Lucas (MSc) Garzarolli

Management Consultant

Hallwang bei Salzburg, Austria

Experience

Nov 2021 - Present
3 years 9 months

Management Consultant

nospia e.U.

  • Improvement of security posture and risk reduction for numerous companies.
  • Establishing a stable foundation for data protection and information security.
  • Successful handling of complex IT projects.
Jun 2020 - May 2021
1 year

Security Officer

x-tention

  • Executed internal and external data protection and information security projects.
  • Conducted workshops for clients with critical infrastructure in industry and healthcare.
Jun 2018 - Feb 2020
1 year 9 months

Security Officer

Usabilla by Surveymonkey

  • Responsible for information security and data protection: strategy, processes, communication and product enhancements.
  • Implemented an information security management system (ISMS).
  • Achieved successful ISO 27001 initial certification with no non-conformities.
Aug 2016 - May 2018
1 year 10 months

Security & Privacy Consultant

Deloitte

  • Advising on data protection (GDPR), information security and risk management.
  • Conducted security awareness training for clients in various industries.
Dec 2013 - May 2016
2 years 6 months

Quality Specialist

Socionext EU

  • Managed and developed the central project management platform.
  • Designed and implemented an authorization concept to resolve SoD conflicts.
  • Optimized existing IAM systems.

Summary

For over a decade, I have supported companies in information security, data protection, governance, risk management, compliance (GRC) and project management. Working as an external consultant and internal security officer has given me not only a solid understanding of compliance management but also taught me how to handle the various organizational challenges that come with it. I am highly committed and always do my best to complete projects as efficiently as possible and to the full satisfaction of my clients.

  • Introduction and optimization of information security management systems (ISMS) Leadership and support for ISO 27001 initial and re-certifications. Projects included defining clear security strategies and setting measurable goals as well as implementing and optimizing documentation, processes and controls in the following areas: risk management, business continuity management, change management, coordination of penetration tests, asset management, business partner vetting, internal audit.
  • Compliance and data protection consulting: structuring and formalizing compliance management, creating and improving documentation, policies and processes, conducting gap analyses and implementing measures to ensure compliance with the EU GDPR, other European laws and some international legislation in data protection and information security.
  • Workshops and training: Security awareness: designing and delivering security awareness programs for employee onboarding, as well as advanced modules for continuing education and refreshers, additional materials and regular communications. Data protection and EU GDPR: conducting workshops and training to raise awareness of general data protection requirements and to implement and communicate policies to ensure compliance with defined processes.
  • Audits and assessments: conducting internal and external audits, including comprehensive risk assessments, GDPR gap analyses and IT audits as part of annual audits. Planning and documenting required measures, carrying out controls, training employees, presenting results in management reports.
  • Contract agreements and negotiations: drafting and adapting NDAs, data processing agreements under the EU GDPR and information security agreements, and negotiating them in the international B2B sector with SMEs and Fortune 500 companies.
  • Project management: coordinating complex projects with various internal and external stakeholders, including cross-functional collaboration in alignment with management.
  • CISO and data protection officer: leading security and data protection initiatives as an experienced security officer and certified data protection officer. In addition to my practical experience, I am prepared for many technical and organizational challenges through certifications such as ISACA CRISC or Mediation.

Languages

German
Native
English
Advanced
Dutch
Elementary
Italian
Elementary
Portuguese
Elementary

Education

JKU Linz

Master of Science · Business Informatics · Linz, Austria

Certifications & licenses

Certified Data Protection Officer

WIFI Austria

Certified Mediator

London School of Mediation

CRISC Certification

ISACA