Günther E.

Senior Consultant

Offenbach am Main, Germany

Experience

Jun 2023 - Aug 2025
2 years 3 months

Senior Consultant

ISMS Rollout – Information Security Certification (ISO 27001)

Setup and successful certification of the Information Security Management System (ISMS) according to ISO 27001 in seven country organizations (Ghana, India, Bangladesh, Uzbekistan, Serbia, Kosovo, Albania).

  • Full implementation of the ISMS from kick-off phase to certification, including defining the governance structure and process landscape.
  • Development and delivery of targeted training, workshops, and coaching for local stakeholders on information security basics and ISMS operations.
  • Designing and continuously optimizing training concepts and content to increase understanding and acceptance.
  • Identifying and implementing improvements in processes and tools, including risk management for international projects.
  • Optimizing central ISMS core processes from initial idea through pilot phase and fine-tuning to global rollout.
  • Improving knowledge management as well as tools and methods for the global ISMS team.
  • Setting up and moderating cross-departmental coordination with key ISMS interfaces.

Tools:

  • Microsoft Teams, Excel, SharePoint Lists, Power Apps
Feb 2022 - Jun 2023
1 year 5 months

Project Manager / Business Analyst

Governance & Corporate Security & Information Cyber Security Program

Expansion of management systems for crisis response and maintaining delivery capability in terms of business continuity. Project coordinator in the company-wide cyber security program.

Combination of agile and traditional approaches.

  • Updating the guiding principles of business units: values, tasks, and guidelines in line with the corporate strategy
  • Revising central policies for corporate security, crisis management, and information security
  • Conceptual and technical design of the KPI reporting
  • Concept and facilitation of the roadmap development for company-wide ISMS governance in line with TISAX / ISO 27001
  • Main focus areas: cyber risk assessment and cyber incident and emergency management
  • Coaching project teams for efficient project execution and ensuring project deliverables
  • Project management according to an agile framework

Tools:

  • Microsoft Teams, Excel, SharePoint Lists, Power Apps, Power BI
Sep 2021 - Dec 2021
4 months

Business Analyst

Konzept Finanzkonten-Informationsgesetz (FKAustG)

Business analysis and design to implement the new legal requirements for reporting account information to tax authorities (FKAustG).

  • Validating the assignment and objectives
  • Designing and facilitating management workshops to identify relevant processes and systems
  • Leading the definition of technical requirements
  • Evaluating technical and operational risks
  • Process analysis and documentation
  • Deriving solution concepts and recommendations
  • Creating the final report

Tools: Confluence, MS Office 365

Mar 2021 - Dec 2021
10 months

Project Lead

IT Implementierung Neureglung Pfändungsschutzkonten

Implementing the new legal requirements for garnishment protection accounts in the Mainframe HOST area, including integration of self-service devices (banking terminal and digital child terminal).

Combination of agile and traditional approaches.

  • Verifying the assignment and objectives
  • Supporting the technical analysis, including risk analysis
  • Defining project organization and milestone planning
  • Defining IT requirements
  • Leading management workshops to define technical requirements, including risk and security requirements
  • Approving technical concepts for mainframe infrastructure
  • Budgeting, contracting, and overseeing the technical implementation by vendors
  • Managing the product backlog for agile program parts
  • Quality assurance & testing: coverage, test strategy, etc.
  • Creating the test concept and leading its execution across all phases and final acceptance
  • Preparing commissioning, piloting, and rollout
  • Budgeting, project control, and reporting to the Steering Committee (SteeCo)

Tools:

  • HP ALM for requirement definition
  • In-house tool for budget and progress reporting
  • Confluence for defining requirements, use cases, and product backlog
Jun 2019 - Dec 2020
1 year 7 months

Project Manager

Information and Cyber Security Program

Expansion of the digital security architecture in the areas of IT Security, Operations Technology Security (OT-Security), and Information Security. Expansion of the Information Security Management System as a binding function in close cooperation with the CISO.

Supporting the Chief Information Security Officer (CISO) as program manager in conceptual and administrative matters:

  • Strategic project alignment
  • Definition of workstreams and deliverables
  • Prioritization of measures
  • Milestone planning
  • Designing and preparing project reports for senior management
  • Stakeholder management and communication
  • Budget planning and control
  • Approval of deliverables from the workstreams
  • Ensuring audit-compliant project documentation
  • Structured project management according to PRINCE
May 2018 - Feb 2019
10 months

Project Manager

Heraeus Group

Expansion of corporate data protection to meet GDPR requirements. Corresponding expansion of the data protection management system for the Heraeus Group and its subsidiaries.

Agile development for design, development, and implementation of the IT platform; classic methodology in the overall project.

Leading the project for the compliance area under the guidelines and close support of the data protection officer:

  • Stakeholder analysis
  • Deriving project strategy, roadmap, and project structure
  • Defining data protection processes: from documenting procedures to handling incidents
  • Change management: developing and delivering comprehensive training and awareness measures for over 400 participants
  • Leadership workshops with all business units
  • Recording and analyzing existing personal data processing activities

IT system implementation for data protection management:

  • Business analysis, gathering requirements from stakeholders
  • Process design and defining user stories
  • Managing the product backlog
  • Overseeing development closely with the Scrum team
  • Project management using classic methods and agile management for the IT solution
  • Reporting to the Steering Committee
Apr 2016 - Apr 2018
2 years 1 month

Product Owner

lexiCan

Concept, technical implementation, and delivery of the fully redesigned product version for over 500 business customers.

Agile (Scrum).

Responsible IT project manager:

  • Analyzing market requirements and competitive situation
  • Market positioning
  • Defining the basic requirements
  • Converting into use cases
  • Developing use cases as technical designs
  • Managing the product backlog
  • Overseeing UX design processes
  • Supporting development and testing
  • Assisting product launch and market penetration
  • Establishing quality assurance for end customers
Oct 2014 - Aug 2016
1 year 11 months

Project Manager

Schaeffler AG

The project covered the company-wide expansion and establishment of the Compliance Management System (CMS) for Schaeffler AG and the Schaeffler Group. This included analyzing the entire IT landscape for compliance risks.

Classic methodology.

Supporting the Chief Information Security Officer (CISO) as program manager in conceptual and administrative matters:

  • Assisting with defining objectives
  • Designing the extended Compliance Management System
  • Developing the approach for a first comprehensive and structured compliance risk analysis
  • Designing and planning a series of workshops to define and prioritize compliance measures
  • Evaluating inputs for analysis
  • Setting up risk reporting
  • Planning and implementing the establishment of the Group Compliance Risk Committee (GCRC)
  • International rollout of measures across all regions
  • Tracking implementation and reporting
May 2014 - Oct 2014
6 months

Team Lead Central Compliance Services

Deutsche Bank AG

The program enforces IT governance and audit compliance for all critical business applications of the Deutsche Bank Group. The team was responsible for translating audit requirements into a remediation plan and establishing the necessary business processes.

Agile (Scrum).

  • Managing the central product backlog in HP ALM
  • Continuous prioritization
  • Setting up consolidated status reporting from the individual Scrum teams
  • Multiple process optimization cycles within the program
  • Reporting to stakeholders and program management
  • Agile project management
Sep 2010 - Mar 2014
3 years 7 months

Business Analyst

Deutsche Bank AG

Various projects to optimize services and operations for the self-service business of Deutsche Bank AG. This included migrating the operations platform, introducing new middleware and operating systems.

Classic methodology.

  • Setting up the business analysis team
  • Defining the scope of analysis based on the framework conditions
  • Developing the approach and methods for business analysis
  • Implementing and structuring analysis areas in workshops
  • Ensuring quality through active coordination with Postbank staff
  • Aligning results with the involved departments until final approval
  • Designing the quality assurance concept and rollout approach
Feb 2010 - Sep 2010
8 months

Project Manager

Deutsche Bank AG

For the migration of the Berlin Bank, the processing of payment transactions (direct debits, transfers, checks) was addressed. Two new software systems and adjustments to the existing core IT infrastructure of Deutsche Bank AG were implemented for this purpose.

Classic methodology.

  • Gathering requirements from the Berlin Bank's products
  • Defining the requirements for IT and process changes
  • Leading the teams in functional and technical system design
  • Monitoring the low-level design and implementation by the IT service provider
  • Managing and monitoring the test cycles (functional test, integration test, UAT)
  • Transitioning the software products into production
  • Project reporting / risk management
  • Facilitating and coordinating between teams and business units
May 2007 - Dec 2009
2 years 8 months

Project Manager

MasterCard

Overall project to take over the largest German credit card portfolio: migration of customer data, design and production of cards, issuance to over 1 million customers. Including the first introduction of contactless payment technology at POS in Germany.

Classic approach for the overall project, agile for resolving quality issues.

  • Verifying project goals and definitions
  • Leading milestone planning and coordinating with the managers responsible at the eight involved partner companies
  • Coordinating project tasks across all participating companies
  • Publishing regular and ad-hoc reports for Senior Management
  • Facilitating coordination meetings
  • Project documentation
  • Temporary project leadership for MasterCard
  • Concept for the technical basis to systematically capture technical issues in card sales
  • Defining criteria for the systematic evaluation of issues
  • Coordinating initial analysis and distribution of issues to subsequent units
  • Tracking and supporting issue resolution
  • Design and execution of reporting

Summary

For more than 10 years I have helped projects succeed in security and risk management, with a clear focus on information security in recent years. I work for international corporate groups and public sector clients alike.

I bring strong skills in designing appropriate policies and service-oriented processes and tools for risk management according to established standards like ISO 27001 and NIST.

My outstanding analytical abilities and structured communication support me in this work. I also have a sense for practical solutions and the human factor.

I think systemically, act pragmatically, and work well in teams.

Languages

German
Native
English
Advanced

Education

Lorem ipsum dolor sit amet

Diploma · Industrial Engineering

Certifications & licenses

ITIL Foundation

Professional Scrum Product Owner I

Scrum Master I

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions