Skip to main content
🇩🇪GDPR-compliant

Hire proven Certified Information Systems Security Professional (CISSP) experts in Germany, matched in minutes from 15,000 CVs with the power of AI.

CISSP holders bring practical depth in security governance, risk management, and enterprise architecture. They are used to designing controls, guiding incident response, and aligning security with business needs. Get fast, precise access to vetted freelancers who hold the CISSP.

About the certification

What CISSP means

The Certified Information Systems Security Professional, better known as CISSP, is ISC2’s flagship credential for senior security work. It signals broad, structured knowledge across information security and the ability to connect policy, architecture, operations, and risk.

What it validates

  • Security governance and program design
  • Risk assessment and control selection
  • Security architecture and engineering decisions
  • Identity, access, and asset protection
  • Incident response and recovery planning
  • Security operations in complex environments

This is not a narrow tool certificate. CISSP is about making sound security decisions across the full enterprise.

Typical holder profile

CISSP is common among security managers, architects, consultants, and senior engineers. It also fits freelancers who advise on security roadmaps, assess maturity, or support regulated projects where trust, documentation, and cross-team coordination matter.

In Germany, companies often look for CISSP holders when they need clear communication with technical and non-technical stakeholders. That matters in mixed teams, international projects, and remote engagements where expectations must be explicit.

Knowledge areas

  • Security and risk management
  • Asset security and data handling
  • Security architecture and network design
  • Identity and access management
  • Security assessment and testing
  • Security operations and incident handling
  • Software development security

The strength of CISSP is breadth. It helps companies see whether a freelancer can reason across domains instead of staying inside one specialty.

What it says about a freelancer

A freelancer with CISSP is usually ready for advisory work, audits, security reviews, policy work, and hands-on coordination in larger environments. The credential suggests they can talk to leadership, challenge weak controls, and translate risk into practical action.

For companies in Germany, that is useful when security work must fit local teams, global standards, and remote collaboration at the same time.

Best-fit project work

  • Security program setup or improvement
  • Cloud and infrastructure security reviews
  • Identity and access redesign
  • Incident response planning and tabletop exercises
  • Third-party and vendor risk reviews
  • Policy and control documentation

CISSP is especially relevant in projects where the main challenge is not a single technology, but the way many security areas need to work together.

Meet FRATCH Certified Information Systems Security Professional (CISSP)

Rudolf Eggelbusch

Datacenter Engineer, Network & Security Administrator

Ratingen

Last position:

Datacenter Engineer, Network & Security Administrator at International insurance group

  • Operation and further development of the network and security infrastructure.

  • Monitoring, analysis and resolution of network and security incidents.

  • Cross-department collaboration with other specialist teams for operations, further development and reporting.

  • Firewall vulnerability analysis.

  • Firewall rule approvals.

  • Troubleshooting IP communication issues in the network and firewall infrastructure.

  • Security-critical IT infrastructure, processing of personal data, compliance with legal regulations.

  • Products: Palo Alto Networks Firewalls, Cisco ACI, Checkpoint Firewalls, F5

  • Technologies: SDN, SDWAN, Cisco EPIC, Cisco ACI

Rudolf Eggelbusch

Julian Wendel

IT Consultant

Ellerstadt

Last position:

Renewal of the active network infrastructure

As part of this project, the existing active network infrastructure was modernized and aligned for the future. The goal was to introduce a high-performance, secure, and scalable network and WLAN infrastructure, including a Network Access Control (NAC) solution to improve network security and central access control.

At the start of the project, a comprehensive requirements analysis was carried out, taking into account the technical, operational, and security-related needs of the clinic sites. Based on this, a technical tender was prepared for new switches, WLAN access points, and the NAC solution.

By successfully delivering the project, a modern, standardized, and secure network infrastructure was established that meets the growing demands for availability, mobility, and IT security in clinical operations.

