Hire the best security leaders with a Certified Information Security Manager (CISM) certificate in Germany in minutes from over 15,000 CVs with the power of AI.
Secure your enterprise assets with senior freelance consultants specializing in security governance, risk assessment, and incident management. FRATCH delivers fast, precise matching with fully vetted security experts in Germany who align your defense strategies with business objectives.
About the certification
Strategic Security Governance in German Enterprises
The Certified Information Security Manager (CISM) credential issued by ISACA is highly regarded across German corporate sectors as the standard for enterprise security leadership. Unlike purely technical cybersecurity certifications, it validates a professional's ability to integrate security measures into the core business strategy. For organizations operating in Germany, engaging an expert with this qualification means establishing a security posture that supports operational growth while meeting stringent local and international compliance standards.
Core Competencies of Certified Professionals
Freelancers holding this designation are equipped to direct, design, and oversee complex security programs. They act as strategic partners to executive boards, translating technical vulnerabilities into clear business risks and mitigation strategies.
- Developing and maintaining comprehensive information security governance frameworks
- Conducting systematic risk assessments and implementing risk management strategies
- Designing, implementing, and monitoring the overall information security program
- Managing security incident response plans and business continuity procedures
When to Engage a Freelance Security Consultant
Organizations in Germany typically seek freelance security managers during periods of organizational change, such as mergers, digital transformations, or when preparing for critical regulatory audits. A contract professional provides immediate leadership to bridge gaps in internal security management, design robust security architectures, and prepare teams for external assessments. This external expertise allows companies to address critical security demands quickly without the overhead of a permanent hire.
Enhancing Local Compliance and Operational Resilience
With German industries deeply integrated into global supply chains and bound by European data regulations, maintaining a resilient security framework is critical. Certified freelancers bring external perspective and standardized methodology to ensure your operations are resilient against cyber threats. They help secure sensitive corporate assets, establish clear incident protocols, and foster a culture of security awareness across all business departments.
Meet FRATCH Certified Information Security Manager (CISM)
Florian Krebs
Self-employed IT and Security Consultant
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Alexander Sänn
Owner and Managing Director
Last position:
Lead Audit Conformity & IT Security Catalog at DAX group energy provider in the renewable energy sector
- Supported the implementation of §8a requirements of the BSI Act for critical infrastructures.
- Systematically prepared and supported internal and external audits, resolving previous deviations (HA, NA, VP)
- Implemented the specific requirements of the IT security catalog
- Developed training, created run books, and conducted assessments to ensure operational effectiveness.
Flamur Abdyli
Fractional Chief Information Security Officer
Last position:
Fractional Chief Information Security Officer at VR Smart Guide GmbH
- Enhance and develop the Information Security Management System (ISMS) in compliance with ISO 27001 and TISAX standards by continuously updating and refining the ISMS to align with evolving global standards.
- Ensure that security practices and policies are integrated into all business processes to achieve and maintain certifications.
- Lead the effort to identify, evaluate and mitigate risks across the organization, setting benchmarks for security measures.
- Oversee and refine security processes, with an emphasis on incident management and rapid response by developing and enforcing policies for rapid detection, investigation and remediation of security incidents.
- Train and lead the incident response team to handle breaches effectively, minimizing impact and ensuring swift recovery.
- Implement continuous monitoring solutions to detect and respond to threats in real time.
- Conduct comprehensive security assessments for internal and external IT projects, ensuring adherence to GDPR, DORA and other relevant standards.
- Oversee security evaluations for all IT projects to ensure they comply with legal and regulatory requirements.
- Integrate security measures from the planning phase through deployment to ensure all projects uphold the organization’s security standards.
- Collaborate with project teams to address findings and ensure that security risks are managed effectively.
- Serve as the principal security advisor to the IT department and senior management, offering insights on potential security challenges.
- Facilitate a culture of security awareness throughout the organization through training and regular communication.
- Lead security initiatives that align with the organization’s long-term strategic goals.
- Establish and oversee a robust third-party risk management framework to mitigate external security threats by regularly assessing third-party security practices and compliance and developing contingency plans and mitigation strategies.
