Oliver F.

Senior IT Enterprise Security Architect | Bank Migration Project

Karlsruhe, Germany

Experience

Jan 2020 - Dec 2023
4 years

Senior IT Enterprise Security Architect | Bank Migration Project

Freelance

Client: Deutsche Bank AG (retail bank). Industry: Financial services / one of Germany’s top private and business banks.

Merger/insourcing project in banking: transferring all data, users, and processes from one bank to the parent company.

  • IT Security Architect in CSO (Chief Security Office) at Deutsche Bank for a Postbank merger/insourcing project
  • Developed a clustering concept for all migrating applications based on complexity criteria (risk profile, protection needs, compliance), considering: Deutsche Bank’s ISMS on ISO27001 vs. Postbank’s ISMS on BSI IT baseline protection. Protection analyses, risk assessments, and risk management processes differ and must be reviewed and adapted per application. Reviewed and aligned IT security architecture with bank, infrastructure, and target domain requirements.
  • IT security architecture: Lead advisory for all program subprojects on architecture and concepts (integration patterns like batch, online/web services, MQ), and prepared new components for review and approval by the bank’s decision councils.
  • IT security consultancy: Lead subject matter expert on all technical and content questions in the project.
  • Compliance: Supported all vertical streams (Sales & Channels, Investments, Lending, Finance, Enterprise, etc.) in creating documentation and architectures for shared patterns and presenting to councils.
  • Risk management: Led review responses for all streams on compliance questions for test system configurations. Reviewed full architecture and analyzed deviations. Conducted threat assessments.
  • Risk governance: Lead security architect in CSO, aligned action plans on risk mitigation, specified actions, and provided evidence to close action items. Validated residual risks and mapped to the risk grid for final IT security/CSO rating. Prepared identified risks and non-compliances for the bank’s risk units.
Jan 2020 - Dec 2021
2 years
Germany

Senior IT Enterprise Security Architect | Security Design Authority

Freelance

Client: Deutsche Bank AG. Industry: Financial services / leading German private bank.

Review & voting for CSO Identity & Access in the CSO Security Design Authority (SDA) for all global bank projects (~100,000 staff).

  • IT Security Architect in CSO at Deutsche Bank AG in Germany
  • IT security governance: Voting member in the CSO Security Design Authority, reviewing weekly project security docs against bank identity & access policies. Identified non-compliances with internal and external/regulatory requirements. Advised projects and aligned with other CSO units.
  • IT risk governance: Supported risk assessments and described mitigation measures for identified IT security deviations. Defined, documented, and approved measures with action plans, milestones, and closing evidence.
Jan 2020 - Dec 2021
2 years
Milan, Italy

Senior IT Solution & Integration Architect | AIMS++ Project

Freelance

Client: Allianz Germany & Allianz Italy. Industry: Insurance.

Local implementation of the global standard Allianz Input Management System (AIMS++) in Italy.

  • Architected integration of the German parent’s global input management solutions into Allianz Italy’s IT landscape.
  • Advised on cloud integration with legacy systems.
  • Consulted on web service design and corporate architecture patterns.
Jan 2017 - Apr 2020
3 years 4 months
Eschborn, Germany

Senior IT Enterprise Security Architect | IT Security Architecture – Lead Security Architect Outsourcing

Freelance

Client: Deutsche Bank AG | PBC / PWCC Germany & International / PGK / Postbank. Industry: Financial services.

Outsourcing project for Deutsche Bank Italia S.p.A.

  • Lead security architect for integration architecture in a large outsourcing project in Italy.
  • Structured IT security aspects and created a documentation methodology for decision councils.
  • Built high-level security architectures and concepts (batch, online/web services, MQ) and prepared new components for council review and approval.
  • Lead subject matter expert on all technical and content questions.
  • Supported all vertical streams in documentation and architecture aligned to patterns and council presentations.
  • Led review responses for all streams.
  • Conducted cryptographic analysis of single sign-on protocols and implementations, vulnerability analysis, and non-compliance documentation.
  • Analyzed mitigation measures and coordinated action plans.
  • Prepared risks and non-compliances for the bank’s risk teams.
Jan 2016 - Dec 2017
2 years
Frankfurt, Germany

Senior Architect and Senior Consultant

Freelance

Client: DZ Bank. Industry: Financial services.

Long-term advising since 2003, direct contracts from 2008. Guided multiple provider transitions (LH Systems, Fiducia, Atos) and the merger with WGZ BANK on groupware (messaging and collaboration). Supported SLAs, service transition planning, and migration plan reviews. Responsible for analysis and solution design migrating Lotus Domino apps to Microsoft.

