Skip to main content
🇩🇪GDPR-compliant
Hire proven

IT Security Officer / Information Security Officer (TÜV)

experts in Germany, matched in minutes from 15,000 CVs with the power of AI.

For IT risk reviews, security policies, awareness work, incident handling, and control of technical and organizational safeguards. Find vetted freelancers with the TÜV certificate fast and precisely, ready for on-site or remote work in Germany.

Meet FRATCH IT Security Officer / Information Security Officer in Germany

Verified expert

Dustin Dehez

View profile

Regulatory Risk Executive | Risk Governance & 2nd LoD in Banking | EU AI Act, DORA, MaRisk, NFR | CEO Secori Advisors GmbH

Bad Homburg
Dustin Dehez

Last position:

External consultant at Deutsche Leasing

2nd LoD/Change the Bank (CtB)

  • CtB: External consultant and workstream lead for rectifying findings by BaFin following a special IT audit in the 2nd LoD, management of the work package for revising the ICT Risk Management & ICT Asset Classification in accordance with DORA Chapter 2, the processes for structural analysis, protection requirements, and control assessments (4 FTEs).
Verified expert

Alicja Wilczek

View profile

Lawyer • External Data Protection Officer • IT Security Officer

Düsseldorf
Alicja Wilczek

Last position:

Integrated security and emergency documentation for a 24/7 logistics company at Medium-sized logistics company

  • Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, vulnerability management policy, business resilience programme, risk governance plan
  • Consolidation into an integrated emergency handbook (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table, and a formal approval structure
  • Review of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with documented compensating control
  • Review and documentation of NIS2 and HinSchG applicability, including the legal reasoning for non-applicability
Verified expert

Florian Krebs

View profile

Self-employed IT and Security Consultant

Olching
Florian Krebs

Last position:

LAN Planner at Global Network AG

  • As-is assessment of the current network infrastructure and its documentation, including on-site inspections
  • Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
  • Planning of new copper and fiber optic cabling, including patch panels
  • Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
  • Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
  • Additional support after the components go live (hypercare phase)
  • Regular communication with project management and client stakeholders
Verified expert

Florian Schröder

View profile

Information Security Officer / IT Security Architect / Awareness Expert

Norderstedt
Florian Schröder

Last position:

Information Security Officer / Designated InfoSec Officer at Oil Company

  • Complete overhaul of the ISMS according to ISO 27001
  • Conducted a comprehensive gap analysis
  • Reduced ISMS documentation by 30% through consolidation and process optimization
  • Introduced a full PDCA cycle for continuous improvement
  • Established the ISMS within the company
  • Implemented the necessary processes
  • Managed and conducted internal and external audits
  • Developed and implemented a company-wide risk management system
  • Deployed an ISMS tool including process design and training
  • KRITIS compliance: Prepared and provided required evidence, liaised with regulatory authorities, planned, documented, and implemented an attack detection system (SIEM), co-led the BCMS/ITSCM implementation subproject
  • NIS-2 implementation: Gap analysis, risk assessments, training for executives and staff
  • Led a cybersecurity team of 3 members
  • Conducted various internal and external audits, managed providers, introduced continuous improvement
  • Project consulting: closely coordinated with business and system owners, launched an online shop, a mobile app, and a customer portal
  • Redesigned the security architecture, reducing administrative efforts by 20%
  • Implemented ITIL processes (e.g., change management)
  • Revised service agreements with internal and external providers
  • Developed a security awareness strategy, ran social engineering tests, introduced and monitored phishing simulations, created various awareness materials, gave presentations
  • Managed a budget of one million euros
Verified expert

Tarek El Idrisi

View profile

IT-Consultant

Dortmund
Tarek El Idrisi

Last position:

Associate GRC at Egerer Consulting

Carve-out project: Development of certification strategy, implementation and requirement plans across multiple standards — ISO/IEC 27001, ISO 9001, ISO 14001, ISO 22301, ISO/IEC 20000-1, BSI IT-Grundschutz, and BSI TR-RESISCAN

  • Cross-standard inventory and risk assessment
  • Coordination with cross-department stakeholders: ISB, executive management, certification bodies, legal and data protection
  • Consulting in information security, GRC, and IT auditing
Verified expert

Najat Diamante

View profile

Data Protection Officer, Auditor and ICT Risk Control Function

Großkrotzenburg
Najat Diamante

Last position:

Freelance Consultant Microsoft Purview at Bechtlee IT-Systemhaus

  • Design and global rollout of sensitivity labels (confidentiality labels) for automated classification and encryption of business-critical data.
  • Definition and rollout of Data Loss Prevention (DLP) policies to protect IP and personal data across endpoints, Exchange, SharePoint, Teams, and non-Microsoft clouds.
  • Setup of Insider Risk Management policies to detect and contain excessive data leaks and risky user behavior.
  • Implementation of GDPR and retention requirements through automated retention policies and structured records management.
  • Technical support for legal teams in internal and external investigations using eDiscovery (Standard/Premium) and Content Search.
  • Continuous improvement of the security and compliance level by reviewing the Microsoft Compliance Manager and closing gaps (regulations such as ISO 27001, NIS-2)
Verified expert

Hüseyin Altuntas

View profile

Business Analyst

Köln
Hüseyin Altuntas

Last position:

Business Analyst at Niedersächsisches Ministerium für Inneres, Sport und Digitalisierung

  • Responsibility, also as rollout manager, for the successful transition of a basic OZG platform into the client's standard operations by planning and implementing measures along Service Transition and Service Operation according to ITIL, including workshops in a SAFe environment with more than 40 operational stakeholders
  • Building and maintaining cross-organizational stakeholder relationships by organizing and running various information sessions on technical configurations and user guides (platform and EfA services)
  • Designing and improving various operational and project documents such as the ITIL operations manual, OLA, SLA, service support concept and rollout instructions
  • Modeling project-based processes according to BPMN 2.0, EPK and UML related to OZG services with the goal of integrating them into the operational e-government process landscape (SOA)
  • Coordinating operational stakeholders and KPI reporting to the project management team using agile methods according to SAFe
  • Tech stack / tools: Microsoft 365 (SharePoint, OneNote, Outlook, Teams), Skype for Business, Cisco Webex, ADONIS, MindManager, Jira, Confluence
Verified expert

Meik Voß

View profile

CEO / Managing Consultant

Elmshorn
Meik Voß

Last position:

CEO / Managing Consultant at MONTUVA GmbH, Germany

Verified expert

Peter Dittkuhn

View profile

Project Coordination, Consulting, IT Security, ISMS, BCM, NIS2, KVP

Callenberg
Peter Dittkuhn

Last position:

Security Consultant at Public Institution of the City Administration

  • Requirements management, process planning, interface role, ISMS implementation and documentation
  • Implementation and establishment of an ISMS according to ISO 27001 as well as setup of emergency management / ITSCM
  • Coordination of conditions with the authority-affiliated IT service provider
  • Consideration of KRITIS relevance in the scope and implementation of a B3S
  • Development of guidelines for document control and the continuous improvement process (KVP)
  • Creation of relevant project documents
  • Analysis of existing processes and development of guidelines
  • Collection of requirements for ISMS and ITSCM and coordination with the IT service provider including definition of interfaces
  • Analysis of communication processes and escalation paths
  • Review of documents for risk management, ISMS, emergency preparedness and emergency response
  • Development of a complete rebuild of all documentation and creation of new relevant documents
  • Development of necessary rules, policies and concepts
  • Interface function between customer and service provider to ensure document quality
  • Coordination of protection needs with departments, especially regarding KRITIS relevance, and planning resulting measures
  • Development of preventive measures to minimize data center outages for various scenarios such as pandemics or ransomware attacks
  • Defining the test strategy for IT emergency exercises
  • Initiation of necessary training measures for raising awareness in departments
  • External Information Security Officer (ISB)
  • Introduction of document control
Verified expert

Thomas Blasi

View profile

CIO of the corporate group

Illertissen
Thomas Blasi

Last position:

