements analysis for SAP S/4HANA predictive analytics AWS platform for media.
- Interim program management coordinating market units for predictive maintenance solutions in energy.
- Managed SCM outsourcing projects and PMO setup for supply chain solutions at UBS Bank.
Project Manager (Pharma); Project Manager (Manufacturing); Project Manager (Telecom)
- Managed data lifecycle and regulatory submissions for Roche Diagnostics, migrating 40 TB across global file servers.
- Led SAP CRM implementations for high-tech manufacturing including Bruker and Techtronic.
- Reengineered business processes for Vodafone CRM systems serving 45 million customers.
Innovation Manager (Gov); Project Manager (Manufacturing); Project Manager (Automotive)
- Developed Swissmedic portal for therapeutic product authorizations, handling 35,000 approvals p.a.
- Managed SAP R/3 to ERP 6.0 upgrades for Bosch Power Tools.
- Migrated SAP CRM data for VW internal customer services across 2000 sites.
Project Manager (Finance); Project Manager (Telco, Logistics); CRM Consultant (Manufacturing)
- Led IT infrastructure and CRM integrations for Postbank, HSBC, Sixt, and TUI.
- Designed SAP CRM 5.0 blueprints and technical architectures for ePlus+, Raiffeisen, Lafarge, Commerzbank, Barilla, and Wella.
- Managed pre-sales, business development, and direct marketing optimizations in DACH region.
Project Manager (IT-Services); Project Manager (Finance); Project Manager (Security Systems)
- Designed customer billing processes and middle office outsourcing in SAP ECC and CRM.
- Managed bank IT infrastructure and implemented MPLS network architecture.
- Led SAP CRM implementation projects and system architecture for Bosch Customer Contact Centers in Germany and Netherlands.
Project Manager (IT-Services); Project Manager (Datacenter); Project Manager (Telco)
- Developed international AI routing system and corporate security policies.
- Managed datacenter services for SMBs and designed global base station network solutions.
- Led GSM/GPRS/UMTS software development and corporate paper archive digitization.
Industries Experience
See where this freelancer has spent most of their professional time. Longer bars indicate deeper hands-on experience, while shorter ones reflect targeted or project-based work.
Experienced in Telecommunication (14 years), Banking and Finance (12 years), Manufacturing (11 years), Information Technology (10 years), Transportation (7.5 years), and Automotive (6 years).
Business Areas Experience
The graph below provides a cumulative view of the freelancer's experience across multiple business areas, calculated from completed and active engagements. It highlights the areas where the freelancer has most frequently contributed to planning, execution, and delivery of business outcomes.
Experienced in Information Technology (26 years), Project Management (26 years), Customer Service (9 years), Finance (8 years), Product Development (7.5 years), and Marketing (7 years).
Summary
Christine Schmitt's vast experience spans 20+ years in international IT project management, with a specialization in cybersecurity for critical infrastructure and GRC (Governance, Risk, and Compliance). She has in-depth knowledge of IEC 62443, ISO 27001, NIS2, ISO 20022, PCI-DSS, DORA, COBIT, and OSC&R.
With a background in cybersecurity, she has a strong background in OT and IT architecture design. Her skill set includes security operations, incident management, policy formulation, risk mitigation, audit readiness, documentation, and data/system cloud migrations.
Her career has encompassed a wide range of industries, including banking, fintech, manufacturing, telecommunications, energy, automotive, rail logistics, insurance, pharmaceuticals, media, government, and R&D. Optimizing predictive maintenance, industrial IoT, and supply chain, she directs a comprehensive cybersecurity and digital transformation portfolio.
Christine has successfully managed large global projects, crisis related initiatives and complex smaller programmes. As an experienced agile coach, Christine has facilitated the shift from conventional methods to agile approaches, deploying SAFe, LeSS, and holocratic processes. She maintains memberships in ISACA, ISC2, Responsible AI Institute, and other industry groups to stay on the cutting edge of technology.
