Skip to main content
🇩🇪GDPR-compliant

Hire proven BSI IT-Grundschutz-Praktiker professionals in Germany, matched in minutes from 15,000 CVs with the power of AI

Find freelancers who can apply IT-Grundschutz in real projects: basic protection checks, risk-oriented safeguards, documentation, and support for secure operations. Get fast, precise matching with vetted professionals who hold the BSI IT-Grundschutz-Praktiker certificate.

About the certification

What it validates

The BSI IT-Grundschutz-Praktiker certificate shows that a person understands the basics of the IT-Grundschutz method from the Federal Office for Information Security. It is aimed at practical work, not abstract theory. A certified professional can support the first steps of a security program, help structure a protection concept, and work with teams that need a clear, German security baseline.

Core skills

  • Understanding the logic of IT-Grundschutz and how it is used in daily security work
  • Identifying typical assets, threats, and protection needs in an organization
  • Supporting basic safeguards and documenting security-relevant measures
  • Working with security officers, administrators, and auditors on a shared method
  • Translating the BSI approach into practical tasks for systems and processes

Typical profiles

People with the IT-Grundschutz-Praktiker, often written as Grundschutz-Praktiker, usually work close to infrastructure, governance, or compliance. They may be IT security coordinators, system administrators, consultants, internal auditors, or project staff who need a solid grasp of the BSI method. In Germany, this certificate is especially useful where teams want a common language for security work and clear documentation.

What companies get

A freelancer with this certificate can help organizations start or strengthen a structured security baseline. They are useful when a team needs support with asset views, safeguard selection, gap checks, or preparation for deeper security work. The certificate does not replace senior security expertise, but it tells you the person can work in a disciplined way with the IT-Grundschutz method and fit into projects where consistency matters.

Knowledge areas

A qualified professional usually understands the practical ideas behind:

  • BSI IT-Grundschutz modules and their purpose
  • Basic protection and how it differs from higher assurance work
  • Documentation, evidence, and repeatable security processes
  • Cooperation between security, operations, and management
  • The role of IT-Grundschutz in audits, internal controls, and secure project delivery

Where it matters

This certificate matters most in public sector work, regulated environments, and organizations in Germany that follow BSI-oriented security practices. It is also relevant in projects that need structured rollout of security requirements, preparation for audits, or clean documentation for existing controls. When you hire for this profile, you get someone who can contribute to methodical security work without needing a long ramp-up on the BSI approach.

Meet FRATCH BSI IT-Grundschutz-Praktiker

Peter Dittkuhn

Project Coordination, Consulting, IT Security, ISMS, BCM, NIS2, KVP

Callenberg

Last position:

Security Consultant at Public Institution of the City Administration

  • Requirements management, process planning, interface role, ISMS implementation and documentation
  • Implementation and establishment of an ISMS according to ISO 27001 as well as setup of emergency management / ITSCM
  • Coordination of conditions with the authority-affiliated IT service provider
  • Consideration of KRITIS relevance in the scope and implementation of a B3S
  • Development of guidelines for document control and the continuous improvement process (KVP)
  • Creation of relevant project documents
  • Analysis of existing processes and development of guidelines
  • Collection of requirements for ISMS and ITSCM and coordination with the IT service provider including definition of interfaces
  • Analysis of communication processes and escalation paths
  • Review of documents for risk management, ISMS, emergency preparedness and emergency response
  • Development of a complete rebuild of all documentation and creation of new relevant documents
  • Development of necessary rules, policies and concepts
  • Interface function between customer and service provider to ensure document quality
  • Coordination of protection needs with departments, especially regarding KRITIS relevance, and planning resulting measures
  • Development of preventive measures to minimize data center outages for various scenarios such as pandemics or ransomware attacks
  • Defining the test strategy for IT emergency exercises
  • Initiation of necessary training measures for raising awareness in departments
  • External Information Security Officer (ISB)
  • Introduction of document control
Peter Dittkuhn

Steffen Lotze

Data Protection Officer and Information Security Consultant

Grafrath

Last position:

Consultant for BSI IT Baseline Protection and ISO 27701 at German Society for International Cooperation

  • Support in setting up and further developing the information security management system
  • Collaboration with external consultants in the certification team for the support structure
  • Participation in project planning, identifying and implementing necessary measures according to BSI IT Baseline Protection
  • Professional support for in-house subject matter experts in preparing documents required for certifications
  • Execution of tasks according to BSI 200-2
Steffen Lotze

Kerstin Strasser

Managing Director, Interim IT Project Leadership, Crisis Project Management

Taunusstein

Last position:

Project management at IT service provider in the SAP area for energy companies

  • Project management for the SAP release upgrade of a large multi-client environment (IT service provider in the SAP area for energy companies)
  • Setting up a release process for future operational workflows
  • Cutover planning
  • Building a test management process with the involved clients
Kerstin Strasser

M. S.

Security Consultant

Last position:

Security consulting, audits & assessments

  • Innovation/pilot project eHealth Germany
  • SaaS company in the media sector, NRW
  • Secure software development lifecycle, NRW
  • BSI IT baseline protection assessments for multiple clinics
M. S.

Matthias Kühnlein

Risk Analyst

Schwindegg

Last position:

Business Owner at AKM

Management of several MFA methods for central authentication within a corporate group. Interface between various stakeholders such as support, accounting, developers, and security departments. Budget controlling and monitoring of KPIs as well as SLAs. Review of operational documentation

Matthias Kühnlein

Markus Blohm

Consultant, Technical Project Manager

Bergheim

Last position:

Consultant, Technical Project Manager at Lanxess

  • Project: ESU Windows and SQL Server consolidation / Configuration Management in ServiceNow
  • Creation of an as-is analysis of all servers worldwide
  • Creation of an as-is analysis of all SQL servers worldwide
  • Creation of requirements analyses for SQL and server migrations
  • Coordination of requirements with partners for migrations to Hyper-V (on-premises) or Azure Cloud
  • Moderation of jour fixe meetings
  • Creation of roadmaps and solution models for server migrations
  • Setup of test scenarios
  • Moderation of workshops for the introduction of a Global Admin Team
  • Creation of data models (CMDB) in ServiceNow
  • Conducting workshops for the CMDB data model
  • Creation of solution models for the CMDB
  • Creation of seamless configuration and work documentation for the CMDB
  • Creation of reports for license management
  • Creation of KPIs for data quality in ServiceNow
  • Creation of a service catalog
  • Moderation of workshops for creating service requests
  • Interface between needs analysis and ServiceNow development team
  • Systems used: Windows 7, Windows 10, Microsoft Office 365/2010, Windows Server 20xx, SQL Server 20xx, SharePoint, Azure Cloud, Hyper-V, ServiceNow, various tools
Markus Blohm

Tarek El Idrisi

IT-Consultant

Dortmund

Last position:

Associate GRC at Egerer Consulting

Carve-out project: Development of certification strategy, implementation and requirement plans across multiple standards — ISO/IEC 27001, ISO 9001, ISO 14001, ISO 22301, ISO/IEC 20000-1, BSI IT-Grundschutz, and BSI TR-RESISCAN

  • Cross-standard inventory and risk assessment
  • Coordination with cross-department stakeholders: ISB, executive management, certification bodies, legal and data protection
  • Consulting in information security, GRC, and IT auditing
Tarek El Idrisi

Florian Krebs

Self-employed IT and Security Consultant

Olching

Last position:

LAN Planner at Global Network AG

  • As-is assessment of the current network infrastructure and its documentation, including on-site inspections
  • Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
  • Planning of new copper and fiber optic cabling, including patch panels
  • Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
  • Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
  • Additional support after the components go live (hypercare phase)
  • Regular communication with project management and client stakeholders
Florian Krebs

Michael Fitschen

Managing Consultant Information Security and Data Protection

Heeslingen

Last position:

Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund

  • Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
  • Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
  • Collaborating with the Information Security Officer (ISO)
  • Identifying company assets for IT risk management
  • Developing a zone concept for IT risk management
  • Creating an action plan for B3S
  • Developing a template for risk analyses
Michael Fitschen

Andreas Ilias

Senior Cybersecurity Governance & ISMS Consultant

Frankfurt am Main

Last position:

Cybersecurity Specialist Assessor at Bundesnetzagentur

  • Recognition of national notified bodies
  • Preparation of cybersecurity competency reports
  • EU Radio Equipment Directive
Andreas Ilias

David Bleyer

Acting Partner

Blieskastel

Last position:

Acting Partner at Bliestal Consulting UG

  • Redesigning cablewise infrastructure with CAT 8.1 keystones, measuring the speed and quality of the new installation with Pockethernet, documentation at a local saddlery
  • CAT 8.1 installation and building a data center, site linking, VPN and VLAN configuration for a local car dealership, implementation of IT-Security standards like virus protection (G Data) and firewalling (OPNSense)
  • Relocation of a tax office with redesign of the IT infrastructure, virus protection (G Data) and backup solutions (QNAP)
  • Planning, conception and implementation of an inhouse data center, BSI-compliant for commercial laundry (including Proxmox-based virtualization of existing infrastructures, QNAP, G Data, OPNSense, APC)
  • Implementation and conception of security solutions in the SME sector
  • Collaboration on the IT-security concept for the Bremen network of authorities (in the dLAN network)
  • Creation of IT-security concept VOIS (modules MESO, KFZ/iKFZ) including audit preparation for KBA
  • Expansion of the IT-security concept for the online service for electronic residence registration (eWA) to include use as an eFA (one-for-all) service (nationwide)
  • Expansion of the IT-security concept to include modules wos & wvp
  • Concept development for the implementation of DIN SPEC 27076 at MSEs and SMEs
  • Creation and evaluation of emergency concepts
  • Creation and evaluation of response actions and BCM plans
  • Assessment of existing business continuity management (ISO 22301)
  • Development of BCM strategy options
  • Conducting awareness training
David Bleyer

Dirk Behringer

Senior Consultant Database Administration and SQL

Mandelbachtal

Last position:

Senior Consultant Database Administration and SQL at Bliestal Consulting UG

  • Complete redesign of IT infrastructure including setup of a server room according to BSI standards, new network concept and planning.
  • Development of security concepts and IT security consulting for the DHCP/DNS election sector.
  • Support of project management for the customer in the VOIS | MESO area.
  • Technical support for setting up the IT infrastructure in new offices, including firewall configuration, router setup and network planning.
  • Setup and configuration of the service management and ticket system JIRA.
  • Implementation and administration of the Azure (Entra) environment for all employees.
  • Setup and administration of the Confluence environment.
  • Planning, setup, configuration and administration of the entire Atlassian Collaboration Suite.
  • Development of BCM strategy options.
  • Development and implementation of measures and creation of BCM plans, as well as evaluation of existing BCM.
Dirk Behringer

Jens Brennscheidt

Senior Cyber Security Consultant

Bochum

Last position:

Senior Cyber Security Consultant at Brennscheidt IT Consulting

  • ISMS consulting

  • Interim management

  • Conducting security analyses & audits

  • BCM consulting

  • Executive management

Jens Brennscheidt

Valeri Milke

Associate Partner - Information Security Consulting

Bonn

Last position:

Associate Partner - Information Security Consulting at Insentis GmbH

  • Improvement of the Information Security Management System (ISMS) based on ISO 27001, NIS2, DORA, B3S, TISAX and BSI IT Baseline Protection
  • Conducting comprehensive gap analyses to identify gaps and derive action plans according to the above standards and regulations; management and KPIs
  • Data Loss Prevention strategy and implementation using MS Purview
  • Vulnerability and patch management, security monitoring
  • Risk analysis and threat modeling using the STRIDE methodology
  • Development of vendor risk assessments, implementation of risk classifications, conducting supplier assessments and implementing technical monitoring solutions (e.g. Security ScoreCard)
  • Securing cloud environments (AWS and Azure); expertise in CSPM/CNAPP (Wiz), cloud migration, secure CI/CD pipelines, container security and best practices in AWS, Azure and Office 365
  • Application security: penetration testing, DevSecOps, OWASP, pre-commit hooks, key and secret management, IDE plugins, static source code analysis, dependency checks, container scanning, vulnerability management, CIS benchmarks and compliance
  • Security assessment and hardening according to CIS benchmarks and cloud conformity in AWS, Office 365 and Azure
Valeri Milke

Frank Joraschkewitz

Lead Project Manager

Lindlar

Last position:

Lead Project Manager at Energy Supply Industry

  • Managed a large-scale transformation project to replace a complex multi-provider, multi-technology infrastructure with a unified single-provider platform
  • Had overall responsibility for planning, managing, and executing the migration of all LAN, WAN, and WiFi components at national and international locations under high availability and security requirements (critical infrastructure)
  • Developed and implemented the migration strategy, including a detailed rollout roadmap and risk management plan
  • Directed interdisciplinary project teams and coordinated with service providers and internal stakeholders
  • Ensured compliance with schedule, budget, and quality requirements
  • Introduced standardized operational processes and handed over to routine operations
  • Provided regular, detailed reporting to the steering committee and C-level executives
Frank Joraschkewitz

Discover over 15,000 top freelancers

BSI IT-Grundschutz-Praktiker statistics

Typical experience

21 years

Average project duration

2.6 years

Certifications per freelancer

11

Top business areas

Information Technology, Project Management, Quality Assurance

Top industries

Information Technology, Professional Services, Banking and Finance

Most common languages

German, English, Spanish

Bachelor's degree or higher

79%

Master's degree or higher

50%

Doctorate

17%

Salary / Daily Rate Distribution

0 3 6 9 12
<€480 €640-800 €800-960 €960-1120 €1120-1280 €1280+

The chart shows how the daily rates of freelancers holding this certification are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

Average rates for BSI IT-Grundschutz-Praktiker & Seniority distribution

Rates are based on recent contracts and do not include FRATCH margin.

1200
900
600
300
Rate comparison chart
Daily rate avg. 993 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1200
900
600
300
Rate comparison chart
Median rate 1000 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Try FRATCH GPT

Frequently Asked Questions

Need clarity? Check out our simple overview of FRATCH

The BSI IT-Grundschutz-Praktiker certificate validates practical knowledge of the BSI IT-Grundschutz method. It shows that the holder can understand basic protection concepts, work with structured security documentation, and support safeguard selection in real projects. It is a hands-on certificate for day-to-day security work, not a high-level design or leadership credential.

The IT-Grundschutz-Praktiker level is about applying the method correctly in practice. More advanced BSI-related roles usually require deeper experience with security management, auditing, or detailed concept work. If you need someone to support implementation and documentation rather than lead a full security program, this level can be a good fit.

The BSI IT-Grundschutz-Praktiker is well suited to people who work close to information security, operations, or compliance. That includes consultants, security coordinators, system administrators, internal control staff, and project members who need a solid understanding of the BSI approach. It is also useful for freelancers who want to support clients using German security standards.

A freelancer with the Grundschutz-Praktiker certificate fits projects that need structured security basics. Typical work includes building or updating a protection concept, mapping assets and safeguards, supporting documentation, and preparing teams for security reviews. It is especially relevant when the client wants a methodical approach based on BSI IT-Grundschutz.

For the BSI IT-Grundschutz-Praktiker, preparation usually means learning the IT-Grundschutz method, the structure of the BSI modules, and the practical use of basic protection in projects. Candidates benefit from real work experience in IT, security, or compliance because the certificate is focused on application. Formal entry requirements are usually handled by the training provider or exam route, so it is worth checking the current path before booking.

The IT-Grundschutz-Praktiker certificate is tied to the BSI training and exam framework, so renewal depends on the current rules of the issuing body and the training path you choose. Professionals should always verify whether their proof of competence is considered current for the role or client they want to support. In practice, companies care less about the label alone and more about whether the person still works confidently with the method.

The BSI IT-Grundschutz-Praktiker is especially relevant in Germany because many organizations use BSI-oriented security concepts and documentation styles. That makes the certificate a useful signal when a client wants a freelancer who understands the local method and can communicate clearly with German-speaking teams. It can also help when on-site collaboration is needed alongside remote work.

A profile with the BSI IT-Grundschutz-Praktiker tells you the person can contribute to structured security work without needing a long introduction to the BSI method. It is a good sign for tasks that require disciplined documentation, basic safeguard thinking, and cooperation with IT and management. For complex security architecture or high-level governance, you may still want to pair that person with a more senior specialist.

Request a Free Demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO Avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH