ISO/IEC 27001 Foundation
expert in Germany in minutes from 15,000 CVs with the power of AI.Compare freelancers who understand information security management systems, risk awareness, control objectives, and basic audit language. Get fast, precise matching with vetted professionals holding the ISO/IEC 27001 Foundation certificate.
Meet FRATCH ISO/IEC 27001 Foundation in Germany
Thorsten Huber
Last position:
Product Owner, AI Manager at crazyALEX.de GmbH
Digitalization of real places with 3D/LiDAR scans to make spatial data usable for AI applications and derive concrete use cases and prototypes from it.
- Digital capture of real places as a basis for faster planning and analysis
- Browser-based access to 3D data for easier use and coordination
- Turning spatial data into concrete use cases, prototypes, and AI training scenarios
- Planning basis for urban development and other digital future applications
Keywords: LiDAR, 3D scan, AI, use cases, AI training, prototyping, Python, web development, data models, architecture
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Karl-Heinz Reis
Last position:
Support in further building a European IT store service organization (15 countries) at European retail company (discount chain)
- Assessment of the as-is processes Incident Management, IT Service Request Management, Problem Management, Change Management, Service Configuration Management (including CMDB)
- Conducting maturity assessments for these processes based on the ITIL® 4 Maturity Model
- Analysis of the different service value streams based on the ITIL® 4 value stream model
- Agreement on maturity levels for the processes under review
- Development and approval of a roadmap to reach and measure the respective maturity levels
- Presentation of the approach, including milestones, to management for approval
- Management of external service providers in 1st level support
Florian Krebs
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Michael Fitschen
Last position:
Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund
- Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
- Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
- Collaborating with the Information Security Officer (ISO)
- Identifying company assets for IT risk management
- Developing a zone concept for IT risk management
- Creating an action plan for B3S
- Developing a template for risk analyses
Benjamin Schötz
Last position:
CRM strategy & requirements analysis for marketing campaigns in the automotive sector at AUDI AG
- Development of strategies, processes and system requirements to further develop the lead and campaign streams of a Salesforce system for the subsystems Sales Cloud, Marketing Cloud and Analytics Cloud
- Gathering and creation of marketing strategy concepts for direct sales, focusing on lead generation for new and existing customers
- Analysis and optimization of existing and new contact points
- Derivation of system requirements and user tests for new developments
- Establishment of a requirements and implementation process for business needs at the interface between CRM strategy and marketing system operations
- Facilitation of ideation workshops with the project's stakeholders
- Mediation between business and technical project stakeholders
- Analysis and post-documentation of existing marketing strategies and the system functions already created for them
- Analysis of target groups and pre-system data quality as a foundation for new CRM strategies
- Consultation on content and asset strategy for marketing campaigns
- Definition of KPIs and other performance criteria for the system and CRM strategy
Björn Bausch
Last position:
Project Manager NIS-2 at Chemicals Group
- Basic NIS-2 impact assessment
- NIS-2 registration
- Conducting a current state analysis
- Creating the requirements specification
- Monitoring the implementation of NIS-2 compliance
- Establishment of reporting procedures in the context of NIS-2
- Risk analysis and security for information systems
- Handling security incidents
- Maintenance and recovery, backup management, crisis management
- Supply chain security, interfacility security, third-party security
- Security in development, procurement and maintenance, vulnerability management
- Evaluating the effectiveness of cybersecurity and risk management
- Cybersecurity and cyber hygiene training
- Cryptography and encryption
- Personnel security, access control and asset management
- Multi-factor authentication and continuous authentication
- Secure communication (voice, video and text)
- Secure emergency communication
Holger Görz
Last position:
IAM Expert for current-state analysis and migration concept from bi-Cube to IdentityIQ (SailPoint) at Stadtwerke
- Creation of a current-state analysis of the bi-Cube system with the goal of delivering a concept incl. recommendations on how the bi-Cube system can be replaced by IdentityIQ (SailPoint) while ensuring ongoing operations and taking into account the processes and the modification of the IAM workflow by third parties.
- On-site IAM workshop to carry out an IAM system analysis.
- Creation of an implementation concept and recommendations for the transition from bi-Cube to IdentityIQ (SailPoint) while ensuring ongoing operations and taking into account the processes and the modification of the IAM workflow by third parties.
- Evaluation and further development of the role model for the migration, taking activities/functions and SoD rules into account.
- Creation of detailed technical documentation according to UML standards in Confluence (Atlassian).
Zakaria Aoune
Last position:
Vice President Technology EMEA at Aparavi Software Europe GmbH
- Always looking for solutions to problems and finding ways to tackle business challenges
- Leading and managing large multi-disciplinary teams (product development, project management, engineering, operations, QA, solution management, customer success)
- Developing and executing innovation and digitalization strategies for complex transformation projects
- Acting as Information Security Officer, planning, conducting, and successfully completing all ISO 27001:2022 standard audits and continuously ensuring compliance
- Leading and coaching managers across the organization
- Representing the company at industry events and coordinating external partnerships
- Providing technical support to the Aparavi sales team
- Working with account managers to lead and grow enterprise customers
- Collaborating with technical and non-technical customer departments to manage and meet expectations (e.g., C-level, finance, IT services, data security and works council)
- Leading technical integration and coordinating seamless solution implementation
- Hands-on development and management of cloud, AI, and SaaS solutions to meet demanding customer expectations
- Promoting agile, DevOps-based methods and organizational structures for innovation and sustainable growth
- Continuously analyzing and solving technical and business challenges to boost company success
Georg Schönhof
Last position:
Internal environmental auditor at VOREST AG
- Function of environmental audits
- ISO 19011: Principles, planning and conduction of audits
- Meeting the requirements of ISO 14001
- Identifying and assessing the EMS requirements
- Conducting audit interviews
- Documenting audit results
- Function and tasks of ISO 14001 auditors
- Function and tasks of environmental auditors
Thorsten Limbach
Last position:
IT Architect, System Engineer, VS-NFD Consultant at Helsing GmbH
- Design and development of an internal collaboration platform that enables VS-NFD-compliant communication and data storage
- Design and development of an internal development platform (Kubernetes, Git CI/CD, Jira, etc.) as well as use and administration of virtualization solutions
- Design and development of an internal AI system with custom training and automated processes
- Migration of a HyperV cluster to Proxmox for the automatic control of Kubernetes clusters and savings in licensing costs
Michael Lasslop
Last position:
IT Project Manager at Self-employed
- Tendering, IT architecture, and implementation
- Project and budget planning, resource management
- Stakeholder and risk management
- The project was delivered on time and within budget
- Implementation of SAP IBP Cloud S&OP Demand & Supply
- Building materials group with €1.3 billion in revenue and 30 plants
Matthias Lepka
Last position:
Head of IT System Architecture at Internal IT service provider
- Industry: metal processing industry
- Revenue: 740 million EUR
- Employees: 4,400
- Budget: 7 million EUR, 15 staff
- Designing and operating technical services
- Ensuring IT security
- Managing the central support organization (first, second, and third level)
- Digital transformation: strategic support / project management for OT platform and OT security
- Developing and introducing ITIL processes (incident management, problem management, service request fulfillment, change management, access management, service level management)
- Supporting and coordinating external service providers (provider management)
- Project management: planning and delivering IT services for a new main plant
- Promoting IT-OT convergence / OT asset management / OT security
- Organization: mediating and supporting reorganization
Achievements:
- Improving IT operations maturity (introducing and stabilizing processes, KPIs, ensuring transition)
- Replacing the ticket system with ServiceNow
- Stabilizing and developing IT security / ensuring resilience
- Successfully introducing OT segmentation (architecture, remote access control, micro-segmentation, OT asset management)
- Supporting introduction of manufacturing execution system (technical services / SaaS provider management)
- Integrating foreign sites (rollout of central IT services)
- Migrating on-premises server environment to MS Azure
- Rolling out Windows 11
- Supporting migration of on-premises SAP environment to SAP RISE
- Creating planning basis for IT network infrastructure of the new main plant
- Planning web shop
- Organizational development "From Operating to Designing" (target SIAM organization)
- Supporting BCM
Norbert Stilling
Last position:
Self-Employed Consultant and Project Manager at Self-Employed Consultant and Project Manager
- 21 projects ≥ 6 months at large and medium-sized companies
- 13 projects as project or subproject manager
- 6 international projects with English as project language
Serhat Küpeli
Last position:
Scrum Coach at Cologne University of Applied Sciences
- Supporting the application of agile principles and practices
- Training and coaching the Scrum team and leaders in agile ways of working and self-organization
- Running retrospectives and identifying continuous improvement actions
- Identifying impediments and coordinating actions to remove them
- Coordinating sprint planning, daily stand-ups, reviews, and retrospectives
- Supporting the management of project tools (JIRA, Confluence, Concept-Board)
- Establishing additional Scrum teams and promoting cross-team communication and metrics
Discover over 15,000 top freelancers
ISO/IEC 27001 Foundation statistics
Aggregated from the professional profiles of matched freelancers.
Experience
25 years
Position duration
3.3 years
Positions per freelancer
15
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Professional Services, Manufacturing
Certification focus areas
Information Technology, Audit, Quality Assurance
Bachelor's degree or higher
87%
Master's degree or higher
40%
Doctorate
13%
Certifications per freelancer
10
Most common languages
German, English, French
Speak two or more languages
96%
Based on our profile pool as of 27 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers holding this certification in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates for ISO/IEC 27001 Foundation in Germany
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 27 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the certification
What it covers
ISO/IEC 27001 Foundation, often searched as ISO 27001 Foundation, is an entry-level credential for people who work with information security management. It shows that a freelancer understands the purpose of an ISMS, the logic behind controls, and the basic language used in ISO/IEC 27001 projects.
What it validates
- Core ideas behind information security management systems
- Risk awareness and why treatment matters
- The role of policies, controls, and documented processes
- Basic understanding of internal review and improvement
- Common terms used by auditors, managers, and security teams
Typical holders
You will often see this certificate on consultants, junior security specialists, compliance support staff, and project professionals who work close to governance or audit topics. In Germany, it is useful when companies need clear communication between technical teams, legal or risk functions, and business owners.
Knowledge areas
A holder of this certificate should be able to speak about how an ISMS is set up, why scope matters, and how security risks are identified and handled. The certification also points to familiarity with controls, evidence, awareness, and the idea of continual improvement rather than one-off compliance.
- ISMS structure and purpose
- Risk-based thinking
- Control objectives and governance
- Audit preparation and evidence handling
- Awareness and communication across teams
Where it helps
For companies, the value is not deep technical specialization. It is a reliable baseline. An ISO/IEC 27001 Foundation freelancer can support policy work, prepare teams for audits, help document processes, and keep security discussions grounded in the standard’s language.
Why it matters
This certification is relevant in regulated industries, outsourcing projects, cloud and infrastructure work, and any setting where customer trust depends on controlled information handling. It is also useful when a team is moving toward certification or maintaining an existing ISMS and needs someone who can contribute without long onboarding.
Frequently asked questions
The facts hiring teams ask for most often when it comes to ISO/IEC 27001 Foundation.
A freelancer holding the ISO/IEC 27001 Foundation has shown a basic grasp of information security management and the structure of the ISO/IEC 27001 standard. It signals that the person can work with ISMS terminology, understand why controls exist, and support security-related tasks without needing a full expert-level background.
Yes. ISO 27001 Foundation is a common short form people use when they search for the ISO/IEC 27001 Foundation certificate. Companies may see either wording on a profile or résumé, but both point to the same foundation-level knowledge of the standard.
The ISO/IEC 27001 Foundation is about awareness and shared language, not deep implementation ownership. More advanced certificates usually go further into leading audits, designing controls, or managing an ISMS program. For companies, that means this credential is a good fit for support roles and coordinated project work, while senior governance tasks need stronger experience.
The ISO/IEC 27001 Foundation suits consultants, coordinators, junior security professionals, compliance staff, and project managers who work near information security topics. It is also useful for freelancers who want to support audit preparation, policy documentation, or security awareness work. In Germany, it can help when clients expect structured communication and familiarity with ISO-based processes.
Preparation for the ISO/IEC 27001 Foundation is usually focused on reading the standard’s concepts, learning the purpose of an ISMS, and understanding common terms such as scope, risk, controls, and audit evidence. Many candidates also review practice questions or short training materials to get used to the style of the exam. The goal is clear understanding rather than advanced design work.
For the APMG International ISO/IEC 27001 Foundation route, this level is generally intended as an entry point. It is often chosen by people who are new to the standard or want a formal baseline before moving into more advanced security or compliance work. Always check the current scheme guidance if you need confirmation for a specific hiring process.
Renewal rules depend on the current certification scheme and the issuing body’s policy. For ISO/IEC 27001 Foundation, companies and freelancers should verify the latest APMG guidance before assuming any renewal or continuing-development requirement. In practice, many teams treat the credential as a starting point and look closely at recent project experience as well.
The ISO/IEC 27001 Foundation is useful in any project where information security, compliance, or customer trust is part of the scope. It is especially relevant in IT services, finance, healthcare, outsourcing, SaaS, and internal governance work. It helps when a team needs someone who understands the standard well enough to support audits, documentation, or control alignment in Germany or in distributed teams.
The average hourly rate for freelancers with ISO/IEC 27001 Foundation in Germany is 120 €, which corresponds to a daily rate of about 961 € based on an 8-hour working day.
Of the freelancers with ISO/IEC 27001 Foundation in Germany, 87% hold at least a Bachelor's degree, 40% hold at least a Master's degree, and 13% hold a doctorate.
On average, freelancers with ISO/IEC 27001 Foundation in Germany have 25 years of professional experience, with a single engagement typically lasting around 3.3 years.
The most common languages among freelancers with ISO/IEC 27001 Foundation in Germany are German (96%), English (96%), and French (29%).
The most common industries among freelancers with ISO/IEC 27001 Foundation in Germany are Information Technology (88%), Professional Services (83%), and Manufacturing (46%).
The most common business areas among freelancers with ISO/IEC 27001 Foundation in Germany are Information Technology (96%), Project Management (96%), and Operations (75%).
FRATCH ISO/IEC 27001 Foundation main locations
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