CIO of the corporate group at Badische Stahlwerke GmbH

  • Member of the strategic management team
  • Responsible for 50 direct reports and functional responsibility for 25 more
  • Realigned the global IT strategy and merged individual IT divisions of the business units
  • Led the central international IT organization of the corporate group
  • Budget responsibility of €20 million p.a.
  • Strategic advisor to the executive board
  • Contributor to the company's strategic decisions as a leadership team member
  • Driver of digitalization
  • Evolved the global team structure across entities in a matrix setup
  • Initiated and implemented process changes
  • Operated and provided the central IT infrastructure including the data center for the entire group
  • Designed the global application architecture
  • Implemented AI-powered solutions
  • Responsible for IT governance based on ISO 27001
  • Rolled out Microsoft M365
  • Conducted an ERP selection process for the corporate group
  • Designed and implemented the new organizational structure as a foundation for future success
  • Introduced requirements management, project portfolio management and capacity planning for cross-company IT within six months
Verified expert

Federico Leefhelm

View profile

ISO – Senior Consultant Quality & Information Security

Düsseldorf
Federico Leefhelm

Last position:

Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG

As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW.  Developed and implemented a holistic process view covering both technical and organizational aspects  Ensured end-to-end control of all IAM-related technical services  Established clear responsibilities and accountabilities within the IAM landscape  Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security  Introduced and monitored governance policies to ensure compliance and security  Continuously improved IAM processes and systems through regular audits and evaluations  Participated in external audits of the process as part of official ISO audits  Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units  Conceptually advanced the KPI system to measure process quality

Verified expert

Vladimir Mildenberger

View profile

IT & Cybersecurity Project Manager

Bad Soden-Salmünster
Vladimir Mildenberger

Last position:

IT & Cybersecurity Project Manager at Technology company / IT security solutions

  • Planning, directing, and implementing IT security projects focused on Palo Alto solutions (e.g., Next-Gen Firewalls, Prisma Access, Cortex, SASE, Zero Trust)
  • Coordinating interdisciplinary teams and resources throughout all project phases
  • Managing project scope, schedule, budget, and quality according to client goals
  • Active stakeholder management and ensuring transparency and communication
  • Risk management: identifying, assessing, and controlling project-related risks
  • Creating and maintaining project plans, budget overviews, and reports
  • Ensuring customer satisfaction through high-quality project and relationship management
  • Applying established project management methods such as PMI, PRINCE2, or SCRUM for structured project execution
Verified expert

Marco Trautmann

View profile

Chief Financial Officer & ExCo Member

Bad Soden am Taunus
Marco Trautmann

Last position:

Chief Financial Officer & ExCo Member at Senacor Technologies AG

  • Led assessment and preparation for finance and business management transformation including roll-out of SAP S/4 HANA Cloud, Public Edition.
  • Enhanced financial and project reporting by streamlining tools and introducing a management dashboard.
  • Introduced opportunity management reporting as part of business operations activities.
  • Prepared annual financial statements (HGB).
  • Directed annual budget development and aligned it with the ExCo.
Verified expert

Klaus Rheinwald

View profile

Senior Project Manager

Hamburg
Klaus Rheinwald

Last position:

Management Consultant Compliance/Data Protection at Telefónica Germany GmbH & Co. OHG

Consulting on compliance and data protection topics in the telecommunications environment.

Discover over 15,000 top freelancers

IT Security Officer / Information Security Officer statistics

Aggregated from the professional profiles of matched freelancers.

Experience

23 years

Position duration

2.7 years

Positions per freelancer

14

Top business areas

Information Technology, Project Management, Operations

Top industries

Information Technology, Professional Services, Banking and Finance

Certification focus areas

Information Technology, Audit, Quality Assurance

Bachelor's degree or higher

89%

Master's degree or higher

68%

Doctorate

14%

Certifications per freelancer

8

Most common languages

German, English, Spanish

Speak two or more languages

96%

Based on our profile pool as of 27 Aug 2026.

Daily rate distribution

0 5 10 15 20
<€480 €480-​640 €640-​800 €800-​960 €960-​1120 €1120+

The chart shows how the daily rates of freelancers holding this certification in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates for IT Security Officer / Information Security Officer in Germany

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 921 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 960 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 27 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

About the certification

What it covers

The TÜV certificate for an IT Security Officer, also known as an Information Security Officer, shows that a professional can help protect company data, systems, and processes. It is relevant for people who turn security rules into daily practice and who work with management, IT, and business teams.

Core skills

  • Building and maintaining security policies and procedures
  • Identifying risks and documenting safeguards
  • Supporting incident response and follow-up actions
  • Raising security awareness across teams
  • Working with technical, organizational, and legal requirements

Typical profiles

Holders often come from IT operations, system administration, governance, risk, compliance, or internal audit. Many support security programs alongside other responsibilities, while some focus fully on information security management. In Germany, companies often look for this profile when they need practical support that bridges policy and implementation.

Where it matters

This certification fits projects where security needs structure and clear ownership. Typical work includes introducing or improving an information security management system, preparing for audits, handling supplier security questions, or strengthening incident processes. It is especially useful in regulated sectors, larger IT environments, and companies that want a reliable security contact who can work with technical teams and management.

What it tells a company

A freelancer with this TÜV certification is expected to understand common security threats, basic controls, and how to organize security work without slowing the business down. It signals a structured approach, clear communication, and the ability to translate requirements into practical steps. For companies in Germany, it also suggests a professional who can work in German-speaking environments and handle both remote coordination and on-site cooperation when needed.

Related terms

Searchers may look for the role under IT-Sicherheitsbeauftragter, Information Security Officer, or IT security officer. These names usually point to the same practical need: someone who can support information security governance, awareness, and day-to-day control. When comparing freelancers, look for proof of real project work in addition to the TÜV certificate.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

Before you brief your next project: the most common questions about IT Security Officer / Information Security Officer.

The IT Security Officer / Information Security Officer (TÜV) certificate shows that a professional understands how to organize and support information security in a company. It focuses on practical security governance, risk handling, awareness, and coordination with IT and management.

In Germany, IT-Sicherheitsbeauftragter is a common search term for this role, and it often refers to the same kind of security responsibility. The exact wording can vary by provider, but the core topic is the same: managing and supporting information security in practice.

The Information Security Officer profile fits people who take responsibility for security processes, policies, and controls. It is a strong match for IT administrators, security coordinators, compliance staff, and consultants who need to connect technical and organizational security work.

A TÜV-certified IT Security Officer typically helps define security rules, assess risks, support incident handling, and keep security measures aligned with business needs. In projects, this often means working on security concepts, awareness programs, supplier questions, and preparation for audits or reviews.

This certificate is usually more focused on practical security coordination than on highly specialized technical or forensic work. Compared with advanced offensive, cryptography, or architecture certifications, IT Security Officer / Information Security Officer is broader and more governance-oriented.

A candidate should be comfortable with basic IT environments, common threats, and the logic of controls, policies, and responsibilities. The TÜV path usually makes the most sense for professionals who already work with security, risk, or compliance and want a recognized qualification for that role.

Yes. Many organizations in Germany use an Information Security Officer both remotely and on site, depending on the project and the need for workshops or stakeholder meetings. German language skills are often helpful because security policies, audits, and internal coordination are frequently handled in German.

Like many professional security qualifications, the value of the IT Security Officer / Information Security Officer certificate depends on staying current with practice, threats, and company requirements. Companies usually look for recent project experience, not just the certificate itself, so continued work in the field matters a lot.

The average hourly rate for freelancers with IT Security Officer / Information Security Officer in Germany is 115 €, which corresponds to a daily rate of about 921 € based on an 8-hour working day.

Of the freelancers with IT Security Officer / Information Security Officer in Germany, 89% hold at least a Bachelor's degree, 68% hold at least a Master's degree, and 14% hold a doctorate.

On average, freelancers with IT Security Officer / Information Security Officer in Germany have 23 years of professional experience, with a single engagement typically lasting around 2.7 years.

The most common languages among freelancers with IT Security Officer / Information Security Officer in Germany are German (100%), English (96%), and Spanish (16%).

The most common industries among freelancers with IT Security Officer / Information Security Officer in Germany are Information Technology (84%), Professional Services (63%), and Banking and Finance (55%).

The most common business areas among freelancers with IT Security Officer / Information Security Officer in Germany are Information Technology (98%), Project Management (86%), and Operations (67%).

FRATCH IT Security Officer / Information Security Officer main locations

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH