Thomas Ullrich

Senior Consultant / PM Infrastructure Services & Workplace Migration – Transport & Logistics, Passenger Transport

Brühl, Germany

Experience

Mar 2024 - Dec 2025
10 months
Hybrid

Senior Consultant / PM Infrastructure Services & Workplace Migration – Transport & Logistics, Passenger Transport

Freiberuflich

As part of the "Accelerate-IT" program the main goals of the projects are:

  • All Windows clients are managed in a hybrid, central AD
  • Client standardization
  • Implementation of information security policy requirements
  • Development of new infrastructure services provided as a managed service by a new provider
  • New IT platform as a central and secure directory service
  • M365 Azure AD
  • MS Remote Desktop Services
  • Zscaler
  • M365 cloud for workplace management
  • PaaS / SaaS sourced through the new provider
Apr 2023 - Oct 2023
7 months

Interim Director IT-Security / Interim Cybersecurity Manager – Construction Industry

Freiberuflich

  • "Improvement of the client's IT and cybersecurity strategy"
  • CIS (Center for Internet Security), cybersecurity assessment / CIS control benchmark
  • Advise on improving the organization of the client's IT and cybersecurity activities (prioritization, topic management, hands-on when needed, e.g., customer inquiries)
  • Advise on improving development and implementation of the IT and cybersecurity strategy
Jul 2022 - Dec 2022
6 months

Senior Security Consultant - Biopharma

Freiberuflich

  • Support services for the "ISMS implementation" / ISO 27001 certification project
  • Assistance with implementing an ISO 27001 compliant information security concept
  • Support in defining the information security incident management process
Nov 2020 - May 2022
1 year 7 months

Senior Security Consultant / Senior IT Infrastructure Management Consultant - Public Administration

Freiberuflich

  • Consulting on identity and access management (IAM)
  • Operating model & IAM processes
  • Support within the transformation program for provider control and service delivery
  • Support in managing different providers during the transition (handover to operations / IAM operational readiness)
  • Consulting on SACM process management, IT configuration management interim process
  • Support in IT infrastructure management, provider management and ITSM
  • Support in coordinating IT operations topics during transition with IT service management
  • Support in overall coordination and validation in the development, implementation and further development of a professional ITSM process landscape
  • Support in building and coordinating KPI systems and analysis methods to control and review IT service processes and identify optimization potentials
Jul 2020 - Jul 2020
1 month

Lead Auditor ISMS/ISO27001

Freiberuflich

  • Internal ISMS audit, medical technology
Mar 2020 - Jun 2020
4 months

Senior Consultant IT-Compliance/IT-Security

Freiberuflich

Project “Support Security Architecture” - auditing firm

  • Creation of a security architecture framework (NIST/ISO 27001) covering goals, strategy, awareness, culture, processes (ISMS) and technology (AI, protection; detection & response; access; etc.)
  • Current state analysis IT / information security
  • Definition of action fields
  • Prioritization by protection needs and threat
  • Recommendation of AI-based detection technology solution
Oct 2019 - Feb 2020
5 months

Key Account & Partner Management Europe / Quality Assurance & Security Officer

Freiberuflich

Consulting for the pharmaceutical industry.

  • Customer relationship
  • Contract management
  • Pre-sales (SaaS solution for pharmaceutical industry)
  • Information security (internal audit, controls, compliance)
  • Quality assurance
  • Business consulting
Jan 2018 - Mar 2019
1 year 3 months
Cologne, Germany

Capability Build & Improvement Lead

AXA Group Operations - AXA Technology Services Germany GmbH

Security service management

  • Management of new service requests (demand management) for information security operations (ISOPS) worldwide
  • Security services: DDoS, IPS, SIEM, endpoint protection, PUAM, password management
  • Provider management (managed security services)
Feb 2017 - Dec 2017
11 months
Cologne, Germany

TOM Transition Lead

AXA Group Information Security - AXA Technology Services Germany GmbH

  • Capability build & improvement – managing the transformation of the existing security organization into the AXA Group Information Security organization
  • IS Lead ATS ISNE - Germany (interim)
  • Local security manager (LCISO) AXA Technology Services Information Security NE - Germany (interim), with local responsibility for security governance, management & control, security architecture, operational security
Jun 2016 - Feb 2017
9 months
Cologne, Germany

Regional Head of Department - ATS Information Security NE (CISO)

AXA Technology Services Germany GmbH - North Europe Region

  • Security governance, assurance & reporting
  • Management & control
  • Security architecture
  • Operational security
  • Security processes (SPM, VaTiS)
  • Identity & access management
  • Security incident & crisis management
  • IT audit (security processes, policy)
  • Managing the transformation of the existing security organization into the AXA Group Information Security organization
Mar 2012 - May 2016
4 years 3 months
Cologne, Germany

Regional Head of Department Global Risk, Security & Compliance

AXA Technology Services Germany GmbH - North Europe Region

  • Responsible for 20 employees and 1 local manager in Belgium
  • Focus on IT risk, security & compliance within the global business unit
  • Risk assessments
  • Policy compliance
  • Information security policy
  • Governance
  • Security processes
  • Cybersecurity defense & operations
  • Operational security (SPM, vulnerability management, etc.)
  • ISO 27001 maturity assessment (IT audit)
  • Security incident & crisis management
  • Security consulting
  • Regulatory matters like BaFin – VAIT, MaRisk, etc.
  • Standardization of security tools & processes
  • Strategic further development (cybersecurity strategy) toward AXA Information Security Practice as part of the Information Security Transformation Program
Mar 2011 - Feb 2012
1 year
Cologne, Germany

Regional Program Manager

AXA Technology Services Germany GmbH - North Europe Service Delivery

  • Management of various local and international projects
Nov 2009 - Feb 2011
1 year 4 months
Cologne, Germany

Regional Head of Department Configuration & Capacity Management & Request Fulfilment

AXA Technology Services Germany GmbH - North Europe Service Delivery

Service Control division

  • Responsible for 18 employees and 1 local manager in Belgium, plus dotted-line leadership of the local Risk, Security & Compliance department with 5 employees until 05/2010
  • Implementation of the roadmap for regionalization and completion of the centralization of tasks/teams for configuration management, capacity management, service request fulfilment and service reporting
Oct 2007 - Oct 2009
2 years 1 month
Cologne, Germany

Regional Head of Department Config, Order & Service Management

AXA Technology Services Germany GmbH - North Europe Service Delivery

Service Control division

  • Responsible for 29 employees
  • Configuration management, order management, service reporting, OLA/SLA management, capacity management
  • Creation of the roadmap for regionalization including headcount plan until 2010
  • Planning and start of convergence projects
  • Centralization of tasks and teams
  • Standardization of processes and tools
  • Change management, building a regionally operating department
Sep 2006 - Oct 2007
1 year 2 months
Cologne, Germany

Head of Production Quality

AXA Technology Services Germany GmbH

Department manager in operations management

  • Responsible for 16 employees
  • Change management, incident management, problem management, test management, test center, OLA management
Dec 2004 - Sep 2006
1 year 10 months
Cologne, Germany

Global Infrastructure Strategy Manager

AXA Technology Services Germany GmbH

  • Functionally part of AXA Tech Corporate, Technology Office Paris – domain distributed server and since 01/2006 also domain mainframe – responsible globally for AXA Tech
  • Definition of technology standards (hardware & software)
  • Definition of global server standards with IBM
  • Monitoring compliance with standards, including the implementation of the “RISC to Intel” strategy
  • Strategic collaboration with Microsoft, IBM, Intel, DELL, etc.
Sep 1977 - Jan 1980
2 years 5 months
Cologne, Germany

Training as Wholesale and Foreign Trade Merchant (IHK)

Paul Brömmelhaupt KG, Fachgroßhandlung für Unterhaltungselektronik

Summary

Thomas Ullrich has more than 35 years of experience in the private sector in an international environment with an IT focus

  • Architecture / Infrastructure
  • Information Security
  • Cybersecurity

Languages

German
Native
English
Advanced

Education

Oct 1980 - Jun 1982

Fachoberschule für Wirtschaft Köln-Buchheim

Advanced technical college entrance qualification in business · Business · Cologne, Germany

Sep 1977 - Jan 1980

Fachgroßhandlung für Unterhaltungselektronik Paul Brömmelhaupt KG

Training as Wholesale and Foreign Trade Merchant (IHK) · Wholesale and foreign trade merchant · Cologne, Germany

Certifications & licenses

CSV basic training (GMP)

DORA (& NIS2) – IT security in the focus of supervision

IT baseline protection practitioner

BSI – Federal Office for Information Security

ITILv2 foundation certification

PECB Certified ISO/IEC 27001 Lead Auditor

PECB

SCRUM for agile project management (SCRUM Master & Product Owner Training)

CISO certificate (ITSiBe)

CERT/TeleTrust

Certified systemic management coach (VDMTC)

VDMTC