Günther Eufinger
Senior Consultant
Experience
Senior Consultant
ISMS Rollout – Information Security Certification (ISO 27001)
- Set up and successfully certified the Information Security Management System (ISMS) according to ISO 27001 in seven country organizations (Ghana, India, Bangladesh, Uzbekistan, Serbia, Kosovo, Albania).
- Fully implemented the ISMS from kickoff to certification, including defining the governance structure and process landscape.
- Developed and delivered target-group-oriented training and coaching for local leads on information security basics and ISMS operations.
- Designed and continuously optimized training concepts and content to increase understanding and acceptance.
- Identified and implemented improvements in processes and tools, including in risk management for international projects.
- Optimized central ISMS core processes from concept through pilot operation and fine-tuning to global rollout.
- Enhanced knowledge management as well as tools and methods for the global ISMS team.
- Led and facilitated cross-functional alignments with key ISMS interfaces.
- Microsoft Teams, Excel, SharePoint Lists, Power Apps.
Project Manager / Business Analyst
Governance & Corporate Security & Information Cyber Security Program
- Expanded management systems for crisis management and maintaining delivery capability in terms of business continuity.
- Served as project coordinator in the company-wide cyber security program.
- Updated mission statements for business units: values, tasks, and guidelines in line with corporate strategy.
- Revised central policies on corporate security, crisis management, and information security.
- Conceptualized and technically designed KPI reporting.
- Designed and facilitated the development of the road map for company-wide ISMS governance in line with TISAX / ISO 27001.
- Main focus areas: cyber risk assessment, cyber incident and emergency management.
- Coached project teams for efficient project execution and ensured project results.
- Project management using agile framework.
- Microsoft Teams, Excel, SharePoint Lists, Power Apps, Power BI.
Business Analyst
Financial Accounts Information Act Concept (FKAustG)
- Business analysis and design to implement the new legal regulation on reporting account information to tax authorities (FKAustG).
- Validated tasks and objectives.
- Designed and facilitated management workshops to identify relevant processes and systems.
- Led the definition of technical requirements.
- Evaluated technical and operational risks.
- Process analysis and documentation.
- Derived solution concepts and recommendations.
- Prepared the results report.
- Confluence, MS Office 365.
Project Manager
IT Implementation of the New Garnishment Protection Accounts Regulation
- Implemented new legal requirements for garnishment protection accounts on the mainframe host, including integration of self-service devices (banking terminal and digital child terminal).
- Verified tasks and objectives.
- Supported business analysis including risk analysis.
- Defined project organization and milestone planning.
- Defined IT requirements.
- Led management workshops to define technical requirements, including risk and security requirements.
- Approved technical concepts for mainframe infrastructure.
- Managed budgeting, contracting, and oversaw technical implementation by vendors.
- Maintained the product backlog for agile program components.
- Quality assurance & testing: coverage, test strategy, etc.
- Developed test concept and led execution across all phases to final acceptance.
- Prepared commissioning, pilot, and rollout.
- Handled budgeting, project control, and reporting to the steering committee.
- Used HP ALM for requirements definition, in-house tool for budget and progress reporting, Confluence for defining requirements, use cases, and product backlog.
Project Manager
Information and Cyber Security Program
- Expanded the digital security architecture in IT security, operations technology security (OT security), and information security.
- Enhanced the Information Security Management System as a coordinating function in close collaboration with the CISO.
- Supported the Chief Information Security Officer (CISO) as program manager in conceptual and administrative matters.
- Set project strategy.
- Defined workstreams and deliverables.
- Prioritized measures.
- Planned milestones.
- Designed and prepared project reports for management.
- Managed stakeholders and communication.
- Planned and controlled budget.
- Approved deliverables from workstreams.
- Ensured audit-compliant project documentation.
- Structured project management according to PRINCE.
Project Manager
Heraeus Group
- Expanded corporate data protection to meet GDPR requirements.
- Expanded the data protection management system for the Heraeus Group and its subsidiaries.
- Conducted stakeholder analysis.
- Derived project strategy, roadmap, and project structure.
- Defined data protection processes: from documenting procedures to handling incidents.
- Change management: developed and delivered extensive training and awareness measures for over 400 participants.
- Led management workshops with all business units.
- Recorded and analyzed existing personal data processing activities.
- Implemented IT system for data protection management.
- Conducted business analysis and gathered requirements from stakeholders.
- Designed processes and defined user stories.
- Managed the product backlog.
- Supported development in close collaboration with the Scrum team.
- Led the project using traditional and agile management methods for the IT solution.
- Reported to the Steering Committee.
Product Owner
lexiCan
- Designed, developed, and delivered the completely revamped version of the lexiCan Wiki software to over 500 business customers.
- Analyzed market requirements and competitive landscape.
- Positioned the product in the market.
- Defined core requirements.
- Translated requirements into use cases.
- Developed use cases into technical concepts.
- Managed the product backlog.
- Oversaw UX design processes.
- Supported development and testing.
- Supported product launch and market penetration.
- Established quality assurance for the end customer.
Project Manager
Schaeffler AG
- Expanded and implemented the compliance management system (CMS) group-wide for Schaeffler AG and the Schaeffler Group.
- Analyzed the entire IT landscape for compliance risks.
- Supported the Chief Information Security Officer (CISO) as program manager in conceptual and administrative matters.
- Supported the definition of objectives.
- Conceptualized and designed the enhanced compliance management system.
