Setup and successful certification of the Information Security Management System (ISMS) according to ISO 27001 in seven country organizations (Ghana, India, Bangladesh, Uzbekistan, Serbia, Kosovo, Albania).
Tools:
Expansion of management systems for crisis response and maintaining delivery capability in terms of business continuity. Project coordinator in the company-wide cyber security program.
Combination of agile and traditional approaches.
Tools:
Business analysis and design to implement the new legal requirements for reporting account information to tax authorities (FKAustG).
Tools: Confluence, MS Office 365
Implementing the new legal requirements for garnishment protection accounts in the Mainframe HOST area, including integration of self-service devices (banking terminal and digital child terminal).
Combination of agile and traditional approaches.
Tools:
Expansion of the digital security architecture in the areas of IT Security, Operations Technology Security (OT-Security), and Information Security. Expansion of the Information Security Management System as a binding function in close cooperation with the CISO.
Supporting the Chief Information Security Officer (CISO) as program manager in conceptual and administrative matters:
Expansion of corporate data protection to meet GDPR requirements. Corresponding expansion of the data protection management system for the Heraeus Group and its subsidiaries.
Agile development for design, development, and implementation of the IT platform; classic methodology in the overall project.
Leading the project for the compliance area under the guidelines and close support of the data protection officer:
IT system implementation for data protection management:
Concept, technical implementation, and delivery of the fully redesigned product version for over 500 business customers.
Agile (Scrum).
Responsible IT project manager:
The project covered the company-wide expansion and establishment of the Compliance Management System (CMS) for Schaeffler AG and the Schaeffler Group. This included analyzing the entire IT landscape for compliance risks.
Classic methodology.
Supporting the Chief Information Security Officer (CISO) as program manager in conceptual and administrative matters:
The program enforces IT governance and audit compliance for all critical business applications of the Deutsche Bank Group. The team was responsible for translating audit requirements into a remediation plan and establishing the necessary business processes.
Agile (Scrum).
Various projects to optimize services and operations for the self-service business of Deutsche Bank AG. This included migrating the operations platform, introducing new middleware and operating systems.
Classic methodology.
For the migration of the Berlin Bank, the processing of payment transactions (direct debits, transfers, checks) was addressed. Two new software systems and adjustments to the existing core IT infrastructure of Deutsche Bank AG were implemented for this purpose.
Classic methodology.
Overall project to take over the largest German credit card portfolio: migration of customer data, design and production of cards, issuance to over 1 million customers. Including the first introduction of contactless payment technology at POS in Germany.
Classic approach for the overall project, agile for resolving quality issues.
For more than 10 years I have helped projects succeed in security and risk management, with a clear focus on information security in recent years. I work for international corporate groups and public sector clients alike.
I bring strong skills in designing appropriate policies and service-oriented processes and tools for risk management according to established standards like ISO 27001 and NIST.
My outstanding analytical abilities and structured communication support me in this work. I also have a sense for practical solutions and the human factor.
I think systemically, act pragmatically, and work well in teams.
Discover other experts with similar qualifications and experience
2025 © FRATCH.IO GmbH. All rights reserved.