Merger support of WGZ BANK and DZ BANK.

High availability | Enterprise architectures | Lotus Domino:

  • Technical lead in groupware for designing a unified target infrastructure and migration of existing environments.
  • Attended meetings and alignments.
  • Created, reviewed, and assured quality of documents as the DZ Bank’s groupware contact with other bank units, external vendors, and project staff.
Jan 2016 - Dec 2017
2 years
Frankfurt, Germany

Senior Architect and Senior Consultant

Freelance

Client: DZ Bank. Industry: Financial services.

Long-term advising since 2003. Supported provider transitions and WGZ BANK merger for groupware. Aided SLAs, service transitions, and migration reviews. Led analysis and solution design for preparing Lotus Domino apps for future mail and app infrastructure.

High availability | Enterprise architectures | Lotus Domino:

  • Technical lead for application analysis and qualification for potential tech replacements.
  • Led and advised a third-party provider working for DZ Bank.
  • Attended meetings and alignments.
  • Created, reviewed, and quality-assured documents as the groupware contact with other units, vendors, and project staff.
  • Contributed to solution designs and studies integrated into DZ Bank’s project portfolio.
Jan 2015 - Dec 2023
9 years
Eschborn, Germany

Senior IT Enterprise Security Architect | IT Security Risk Review

Freelance

Client: Deutsche Bank AG | PBC. Industry: Financial services.

IT security architecture in an enterprise context, advising on IT security questions.

IT security architecture | IT security review | IT enterprise architecture | IT security risk analysis:

  • Key lead in establishing the IT Security Architecture department in private & business clients (later Private Wealth & Commercial Clients, including Postbank).
  • Advised projects (Change The Bank) and application owners (Run The Bank) on security concepts and processes for compliance with bank security requirements.
  • From 2016, extended responsibilities to international business (mainly Europe).
  • From 2017, added global wealth management.
  • From 2018, added Postbank reintegration.
  • Post-Magellan, advised on IT security in the Postbank deconsolidation project.
  • Conducted security concept reviews, risk analyses, and qualification per the bank’s operational risk management.
  • Advised CTB projects and RTB owners on all IT security issues at Deutsche Bank.
Jan 2015 - Dec 2016
2 years
Frankfurt, Germany

Senior Architect and Senior Consultant

Freelance

Client: DZ Bank. Industry: Financial services.

Long-term advising since 2003. Supported provider transitions and WGZ BANK merger for groupware. Aided SLAs, service transitions, and migration reviews. Led analysis and solution design migrating Lotus Domino apps to Microsoft.

GDPR-compliant email archiving:

  • Technical lead for concept and proof of concept of company-wide compliant email archiving.
  • Attended meetings and alignments.
  • Created, reviewed, and quality-assured documents as the groupware contact with other units, vendors, and project staff.
  • Designed, ran, and documented a POC with d3.de’s d.velop software.
Jan 2015 - Dec 2015
1 year
Frankfurt, Germany

Senior Architect and Senior Consultant

Freelance

Client: DZ Bank. Industry: Financial services.

Long-term advising since 2003. Supported provider transitions and WGZ BANK merger for groupware. Aided SLAs, service transitions, and migration reviews. Led analysis and solution design migrating Lotus Domino apps to Microsoft.

Address error analysis in a cascaded address book environment: Groupware | Messaging | Lotus Domino:

  • Data protection and audit-driven project
  • Analyzed repeated misadreses and delivery failures in a large network of central bank, over 1,000 local banks, and service providers
  • Examined technical processes, restrictions, and root causes
  • Designed a multi-stage solution with name adjustments, aligned with IT leadership and providers
  • Coordinated solution implementation with the bank’s IT providers
  • Advised on user communication methods and approaches for different user groups
Jan 2014 - Dec 2015
2 years
Eschborn, Germany

Senior IT Enterprise Security Architect | Core Banking Migration to SAP Project

Freelance

Client: Deutsche Bank AG | PBC. Industry: Financial services.

End-to-end security concept for retail banking core system migration to SAP (Magellan project): IT security architecture | IT security review | IT enterprise architecture | Identity & Access architecture:

  • Developed an end-to-end security concept for SAP backend and connected systems (Retail Target Platform)
  • Designed a layer model with frontend, middleware, integration, backend, and secured interfaces
  • Created security context diagrams for application clusters per Magellan release
  • Supported SAP roles team in creating context diagrams to show business and technical user access
  • Helped define a target operating model with authentication, authorization, interface patterns, and security rules for Magellan
  • Coordinated with IT risk/governance, solution architecture, security architecture, integration & governance teams
  • Advised on bank-wide projects and initiatives related to Magellan
Jan 2014 - Dec 2014
1 year
Frankfurt, Germany

Senior Architect and Senior Consultant

Freelance

Client: DZ Bank. Industry: Financial services.

