Executive snapshot
- Experience: 14+ Jahre
- Seniority: Experte
- Work mode: Verhandelbar
- Availability: Nach Absprache
- Region: Deutschland / EU
- Focus: Information Security, GRC, Cybersecurity, Automotive (ASPICE)
At a glance
Profile ID
DP-207692
Role
Cybersecurity Governance, Information Security Management, Risk Management, Compliance, Project Management
Seniority
Experte
Experience
14+ Jahre
Work mode
Verhandelbar
Availability
Nach Absprache
Region
Deutschland / EU
Languages
English: C1
Engagement models
Festanstellung, Projektarbeit
Indicative rate
Nach Absprache
Short profile
Experienced Information Security & GRC Expert with over 14 years of professional experience in Information Security Governance, ISMS, Information Risk Management, and regulatory compliance. Specializes in planning and conducting internal and external audits, assessing information security risks, and establishing effective governance structures. Advises project and management teams on implementing ISO/IEC 27001 and ASPICE requirements and integrates AI-driven approaches to enhance the efficiency of compliance processes. A video introduction is already available.
Focus (domains)
Information SecurityGRCCybersecurityAutomotive (ASPICE)SoftwareASPICESecurityConsultingManagementStakeholder Management
Core skills
Information Security Management (ISMS)GovernanceRisk & Compliance (GRC)Information Risk ManagementInternal & External AuditsAudit ReadinessControl Design & CAPARisk AssessmentsExecutive ReportingStakeholder ManagementCybersecuritySecuritySoftwareASPICECybersecurity / SecurityConsulting / Stakeholder / Leadership
Tools & technologies
LLMsRAGPythonFastAPIDockerPostgreSQLPGVectorOpenAIn8nCybersecuritySecuritySoftware
Track record & project highlights
Conception and development of an AI-powered compliance platform (AI3C) to support Information Security Governance, ISMS, and Audit Readiness according to ISO/IEC 27001. Led over 10 internal and external audits to assess information security risks and improve audit readiness. Advised international project and management teams on implementing ISO/IEC 27001 and ASPICE requirements. Established risk-oriented governance processes and continuously developed Information Security Management Systems.