ISO/IEC 27001 Information Security Management
experts in Germany, matched in minutes from 15,000 CVs with the power of AI.Find freelancers who understand ISMS design, risk treatment, internal audits, control implementation, and certification readiness. Get fast, precise matching with vetted professionals who know ISO/IEC 27001 and the work behind it.
Meet FRATCH ISO/IEC 27001 Information Security Management Professionals in Germany
Wilhelm Haupt
Last position:
Project Manager / Senior Consultant at Anseres GmbH
- Review of BVA sites – compliance checks under VS-NfD conditions
- Application of BSI baseline protection and NdB user obligations
- Carrying out security and compliance checks at sites of the Federal Office of Administration
- Documenting the results in the VS-NfD context
- Representing the client in workshops and meetings with other federal authorities
- Representing the client to the BSI and aligning security requirements
Ralf Barthel
Last position:
Test Manager and Subproject Manager at SvenMahn IT GmbH & Co. KG
- Leading the subproject Test & Acceptance & Quality Assurance
- Project/program management according to Prince2
- Create and update subproject plan
- Resource management
- Creating and carrying out tests, creating tests in Azure DevOps, MS Dynamics etc.
- Process modeling
- Documenting project progress with PowerPoint and SÖREN (in-house development)
- Acceptance of the respective tests by the end customer
- Monitoring and reporting for the subproject
- Budget: N/A
- Team: 4 people
Serdar Colak
Last position:
Consultant at Freelance
- ISO 27001 implementation & audit readiness
- NIS2 & DORA compliance support
- Interim / fractional CISO services
- IT risk & controls (ITGC, SOX, COBIT, BAIT)
- M&A and IT due diligence for startups/ventures
- Business continuity management (BCM, ISO 22301)
- Cybersecurity framework development (NIST, ISO, BSI)
- GRC tool advisory (Archer, ServiceNow)
André Görst
Last position:
IT Consulting Project Management / Engineering Subproject Management at T-Systems (on assignment for government agencies)
- Projects for federal networks (NdB).
- CR management, EoL change requests, design and documentation according to ITSCM.
- Data center planning.
- Project management and engineering subproject management.
- Software development for virtual server environments according to BSI.
Stanislav Stolberg
Last position:
Interim CTO / IT Consultant (Cloud & App Security · AI & Web3) at Deutsche Bank Group; Startups
- Spearheaded strategic and operational oversight of IT infrastructures to accelerate innovation and ensure audit-proof delivery.
- Acted as key liaison between management, business departments, and engineering, actively engaging in coding, cloud architecture, and CI/CD to resolve critical path challenges.
- Engineered and implemented an AI Governance Program to manage risks and ensure compliance with the EU AI Act, reducing AI use-case approval times from 8 to 3 weeks.
- Delivered and deployed secure AI systems into production (RAG-based knowledge platforms), resulting in a 35% decrease in standard support ticket volume.
- Established robust security standards and governance frameworks for APIs (OAuth2/OIDC, mTLS) and cloud platforms (AWS/GCP) to guarantee compliance and system integrity.
- Hardened cloud infrastructure by implementing Zero Trust principles and a comprehensive observability stack (logging/alerting), achieving 99.9% availability in a 24/7 on-call environment.
Udo Schnell
Last position:
GRC Project Manager at 1 & 1 Mobilfunk
Developed a GRC guideline for project management in the rollout area.
Zakaria Aoune
Last position:
Vice President Technology at APARAVI Software GmbH
- Lead Presales, R&D, Product, and Engineering for EMEA region – remote/hybrid, multicultural teams of 30+
- Serve as Information Security Officer (ISO), leading ISO 27001 certification efforts and conducting regular security audits
- Implement and maintain comprehensive information security management systems (ISMS) ensuring compliance with GDPR, DORA, and international regulations
- Architect data intelligence, SaaS, and unstructured data solutions using AI, ML, and cloud-native tech
- Drive solution sales initiatives, conduct technical demonstrations and engage with enterprise customers to deliver tailored solutions
- Engaged in hands-on pilots with cutting-edge cloud platforms, Generative AI, and edge computing
- Represent company in major industry forums – regular interface with C-level, customers, and partners
- Delivered proven 35-45% cost/complexity reduction with innovative, automated compliance and privacy frameworks.
Peter Langheinrich
Last position:
Zoho Consulting and Development at Zuperstars mit Z wie Zoho
- Consulting on functional topics and their feasibility with Zoho technologies
- Implementing solutions based on Zoho
- Integrating Zoho solutions with third-party systems
- Performing data migrations
- Training and support
Benito Exner
Last position:
Cloud DevOps Engineer at E.ON Se (Syna GmbH)
Developed and implemented an operating concept
Created and executed a migration plan
Automated administrative tasks in on-premises environments
Provided 3rd-level support
Created documentation (Confluence) and managed tasks (Jira) using agile Scrum methods
Implemented and monitored disaster recovery plans and backup strategy in Azure
Planned and carried out software and system upgrades
Advised on selecting and implementing new technologies and tools
Trained employees on new technologies and processes
Conducted code reviews to ensure quality and adherence to best practices
Advised the Product Owner and other stakeholders on developing and refining solution approaches and concepts
Responsible for the stable operation of a hybrid on-premises/Azure environment in a highly regulated setting (critical infrastructure)
Worked closely with business units, IT security, and external service providers to align operational and migration concepts
Designed and executed the migration of central on-premises systems to a hybrid Azure environment (including landing zone, network segmentation, backup, and disaster recovery strategy), establishing the technical foundation for future cloud governance in the KRITIS sector
Introduced Ansible & AWX to fully automate formerly manual operational documentation
Result: Replaced over 100 operation manuals, reduced operational effort by 80%, and created a sustainable foundation for scalable operational processes
Sisco Schultis
Last position:
Director Data Strategy at ProSiebenSat.1 Digital Data GmbH
- Strategic and operational responsibility for group-wide data management in the area of Customer Identity & Access Management (CIAM).
- Business owner of the group-wide CIAM solution 7Pass and the netID SSO standard.
- Established and managed data governance structures and data processes.
- Defined and implemented policies for data quality, data security, and data usage.
- Planned, executed, and led a comprehensive organizational and process restructuring, including due diligence, tenders, and migration to the group's platforms (streaming, e-commerce, publishing).
- Successfully achieved ISO-27001 certification for the entire division.
- Led an interdisciplinary team and managed multiple external service providers.
- Responsible for B2B account management, contract negotiations, and partner management.
Szabolcs Kardos
Last position:
Senior Network Security Consultant at Mann+Hummel
- Network segmentation in a production IT environment
- Firewall migrations
- Integration of remote access sites
- Implementation of POCs (Backup, SCADA)
- Working in a multicultural environment
- Applied technologies: Panorama & Palo Alto Firewalls, Checkpoint, ServiceNOW, MS Azure Cloud
Johannes Thanner
Last position:
Co-Founder at Selphspace
- Responsible for product management of our SaaS: understood customers, developed product roadmap, collected data insights and prioritized features
- Responsible for software development: defined IT architecture, built mockups and software
- Business development: conducted market analysis and set strategic direction
Katarina Burghard
Last position:
Lecturer in Project Management, Scrum and DevOps at velpTEC
- Workshops and professional support in adult education
Melanie Linden
Last position:
IT Consultant at BOVERMANN IT SOLUTIONS GmbH
- Design and development of an information security management system (ISMS) according to DIN EN ISO/IEC 27001
Johannes Ostertag
Last position:
Product Owner at Bundesdruckerei GmbH
- Gathering functional requirements from legally binding sources based on market trends and established solutions
- Capturing customer wishes and formal customer requirements
- Creating initial documentation for system development
- Collaborating with the overall system architect on the possible solution space
- Working with an agile development team and with project management on methodology and customer interfaces
- Conceptually breaking down requirements into generic and specific parts as input for specialist departments
- Developing requirements and implementation concepts with legal and data protection officers
- Technical leadership of an English-speaking, cross-functional development team in a large project with over 100 people and multiple agile Scrum teams
- Successful and on-time implementation of the application process 'Visa for family reunification' in the foreign portal
- Functional expansion of the visa navigator for quick and easy determination of the correct visa for applicants
- Using agile methods with elements from SAFe and LeSS
- Identifying and evaluating requirements with stakeholders, including change requests and feedback from foreign missions and end users
- Capturing, documenting and consolidating requirements in Jira and Confluence
- Analyzing technical and business requirements, reviewing bugs and converting them into epics and user stories with clear acceptance criteria
- Continuous backlog refinement and prioritization of product backlog items
- Mediating between different stakeholder interests and the capabilities of the development team
- Facilitating workshops and meetings for consensus building and conflict resolution
- Participating in and facilitating Scrum of Scrums
- Close coordination with architects, UI/UX experts and business analysts
- Continuously removing barriers according to BITV and performing recurring audits
- Acceptance of implemented user stories and epics with the development team
- Joint roadmap planning with the client for the next four quarters
- Creating and using initiatives in JIRA
- Coordinating release planning with test and release managers
- Regularly presenting sprint results to stakeholders
- Configuring complex Jira and Kanban workflows
- Point of contact for stakeholders on content-related questions
- Identifying and evaluating project risks and continuous monitoring
Discover over 15,000 top freelancers
ISO/IEC 27001 Information Security Management Professionals statistics
Aggregated from the professional profiles of matched freelancers.
Experience
24 years
Position duration
2.4 years
Positions per freelancer
18
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Professional Services, Telecommunication
Certification focus areas
Information Technology, Quality Assurance, Project Management
Bachelor's degree or higher
77%
Master's degree or higher
46%
Doctorate
8%
Certifications per freelancer
4
Most common languages
German, English, Spanish
Speak two or more languages
100%
Based on our profile pool as of 26 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers holding this certification in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates for ISO/IEC 27001 Information Security Management Professionals in Germany
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 26 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the certification
What it means
ISO/IEC 27001 Information Security Management is the main international standard for an information security management system, or ISMS. It shows that a professional can help an organisation protect information in a structured, repeatable way. In profiles, you may also see it as ISO 27001 or ISO/IEC 27001.
Core competence
- Build and maintain an ISMS around business risk
- Define policies, controls, and responsibilities
- Run internal reviews and prepare for certification audits
- Support corrective actions and continual improvement
- Align security work with business and compliance needs
Typical profiles
People with this background often work as information security managers, ISMS consultants, lead auditors, compliance specialists, or security project leads. They are usually brought in when a company needs to prepare for certification, improve an existing ISMS, or close gaps found in an audit. In Germany, they are also useful when teams need someone who can work across local stakeholders and international security requirements.
Knowledge areas
The value of ISO/IEC 27001 sits in practical understanding of security management, not just theory. A strong professional knows how to assess risk, choose suitable controls, document evidence, and keep the management system alive after the audit is over.
- Risk assessment and risk treatment
- Statement of Applicability and control selection
- Asset, access, incident, and supplier management
- Audit preparation and evidence handling
- Governance, leadership support, and continual improvement
What it tells companies
A freelancer with this certification can help turn security goals into an operating system for the organisation. That matters when you need clear ownership, traceable controls, and a clean path to certification or recertification. It is especially relevant for regulated environments, B2B services, software firms, and any team handling sensitive customer or employee data.
When to hire
Hire someone with ISO/IEC 27001 Information Security Management experience when you need an ISMS built from scratch, an existing system repaired, or an audit response handled under pressure. It also fits well when a company wants a gap assessment, policy refresh, risk workshop, or supplier security review. For German teams, it can help to have a professional who can work in German or English, depending on the audit and internal audience.
Frequently asked questions
What clients ask us most about ISO/IEC 27001 Information Security Management Professionals — answered in short.
ISO/IEC 27001 Information Security Management shows that a freelancer understands how to design, run, and improve an information security management system. The focus is on risk-based controls, documented processes, internal audits, and readiness for external certification. It is stronger evidence of security governance than of only technical security tooling.
In practice, people often say ISO 27001 when they mean ISO/IEC 27001. The standard is the same one: the international framework for an ISMS. Different profiles may use the full name, the shortened form, or both.
This background fits people who manage information security programmes, advise on compliance, lead audit preparation, or own ISMS processes. It is also useful for consultants who support policy design, risk treatment, supplier security, or management review. Companies usually look for it when security has to be organised across teams, not handled as a one-off task.
ISO/IEC 27001 Information Security Management is about the management system behind security, not just technical defence. It covers governance, process, evidence, and continuous improvement, while many technical certifications focus on tools, systems, or hands-on security operations. A strong holder often works with technical specialists, but the certification itself points to management and audit readiness.
Preparation usually involves learning the structure of the standard, the ISMS lifecycle, and how controls are selected from risk. Many professionals also need practice with documentation, audit evidence, and management reporting. People who already work in compliance, security, quality, or internal audit often adapt to this field more easily.
There is no single background that fits everyone, but companies usually expect solid understanding of security, risk, and business processes. Experience with audits, governance, or regulated environments is very helpful. For some certification paths, accredited bodies may have their own rules, but the practical work itself depends more on competence than on a formal entry route.
The standard itself is not a one-time achievement in practice. Organisations must keep the ISMS current through reviews, audits, corrective actions, and ongoing improvement. For professionals, staying credible means keeping up with the standard, audit practice, and changing security risks.
This profile is useful for certification projects, audit remediation, security governance setup, and supplier or customer assurance work. In Germany, it often matters in software, manufacturing, professional services, and international businesses that need clear security documentation. It can also help when a team must coordinate with German-speaking stakeholders and global auditors at the same time.
The average hourly rate for freelancers with ISO/IEC 27001 Information Security Management Professionals in Germany is 114 €, which corresponds to a daily rate of about 912 € based on an 8-hour working day.
Of the freelancers with ISO/IEC 27001 Information Security Management Professionals in Germany, 77% hold at least a Bachelor's degree, 46% hold at least a Master's degree, and 8% hold a doctorate.
On average, freelancers with ISO/IEC 27001 Information Security Management Professionals in Germany have 24 years of professional experience, with a single engagement typically lasting around 2.4 years.
The most common languages among freelancers with ISO/IEC 27001 Information Security Management Professionals in Germany are German (100%), English (100%), and Spanish (27%).
The most common industries among freelancers with ISO/IEC 27001 Information Security Management Professionals in Germany are Information Technology (93%), Professional Services (60%), and Telecommunication (47%).
The most common business areas among freelancers with ISO/IEC 27001 Information Security Management Professionals in Germany are Information Technology (100%), Project Management (87%), and Operations (67%).
FRATCH ISO/IEC 27001 Information Security Management Professionals main locations
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