- Developed the first comprehensive and structured compliance risk analysis framework.
- Conceptualized and planned workshop series to define and prioritize compliance measures.
- Evaluated inputs for analysis.
- Set up risk reporting.
- Conceptualized and implemented the establishment of the Group Compliance Risk Committee (GCRC).
- Rolled out measures internationally across all regions.
- Tracked implementation and reporting.
Team Lead Central Compliance Services
Deutsche Bank Group
- Enforced IT governance and audit compliance for all critical business applications of the Deutsche Bank Group.
- Translated audit requirements into a remediation plan and established the necessary business processes.
- Managed the central product backlog in HP ALM.
- Continuously prioritized backlog items.
- Set up consolidated status reporting from individual Scrum teams.
- Ran multiple process optimization cycles in the program.
- Reported to stakeholders and program management.
- Agile project management.
Business Analyst
Deutsche Bank AG
- Various projects to optimize services and operations for the self-service business of Deutsche Bank AG.
- Migrated the operations platform and introduced new middleware and operating systems.
- Set up the business analysis team.
- Defined the analysis scope based on constraints.
- Developed the approach and methods for business analysis.
- Implemented and structured the analysis areas in workshops.
- Ensured quality through active coordination with Postbank employees.
- Aligned results with the relevant departments until final approval.
- Designed the quality assurance concept and rollout approach.
Project Manager
Deutsche Bank AG
- Migration of Berliner Bank and processing transactions in payments (direct debits, transfers, checks).
- Implementation of two new software systems and adjustments in the existing core IT infrastructure of Deutsche Bank AG.
- Gathering requirements from Berliner Bank's products.
- Defining requirements for IT and process changes.
- Leading teams for functional and technical system design.
- Monitoring low-level design and implementation by the IT service provider.
- Managing and monitoring test cycles (functional testing, integration testing, UAT).
- Deploying software products to production.
- Project reporting and risk management.
- Facilitating and coordinating between teams and business units.
Project Manager
MasterCard Worldwide
- Lead project for the takeover of the Lufthansa Miles & More credit card portfolio: importing customer data, designing and producing cards, issuing to over 1 million customers.
- First introduction of contactless payment technology at POS in Germany.
- Verifying project goals and milestone planning with eight partner companies.
- Coordinating project tasks across all involved companies.
- Publishing regular and ad-hoc reports for senior management.
- Facilitating coordination meetings and project documentation.
- Temporarily taking over project leadership for MasterCard.
- Designing concept for technical basis to systematically capture technical issues in card sales.
- Defining criteria for systematic evaluation of issues.
- Coordinating initial analysis and distribution of issues to subsequent units.
- Tracking and supporting issue resolution.
- Designing and executing reporting.
Industries Experience
See where this freelancer has spent most of their professional time. Longer bars indicate deeper hands-on experience, while shorter ones reflect targeted or project-based work.
Experienced in Banking and Finance (8 years), Information Technology (7 years), Manufacturing (2.5 years), Professional Services (2 years), and Automotive (2 years).
Business Areas Experience
The graph below provides a cumulative view of the freelancer's experience across multiple business areas, calculated from completed and active engagements. It highlights the areas where the freelancer has most frequently contributed to planning, execution, and delivery of business outcomes.
Experienced in Project Management (12 years), Information Technology (11 years), Quality Assurance (5.5 years), Business Intelligence (5 years), Product Development (4.5 years), and Audit (2.5 years).
Summary
For more than 10 years I have helped projects succeed in security and risk management, and in recent years I have been focusing clearly on information security. I work with international corporate groups as well as public-sector clients.
I bring strong skills in designing policies and service-oriented processes and tools for risk management according to established standards like ISO 27001 and NIST.
My excellent analytical skills and structured communication support me in this. I also have a good sense for what is practical and for the human factor in this task.
I think systemically, act pragmatically, and work well in teams.
Skills
- Over 10 Years Of Experience In Designing And Implementing Management Systems, Especially Isms And Grc: From Planning To Successful Certification
- Several Years Of Experience In System Design For Kritis
- Several Years Of Hands-on Experience With Standards (Iso 27001, Iso 31000, Bsi, Nist, Etc.)
- Outstanding Skill In User-oriented Design Of Policies, Processes, And Systems And In Coordinating With Related Areas
- Project Management Pro With Over 20 Years Of Experience, Skilled In Both Agile And Traditional Methods
- Automation And Integration Of Compliance Requirements Into Processes, Including Strict Supplier Management
- Extensive Expertise In Performance Measurement (Kpis)
- Strong Implementation Skills And Teamwork
- Proven Communication Skills, Especially In Presenting Complex Technical Matters In A Reader-friendly Way For Board Level
Languages
Education
Diploma in Industrial Engineering · Industrial Engineering
Certifications & licenses
ISO 27001
ITIL Foundation
Scrum Master
Scrum Product Owner
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Günther based?
What languages does Günther speak?
How many years of experience does Günther have?
What roles would Günther be best suited for?
What is Günther's latest experience?
What companies has Günther worked for in recent years?
Which industries is Günther most experienced in?
Which business areas is Günther most experienced in?
Which industries has Günther worked in recently?
Which business areas has Günther worked in recently?
What is Günther's education?
Does Günther have any certificates?
What is the availability of Günther?
What is the rate of Günther?
How to hire Günther?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Senior Consultant
Nearby freelancers
Professionals working in or nearby Offenbach am Main, Germany