Kerim Tvrtkovic
Senior Cybersecurity Professional
Experience
Head of Cybersecurity Audit and Advisory
Henkel Chemicals
- Directed global IT and cybersecurity audit and advisory engagements, steering cross-functional teams across multiple regions and business units.
- Provided strategic advisory to senior management, interacting with stakeholders and communicating with relevant departments on the second line of defense.
- Evaluated risks for strategic developments and emerging technologies and designed security assessment approaches for ISMS, DevOps, automation tools, cloud services, SAP Cloud, web application security, and vulnerability management.
- Provided training to the team and other relevant staff on IT and cybersecurity audit practices and standards.
Cybersecurity Management Consultant (IT/OT)
Freelance
- Led the implementation of an ISMS aligned with the BNetzA IT Security Catalogue, achieving regulatory compliance for an energy company.
- Supported regulatory audit readiness initiatives by structuring evidence collection processes, aligning IT controls with supervisory expectations, and tracking remediation measures to closure.
- Conducted an IEC 62443-based OT security assessment for a rail logistics company, identifying critical control gaps and defining a target security architecture roadmap prioritized by risk and operational impact.
- Designed and implemented an IT emergency and recovery framework for AWS-based platforms, improving incident response coordination and strengthening operational resilience capabilities.
Senior Manager IT Audits
DHL Group
- Held end-to-end responsibility for all IT audit projects including stakeholder management and audit topic alignment.
- Focused on cybersecurity areas such as Privileged Access Management (PAM), technical threat and vulnerability assessments, web application security, and cloud security.
- Identified and evaluated strategic IT risks for the DHL Group and defined IT audit plans.
- Presented at conferences of the German Institute of Internal Auditors (DIIR).
- Led and managed audit teams for various internal IT audits.
- Developed risk and compliance-based audit programs for SAP ERP and HANA.
- Presented audit findings and prepared audit reports.
Associate Security Consulting & IT Compliance
KPMG AG
- Conducted IT audits for accounting-relevant IT systems within the scope of annual financial statement audits.
- Audited archiving and email messaging systems according to regulatory requirements.
- Provided consulting services for information security management systems according to ISO 27001 and business continuity management systems according to ISO 22301.
Industries Experience
See where this freelancer has spent most of their professional time. Longer bars indicate deeper hands-on experience, while shorter ones reflect targeted or project-based work.
Experienced in Transportation (11 years), Energy (2.5 years), Chemical (1.5 years), and Professional Services (1 year).
Business Areas Experience
The graph below provides a cumulative view of the freelancer's experience across multiple business areas, calculated from completed and active engagements. It highlights the areas where the freelancer has most frequently contributed to planning, execution, and delivery of business outcomes.
Experienced in Information Technology (12 years) and Audit (11 years).
Summary
Senior Cybersecurity & IT Audit Expert with over 10 years of experience in regulatory audit coordination, IT risk management, and operational resilience within international corporations and critical infrastructure environments. Specialized in regulatory compliance (DORA, NIS2, BAIT, EnWG, MaRisk, ISO 27001) as well as the coordination of complex audit and evidence collection processes involving internal and external auditors. Extensive experience in the structured implementation of ICT risk management, operational resilience frameworks, and third-party governance.
Skills
- Cybersecurity & Isms: Design And Implementation Of Isms Aligned With Iso 27001, Bsi It-grundschutz And Nist; Regulatory Audit Readiness And Control Optimization.
- It Governance, Risk & Compliance (Grc): It Risk Management And Regulatory Compliance (Kritis, Nis2, Dora, Bait, Vait, Marisk, Gdpr) In Regulated Environments.
- Identity & Access Management: Privileged Access Management (Pam) And Identity Governance To Reduce Operational And Regulatory Risk.
- Cloud Security: Azure And Sap Cloud Security Assessments, Governance Models And Control Enhancement.
- Ot Security: Security Assessments And Resilience Improvement For Ics Environments (Scada, Plcs, Industrial Networks).
- Operational Resilience & Itscm: Business Continuity, It Service Continuity And Disaster Recovery Governance.
- Secure Development & Devsecops: Security-by-design In Ci/cd Pipelines (Sast, Dast, Sca, Owasp).
- Third-party Risk & Service Governance: It Third-party Risk Assessments, Provider Oversight And Remediation Tracking.
- Leadership & Talent Development: Steering Cross-functional Teams And Security Initiatives In Complex, Regulated Environments.
Languages
Education
Fern Universität Hagen
Bachelor studies · Business Informatics · Hagen, Germany
Bergische Universität Wuppertal
Master’s degree · Technology and Innovation Management · Wuppertal, Germany
Hochschule Koblenz - RheinAhrCampus
Bachelor’s degree · Logistics, Supply Chain, and e-Business · Remagen, Germany
Certifications & licenses
Certified Information Systems Security Professional (CISSP)
Microsoft Azure Fundamentals (AZ 900)
Microsoft Security, Compliance, and Identity Fundamentals (SC 900)
Certified Information Systems Auditor (CISA)
Cobit® 5 Foundation
ISO 27001 Lead Auditor
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Kerim based?
What languages does Kerim speak?
How many years of experience does Kerim have?
What roles would Kerim be best suited for?
What is Kerim's latest experience?
What companies has Kerim worked for in recent years?
Which industries is Kerim most experienced in?
Which business areas is Kerim most experienced in?
Which industries has Kerim worked in recently?
Which business areas has Kerim worked in recently?
What is Kerim's education?
Does Kerim have any certificates?
What is the availability of Kerim?
What is the rate of Kerim?
How to hire Kerim?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Head of Cybersecurity Audit and Advisory
Nearby freelancers
Professionals working in or nearby Sankt Augustin, Germany