Recommended expert

Peter Weileder

Program and Project Manager / Internal Auditor / CISO

Peter Weileder
Frankfurt am Main, Germany

Experience

Nov 2025 - Dec 2025
2 months
Germany

ISO 27001 Auditor for health insurance archive system

Health insurance company

  • The replacement of the existing archive system (document management system – DMS) on a host-based platform is well advanced.

  • The internal audit is meant to ensure the company's quality standards.

  • GDPR

  • ISO 27001 ff.

  • BSI

  • DORA

  • Patient data regulations

  • Host / Cloud / S3 / Container / highly scalable / Nuxeo

  • Budget: 50,000

  • Team: 1

Oct 2024 - Oct 2024
1 month
Germany

Public Sector – European Public Tender for NBank

NBank

  • NBank must meet the stricter regulatory challenges.

  • As part of the data center renewal, various new solutions are being introduced. The tender for a DDoS security solution is one of them.

  • In addition to the introduction of attack protection, the setup of a second data center must be considered, along with the complexity of regulatory requirements for a European tender.

  • NIS2

  • GDPR

  • KRITIS

  • ISO 27001 ff.

  • BSI

  • RACI model

  • DORA

  • DDoS according to BSI guidelines

  • Budget: 50,000

  • Team: 1

Jul 2024 - Dec 2025
1 year 6 months
Germany

Finance – Compliance / Strategy Consulting / Enterprise Architecture Implementation / DORA / Data Protection / Lead Architect

LBS Süd

  • Due to the merger of LBS South-West and LBS Bavaria, the requirements for KRITIS (critical infrastructure) / DORA in the financial sector now must be met.

  • The merger is under time pressure due to upcoming audits, and the existing structures and documents are now being merged and the enterprise architecture is being established in this context.

  • Consolidation of ICT enterprise architecture

  • Introduction of AI-supported input management

  • Introduction of AI-supported information management

  • Introduction of new network infrastructure (IaC principle)

  • Introduction of AI-based voice assistance

  • Introduction of DWH & regulatory reporting

  • Harmonization of document management systems (DMS) across different companies

  • Security management system

  • Windows 11 hardening

  • Policy revision

  • Process design

  • ARC42 (Archimate), modeling of end-to-end processes with compliance requirements in mind

  • Introduction of automated controls

  • Designing a UAT standard process

  • AI support for process optimization

  • Introduction of Azure Cloud for: governance SLA management / IAM / security (firewalls / WAF / PGP / documentation & processes) / workplace (Win 11) / field service / Exchange (mail / users and roles) / voice (Teams & fax) / print / SAP / UHD

  • GDPR

  • KRITIS

  • ISO 27001 ff.

  • BSI

  • Banking regulations

  • DORA

  • BSI basic protection compendium

  • ARC42

  • Multi-cloud environment (Azure / AWS / private cloud / on-prem)

  • DMS - DOXIS

  • Microsoft Azure Cloud

  • SharePoint

  • Budget: 250,000 / 500,000

  • Team: 3 / 10

Apr 2024 - Oct 2024
7 months
Germany

Public Sector – European Public Tender for ITV Stormarn

ITV Stormarn

  • Preparation of tender documents for the public sector in a KRITIS environment.

  • CMDB

  • Infrastructure firewall

  • MSSQL migration

  • Introduction of key management

  • Document management system

  • SIEM

  • GDPR

  • KRITIS

  • ISO 27001 ff.

  • BSI

  • Tender portal

  • Budget: 50,000

  • Team: 1

Mar 2024 - Apr 2024
2 months
Germany

Public Sector – Network Strategy Consulting / BSI / NIS2 Healthcare

HBSN / Bavarian Medical Service

  • The requirements for the Bavarian Medical Service have greatly increased due to electronic patient records, e-prescriptions, and more.

  • The increased dependence on service providers and their services requires revising existing processes and access strategies in a multi-cloud approach.

  • Pursuing a strategy for single sign-on / onboarding / RBAC for service providers, considering the higher monitoring requirements.

  • Unstable strategy caused by new legislation and time pressure from late approvals.

  • Legacy implementations with limited scalability.

  • NIS2 requirements for infrastructure and processes.

  • Extended BSI basic protection.

  • Active Directory (user and role model / IAM)

  • Monitoring (revision of the current solution)

  • Cisco upgrade (test concept – release planning and execution for 30 locations)

  • Firewall concept

  • Onboarding of external staff (BPMN)

  • NIS2

  • GDPR

  • KRITIS

  • ISO 27001 ff.

  • BSI

  • RACI model

  • CISCO

  • Active Directory

  • Fortinet Firewall

  • Budget: 50,000

  • Team: 1

Dec 2022 - Jul 2023
8 months
Germany

Finance – Compliance - Multi-Project Management DWH Migration – KRITIS – ISO 27001 Multi-Cloud

ING-Diba

  • Responsibility for ensuring and implementing regulatory requirements.

  • Role of IT custodian for applications in implementing and complying with risk management and governance processes.

  • Deriving risk requirements from BAIT requirements of BaFin and formulating risk processes.

  • Sustainable risk reporting.

  • Topics such as SOX.

  • Presenting the applications to the respective risk departments.

  • Contact person for second line, IT security, and governance.

  • Developing relevant security functions for the applications.

  • Coordination with IT architects regarding the required architecture of the applications.

  • Writing documentation.

  • Modeling end-to-end processes considering compliance requirements.

  • Introducing automated controls.

  • Designing a UAT standard process.

  • Further development of processes based on IPE compliance.

  • Strengthening IT general controls (ITGC) and business controls.

  • Over 30 years of legacy systems need to be moved to a private cloud.

  • The data lake is the heart of the bank's functionality as all regulatory requirements are mapped there.

  • Over 70 source systems and over 50 target systems.

  • Complex data preparation in the data lake.

  • NIS2

  • GDPR

  • KYC

  • KRITIS

  • ISO 27001 and related standards

  • BSI

  • EIOPA

  • SOX

  • Exadata (Oracle)

  • Business Objects

  • Cognos

  • Cloud Pack for Data (CP4D) (IBM)

  • Information Server

  • Data lineage

  • Data quality

  • Automic

  • Metadata repository

  • Budget: 20,000,000

  • Team: 50

Dec 2022 - May 2023
6 months
Germany

Trading – Product Owner - Web Shop Establishment – Multi-Cloud – SAP – Payment System

Hornbach

  • Opening the marketplace to third-party providers.

  • Maintaining existing ERP systems and creating new ERP systems for third-party providers.

  • Ensuring consistency in order management.

  • Transitioning the IT landscape to an event-driven design approach.

  • Introducing new payment processes and billing for mixed orders.

  • Managing 9 Scrum teams to catch up on delays.

  • Scrum

  • NIS2

  • GDPR

  • KYC

  • Mirakel

  • SAP S/4 Retail

  • SAP Cloud

  • Google Cloud

  • Kafka

  • ASAPIO

  • NiFi

  • PayPal Hyperwallet (ESCROW)

  • Budget: 600,000

  • Team: 81

Dec 2021 - Mar 2022
4 months
Germany

Finance – Compliance - Enterprise Architect – Kubernetes / OpenShift

Debeka

  • Adapting the current infrastructure and introducing a container solution based on OpenShift.

  • Reforming the process landscape and software management.

  • Managing various service providers during the migration of key business systems.

  • Scrum

  • KRITIS

  • ISO 27001 and related standards

  • BSI

  • EIOPA

  • MaRisk

  • BaFin

  • Kubernetes

  • Azure AD

  • Azure B2C

  • Networking

  • Budget: 120,000

  • Team: 18

Jun 2021 - Jun 2023
2 years 1 month
Germany

Public Sector – Enterprise Architecture – Multi-Cloud – Container

HZD (Hessische Zentrale für Datenverarbeitung)

  • IT service provider for the state of Hesse for police, judiciary, tax offices, and public administrations.

  • Supporting the federal initiative for the cross-government provision of cloud services.

  • Architectural support for Azure topics & on-premise

  • Azure AD login (incl. B2C)

  • DESTATIS (Federal Statistical Office)

  • SchwebNet system for severely disabled applications

  • Implementation of HöMS (Hessian University for Public Management and Security)

  • Export license for medical products

  • Aerial image analysis for ordnance disposal

  • Security portal

  • FIDO2 implementation

  • Code signing

  • SKAT (radiation protection registry)

  • Winegrower's register

  • Dike register

  • Robotic process automation (RPA)

  • Housing benefit, OSCI, Ekom21, Moodle, address service, aviation security, accreditation database

  • Implementing a service provider model based on hyperscaler standards.

  • Strong dependencies on cross-state measures.

  • Waterfall / TOGAF / V-Model / Kanban

  • KRITIS

  • ISO 27001 and related standards

  • BSI

  • EIOPA

  • MaRisk

  • GDPR

  • Linux

  • Kubernetes

  • Azure AD

  • Azure B2C

  • Hadoop

  • Cloudera

  • Networking

  • ADOit

  • EAM

  • Nextcloud

  • Alfresco

  • Budget: 400,000

  • Team: 8

Jun 2021 - Jun 2023
2 years 1 month
Germany

Finance – Scrum Master – Credit Check

VW-Financial Services

  • Combining agile approaches with existing waterfall structures.

  • Using pragmatic methods outside SAFe 4.x.

  • Modeling end-to-end processes considering compliance requirements.

  • Introducing automated controls.

  • Designing a UAT standard process.

  • Further developing processes based on IPE compliance.

  • Strengthening IT general controls (ITGC) and business controls.

  • Managing stakeholder expectations in the credit service area.

  • Scrum

  • KRITIS

  • ISO 21001 and related standards

  • BSI

  • EIOPA

  • MaRisk

  • BaFin

  • GDPR

  • Kubernetes

  • Java

  • Quarkus

  • Budget: 400,000

  • Team: 8

Feb 2019 - Jan 2020
1 year
Germany

Finance – Program Manager – Monitoring – Container – KYC – Security

ING

  • Established a near-time solution for fraud detection and customer tracking using Flink / Cassandra (NoSQL) on OpenShift.

  • Managed objectives for 4 Scrum teams.

  • Operated the Hadoop cluster in parallel during the rollout of the new solution.

  • Introduced DevOps based on Ansible / GIT.

  • Reviewed the use of Terraform.

  • Redesigned firewall rules for domain segmentation and load balancing with F5.

  • Supported the migration of over 400 VMs to SCS (Self Contained Services).

  • Assessed switching from direct attached storage to Ceph.

  • Created new role definitions for the CMDB.

  • Implemented a data model according to GDPR (BDSG) for the banking app to strengthen IT General Controls (ITGC) and business controls.

  • Scrum

  • Kubernetes

  • OpenShift

  • Cassandra

  • Flink

  • Kafka

  • Jupyter Notebook

  • S3

  • ELK

  • Azure

  • IaaS

  • PaaS

  • SaaS

  • MicroServices

  • Self Contained Services (SCS)

  • CyberArk

  • Keycloak

  • Budget: 1,000,000

  • Team: 6

Oct 2018 - Feb 2019
5 months
Germany

Finance – Architect – IoT – Container – Multi-Cloud

Siemens Building Services

  • Adapted the architecture to meet new IoT sector requirements based on AWS.

  • Covered international requirements of Siemens AG in Building Services.

  • Adjusted the current solution to a microservice architecture.

  • Built continuous delivery.

  • SAFe 6

  • AWS

  • Kubernetes

  • MSSQL

  • Web Services

  • JAZZ

  • Budget: 1,000,000

  • Team: 14

May 2017 - Oct 2018
1 year 6 months
Germany

Finance – Product Owner – Security – Container

ING Diba

  • Created a suitable message bus (Kafka) and a monitoring solution for log events (ELK stack).

  • Separated business events from log events.

  • Made the strategic decision for OpenShift on bare metal / ELK as a container solution.

  • Implemented fully automated provisioning.

  • Developed a metadata model for logging to strengthen IT General Controls (ITGC) and business controls.

  • Met high demands for scalability, transaction security, and regulatory requirements.

  • Scrum

  • Kafka

  • ELK Stack

  • Kubernetes

  • OpenShift

  • Docker

  • Kibana

  • IaaS

  • PaaS

  • SaaS

  • CyberArk

  • Budget: 2,100,000

  • Team: 5

Germany

Finance – Security Architect – Compliance – Kubernetes / OpenShift

NORD/LB

  • Identified changes in governance and compliance for a cloud strategy.

  • Analyzed affected stakeholders and communicated cloud services in a hybrid cloud model.

  • Developed a hybrid cloud approach with diverse service offerings.

  • Built the second cloud infrastructure in parallel.

  • Scrum

  • KRITIS

  • ISO 27001 ff.

  • BSI

  • EIOPA

  • MaRisk

  • Kubernetes

  • Fluentd

  • S3

  • ELK

  • Azure

  • SCS

  • IaaS

  • PaaS

  • SaaS

  • HashiCorp

  • ArcSight

  • NGINX+

  • Gardener

  • JFrog

  • Ansible

  • Xray

  • Prometheus

  • Loki

  • MongoDB

  • Lightbit

  • PostgreSQL

  • GIT

  • CyberArk

Frankfurt, Germany

Lecturer (Compliance)

SHEER GmbH

  • DORA – An introduction
  • Security guidelines – How to write a security policy
  • NIS2 – An overview of the requirements

Summary

Over 30 years of experience in complex IT solutions in an international environment as a program and project manager. In the last 10 years - internal auditor / CISO according to ISO 27001 ff.; KRITIS; DORA; NIS2; BSI basic protection; ESG reporting; EU Data Act; compliance; reporting; data protection. My approach: Let's start pragmatically to find solutions by consensus. I will support you with detailed, proven templates.

Skills

  • Security Policies (Standards) According To Bsi Basic Protection Since 2015
  • Implementation Of Information Security Management Systems According To Iso 27001
  • Business Analyst With Over 10 Years Of Experience Including Processes
  • Auditor (Iso 27001)
  • Building Organizational Structures
  • Ciso (Iso 27001)
  • Ai (Eu Ai Act) Since 2024
  • Bsi Basic Protection
  • Gdpr Since 2016 / Marisk Since 2016 / Bait Since 2015 / Cloud Since 2015
  • Agile Product Owner & Scrum
  • Project Management Using Agile And Classic Methods Since 2000
  • Security Architect For Multi-cloud Solutions Since 2015
  • Migration / Establishment Of Solutions For Over 100,000 Desktop Systems Since 2000
  • Regulatory Work For Over 9 Years
  • International Assignments In Asia / India / Eu / Switzerland / Usa Since 2000
  • Itil
  • "Political Correctness"
  • Finance For Over 25 Years
  • Architect For Security / Infrastructure / Aws / Azure

Languages

German
Advanced
English
Advanced

Education

Lorem ipsum dolor sit amet

Banking Specialist (higher school diploma) · Banking Specialist

Certifications & licenses

EU AI Act

ISO 27001 Auditor

ISO 27001 CISO

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Similar Freelancers

Discover other experts with similar qualifications and experience

Michael Schwendemann
Michael Schwendemann

Compliance Consultant

View Profile
Federico Leefhelm
Federico Leefhelm

ISO – Senior Consultant Quality & Information Security

View Profile
Zakaria Aoune
Zakaria Aoune

Vice President Technology

View Profile
Robert Francia
Robert Francia

Interim Project Manager

View Profile
Alexander Sänn
Alexander Sänn

Owner and Managing Director

View Profile
Bernhard Bowitz
Bernhard Bowitz

Senior Security Architect

View Profile
Alagi Mansaray
Alagi Mansaray

Senior Project Manager S4HANA in the Energy Sector

View Profile
Pierre Gronau
Pierre Gronau

Ansible Automation, Windows Third Level Support

View Profile
Zoran Jovanovic
Zoran Jovanovic

Senior IT PM & Governance & Operational Resilience Consultant | Financial Services

View Profile
Vladimir Mildenberger
Vladimir Mildenberger

IT & Cybersecurity Project Manager

View Profile
Dirk Meissner
Dirk Meissner

Project Manager AOS

View Profile
Christian Gebhardt
Christian Gebhardt

Deputy Chief Information Security Officer

View Profile
Christian Decker
Christian Decker

Managing Director and Senior Consultant

View Profile
Valeri Milke
Valeri Milke

Associate Partner - Information Security Consulting

View Profile
Luca Pacor
Luca Pacor

ERP Program Manager

View Profile
Daniel Jüntgen
Daniel Jüntgen

Information Security Consultant

View Profile
Burkhard Hinz
Burkhard Hinz

Consultant for Data Protection, AI, Compliance and Organizational Development

View Profile
Markus Willems
Markus Willems

KRITIS Consultant

View Profile
Michael Vogelbacher
Michael Vogelbacher

AI Project Management and Governance Setup

View Profile
Björn Bausch
Björn Bausch

Project Manager NIS-2

View Profile
Thomas Ullrich
Thomas Ullrich

Senior Consultant / PM Infrastructure Services & Workplace Migration

View Profile
Christian Enderle
Christian Enderle

IT Consulting / IT Rebuild

View Profile
Karl-heinz Reis
Karl-heinz Reis

ITIL 4 Master

View Profile
Frank Joraschkewitz
Frank Joraschkewitz

Lead Project Manager

View Profile
Oliver Frömel
Oliver Frömel

Senior IT Enterprise Security Architect | Project Bank Migration

View Profile
Markus Marschollek
Markus Marschollek

Project Manager / Senior Consultant (multiple projects)

View Profile
Martin Rusnak
Martin Rusnak

Interim CTO

View Profile
Peter Dittkuhn
Peter Dittkuhn

Project coordination, consulting, IT security, ISMS, NIS2, continuous improvement

View Profile
Elias Vasiliadi
Elias Vasiliadi

Cloud Architect & Security Advisor

View Profile
Nikolaus Betzler
Nikolaus Betzler

ICT Risk Management and Information Security

View Profile