Peter Weileder
Program and Project Manager / Internal Auditor / CISO
Experience
ISO 27001 Auditor for health insurance archive system
Health insurance company
The replacement of the existing archive system (document management system – DMS) on a host-based platform is well advanced.
The internal audit is meant to ensure the company's quality standards.
GDPR
ISO 27001 ff.
BSI
DORA
Patient data regulations
Host / Cloud / S3 / Container / highly scalable / Nuxeo
Budget: 50,000
Team: 1
Public Sector – European Public Tender for NBank
NBank
NBank must meet the stricter regulatory challenges.
As part of the data center renewal, various new solutions are being introduced. The tender for a DDoS security solution is one of them.
In addition to the introduction of attack protection, the setup of a second data center must be considered, along with the complexity of regulatory requirements for a European tender.
NIS2
GDPR
KRITIS
ISO 27001 ff.
BSI
RACI model
DORA
DDoS according to BSI guidelines
Budget: 50,000
Team: 1
Finance – Compliance / Strategy Consulting / Enterprise Architecture Implementation / DORA / Data Protection / Lead Architect
LBS Süd
Due to the merger of LBS South-West and LBS Bavaria, the requirements for KRITIS (critical infrastructure) / DORA in the financial sector now must be met.
The merger is under time pressure due to upcoming audits, and the existing structures and documents are now being merged and the enterprise architecture is being established in this context.
Consolidation of ICT enterprise architecture
Introduction of AI-supported input management
Introduction of AI-supported information management
Introduction of new network infrastructure (IaC principle)
Introduction of AI-based voice assistance
Introduction of DWH & regulatory reporting
Harmonization of document management systems (DMS) across different companies
Security management system
Windows 11 hardening
Policy revision
Process design
ARC42 (Archimate), modeling of end-to-end processes with compliance requirements in mind
Introduction of automated controls
Designing a UAT standard process
AI support for process optimization
Introduction of Azure Cloud for: governance SLA management / IAM / security (firewalls / WAF / PGP / documentation & processes) / workplace (Win 11) / field service / Exchange (mail / users and roles) / voice (Teams & fax) / print / SAP / UHD
GDPR
KRITIS
ISO 27001 ff.
BSI
Banking regulations
DORA
BSI basic protection compendium
ARC42
Multi-cloud environment (Azure / AWS / private cloud / on-prem)
DMS - DOXIS
Microsoft Azure Cloud
SharePoint
Budget: 250,000 / 500,000
Team: 3 / 10
Public Sector – European Public Tender for ITV Stormarn
ITV Stormarn
Preparation of tender documents for the public sector in a KRITIS environment.
CMDB
Infrastructure firewall
MSSQL migration
Introduction of key management
Document management system
SIEM
GDPR
KRITIS
ISO 27001 ff.
BSI
Tender portal
Budget: 50,000
Team: 1
Public Sector – Network Strategy Consulting / BSI / NIS2 Healthcare
HBSN / Bavarian Medical Service
The requirements for the Bavarian Medical Service have greatly increased due to electronic patient records, e-prescriptions, and more.
The increased dependence on service providers and their services requires revising existing processes and access strategies in a multi-cloud approach.
Pursuing a strategy for single sign-on / onboarding / RBAC for service providers, considering the higher monitoring requirements.
Unstable strategy caused by new legislation and time pressure from late approvals.
Legacy implementations with limited scalability.
NIS2 requirements for infrastructure and processes.
Extended BSI basic protection.
Active Directory (user and role model / IAM)
Monitoring (revision of the current solution)
Cisco upgrade (test concept – release planning and execution for 30 locations)
Firewall concept
Onboarding of external staff (BPMN)
NIS2
GDPR
KRITIS
ISO 27001 ff.
BSI
RACI model
CISCO
Active Directory
Fortinet Firewall
Budget: 50,000
Team: 1
Finance – Compliance - Multi-Project Management DWH Migration – KRITIS – ISO 27001 Multi-Cloud
ING-Diba
Responsibility for ensuring and implementing regulatory requirements.
Role of IT custodian for applications in implementing and complying with risk management and governance processes.
Deriving risk requirements from BAIT requirements of BaFin and formulating risk processes.
Sustainable risk reporting.
Topics such as SOX.
Presenting the applications to the respective risk departments.
Contact person for second line, IT security, and governance.
Developing relevant security functions for the applications.
Coordination with IT architects regarding the required architecture of the applications.
Writing documentation.
Modeling end-to-end processes considering compliance requirements.
Introducing automated controls.
Designing a UAT standard process.
Further development of processes based on IPE compliance.
Strengthening IT general controls (ITGC) and business controls.
Over 30 years of legacy systems need to be moved to a private cloud.
The data lake is the heart of the bank's functionality as all regulatory requirements are mapped there.
Over 70 source systems and over 50 target systems.
Complex data preparation in the data lake.
NIS2
GDPR
KYC
KRITIS
ISO 27001 and related standards
BSI
EIOPA
SOX
Exadata (Oracle)
Business Objects
Cognos
Cloud Pack for Data (CP4D) (IBM)
Information Server
Data lineage
Data quality
Automic
Metadata repository
Budget: 20,000,000
Team: 50
Trading – Product Owner - Web Shop Establishment – Multi-Cloud – SAP – Payment System
Hornbach
Opening the marketplace to third-party providers.
Maintaining existing ERP systems and creating new ERP systems for third-party providers.
Ensuring consistency in order management.
Transitioning the IT landscape to an event-driven design approach.
Introducing new payment processes and billing for mixed orders.
Managing 9 Scrum teams to catch up on delays.
Scrum
NIS2
GDPR
KYC
Mirakel
SAP S/4 Retail
SAP Cloud
Google Cloud
Kafka
ASAPIO
NiFi
PayPal Hyperwallet (ESCROW)
Budget: 600,000
Team: 81
Finance – Compliance - Enterprise Architect – Kubernetes / OpenShift
Debeka
Adapting the current infrastructure and introducing a container solution based on OpenShift.
Reforming the process landscape and software management.
Managing various service providers during the migration of key business systems.
Scrum
KRITIS
ISO 27001 and related standards
BSI
EIOPA
MaRisk
BaFin
Kubernetes
Azure AD
Azure B2C
Networking
Budget: 120,000
Team: 18
Public Sector – Enterprise Architecture – Multi-Cloud – Container
HZD (Hessische Zentrale für Datenverarbeitung)
IT service provider for the state of Hesse for police, judiciary, tax offices, and public administrations.
Supporting the federal initiative for the cross-government provision of cloud services.
Architectural support for Azure topics & on-premise
Azure AD login (incl. B2C)
DESTATIS (Federal Statistical Office)
SchwebNet system for severely disabled applications
Implementation of HöMS (Hessian University for Public Management and Security)
Export license for medical products
Aerial image analysis for ordnance disposal
Security portal
FIDO2 implementation
Code signing
SKAT (radiation protection registry)
Winegrower's register
Dike register
Robotic process automation (RPA)
Housing benefit, OSCI, Ekom21, Moodle, address service, aviation security, accreditation database
Implementing a service provider model based on hyperscaler standards.
Strong dependencies on cross-state measures.
Waterfall / TOGAF / V-Model / Kanban
KRITIS
ISO 27001 and related standards
BSI
EIOPA
MaRisk
GDPR
Linux
Kubernetes
Azure AD
Azure B2C
Hadoop
Cloudera
Networking
ADOit
EAM
Nextcloud
Alfresco
Budget: 400,000
Team: 8
Finance – Scrum Master – Credit Check
VW-Financial Services
Combining agile approaches with existing waterfall structures.
Using pragmatic methods outside SAFe 4.x.
Modeling end-to-end processes considering compliance requirements.
Introducing automated controls.
Designing a UAT standard process.
Further developing processes based on IPE compliance.
Strengthening IT general controls (ITGC) and business controls.
Managing stakeholder expectations in the credit service area.
Scrum
KRITIS
ISO 21001 and related standards
BSI
EIOPA
MaRisk
BaFin
GDPR
Kubernetes
Java
Quarkus
Budget: 400,000
Team: 8
Finance – Program Manager – Monitoring – Container – KYC – Security
ING
Established a near-time solution for fraud detection and customer tracking using Flink / Cassandra (NoSQL) on OpenShift.
Managed objectives for 4 Scrum teams.
Operated the Hadoop cluster in parallel during the rollout of the new solution.
Introduced DevOps based on Ansible / GIT.
Reviewed the use of Terraform.
Redesigned firewall rules for domain segmentation and load balancing with F5.
Supported the migration of over 400 VMs to SCS (Self Contained Services).
Assessed switching from direct attached storage to Ceph.
Created new role definitions for the CMDB.
Implemented a data model according to GDPR (BDSG) for the banking app to strengthen IT General Controls (ITGC) and business controls.
Scrum
Kubernetes
OpenShift
Cassandra
Flink
Kafka
Jupyter Notebook
S3
ELK
Azure
IaaS
PaaS
SaaS
MicroServices
Self Contained Services (SCS)
CyberArk
Keycloak
Budget: 1,000,000
Team: 6
Finance – Architect – IoT – Container – Multi-Cloud
Siemens Building Services
Adapted the architecture to meet new IoT sector requirements based on AWS.
Covered international requirements of Siemens AG in Building Services.
Adjusted the current solution to a microservice architecture.
Built continuous delivery.
SAFe 6
AWS
Kubernetes
MSSQL
Web Services
JAZZ
Budget: 1,000,000
Team: 14
Finance – Product Owner – Security – Container
ING Diba
Created a suitable message bus (Kafka) and a monitoring solution for log events (ELK stack).
Separated business events from log events.
Made the strategic decision for OpenShift on bare metal / ELK as a container solution.
Implemented fully automated provisioning.
Developed a metadata model for logging to strengthen IT General Controls (ITGC) and business controls.
Met high demands for scalability, transaction security, and regulatory requirements.
Scrum
Kafka
ELK Stack
Kubernetes
OpenShift
Docker
Kibana
IaaS
PaaS
SaaS
CyberArk
Budget: 2,100,000
Team: 5
Finance – Security Architect – Compliance – Kubernetes / OpenShift
NORD/LB
Identified changes in governance and compliance for a cloud strategy.
Analyzed affected stakeholders and communicated cloud services in a hybrid cloud model.
Developed a hybrid cloud approach with diverse service offerings.
Built the second cloud infrastructure in parallel.
Scrum
KRITIS
ISO 27001 ff.
BSI
EIOPA
MaRisk
Kubernetes
Fluentd
S3
ELK
Azure
SCS
IaaS
PaaS
SaaS
HashiCorp
ArcSight
NGINX+
Gardener
JFrog
Ansible
Xray
Prometheus
Loki
MongoDB
Lightbit
PostgreSQL
GIT
CyberArk
Lecturer (Compliance)
SHEER GmbH
- DORA – An introduction
- Security guidelines – How to write a security policy
- NIS2 – An overview of the requirements
Summary
Over 30 years of experience in complex IT solutions in an international environment as a program and project manager. In the last 10 years - internal auditor / CISO according to ISO 27001 ff.; KRITIS; DORA; NIS2; BSI basic protection; ESG reporting; EU Data Act; compliance; reporting; data protection. My approach: Let's start pragmatically to find solutions by consensus. I will support you with detailed, proven templates.
Skills
- Security Policies (Standards) According To Bsi Basic Protection Since 2015
- Implementation Of Information Security Management Systems According To Iso 27001
- Business Analyst With Over 10 Years Of Experience Including Processes
- Auditor (Iso 27001)
- Building Organizational Structures
- Ciso (Iso 27001)
- Ai (Eu Ai Act) Since 2024
- Bsi Basic Protection
- Gdpr Since 2016 / Marisk Since 2016 / Bait Since 2015 / Cloud Since 2015
- Agile Product Owner & Scrum
- Project Management Using Agile And Classic Methods Since 2000
- Security Architect For Multi-cloud Solutions Since 2015
- Migration / Establishment Of Solutions For Over 100,000 Desktop Systems Since 2000
- Regulatory Work For Over 9 Years
- International Assignments In Asia / India / Eu / Switzerland / Usa Since 2000
- Itil
- "Political Correctness"
- Finance For Over 25 Years
- Architect For Security / Infrastructure / Aws / Azure
Languages
Education
Banking Specialist (higher school diploma) · Banking Specialist
Certifications & licenses
EU AI Act
ISO 27001 Auditor
ISO 27001 CISO
Similar Freelancers
Discover other experts with similar qualifications and experience