Tasks:

  • Support of the tender process, including technical evaluation of the offers and bidder assessment
  • Lead and coordinate the entire project delivery
  • Align the project process with internal stakeholders, business units, and the hospital IT team
  • Manage external service providers during implementation and installation of the systems
  • Monitor implementation, including quality control, project acceptance, and issue management
  • Coordinate communication between hospital IT and external service providers during the NAC implementation
  • Carry out escalation management for technical and organizational challenges
  • Ongoing budget tracking as well as monitoring of project effort and additional costs
  • Prepare decision papers on project changes, additional services, and risks for management
Julian Wendel

Robert Francia

Interim Project Manager

Kriftel

Last position:

Interim Project Manager at IT services company of a regional energy supplier

  • Delivery of various end-customer projects in server and network infrastructure on time, in quality, and within budget.
  • Project 1: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall at an automotive supplier.
  • Project 2: Migration of file services from dedicated servers at 5 branch locations into a central managed file service, including DHCP, directory, and print services, as well as decommissioning of the old domain controllers.
  • Project 3: Renewal of the network infrastructure at the headquarters and branch locations of a logistics company and transition of the LAN, WLAN, and firewall environments into a managed network service.
  • Project 4: Network renewal, replacement of the core and access switches at the headquarters of a medical technology company and transition into a managed network service.
  • Project 5: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall for a city.
  • Environment: ASA and Fortinet firewalls, Cisco network components, ITSM Heat/Ivanti, Confluence.
Robert Francia

Enrique Gallardo

Data Security

Hamburg

Last position:

Security Architect at Capgemini

I implemented a Zero-Trust architecture for robust, military-grade maritime container mini data centers based on VMware & Tanzu to support containerized GIS workloads for ground forces. The main focus was on securing communications, workload protection, and data access in contested electronic battle environments affected by jamming, interception, signal manipulation, and constantly changing operational conditions. I designed and architected use cases so that every element of workload, identity, and system could continue to operate independently and securely even in degraded or disrupted scenarios. In parallel, I defined the enterprise and solution security architecture with LeanIX, Bizzdesign, and HOPEX as enterprise architecture, repository, and governance platforms to maintain architecture inventory, relationships, traceability, target pictures, and security governance in complex environments. For the architectural designs, I used Sparx Enterprise Architect to describe formal architecture views, interfaces, trust boundaries, and system architecture in both IT and OT environments. IriusRisk was used for threat modeling of the solution to identify architecture-driven risks, derive security requirements, and detect countermeasures and design gaps directly from the solution models. Risk and compliance management was supported with Archer. Architecture decisions, control gaps, and operational risks were translated into controlled governance and auditable compliance measures. For documentation, collaboration, and visual design, I used Confluence to maintain Architecture Decision Records, Security Blueprints, and workflows. I used Lucidchart and draw.io to create design artifacts tailored to stakeholders. I also defined OT security concepts with support from electrical and mechanical engineers in the areas of oil, vehicle onboard systems, rail, power plants, pharma, gas turbines, and nuclear technology. I created the end-to-end OT security strategy, starting with global policy, developed into standards and procedures, and finally aligned with Bell-LaPadula, Purdue Model, SABSA, TOGAF ADM, CENELEC 50701, IEC 62443, and NIST standards. In addition, I worked with engineering team leads to identify critical KBP assets and place them under protective measures that segmented SCADA, PLC, and HMI assets. I drove collaboration between Security, IT, and OT teams to create standardized workflows and use cases for the OT security solution catalog, while integrating Defense-in-Depth and Zero-Trust principles into operational environments. A key part of my work was integrating multidisciplinary engineering, security, and operations stakeholders into a unified security blueprinting strategy and ensuring that architecture, threat modeling, governance, and documentation were technically strong and operationally practical.

Enrique Gallardo

Marco Zehner

Product Owner IT Services; Solution Architect central service delivery

Wiesbaden

Last position:

Product Owner IT Services; Solution Architect central service delivery at BWI

  • Create product vision

  • Commission Scrum teams

  • Create schedule and coordinate with project lead

  • Coordinate and align with stakeholders

  • Harmonize processes across initiatives

  • Present project content at C-level

  • Create security concept for classified information up to DEU GEHEIM and NATO SECRET considering BSI GS, KRITIS, SÜG, VSA

  • Plan service changes to underpinning services

  • Design architecture for secure infrastructures

  • Dependency management in project context

  • Risk management

  • Requirements management

  • Commission and oversee protection needs analysis and information security concept

  • Coordinate service design activities

Marco Zehner

Stanislaus Stelle

Security Consultant at Rohde & Schwarz AG

Monheim am Rhein

Last position:

Security Consultant at Rohde & Schwarz AG at Star Labs GmbH

  • Worked on FPGA enhanced network encryption device with secure boot, TPM2.0 and smart card integration for BSI approved usage with Post Quantum Cryptography
  • Developed and audited Linux drivers
  • Collaborated using GitLab, Gerrit, Confluence and Jira
  • Technologies: C, C++, Secure Boot
Stanislaus Stelle

Andreas Ilias

Senior Cybersecurity Governance & ISMS Consultant

Frankfurt am Main

Last position:

Cybersecurity Specialist Assessor at Bundesnetzagentur

  • Recognition of national notified bodies
  • Preparation of cybersecurity competency reports
  • EU Radio Equipment Directive
Andreas Ilias

Sergey Komarov

Managing Director Cybersecurity

Stuttgart

Last position:

Managing Director Cybersecurity at CBA-Cybersecurity and Business Advisory GmbH

  • Development of comprehensive services in cybersecurity, IT governance, and AI
  • Building and delivering strategic security solutions such as vCISO service, ISMS, SOC-as-a-Service (SIEM, SOAR, use cases, playbooks, threat hunting, incident response), AI-driven risk and compliance tools, and frameworks for outsourcing and third-party risks
  • Supporting companies in meeting regulatory requirements and certifications (ISMS, NIS-2, DORA, CRA, KRITIS, ISO 27001, TISAX, BSI IT Baseline Protection, EU AI Act)
  • Promoting innovations in cybersecurity automation, AI governance, and secure digital transformation
  • Responsible for company growth, client relations, and strategic partnerships
Sergey Komarov

Stefan Vesenmeier

PMO

Lörrach

Last position:

PMO at Roche

  • Mission: PMO for ASPIRE MES Integration Project, alleviating technical project managers from routine project management responsibilities, with emphasis on risk management.
  • Monitor and steer compliance-relevant documentation handling.
  • Tasks:
  • Establish and monitor a continuous risk management process.
  • Implement a regular automated reporting system.
  • Prepare and facilitate the SteerCo meetings.
  • Organize workshops and team-building activities.
  • Support validation of test documents in the eVAL Validation tool.
  • Skills: Risk management, project reporting, data analysis, communication, project management, organizational and leadership skills, critical thinking, problem-solving.
Stefan Vesenmeier

Alexander Pohl

Senior Interim and Transition Manager - proven in mid-sized businesses and multinationals for change and crisis

Hamburg

Last position:

Head of integration for six country subsidiaries at XSYS Holding

  • Analyzed the required scope of processes, infrastructure, and SAP for integrating the MacDermid subsidiaries
  • Validated proposals from the new service providers
  • Managed the collaboration and tracked the tasks of business and IT experts
  • Coordinated communication and the PMO
  • Created cutover plans in three waves for SAP conversion, Salesforce, and Ariba
Alexander Pohl

Bernhard Bowitz

Senior Security Architect

Wiesbaden

Last position:

Senior Security Architect at Intermediate Beratung

  • Consulting on an ongoing IT security architecture project
  • Documenting past progress and planning next steps
  • Applying and implementing the BSI IT baseline protection
  • Building and maintaining security management systems
  • Applying the ISO 27001 standard series
  • Integrating ITIL processes into security architectures
  • Collaborating with public clients, regulatory authorities and internal and external service providers
Bernhard Bowitz

Christian Decker

Managing Director and Senior Consultant

Groß-Umstadt

Last position:

Managing Director and Senior Consultant at business-security (b-sec®) GmbH

  • Conceptual consulting for securing business processes
  • Consulting on planning and implementation of IT and IT security projects
  • Security and policy checks, process optimizations, emergency planning
  • Project management and interim management in IT infrastructure and information security

Overview of relevant projects:

  • 2025: Consulting on a DLP concept for Digid GmbH.
  • 2025: Consulting a client after a cybersecurity attack that compromised the IT infrastructure and where the attacker obtained M365 tenant admin rights. Investigated the IT infrastructure and restored it. Developed recommendations to improve IT security.
  • 2025: Continued the projects listed below for Thyssenkrupp Marine Systems and Norddeutsche Landesbank.
  • 2024: Created a DNS concept including advice on DNS strategy and technology, DNS design, DNS security, load balancing, reverse lookup zones, and automation. Created a DHCP concept including advice on DHCP design, a central DHCP management system and automation. Advised on operating the mentioned products, the operational processes, and updated IT documentation and IT service descriptions for Thyssenkrupp Marine Systems.
  • 2024: As-is analysis and assessment of the network and security infrastructure established by providers in terms of overall architecture including design and components. Designed solution proposals to improve current operations for performance and security maximization as well as complexity reduction. Presented the results to C-level, their causes and possible solutions including required decision templates. Developed a SASE concept based on a zero-trust architecture for Norddeutsche Landesbank.
  • 2024: Continued the projects listed below for Atlas GmbH and Deutsche Vermögensberatung AG.
  • 2023: Consulting on resolving findings from an IT security assessment of the IT infrastructure, conducting proofs of concept for DDoS protection and digital experience monitoring (DEM) with Zscaler (ZIA, ZPA & ZDX), creating a new security architecture based on zero trust, redesigning a Cisco ISE implementation, and designing a DNS security solution to protect guests and financial advisors for Atlas GmbH / Deutsche Vermögensberatung AG.
  • 2023: Continued the projects listed below for Digid GmbH, Vaillant Group GmbH (until 09/2023), Federal Institute for Geosciences and Natural Resources (until 05/2023), and Union Investment IT-Services GmbH (until 07/2023).
  • 2022: Created and reviewed whitepapers for infrastructure and security architectures, and planned new network infrastructures for the German Aerospace Center.
  • 2022: Developed a concept for the technical and procedural modernization of a disaster recovery plan for United Nations Volunteers.
  • 2022: Developed a concept for migrating measurement data to a cloud environment, introduced network access control, and conducted an awareness training for Digid GmbH.
  • 2022: Developed a network segmentation concept for DZ Hyp AG.
  • 2022: Developed a network segmentation concept for the Federal Employment Agency.
  • 2021: Developed a new load balancer architecture concept for Bundeswehr Fuhrparkservices GmbH.
  • 2021: Conducted a vulnerability scan and penetration test of a web frontend including analysis and recommendations for remediation considering risk and likelihood for the client ifi GmbH.
  • 2021: Consulting, design, and subproject management for implementing a network access control solution (certificate authentication and MAC address bypass) and macro segmentation (area and zone concept based on dynamic device assignment) in office and production IT for Vaillant Group GmbH.
  • 2021: Upgraded and optimized LAN and WLAN infrastructure for United Nations Volunteers.
  • 2021: Developed a target concept for modernizing the IT security infrastructure including the DMZ (Cisco switches, firewalls, WSA, ESA, SMA), internet connections, admin and management networks, and the wireless LAN, including overseeing implementation for the Federal Institute for Geosciences and Natural Resources.
  • 2021: Created a micro-segmentation concept based on Cisco DNA, SGT, and zero trust for Union Investment IT-Services GmbH.
  • 2021: Reviewed and updated ISMS level 3 policies and created procedure instructions for Software AG.
  • 2021: Project lead for the global tech refresh project Meraki WLAN 2.0, coordinated the outsourcing of LAN/WLAN infrastructure to a managed service provider, and created a WLAN concept for automated guided vehicles for Heraeus Infosystems GmbH.
  • 2021: Project management and technical support for the 'Transition of SIEM/SOC Services' project migrating a client to a shared environment, and took on the interim role of Head of Security Operations at Datagroup SE.
  • 2021: Conducted a workshop for the future implementation of mobile device management for Allgeier Experts Go GmbH.
  • 2021: Subproject management for implementing a firewall rule management tool and recertifying NAC endpoints based on 802.1x and MAB for Union Investment IT-Services GmbH.
  • 2020: Developed a network segmentation concept for two data centers based on Cisco and VMware for Aareon AG.
  • Recorded and analyzed the current network architecture including project initiation.
  • Designed a micro-segmentation concept in the data center and access network.
  • 2020: Infrastructure and security architecture audit for Stuttgarter Versicherung AG.
  • Analyzed the IT infrastructure and security architecture regarding network and security component configurations. Also reviewed contracts, process documents, and manuals for completeness. Developed recommendations to improve the stability and operation of the infrastructure. Created a network segmentation concept and led the project to implement the measures from the audit.
  • 2020: Consulting on setting up an ISMS-light for Josera foodforplanet GmbH & Co. KG.
  • 2020: Security architecture consulting for Datagroup SE.
  • Developed a future IT infrastructure and IT security architecture.
  • Documented the current IT architecture of all 23 entities.
  • Made recommendations to optimize the IT infrastructure and drafted a comparison of a traditional perimeter security concept versus a zero trust model.
  • Created a security zone concept.
  • Designed an IT infrastructure architecture in coordination with all entities.
  • 2018 - 2019: Stream lead in the cybersecurity program at Deutsche Lufthansa AG.
  • Responsible for designing and implementing 9 projects in IT security infrastructure and user access management, as well as managing project managers and experts.
  • Project area: Network segmentation and access control.
  • Project area: Security architecture.
  • Project area: Privileged, identity & access management.
  • Project area: Simplify user authentication (MFA).
  • Project area: Mobile & endpoint security.
  • Project area: OT security.
  • Project area: E-enabled aircraft.
  • 2018: Security architecture consulting for Deutsche Lufthansa AG.
  • Project management for the development, evaluation, and management of the company-wide information security architecture.
  • Developed a security strategy and a roadmap to align the security architecture with the zero trust model.
  • Evaluated market security solutions, services, and tools.
  • Defined requirements for RFPs and assessed proposals.
  • Developed, maintained, and monitored security architecture artifacts.
  • Conducted security assessments of existing and new IT systems and security services.
  • 2018: ISMS consulting for GLS IT Services GmbH.
  • Advised on implementing and initially operating an ISMS based on ISO27001.
  • Audited the IT environments of GLS country subsidiaries.
  • Analyzed and assessed IT security risks and derived necessary measures.
  • Developed solution proposals in coordination with relevant stakeholders.
  • Managed the project and handed over the ISMS to operations.
  • 2016 - 2018: Security pre-sales consultant for Cisco Systems GmbH.
  • Provided nationwide strategic and conceptual consulting to major enterprise and financial and insurance clients on Cisco and Meraki security products and services such as Firepower, WSA, ESA, Stealthwatch, and ISE.
  • 2017 - 2018: Designed and implemented an ISMS for Verivox GmbH.
  • Conducted various BIAs and gap analyses.
  • Developed security policies based on ISO 2700x.
  • Served as interim information security officer.
  • 2017: Developed an emergency concept for VPV Lebensversicherungs-AG.
  • Reviewed and updated the IT emergency manual.
  • 2016: Consulting and project management for designing cloud & hosting services for Vodafone Group Services GmbH.
  • Analyzed and optimized the sell-build-run process.
  • Created detailed level designs for cloud products.
Christian Decker

Stephan Lewering

Managing Director

Mühlhausen-Ehingen

Last position:

Managing Director at SwissArx UG (haftungsbeschränkt)

  • Sole management and strategic direction of an IT services and consulting company
  • Responsible for company setup, business development and market positioning
  • Development and implementation of corporate strategy, business models and processes
  • Point of contact for customers, partners and stakeholders
Stephan Lewering

Rupesh Kumar Sendge

IT Baseline Compliance Consultant

München

Last position:

IT Baseline Compliance Consultant at Consultant

  • Baseline compliance verification against MAS audit findings
  • Building technical architecture concept for 30 technologies to build hardening standard artifacts
  • Identifying and building automation possibilities for given technologies based on CIS
  • Building the standard baseline configuration based on internal security standard
  • Responsible for building Cloud Native Application Protection Platform (CNAPP) architecture artifacts based on Azure cloud platform
  • Responsible for RFQ and RFP for different CNAPP solutions (Qualys Total Cloud, CrowdStrike, Azure Security Center)
  • Supporting compliance verification and validation via automated scripts for a sample population of IT devices and instances
  • Responsible for complete vulnerability management lifecycle using Nexpose, remediation, reporting and integration of results with Splunk, HPSM and Tableau
  • Audit support for MAS
Rupesh Kumar Sendge

Arndt Schürg

Information Security Officer according to TISAX

Ludwigshafen

Last position:

Information Security Officer according to TISAX at Automotive Supplier

Arndt Schürg

Discover over 15,000 top freelancers

Certified Information Systems Security Professional (CISSP) statistics

Typical experience

23 years

Average project duration

2.4 years

Certifications per freelancer

11

Top business areas

Information Technology, Project Management, Operations

Top industries

Information Technology, Banking and Finance, Professional Services

Most common languages

German, English, French

Bachelor's degree or higher

83%

Master's degree or higher

63%

Doctorate

13%

Salary / Daily Rate Distribution

0 3 6 9 12
<€640 €640-800 €800-960 €960-1120 €1120-1280 €1280-1440 €1440+

The chart shows how the daily rates of freelancers holding this certification are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

Average rates for Certified Information Systems Security Professional (CISSP) & Seniority distribution

Rates are based on recent contracts and do not include FRATCH margin.

1200
900
600
300
Rate comparison chart
Daily rate avg. 974 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1200
900
600
300
Rate comparison chart
Median rate 1000 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Try FRATCH GPT

Frequently Asked Questions

Looking for clear information? Everything important about FRATCH is here

A freelancer with the CISSP has shown broad competence across security governance, architecture, risk, and operations. It tells you they can work beyond one tool or niche and understand how security decisions affect the whole business. That is why it is often seen on senior consultants, architects, and security leads.

CISSP sits between both worlds. It is not a pure management badge, but it is also not a deep product-specific technical certification. CISSP is most valuable when you need someone who can make sound security decisions, coordinate stakeholders, and still understand the technical details behind the controls.

The Certified Information Systems Security Professional (CISSP) is broader and more senior than many focused security credentials. It covers the full security lifecycle instead of one specialty such as cloud, testing, or access control. For companies, that makes it a good signal for strategic or cross-domain security work.

CISSP is a strong fit for security architects, consultants, managers, and experienced engineers who work across multiple security domains. It also suits freelancers who advise clients on governance, risk, compliance, or enterprise security design. If your work connects strategy and implementation, this credential is often a good match.

Preparation for the CISSP is broad and structured. Candidates usually study the full set of security domains, work through practice scenarios, and review how concepts apply in real environments. Because the exam rewards judgment as well as knowledge, practical experience matters a lot.

CISSP is designed for experienced professionals, so it is not usually a beginner certification. ISC2 expects a strong background in security-related work, and there is also an endorsement step after passing. Some candidates may use an associate pathway if they are still building the required experience.

The CISSP is maintained through ongoing professional education and continuing activity in the field. Holders are expected to stay current with changing threats, controls, and practices. For clients, that is a useful signal that the freelancer should be engaged with modern security work, not old habits.

In Germany, CISSP is especially relevant for enterprise security programs, regulated environments, and projects that involve both local teams and international stakeholders. It is also useful when remote collaboration demands clear documentation and disciplined decision-making. Companies often look for it when they need a freelancer who can lead or advise across several security topics at once.

Request a Free Demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO Avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH