Federico (F.) Leefhelm
ISO – Senior Consultant Quality & Information Security
Experience
Senior IAM Manager & Single Point of Contact for Information Security
EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. They are expanding their renewable energy sources, commit to a socially responsible coal phase-out and drive key technologies such as green hydrogen use. A fast energy transition and achieving climate neutrality by 2035 are priorities for EnBW.
- Developed and implemented a holistic process view covering both technical and organizational aspects
- Ensured end-to-end control of all IAM-related technical services
- Established clear responsibilities and accountabilities within the IAM landscape
- Collaborated with various departments to identify and optimize a holistic architecture, acting as the single point of contact (SPoC) for information security
- Introduced and monitored governance policies to ensure compliance and security
- Continuously improved IAM processes and systems through regular audits and service reviews
- Participated in external audits of processes as part of the official ISO standard audits
- Further developed the policy for defining administrative requirements and procedures and aligned it with administrative areas
- Conceptually enhanced the KPI system to measure process quality
Senior PMO for the Global IT CDC Project
Daimler Truck Financial Services (DTFS)
Daimler Truck Financial Services is moving from traditional data centers to the Azure cloud. As part of the Cloud Data Center project (CDC), DTFS is migrating traditional data centers in Europe (EMEA), Asia & South Africa (APAC), Canada, South, Central and North America (NAFTA) and transferring the service to the Azure cloud. DTFS supports the global sale of Daimler commercial vehicles through leasing, financing and insurance and, with a contract volume of €25.4 billion, is one of the world's largest financial service providers for commercial vehicles ([link]).
- Worked as Senior PMO and Senior Management Consultant with the Global IT Director and Head of Innovation Projects
- Collaborated as Senior PMO and Management Consultant with the international PM and PO teams (Project Management/Project Owner)
- Created a master plan based on MS Project for the CDC project, which allowed DTFS to have a clear overview and transparency over the project after one year
- The master plan provided management and teams with clear and accurate information on the status of the overall project and each subproject, both by region and by country
- Reports from the master plan enabled management and teams to take corrective actions to keep the project on time, on budget and on quality
- Regular reporting of project progress to the Global IT Director and PM teams
- Handed over the CDC master plan to the DTFS PM at the end of the contract period
ISO – Senior Consultant Quality & Information Security
Gemeinsame Klassenlotterie der Länder (GKL)
- Responsible for implementing the QMS & ISMS on behalf of the partner company ModernX GmbH & Co. KG
- Responsible for benchmarking and the future introduction of an ISO tool for central management of all management systems
- Responsible for deploying a Quality Management System (QMS) according to ISO 9001:2015
- Responsible for deploying an Information Security Management System (ISMS) according to ISO 27001:2022
- Prepared and developed the necessary measures (scope, SoA, policies, security concepts, process instructions, SOPs, etc.) to build a QMS and ISMS
- Risk management: identifying, assessing and treating critical and potential attack scenarios
- Conducted risk analysis, risk treatment, determination of protection needs and vulnerability analysis of the IT infrastructure
ISO – Senior Consultant Cyber- & Information Security
Northland Power Europa GmbH
- Northland Power is a developer, operator and owner of clean wind power plants
- Member of the security team, co-responsible for the cyber and information security of the wind power plants
- Responsible for creating all documentation and measures (policies, security concepts, cryptography, key management) to implement attack detection systems (SzA) according to BSI IT-SiG 2.0 and EnWG
- Prepared and developed measures (policies, SOPs, ISMS manual, BCM, IT emergency plans, IAM, backup & recovery, MDM, supplier, password, patch, asset & configuration, network management) to build an ISMS according to ISO 27001:2022
- Identified, assessed and treated critical and potential attack scenarios of the wind power plants in risk management
- Conducted risk analysis, risk treatment, determination of protection needs and vulnerability analysis of the IT/OT infrastructure
- Developed IT/OT emergency plans, incident response processes and rebuilding IT/OT systems as part of BCM (BIA, RIA & DRP)
- The project was terminated early as the wind turbines were sold and the company in Germany was closed
CISO ad Interim & Senior Management Consultant ISMS, BCM & IAM
Huf Hülsbeck & Fürst GmbH & Co. KG
- Led and managed the project to implement Business Continuity Management (BCM) according to ISO 22301
- Defined the scope, developed a BCM policy, business impact analysis (BIA), risk impact analysis (RIA) and disaster recovery plan (DRP)
- Developed IT emergency plans, vulnerability analysis, incident response processes and rebuilding IT systems
- Conducted the first review of the corporate Identity and Access Management (IAM) process and identified improvements
- Contributed to the continuous improvement process of the TISAX and ISMS certification according to ISO 27001
- The BCM project was not completed due to budget planning
ISO, Sr. Management Consultant and Sr. PMO
University Hospital Düsseldorf (UKD)
- The UKD is the largest hospital in the state capital and one of the most important medical centers in North Rhine-Westphalia.
