Experience
May 2024 - Dec 2024
8 months
- Led the DevOps team.
- Acted as the main contact for BMW on all topics.
- Coordinated with development partners in Germany and India.
Achievements:
- Established a PIC process to reduce tickets and escalations.
- Created inter-team communication across five teams in Germany and India.
- Increased the customer satisfaction score from 2 to 4 out of 5.
Jan 2023 - Dec 2025
3 years
- Defined security concepts for all relevant applications running on the AWS cloud platform.
- Connected applications to BMW’s central SOC/Splunk.
- Performed regular penetration tests, IAST/SAST/DAST application scans.
- Ensured compliance with BMW regulations.
Achievements:
- Achieved over 95% on Security KPIs.
- Exceeded 90% on Compliance KPIs.
Dec 2022 - Aug 2023
9 months
- Served as Interim CISO for EMEA after Evident Scientific’s spin-off from Olympus.
- Defined a PPP framework.
- Established an IT risk register for EMEA.
- Achieved UK Cyber Essentials certification.
- Conducted an ISO 27001:2022 maturity assessment.
Jan 2022 - Present
3 years 8 months
- Conducted Cloud Vendor Assessments (CVA) based on DCSO’s security domains (NIST/ISO).
Achievements:
- Completed over 10 assessments in 2022.
- Completed over 10 assessments in 2023.
Oct 2021 - Jan 2022
4 months
- Performed ISO 27001:2021 control assessments.
- Conducted BSI C5 control assessments.
- Defined risk-based technical and organizational measures to improve cybersecurity maturity and resilience.
Achievements:
- Created and presented the final report to the Board and CISO.
Jan 2020 - Dec 2023
4 years
- Defined the Information Security roadmap through 2025.
- Implemented an ISMS according to ISO 27001, enriched with NIST-800 and NIST CSF controls.
- Built a global IS organization and a 24/7 Incident Response Team.
- Conducted Business Impact Analysis and TCM/BCM planning.
- Designed and implemented endpoint protection, data classification, and data loss prevention concepts.
Achievements:
- Secured approval for the Information Security strategy and policy.
- Published IS and GRC policies.
- Established IS awareness programs and a management dashboard with defined KPIs.
- Set up an MDR Security Operations Center and Security Incident Response Team.
- Deployed endpoint protection on over 8,000 endpoints with Sentinel monitoring.
- Integrated data classification and DLP into business processes.
Jan 2020 - Mar 2021
1 year 3 months
- Defined and implemented security concepts for the OpenShift platform and related applications hosted in AWS.
- Developed a Security Operations model.
- Connected the platform and applications to BMW’s central SOC/Splunk.
- Conducted regular penetration tests and IAST/SAST scans.
Achievements:
- Passed BMW’s internal audit with no major or medium issues.
- Established the interface to BMW SOC/Splunk.
Oct 2019 - Mar 2020
6 months
- Conducted an as-is analysis of existing IT infrastructure and services.
- Mapped business processes to IT services.
- Evaluated options for future IT strategy and organization.
- Proposed and defined the IT strategy based on these evaluations.
Achievements:
- Produced as-is documentation and business process maps.
- Reviewed the business impact analysis.
- Defined the IT strategy and handed over rollout preparation to the IT Manager.
Jul 2019 - Sep 2022
3 years 3 months
- Managed GDPR compliance activities and data privacy audits.
- Implemented technical and organizational measures.
- Fulfilled general GDPR officer responsibilities.
Achievements:
- Implemented a Data Privacy Management System.
- Created and maintained Records of Processing Activities (RPA).
- Established Data Processing Agreements with subcontractors and suppliers.
Jan 2018 - Jun 2019
1 year 6 months
- Aligned project pillars for Data Centre (DCC), Virtual Client (AVC), Global Mail (GM), AGN Network, and AGN security services.
- Monitored overall project budgets.
- Coordinated execution between projects and local CIOs in APAC.
Achievements:
- Successfully rolled out AGN, AGN security services, and GM in 2018.
- Completed the rollout for AVC and DCC in 2019.
Jan 2016 - Dec 2018
3 years
- Held P&L responsibility for the AVC program.
- Defined rollout plans for Allianz Virtual Client (AVC) to 140,000 users worldwide.
- Led architecture, package factory, engineering, rollout, finance, and PMO teams.
- Reported to Allianz SE top management.
Achievements:
- Customized the AVC solution for 24/7 operations.
- Rolled out AVC to over 70,000 users across Europe and APAC by end of 2018.
Jan 2016 - Dec 2018
3 years
- Defined and implemented information security concepts based on BSI 100-x and ISO 27000 series.
- Created an ISMS for over 20 locations and business units.
- Conducted audits and follow-up checks.
Achievements:
- Delivered BSI 100-1/2 and ISO 27000 series security concepts.
- Developed IT emergency plans based on BSI 100-4.
- Handed over the ISMS to my successor at the end of my tenure.
Jan 2016 - Dec 2016
1 year
- Developed a new SAP IT security concept.
- Tested the pilot production environment.
- Planned the worldwide rollout and handed it off to the rollout manager.
Achievements:
- Created a new SAP IT security blueprint and validated its feasibility.
- Defined the rollout plan and aligned all necessary stakeholders successfully.
Jan 2016 - Dec 2016
1 year
- Designed a new data center concept to meet regulatory requirements in multiple countries.
- Conducted BIA with RTO/RPO definitions.
- Managed project costs, budget, and milestones.
Achievements:
- Consolidated data center infrastructure from six to two global locations.
- Introduced DR concepts and reduced IT costs.
Jan 2015 - Dec 2016
2 years
- Created new IT organizational concepts based on the COBIT 5 framework.
- Defined an IT operations handbook with process and role descriptions.
- Advised on IT architecture for cloud solutions.
Achievements:
- Implemented the IT organization concept and onboarded existing staff.
- Successfully defined and implemented cloud operations.
Jan 2014 - Dec 2014
1 year
- Defined an IT governance policy according to CBRC, PBOC requirements, ISO 38500, and COBIT 5 standards.
- Aligned the policy with BMW AG and BMW Bank.
- Prepared a presentation for top management.
Achievements:
- Submitted and gained approval for the IT governance policy tailored to the Chinese market.
Jan 2014 - Dec 2014
1 year
- Created IT security concepts for COFIS, integrating CRM and CIC modules.
- Conducted risk assessments per ISO 27001.
Achievements:
- Finalized security concepts, had the ITPM review them, and prepared the system for go-live.
Jan 2014 - Dec 2014
1 year
- Prepared business proposals summarizing security requirements.
- Designed information protection and DLP concepts.
Achievements:
- Finalized DLP concepts and carried out successful PoCs with various business cases.
- Provided handover including rollout preparations for operations.
Jan 2013 - Dec 2014
2 years
- Led the BMW JV Butterfly IT project in China.
- Managed IT dependencies and identified risks.
Achievements:
- Aligned IT deliverables successfully for the NEV-focused launch timeline.
Jan 2013 - Dec 2013
1 year
- Conducted security workshops to clarify requirements.
- Provided information security guidance for protected R&D work.
Achievements:
- Delivered a complete information security framework for Audi R&D’s secure operations.