Skills
Project Management And Methodology: Agile And Waterfall Methodologies; Stakeholder Engagement And Communication; Budget Planning And Cost Control; Risk And Issue Management; Team Leadership And Mentorship; Resource Allocation And Scheduling; Project Reporting And Presentations.
Cloud Migrations And Infrastructure: Cloud Platforms (Aws, Azure, Gcp); Hybrid And Multi-cloud Deployments; Infrastructure As A Service (Iaas), Paas, Saas; On-premises To Cloud Migrations.
Strategic Planning And Business Alignment: It Strategy Development; Process Reengineering; Digital Transformation; Kpi Definition And Performance Measurement; Change Management Strategies; Executive-level Communication.
Governance And Reporting: Policy And Procedure Development; Internal Controls And Auditing; Security Framework Implementation; Business Continuity And Disaster Recovery; Vendor Compliance Management.
Governance, Risk And Compliance (Grc): Regulatory Compliance (Iso 27001, Nist, Gdpr); Risk Assessment And Mitigation; Compliance Management.
Emerging Technologies And Cyber Security For Critical Infrastructure: Critical Infrastructure Protection (Ics/scada); Security Risk Identification And Security Concepts; Incident Response And Vulnerability Management; Iam/pam; Ids/ips And Zero Trust Architectures.
Emerging Technologies And Innovation: Artificial Intelligence And Machine Learning Applications; Internet Of Things (Iot) Integration; Blockchain Solutions; Edge Computing Strategies; 5g Network Implementations; Quantum Computing Awareness.
Project Planning: Microsoft Project, Jira, Smartsheet.
Policy And Document Management: Doors, Confluence, Trello, Slack, Sharepoint.
Governance, Risk And Compliance (Grc) Tools And Standards: Rsa Archer, Sap Grc, Riskwatch, Cura Grc, Iec 62443, Cenelec, Iso 27001, Iso 27005, Iso/iec Jtc 1/sc 42, Nist 2.0, Ieee P7000, Nist Ai Rmf, Enisa, Eu Ai Act.
Emerging Technologies: Ai And Ml (Tensorflow, Pytorch, Azure Ai, Google Ai); Iot Platforms (Aws Iot Core, Azure Iot Hub); Blockchain (Hyperledger, Ethereum); Edge Computing (Aws Greengrass, Azure Stack Edge).
Cybersecurity Technologies: Threat Monitoring (Splunk, Qradar); Vulnerability Scanning (Nessus, Qualys, Openvas); Endpoint Security (Crowdstrike, Sentinelone, Symantec); Identity And Access Management / Pam (Keycloak, Auth0, Forgerock, Okta, Cyberark); Firewalls And Security Platforms (Palo Alto Networks, Fortinet, Cisco Asa).
Devops And Automation: Ci/cd Pipelines (Jenkins, Gitlab Ci/cd, Azure Pipelines); Containerization (Docker, Kubernetes); Infrastructure As Code (Terraform, Ansible, Cloudformation); Version Control (Git, Bitbucket).
Sap And Enterprise Systems: Sap Modules (Sap S/4hana, Sap Ecc, Sap Fiori); Data Migration (Sap Data Services); Testing (Abap Workbench, Sap Solution Manager, Ecatt); Integration (Sap Pi/po, Mulesoft).
Languages
Education
Lette Verein Berlin
State-certified Technical assistant for metallography and physical material analysis · Berlin, Germany
Certifications & licenses
AttackIQ Foundations Of AI Security
TÜV Data Security Officer
TÜV Industry 4.0 Transformation Expert
Scrum Master PSM I
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Christine based?
What languages does Christine speak?
How many years of experience does Christine have?
What roles would Christine be best suited for?
What is Christine's latest experience?
What companies has Christine worked for in recent years?
Which industries is Christine most experienced in?
Which business areas is Christine most experienced in?
Which industries has Christine worked in recently?
Which business areas has Christine worked in recently?
What is Christine's education?
Does Christine have any certificates?
What is the availability of Christine?
What is the rate of Christine?
How to hire Christine?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a OT Security Architect and Technical Consultant
Nearby freelancers
Professionals working in or nearby Berlin, Norway