- Provide regular updates and security briefings to the executive leadership and relevant committees, highlighting recent security incidents, responses, lessons learned and recommending strategic improvements.
Tariq Burki
Management Consultant
Last position:
Management Consultant
- Functioned as a Fractional CIO for the GCC's largest gaming distributor, leading a complete IT transformation infrastructure upgrade and outsourcing of IT services and ERP applications
- Oversaw the development and rollout of two CEO-sponsored business systems with a $40 million budget, including the implementation of a comprehensive Hydrocarbon Accounting System (Tieto) and a Supply Chain Management System integrating seven multi-vendor applications across Qatargas, Rasgas, and Qatar Petroleum
- Led Schlumberger's global outsourcing, securing a $350 million deal over five years with a 15% cost reduction, managing a global team of over 30 and implementing operational models and frameworks for chargeback, procurement, and IT management
- Navigated technically intricate and organizationally demanding projects for prestigious companies worldwide across more than 30 countries, leading diverse teams and driving strategic innovation
Jens Brennscheidt
Senior Cyber Security Consultant
Last position:
Senior Cyber Security Consultant at Brennscheidt IT Consulting
ISMS consulting
Interim management
Conducting security analyses & audits
BCM consulting
Executive management
Sergey Komarov
Managing Director Cybersecurity
Last position:
Managing Director Cybersecurity at CBA-Cybersecurity and Business Advisory GmbH
- Development of comprehensive services in cybersecurity, IT governance, and AI
- Building and delivering strategic security solutions such as vCISO service, ISMS, SOC-as-a-Service (SIEM, SOAR, use cases, playbooks, threat hunting, incident response), AI-driven risk and compliance tools, and frameworks for outsourcing and third-party risks
- Supporting companies in meeting regulatory requirements and certifications (ISMS, NIS-2, DORA, CRA, KRITIS, ISO 27001, TISAX, BSI IT Baseline Protection, EU AI Act)
- Promoting innovations in cybersecurity automation, AI governance, and secure digital transformation
- Responsible for company growth, client relations, and strategic partnerships
Tobias Greiner
Head of IT D-A-CH (CIO)
Last position:
Head of IT D-A-CH (CIO) at Sodexo Service GmbH
- Responsible for IT strategy and operational IT governance in the D-A-CH region, covering infrastructure, applications, operations, security, and support
- Developed and implemented a strategic IT transformation to improve scalability, efficiency, and security of IT systems
- Managed a team of 25 specialists and coordinated with global and regional IT stakeholders
- Deployed a centralized IT service model for 250+ sites to standardize and optimize processes
- Supported and technically executed a carve-out to ensure business continuity
- Introduced modern cloud technologies and automation solutions to optimize processes
- Ensured compliance with ISO 27001, GDPR, and ITIL standards to minimize security risks
- Reduced IT costs by 20% through cloud migration and IT consolidation
- Built and led a high-performing IT team with focus on innovation and service orientation
- Led IT transformation projects including ERP migration, IT security, and digitalization
- Improved IT security level by implementing ISO 27001 and GDPR-compliant processes
- Optimized service times by 30% through AI-powered process automation
Victor Reyna-Vargas
Senior Consultant - Innovation & Transformation
Last position:
Senior Consultant - Innovation & Transformation at advisio GmbH
- Led cross-industry initiatives in product management, IT governance, agile transformation, and business development.
- Advised executives on portfolio strategy, innovation roadmaps, governance frameworks, and operational execution.
- Developed KPI dashboards and frameworks translating strategy into measurable results.
Bernhard Bowitz
Senior Security Architect
Last position:
Senior Security Architect at Intermediate Beratung
- Consulting on an ongoing IT security architecture project
- Documenting past progress and planning next steps
- Applying and implementing the BSI IT baseline protection
- Building and maintaining security management systems
- Applying the ISO 27001 standard series
- Integrating ITIL processes into security architectures
- Collaborating with public clients, regulatory authorities and internal and external service providers
Norbert Stilling
Self-Employed Consultant and Project Manager
Last position:
Self-Employed Consultant and Project Manager at Self-Employed Consultant and Project Manager
- 21 projects ≥ 6 months at large and medium-sized companies
- 13 projects as project or subproject manager
- 6 international projects with English as project language
Mateusz Pychynski
IT Project Manager
Last position:
IT Project Manager at Universal Investment
- Led infrastructure and security integration project for Private Equity acquisition, reducing security vulnerabilities through streamlined governance.
- Restructured resource allocation for strategic projects, enhancing governance through automated tracking and reporting to executive stakeholders.
Mohamed Ghassen Brahim
Founder & CEO
Last position:
Lead / Principal Cloud, AI & Security Architect at Freelancer / CC Conceptualise GmbH
Projects:
Project: RWE – Development of a company-wide Zero Trust cybersecurity architecture (CITADEL) Role: Senior Enterprise Cybersecurity Architect / Zero Trust Architect Company: RWE AG Description: Concept and implementation of the strategic CITADEL cybersecurity target architecture at RWE, based on the Zero Trust architecture principle and aligned with regulatory requirements such as NIS2, ISO 27001 and company-wide security governance policies. The goal was to build a measurable, auditable and scalable security architecture with a strong focus on Identity Governance, compliance transparency and operational manageability. Responsibilities & Achievements:
- Zero Trust architecture design: Developed a company-wide Zero Trust reference architecture (Identity, Device, Network, Application, Data) including trust zones, control points and enforcement mechanisms according to NIS2.
- Identity & Access Governance (IGA): Designed and introduced IGA governance structures including role models, recertification processes, segregation of duties (SoD) and lifecycle management for identities and access.
- Security governance & KPIs: Defined and implemented security KPIs and metrics to manage Zero Trust maturity, identity risks and compliance at the management level.
- Compliance & reporting: Built standardized compliance reports and dashboards to support internal audits, external assessments and regulatory evidence (e.g. NIS2).
- Architecture & stakeholder alignment: Worked closely with Enterprise Architecture, IT operations and business units to integrate the CITADEL architecture into existing IT and security landscapes.
- Strategic security consulting: Advised programs and projects on Zero Trust compliance, identity centricity and regulatory requirements in the energy and critical infrastructure (KRITIS) environment. Technologies & Methods: Zero Trust Architecture, NIS2, Identity Governance & Administration (IGA), IAM, RBAC, SoD, Entra ID, SailPoint, Zscaler, Terraform / IaC, Policy as Code, security KPIs, compliance reporting, NIST 2.0, ISO 27001, Enterprise Security Architecture, governance frameworks, risk & control management
Project: Scalable AI Workbench Platform on Microsoft Azure Role: Cloud Architect & Engineer Company: Siemens Energy Description: Design, development and operation of a secure, modular cloud infrastructure to support Data Science, Machine Learning and AI applications for various engineering teams at Siemens Energy. Responsibilities & Achievements:
- Cloud architecture: Designed and implemented an Infrastructure-as-Code solution (Terraform) for automated provisioning of Azure resources (Resource Groups, Storage Accounts, Cosmos DB, Application Insights, networking, PostgreSQL Flexible Server, Azure Container Apps, Azure Container Registry).
- Developer portal: Used Backstage with custom frontend and backend plugins (Node.js, TypeScript, React.js, PostgreSQL, Container Apps) to enable self-service and empower developers, data scientists and AI/ML engineers.
- Role-based access control: Implemented Azure RBAC to grant targeted access (e.g. Storage Blob Data Contributor, Reader) to engineering groups (e.g. AI Engineers) for relevant resources.
- Data platform engineering: Built and configured a multi-layered storage landscape (Raw, Curated, Vector data), including automated container creation and access control for advanced analytics and AI workloads.
- DevOps integration: Integrated with Azure DevOps for CI/CD pipelines to automate deployment, monitoring and compliance.
- Security & compliance: Implemented Private Endpoints, network policies and Managed Identities to ensure data protection and regulatory compliance.
- Collaboration: Worked closely with cross-functional teams to align the cloud infrastructure with business and technical requirements and drive digital transformation at Siemens Energy. Technologies: Azure, Terraform, Azure DevOps, Cosmos DB, Application Insights, Azure Storage, Private Endpoints, Azure Synapse, Azure Machine Learning, Azure Entra ID, RBAC, Backstage, Node.js, React.js, PostgreSQL, Python (automation), Git
Christine Mährle
Freelance Regulatory & IT Specialist in Banking
Last position:
Management Consultant at Freelance
Conducting ICT/DORA management trainings based on DORA Article 5(4) at various banking institutions
Teaching the key elements of DORA requirements with a focus on ICT risks, third-party risk management, incident and problem management, and information registers
Deriving implementation measures and recommendations for management and business units
Andreas Karl
Head of Information Management
Last position:
Head of Information Management at BAUR Versand – a part of the OTTO Group
- Head of Service and Operations
- Deputy CIO
- Overall strategic and operational responsibility for 1st and 2nd level IT support for approx. 4500 employees
- Head of IT operations
- Strategic responsibility for IT service management and IT governance, plan/build/run companywide IT service management
Thoralf Thorson
Consultant Digital Operational Resilience Act (DORA)
Last position:
Consultant Digital Operational Resilience Act (DORA) at Swisslife Deutschland GmbH
- Auditing CIS evidence of the SOC providers T-Systems Austria and Cancom GmbH
- Mapping of VAIT, ISO:IEC 27002 and CIS 7.0 requirements for the IT realignment strategy of the German subsidiaries in threat intelligence and zero trust
- Reviewing SIEM evidence, reporting, incident management and security breaches
- Reviewing IT asset management regarding ITSCM and BCM processes
- Employee awareness and compliance training focused on CEO fraud
- Advising the chief information security officer
Discover over 15,000 top freelancers
Certified Information Security Manager (CISM) statistics
Typical experience
23 years
Average project duration
3.7 years
Certifications per freelancer
9
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Professional Services, Banking and Finance
Most common languages
German, English, French
Bachelor's degree or higher
94%
Master's degree or higher
76%
Doctorate
18%
Salary / Daily Rate Distribution
The chart shows how the daily rates of freelancers holding this certification are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Average rates for Certified Information Security Manager (CISM) & Seniority distribution
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Frequently Asked Questions
Curious about FRATCH? Find the answers you need
A professional holding the Certified Information Security Manager (CISM) credential has proven their ability to design, manage, and oversee an enterprise security program. Unlike technical certifications, it focuses heavily on business strategy, governance, and risk management. This ensures that the expert can effectively align cybersecurity initiatives with your organizational goals.
The CISM is designed specifically for security management and focuses on governance, risk assessment, and program development from a business perspective. In contrast, CISSP covers a broader, more technical spectrum of security domains. Companies seeking a leader to align IT security with business operations generally look for the former.
German businesses face strict regulatory environments, including the IT Security Act and European compliance laws. A freelancer with the CISM designation possesses the structured methodology needed to build compliant, auditable governance systems. Their strategic approach helps local organizations avoid costly compliance violations and operational disruptions.
To obtain the qualification, candidates must pass a rigorous examination and prove substantial professional work experience in information security management. They are also required to adhere to a strict code of professional ethics. This ensures that any freelancer holding the CISM has a solid foundation of real-world management experience.
Yes, consultants holding the CISM credential are experts in implementing security frameworks that align with international standards. They can guide your organization through the preparation, risk assessment, policy development, and documentation phases necessary for successful audits. Their systematic management approach streamlines the path to compliance.
A manager with CISM training establishes and refines incident response plans before crises occur to minimize overall business impact. During an active incident, they coordinate the technical response, manage stakeholders, and lead recovery efforts. Their primary focus is maintaining business continuity and preserving operational integrity.
Many freelance security managers operate effectively in hybrid or remote structures. While the initial discovery phases, stakeholder interviews, and alignment workshops benefit from on-site presence in Germany, the development of frameworks and regular monitoring are highly suited for remote execution.
To maintain the CISM status, professionals must complete continuous professional education activities regularly. This mandatory program guarantees that certified freelancers stay informed about emerging global threats, legislative changes, and modern security technologies.
Request a Free Demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