- Operator of critical infrastructures (KRITIS according to §8a BSIG) with an ISMS certified to ISO 27001:2022.
- Works directly as Senior Management Consultant to the head of IKMT (CIO) and leader of the innovation projects.
- Responsible for the entire IT department in information security as ISO.
- Creation, maintenance, and improvement of ISMS policies and SOPs.
- Training and awareness for IT staff in IT security, incident response processes, and IT system recovery.
- Developed and main contact for the new IT strategy of UKD, including a BIA and DRP for IT system recovery.
- Preparations for the upcoming introduction of Business Continuity Management according to ISO 22301 for the IKMT department and UKD.
- Creation of an IT cyber security strategy and roadmap for implementing additional tools and solutions for UKD's cyber security.
- Development of an IT emergency plan (as part of the DRP), IT security concept, incident response, and related supporting concepts (data protection, antivirus, cryptography, configuration and hardening measures, asset & configuration management, patch management, roles & rights (IAM), IT emergency preparedness, etc.).
- Collaboration on the measures to make IDS (intrusion detection systems) compliant with BSI IT-SiG 2.0.
- Development of a security concept, conducting a proof of concept (PoC), evaluation and analysis up to procurement and implementation of a medical device monitoring security system.
- Building a Security Operations Center (SOC) with operating concept and definitions for preventive measures, threat detection, and incident response.
- Building a Security Information and Event Management (SIEM) with Splunk.
- Senior PMO of the department management since February 2023, responsible for overseeing all IT-related projects (>2K projects).
- Creation & management of Gantt charts for all IT-related projects (IT & medical, IT security, SAP, etc.).
- Development of a patch management security concept & processes and standard operating procedures (SOP).
- Participation in the continuous improvement process (CIP) of the certified ISMS in preparation for the first surveillance audit.
- Regular reporting of project progress to the department management and board.
Senior Management Consultant BCM, Compliance & Information Security
Bitmarck Beratung GmbH
- Led and managed the project for implementing a Business Continuity Management (BCM) according to ISO 22301 and BSI IT-GS Standard 200-4.
- Defined the scope, created a BCM policy, and conducted a business impact analysis (BIA) and risk impact analysis (RIA).
- Developed IT emergency plans, vulnerability analysis, incident response processes, and IT system recovery (DRP).
- Created a project Gantt chart and prepared all required certification documents.
- The BCM project was not completed due to budget planning.
CISO as a Service – Chief Information Security Officer
EUROVIA Services GmbH
- Prepared and delivered awareness training for the company and its subsidiaries.
- Reviewed penetration test (PenTest) results and created an action plan to address identified vulnerabilities.
- Optimized IT processes to support business operations.
- Contributed to ensuring IT service availability.
- Reviewed existing ISMS documents for an as-is assessment and gap analysis to implement an ISMS according to ISO 27001.
Security Engineer, ISO, Senior Management Consultant Cyber & Information Security
Thales Deutschland GmbH Naval
- Member of the F126 team and co-responsible for the cyber and information security of the new F126 ships for the German Navy according to the German Military Security Accreditation Authority.
- Led the implementation of the largest Thales innovation projects in information security for the German Navy.
- Identified, assessed, and addressed critical and potential attack scenarios on the new F126 ships.
- Risk management, risk analysis, risk treatment, security requirement determination, IT emergency planning, vulnerability analysis, incident response processes, and IT infrastructure system recovery.
- Developed, adapted, and improved policies, hardening and security concepts, and SOPs.
- Created, maintained, and documented information security and emergency plans considering ISO 27001, BSI IT-Grundschutz & compendium, and German Military Security Accreditation Authority regulations (ZDV A-960/1).
- Contributed to the information security of the Digital Communication Network (DKN), Ship Entry Point (SEP), and satellite communication (SATCOM) systems.
- Advised and collaborated with specialist departments on conflicts between technical implementation and information security requirements.
- Applied the ISO/IEC 27001 standard according to BSI IT-Grundschutz & compendium and Bundeswehr IT-Grundschutz for the ISMS.
- Participated in workshops with the German Navy and other contractors in German and English.
- Collaborated with information security teams from France and the Netherlands.
ISO & Senior Management Consultant Compliance & Information Security
Federal Criminal Police Office (BKA)
- Responsible for certifying (attesting) the new cloud services of the Police Service Platform (PSP) to the international C5 standard.
- Conducted a gap analysis and contributed to building and improving an ISMS according to ISO 27001, IT-Grundschutz, and the new BSI compendium.
- Developed and adapted policies and SOPs for the entire agency (BCM, BIA, RIA, DRP, IT emergency plans).
- Created and improved information security (SiKo) and IT emergency plans for IT operations and cloud services (IAM, backup & recovery, patch management, crypto & key management, asset & configuration management).
- Collaborated with the SOC team to update the threat landscape.
- Conducted internal training sessions, workshops, and awareness activities.
- BKA security clearance SÜ2.
- The project was terminated early due to the COVID-19 pandemic.
CISO & Senior Management Consultant Compliance & Information Security
Dr. Glinz COViS GmbH
- Development of security concepts (SiKo) for the company and various software products.
- Conducting a pre-audit regarding GDPR with the result of over 90% compliance.
- Strategic further development of IT security, continuous improvement, and maintenance of the ISMS according to ISO 27001.
- Introduction of a concept for event handling and improvement of the SOC system.
- Conducting security assessments (penetration tests & vulnerability scans) to fix vulnerabilities.
- Developing new compliance services for clients and conducting workshops on ISMS and GDPR.
- Creating new guidelines, especially for using cloud services as a CSP and CSC.
Lead Auditor & Sr. Management Consultant Compliance & Information Security
TÜV SÜD
- Performing audits according to ISO 27001 for various clients.
- Conducting GDPR workshops and pre-audits for TÜV SÜD Munich and its clients.
Lead Auditor & Sr. Management Consultant Compliance & Information Security
SAP AG
- International Lead Audit Manager in quality management and information security according to ISO 9001, ISO 27001, ISO 22301, SOC, SOX, C5, PCI-DSS & SIEM.
- Focus on Cloud Network Delivery (CND) and global SAP cloud services.
- Collaborating with enterprise compliance, audit, and SOC teams for threat lifecycle management (TLM).
- Reviewing and improving the information security concepts of all SAP cloud services.
- Participating in the development of innovation projects in information security.
- Serving as the single point of contact between Cloud Network Delivery, users, and global compliance teams.
- Compliance project manager for CND (Cisco switches in global data centers).
CISO & Division Manager Compliance Services & Solutions
Makro Factory GmbH & Co. KG
- Planning, expansion, and setup of the new Compliance Services & Solutions division.
- Advising clients on implementing ISMS (ISO 27001), BCM (ISO 22301), IT baseline protection, and BaFin & MaRisk requirements.
- Successful implementation and dual certification of an ISMS (ISO 27001) and a BCM (ISO 22301) within 14 months.
- Achieving ISO 27017 / ISO 27018 certification for personal data protection as a cloud service provider (CSP).
- Conducting IT security assessments (penetration tests, vulnerability scans) and creating IT emergency plans.
- Conducting seminars, training sessions, and workshops on GDPR and information security.
- Performing information security audits according to ISO 27001, ISO 27006, and ISO 19011.
Senior Management Consultant Compliance & Information Security
Stadtsparkasse Düsseldorf
- Conducting banking security consulting regarding BaFin and MaRisk AT 8.2 compliance.
- Advising on IT requirements and secure IT operations measures (SITB).
- Advising on the outsourcing of network services under the German Banking Act (KWG 25a/b).
- Adjusting incident management for the switch of the network provider to Finanz Informatik (FI) according to MaRisk AT 9 outsourcing.
- Business analysis, modeling, and adaptation for outsourcing processes.
Strategic ITSCM, CISO, Business & eGRC Senior Management Consultant
Independent Entrepreneur
- Senior Project Manager, Business Analyst and Senior PMO as interim manager for banks, insurance, retail and industry.
- Technical roll out and change management for an international mining company during the introduction of new ERP systems.
- Strategic development of ITSCM, IT services and IT security as CISO ad interim.
- Implementation of ISMS according to ISO 27001 and BCM according to ISO 22301 in Chile, Argentina and Brazil.
- Business Development Manager ad interim for various IT companies.
- Business Analyst and interpreter for IT projects (Spanish/German/English).
Regional eRCP Manager & Senior PMO for all of Latin America
Zürich Shared Services – Insurance Company
- Responsible for enterprise release, configuration & promotion (deployment) as part of the global Growing Market Platform (GMP) project.
- Roll out of a new core insurance system for all Latin American business units of Zürich Insurance.
- Setting up, training and leading an eRCP team in Chile, Brazil and India.
- Regional problem, incident, change, release and crisis management across the entire application lifecycle.
- Single point of contact for Latin American users and collaboration with regional Change Advisory Boards (CAB).
- QA approval of software releases and development of test cases.
- Review and adjustment of contracts for external service providers (Accenture, CSC, Everis, Wipro).
- Personnel responsibility for more than 80 employees worldwide.
- Senior PMO for all non-core applications (legacy systems) in Latin America.
CISO ad interim & interim manager of IT & IT security departments
INE, Chilean Statistics Office
- Responsible for the preparation, programming and security of wireless solutions for digital data collection in the 2011-2012 census.
- Conducting training sessions for external staff on digital data collection.
- Strategic development of ITSCM, IT services and IT security as well as management of all innovation projects.
- IT department restructuring and negotiations with management and the works council.
- Introduction of policies according to ISO 27001, ISO 22301, ITIL, COBIT and OECD.
- Establishment and introduction of the first SOC with a SIEM platform for automated threat lifecycle management (TLM).
- Implementation of PMO, development and project methodologies (PMI, CMMI, CMMN).
- Leading cross-country telecommunications network improvement (RFP).
- Interim personnel responsibility for more than 50 employees.
CEO & Owner; Managing Director, CISO & Senior Consultant
ATNet Latin America Management Consulting GmbH
- Founder and Managing Director of an international IT management consulting company.
- Specialization in IT governance, risk & compliance, information security and electronic invoicing.
- Implementation and certification of ISMS (ISO 27001) and BCM (ISO 22301) at financial institutions in South America.
- Establishment of SOCs with SIEM platforms for banks in Chile.
- Development and distribution of an application for electronic invoicing with asymmetric cryptography.
- Lecturer for the Ministry of Economy and the Santiago Chamber of Commerce on strategic and technological aspects of cryptography.
- Workflow automation of foreign trade processes for a Brazilian bank.
- Consolidation of networks and server platforms to reduce TCO at a local bank.
- Introduction of IT security guidelines and reorganization of the IT department at Chile's largest mining and steel company.
- Personnel responsibility for over 120 employees.
CIO & COO – IT & Operations Manager
Chipkarten AG (ETISA)
- Introduction of an electronic cash card (eWallet) using smart card technology as a banking subsidiary.
- Management of the technology platform for eWallet administration as an open innovation project.
- Licensing of the cash card with Mondex International (MasterCard).
- Establishment and leadership of an interbank committee for operations and technology topics.
- Development of the model for production, operation and settlement of electronic cash in cooperation with banking supervision and the central bank.
- Development of the financial model for investment and profit distribution considering money market stability.
- Interface (Business Analyst) between banks for project implementation.
- Personnel responsibility for more than 20 employees.
Manager of Technological Remote Channels
Banco Crédito Inversiones (BCI)
- Operational management of technological remote channels: web, mobile banking, telephone banking, and ATMs.
- Drafting and defining the project to launch the first Chilean transaction-oriented banking website.
- Introduction of mobile digital banking.
- Leadership and control of external service providers.
- Personnel responsibility for over 40 employees.
Senior Consultant Electronic Banking
Banco Crédito Inversiones (BCI)
- Development, implementation, and management of all electronic banking products for the corporate sector.
- Development and rollout of e-commerce solutions for the bank.
- Consulting on the secure development of e-commerce and EDIFACT in Chile.
R&D Manager, Research and Technological Development
Banco Crédito Inversiones (BCI)
- Introduction of EDIFACT (Electronic Data Interchange) for the bank.
- Consulting on the setup of a bank EDI subsidiary.
- Development and launch of the first car-banking branch (drive-in branch).
- Personnel responsibility for over 10 employees.
Senior Consultant & Deputy Manager International Banking
Digital Equipment Corporation (DEC)
- Responsible for COMEX, Financial EDIFACT, and e-commerce for German and European banks.
- Responsible for the financial institutions sector at CeBIT.
- Development and roll-out of e-commerce at German banks.
- Member of European interbank committees in Frankfurt, Paris, and London.
- Leadership of an e-commerce project between commercial banks and the State Central Bank (LZB) in Frankfurt.
CIO and Authorized Officer
Société Générale
- Conducting benchmarking and procurement of the SWIFT-ST400 system for the entire bank.
- Planning, rollout, and training of the SWIFT system for all German branches.
- Introduction of the first wide area network (WAN) from Frankfurt to all federal branches using analog multiplexers.
- Definition and introduction of the new data center in Frankfurt.
- Personnel responsibility for over 40 employees.
- Career progression within the bank: promoted to CIO and Authorized Officer (1988), CTO (1986), Deputy CIO (1984), Software Engineering Team Leader (1983).
Summary
Diploma Engineer in Business Informatics from TU Santiago, Chile. Through my skills and experience, I have held various positions in Germany, Chile and other Latin American countries (CEO, CIO, COO, CTO, CISO, ISO, Sr. PM, Sr. PMO, etc.). My experience as CEO includes founding and leading my own IT service company, where I managed over 120 engineers and successfully completed large projects over a period of six years. My leadership style has always been shaped by a holistic talent management approach. Due to my German and Chilean citizenship, my wife and I lived in the Federal Republic of Germany from April 1981 to the end of June 1992 for the first time. Then we returned to Chile, became parents there and came back to Germany 23 years later (June 2015). In 2016, as ISO at an IT service company in Karlsruhe, I achieved a dual certification in Information Security and Business Continuity Management within 14 months, marking my first ISO certifications in Germany. In addition to these tasks, I familiarized myself with the EU General Data Protection Regulation (GDPR). However, my entrepreneurial spirit led me back to self-employment and since 2018 I have been a freelance Senior Management Consultant for Information Security and Business Continuity. For this role, I was certified by a recognized German company as an ISMS Lead Implementer and ISMS Lead Auditor, also for organizations and institutions in the field of critical infrastructures (KRITIS).
Summary of successful projects and key results:
- Makro Factory in Karlsruhe: As CISO, I implemented and certified an ISMS and a BCMS for the CSP and IT service company within 14 months
- SAP in Walldorf: As international Lead Audit Manager, I enabled the Cloud Network Delivery area to pass all audits (ISO 9001, ISO 27001, ISO 22301, C5, SOC, SOX and PCI-DSS)
- COViS in Düsseldorf: The software development company had an oversized ISMS and IT staff worked almost exclusively on it, leading to user dissatisfaction, friction and frustration. After aligning with the CEO and senior management, I adapted the ISMS to the actual needs. Since then, IT colleagues can satisfy their users and their needs
- Federal Criminal Police Office in Wiesbaden (BKA): As ISO, I led the organization to achieve certification of the new cloud services of the Police Service Platform to the international C5 standard and helped build and improve an ISMS according to ISO 27001 and the BSI IT-Grundschutz Compendium
- TÜV SÜD in Munich and Mannheim: Through my consulting and workshops on GDPR, the company was able to start offering data protection services
- German Navy via Thales Naval in Kiel: As Security Engineer and ISO, I helped certify the cyber & information security of the new frigates (F126) of the German Federal Navy according to the German Military Security Accreditation Authority (DEUmilSAA)
- University Hospital Düsseldorf: As ISO, I (among other things) created the new IT strategy for the UKD plus a security concept (BIA & DRP) for the restoration of IT systems; furthermore, I prepared for and successfully conducted both a surveillance audit and a recertification audit of the ISMS according to ISO 27001
- As PMO: Developed a security concept, conducted a proof of concept, evaluation, analysis through to procurement and implementation of a medical device monitoring security system to know which, how many and in what security state medical devices were connected to the campus network and to prevent further threats or attacks via the network
- Daimler Truck Financial Services: As Senior PMO, I created a master plan for the Cloud Data Center project, which gave the company a clear overview of the project after one year
- EnBW Energie Baden-Württemberg in Karlsruhe: As Senior IAM Specialist, I worked on improving the overall IAM concept and IAM processes of the entire company
Skills
Information Security Governance, Risk & Compliance: Consulting & Management For Implementing An Information Security Management System According To Iso 27001, A Business Continuity Management System According To Iso 22301 (Bia, Ria, Drp & Bsi It-gs 100-4 / 200-4), Dora And Nis2 Compliant
Gdpr Compliant With An Isms According To Iso 27001:2022 Plus Iso 27701
Bafin: Dora, Macomp & Xait Compliant; Marisk, Bait, Vait, Zag, Zait, Kait
Bsi: It Baseline Protection & Compendium As The German Foundation For Information Security
C5:2020 & Information Security: Cloud Computing Compliance Criteria Catalogue And Escloud
Setup, Roll-out & Services Of Secure Operation Center (Soc) & Siem, Ueba & Soar Platforms
Iam; Identity & Access Management, Cryptography & Key Management (Symmetric/asymmetric)
Audits In Information Security According To Iso 27001, 27006, 19011, Gdpr & Bsi-gs
Audits For Energy Supply Companies (So-called Kritis), According To Bnetza §11 Art. 1a Enwg
Project Management & Control Methods For Projects (Pgmp & Pmo According To Project Management Institute)
Itscm (Iso 27031), Itsm (Iso 20000), Sla, Crisis, Patch, Security Logging & Monitoring, Event, Incident, Problem Management, Etc.
Ercp Management: Enterprise Release, Configuration & Promotion/deployment, As Well As Release & Change Management (According To Itil & Cobit)
Strong Hands-on Mentality, Fast Analytical, Conceptual, Abstract And Logical Thinking
Service- And Solution-oriented, Conceptual, Strategic, Independent, Goal-oriented And Highly Structured Working Style Based On The Pestel Framework
High Sense Of Responsibility, Self-motivation, Flexibility And Trustworthiness
Creativity And Courage To Introduce And Drive New Ideas Following The Open Innovation Principle
High Assertiveness And Persuasive As A Point Of Contact With Users
Strong Cooperation And Team Skills
Strong Process Thinking In The Overall Concept And Modeling Of Business Processes
Very Good Communication Skills And Social Competence
Confident And Convincing Appearance
Experience Leading International Project Teams, Project Management, Pmo, Etc.
Audits In Eu General Data Protection Regulation (Gdpr)
Information Security Egrc – Enterprise Governance, Risk Management & Compliance According To Iso/iec 2700x Series, Iso 22301, Iso 27031, Bsi It Baseline Protection, Gdpr, German Federal Data Protection Act (Bdsg-new) And According To "Deumilsaa" German Military Security Accreditation Authority (Zdv A-960/1, Etc.)
Bcm, Business Continuity Management According To Iso 22301, Iso 27031 (Bia, Ria, Drp) And Bsi It Baseline Protection Standard 100-4 / 200-4, It Service Continuity Management (Itscm According To Iso 27031), Disaster Recovery Plan, Business Continuity Plan, It Emergency Concepts, Etc.
Kritis: Bsig §8a Para 1a And Use Of Attack Detection Systems (Sza), Early Detection Of Cyber Attacks, Incident Response Management & Rebuilding It Systems
C5 & Escloud: Security Concepts For Using Cloud Services (Csp & Csc)
Iam; Identity And Access Management
Bafin: Dora, Macomp And Xait Compliant (Bait, Vait, Zait, Kait); Management Consulting For Credit Institutions, Marisk, Zag
Audits According To Iso 9001, Iso 27000, Iso 27001, Iso 27006, Iso 19011, Iso 22301, Soc, Sox, C5, Pci-dss And Kritis Regulation §11, Art. 1a Enwg And Bsi It-gs
Irbc According To Iso 27031; It Readiness For Business Continuity To Minimize Enterprise-threatening It Risks And Take Effective Countermeasures
Pm & Pmo According To Pmi, It Service Continuity Management According To Iso 20000 & Itil, Cobit, Cmmi
Languages
Education
TU Santiago
Diploma Engineer (TH/TU), specialization in Business Informatics · Business Informatics · Santiago, Chile
Certifications & licenses
Cisa/Cism: Certified Information System & Security Lead Auditor according to ISO 27000 TÜV SÜD series and ISO 19011
TÜV SÜD
Ciso: Chief Information Security Officer / Professional according to ISO 2700X series
TÜV SÜD
Certified ISMS Lead Auditor according to the IT Security Catalogue of the German Federal Network Agency (BNetzA)
Bundesnetzagentur
Certified ISMS Lead Implementer according to ISO/IEC 2700X series
TÜV SÜD
Similar Freelancers
Discover other experts with similar qualifications and experience