Long-term advising since 2003. Supported provider transitions and WGZ BANK merger for groupware. Aided SLAs, service transitions, and migration reviews. Led analysis and solution design migrating Lotus Domino apps to Microsoft.

Lotus Notes login sync with Windows AD: Groupware | Lotus Domino | IT security | Identity & access | Enterprise architecture:

  • Audit-driven project
  • Architect and advisor for syncing Windows login password with Lotus Notes client
  • Designed a solution with Notes Shared Login and Domino policies for remaining users needing unified password rules
  • Tested and piloted with the bank and IT providers
  • Quality assurance
Jan 2012 - Dec 2013
2 years
Fulda, Germany

Senior Architect and Consultant, Project Lead | Archive Rollback to Standard Methods Project

Freelance

Client: EDAG. Industry: Automotive.

Archive rollback and return to standard archiving methods. Groupware | Archiving | Enterprise architectures | Lotus Domino:

  • Concept, architecture, tool development, and implementation for returning ~9TB of email archive data from Infinite Mailbox for Lotus Domino (IML)
  • Upgraded Domino archive server to 8.5.3
  • Moved attachments to DAOS for space and performance
  • Built a status-driven app to programmatically return archive data to partial replicas on the archive server
  • Removed IML references from source mail databases
  • Reused updated replicas with server-based Domino archiving
Jan 2012 - Dec 2013
2 years
Frankfurt, Germany

Senior Architect and Senior Consultant

Freelance

Client: DZ Bank. Industry: Financial services.

Long-term advising since 2003. Supported provider transitions and WGZ BANK merger for groupware. Aided SLAs, service transitions, and migration reviews. Led analysis and solution design migrating Lotus Domino apps to Microsoft.

Messaging infrastructure provider switch (Fiducia → Atos): Groupware | Lotus Domino:

  • Architect for transitioning messaging for >5,000 users worldwide
  • Quality assured provider transition and transformation plans
  • Ongoing client support across technical and management levels to bridge functional, contractual, and operational needs
  • Acted as translator between levels to ensure client requirements
Jan 2011 - Dec 2013
3 years
Bonn, Germany

Senior Architect and Senior Consultant | Lotus Domino 8.5 Migration Project

Freelance

Client: BWI Systems. Industry: Public-private partnership / IT service provider for the German Armed Forces.

Lotus Domino & Notes 8.5 migration alongside Windows 7 client roll-out. Groupware | Enterprise architectures | Archiving | Lotus Domino | High availability:

  • Infrastructure analysis, advice on automating an ITIL-based environment for >140,000 users
  • Archiving/offloading solution introduction – detailed operational planning, advising operations, UHD, and support teams, ensuring documentation and support processes
  • Project lead for cross-consortium infrastructure changes
  • Analyzed existing Hercules project environment, planned tests and preparatory steps
  • Aligned with internal departments and set cross-consortium processes for migration
  • Designed tools for automated client release detection, user migration, mail template upgrade
  • Supported client packaging, testing, pilot, and rollout
  • Reviewed and optimized backup/recovery with IBM TSM/TDP
  • Designed a portal for user-initiated database restores
  • Moderated between teams, transferred knowledge to UHD, second-level, operations, and other teams
  • Updated security and integration migration concepts
  • Drafted cross-partner DOUs and OLAs
Jan 2010 - Dec 2012
3 years
Frankfurt, Germany

Senior Architect and Senior Consultant

Freelance

Client: DZ Bank. Industry: Financial services.

Long-term advising since 2003. Supported provider transitions and WGZ BANK merger for groupware. Aided SLAs, service transitions, and migration reviews. Led analysis and solution design migrating Lotus Domino apps to Microsoft.

Messaging provider switch (LH Systems → Fiducia): Enterprise architectures | Groupware | Lotus Domino | Archiving:

  • Architect for messaging infrastructure transition for >5,000 users
  • Detailed concepts for architecture, transition, and transformation
  • Quality assurance
  • Planned email archive return to future document management system
  • Tested, piloted, and rolled back + re-archived 2TB of data spanning ten years directly into DMS
  • Acted as translator between levels to ensure client and provider interests
Jan 2009 - Dec 2011
3 years
Berlin, Germany

Senior Consultant | Domino 8.5 Infrastructure Migration & Upgrade Project

Freelance

Client: DRV Bund (German Pension Insurance). Industry: Public service.

Lotus Domino R6 → R8 migration. Groupware | High availability | Enterprise architectures | Lotus Domino:

  • Advisor and architect for Domino 8.5 migration (~25,000 users, ~80 servers, multi-domain, multi-partner, multi-network)
  • Admin support, design, and advice throughout the project
  • Vendor architecture and consulting support
  • Ongoing support to operations and management on strategy and issues
  • Quality assurance of platform-specific implementation
  • Designed archiving and quota management concept using Domino features (policies, server-based archiving, online quotas)
Jan 2007 - Dec 2008
2 years
Frankfurt am Main, Germany

Technical Project Lead, Implementation Leader, Senior Architect | Unix Hardening Project (Implementation)

Freelance

Client: EDS/Sal. Oppenheim Private Bank. Industry: Financial services.

Implementing previously defined hardening measures on bank Unix systems. Unix security / hardening (implementation):

  • Coordinated implementation of hardening measures per the concept project’s specs and timeline
  • Defined operating standards and procedures for continuous monitoring and admin of security aspects
  • Advised on modern security architectures, mechanisms, and best practices
  • Trained and advised bank segment and app owners
  • Coordinated tests by bank and provider
  • Managed implementation of security measures at different levels
  • Implemented role-based security for app management to prevent shared functional accounts
  • Defined processes and advised on transition projects
  • Helped define operating standards
  • Developed and enhanced scripts for software package and file rights analysis
  • Integrated automated tools for the provider
  • Defined and assigned roles and responsibilities to sustain the concepts
Jan 2006 - Dec 2007
2 years
Frankfurt am Main, Germany

Project Lead, Senior Consultant, Senior Business Analyst | Unix Hardening Project (Analysis & Design)

Freelance

Client: EDS/Sal. Oppenheim Private Bank. Industry: Financial services.

Unix security / hardening (design phase). IT security architecture | Enterprise architecture:

  • Created hardening concepts and technical descriptions for Solaris 8/9/10, AIX 5.2/5.3, SuSE Linux SLES based on vendor guides, BSI baseline protection, ISO27001, SIZ catalogs, and secondary sources
  • Aligned with OS vendors
  • Helped define processes, roles, and responsibilities for protection needs, admin/root policies, patch management, and OS imaging per BSI and ISO standards
  • Drafted rollout plan by application group
  • Developed cross-platform Unix shell scripts for data gathering and analysis
  • Supported rollout of EDS tools for compliance management (ePCM), Opsware SAS (sys admin), Opsware ATE (inventory), Retina eEye
  • Wrote specs, project summaries, and plans
  • Developed project progress tracking, led project tasks, and piloted hardening measures
Jan 2004 - Dec 2010
7 years

Senior Consultant | Content and Compliance Management Solution Archiving

Freelance

Client: various. Industry: IT vendor (Sun Microsystems until 2010), multiple sectors.

Open archiving solution C²MS. Archiving | Groupware | Enterprise architecture | Compliance | Legal archiving | Technical presales:

  • Guided architecture and implementation of C²MS based on AXSOne records management
  • Built demo environments at Sun Munich
  • Created competitor comparison papers
  • Defined reference architectures
  • Advised on cross-country compliance and legal archiving
  • Gave talks at internal and external events (IBM Lotusphere 2006, StorageDays Istanbul 2006, DNUG)
  • Designed and ran load and performance tests on various platforms
  • Developed migration strategies
  • Advised Sun customers
Jan 2003 - Jan 2024
21 years 1 month
Karlsruhe, Germany

Senior Consultant and Senior Enterprise Architect

Freelance

Industry sectors: Automotive | Energy | Financial services | Healthcare | IT service providers & vendors | Public service | Consulting | Insurance | Defense.

  • IT projects in mid to very large environments in roles from operations to enterprise architect and management consulting.
  • Architecture and setup of high-availability environments, service design for provider transitions.
  • Various IT security tasks from enterprise security, solution architecture, risk reviews, governance, to cyber security.
  • Led a global support team under support contracts with worldwide customer visits.
  • Covered full range of groupware (Lotus Domino) projects.
Jan 2003 - Dec 2017
15 years

Senior Architect, Senior Consultant, Technical Presales, Global Support Team Leader, Implementation Leader

Freelance

Client: various. Industry: IT vendor (Sun until 2009), multiple sectors.

Email archiving solution Infinite Mailbox for Lotus Domino (IML). Archiving | Groupware | Enterprise architectures | Compliance | Legal archiving:

  • Analyzed client infrastructures for email archiving solutions
  • Ran POCs worldwide
  • Reviewed Domino architecture, topology, and performance
  • Assessed storage and network infra
  • Designed solution architecture for implementation
  • Planned hardware sizing and storage selection
  • Performed capacity and trend analyses, TCO studies
  • Acted as architect, project lead, and tech lead for implementations
  • Ran workshops on IML, Sun SAMFS, Domino on Solaris
  • Troubleshot issues globally
  • Led global support team (2003–2010) for WIPRO/India and Sun
Jan 1998 - Jan 2024
26 years 1 month

Senior Architect, Senior Consultant, Technical Presales, Global Support Team Leader, Implementation Leader | Groupware & Lotus

Freelance

Client: various. Industry: Automotive | Energy | Financial services | Healthcare | IT service provider | Public service | Consulting | Defense.

Email archiving solution Infinite Mailbox for Lotus Domino (IML). Groupware | Enterprise architectures:

  • Architected, specified, implemented, and advised on high-availability Domino infra for 500–100,000 users
  • Analyzed existing Domino infrastructures for mail and apps
  • Assessed data centers and networks
  • Strategy and QA for Domino outsourcing projects
  • Designed disaster-tolerant architectures
  • Performed security analysis and access model design for secure operations
  • Led platform migrations to stable OS
  • Supported app analysis and migration planning (e.g., Windows to Solaris)
  • Ran POCs, tests, and pilots
  • Specified backup and monitoring solutions and integrated them
  • Drafted operations manuals, policies, procedures, and guidelines, including DR plans
  • Ran drills and tests
  • Developed training materials for platform, app admins, and end users
  • Planned and delivered workshops and training on Domino, troubleshooting, and new features

Clients include BWI, Credit Suisse, Deutsche Bahn, DRV Bund, DFS, DZ Bank, EDAG, EDS/ABN AMRO APAC, Fiducia, Fresenius Netcare, Lufthansa Systems, Mainova, Mobilcom, NIIT, PwC, Prudential, Rohde&Schwarz, SachsenLB, Sun Educational Services, Sun Singapore, TK, T-Systems/DaimlerChrysler.

Jan 1997 - Dec 2003
7 years
Karlsruhe, Germany

Team Lead

PRS GmbH (later iunctio GmbH / Prodacta AG)

Industry: IT system integrator and consulting.

Management of ~20–30 staff in Karlsruhe and client sites + 20 in Riga (DeSL) and support locations.

Internal roles: Admin of a mixed client-server environment:

  • Managed hardware, network, and server admin (AIX, OS/2, Solaris, Windows, Linux)
  • Introduced Linux and Solaris replacing AIX and OS/2
  • Built a security infra on Linux: DMZ, firewall, IDS, VPN across sites and countries, established a CA with open-source certificates
  • Remote access solutions (modem, ISDN, VPN)
  • WAN/VPN link with development in Riga

External roles: Senior consultant and architect:

  • Network design and admin
  • System architecture
  • Security analysis and consulting
  • Lotus Domino architectures, implementation, consulting, and support

Summary

With over 30 years of Unix experience (early adopter of Linux when Linus Torvalds shared the disk images on the university network), a solid university education in data security and telematics, and wide-ranging network topics, I’ve spent nearly 25 exciting years on global projects covering insourcing/outsourcing, enterprise architecture, IT security, archiving, groupware, and other platform- and infrastructure-related topics.

Through years of close collaboration with Sun Microsystems and Lotus/IBM, I learned, shaped, and supported the various Unix dialects and many large client infrastructures since the late ’90s—always focused on highly available, scalable/elastic, and secure environments for business-critical infrastructures.

These long-standing and deep experiences in infrastructure, architecture, and IT security now allow me to offer thorough end-to-end consulting in enterprise environments. In recent years, I’ve refocused on information security, co-building an IT security architecture function and acting for years as a senior expert in an international setting, significantly shaping both architecture and risk analysis.

Skilled stakeholder communication at all levels and a passion for documentation are also the result of years of experience.

Languages

German
Native
English
Advanced
Italian
Advanced
French
Intermediate

Education

Oct 1991 - Jun 1999

University of Karlsruhe (TH)

Diplom-Informatiker in Telematics and Data Security Engineering · Computer Science · Karlsruhe, Germany

Certifications & licenses

Certified Cloud Security Knowledge

Cloud Security Alliance

TeleTrust Information Security Professional

European Institute for System Security

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions