Hire proven IT Security Officer / Information Security Officer (TÜV) experts in Germany, matched in minutes from 15,000 CVs with the power of AI.
For IT risk reviews, security policies, awareness work, incident handling, and control of technical and organizational safeguards. Find vetted freelancers with the TÜV certificate fast and precisely, ready for on-site or remote work in Germany.
About the certification
What it covers
The TÜV certificate for an IT Security Officer, also known as an Information Security Officer, shows that a professional can help protect company data, systems, and processes. It is relevant for people who turn security rules into daily practice and who work with management, IT, and business teams.
Core skills
- Building and maintaining security policies and procedures
- Identifying risks and documenting safeguards
- Supporting incident response and follow-up actions
- Raising security awareness across teams
- Working with technical, organizational, and legal requirements
Typical profiles
Holders often come from IT operations, system administration, governance, risk, compliance, or internal audit. Many support security programs alongside other responsibilities, while some focus fully on information security management. In Germany, companies often look for this profile when they need practical support that bridges policy and implementation.
Where it matters
This certification fits projects where security needs structure and clear ownership. Typical work includes introducing or improving an information security management system, preparing for audits, handling supplier security questions, or strengthening incident processes. It is especially useful in regulated sectors, larger IT environments, and companies that want a reliable security contact who can work with technical teams and management.
What it tells a company
A freelancer with this TÜV certification is expected to understand common security threats, basic controls, and how to organize security work without slowing the business down. It signals a structured approach, clear communication, and the ability to translate requirements into practical steps. For companies in Germany, it also suggests a professional who can work in German-speaking environments and handle both remote coordination and on-site cooperation when needed.
Related terms
Searchers may look for the role under IT-Sicherheitsbeauftragter, Information Security Officer, or IT security officer. These names usually point to the same practical need: someone who can support information security governance, awareness, and day-to-day control. When comparing freelancers, look for proof of real project work in addition to the TÜV certificate.
Meet FRATCH IT Security Officer / Information Security Officer
Peter Dittkuhn
Project Coordination, Consulting, IT Security, ISMS, BCM, NIS2, KVP
Last position:
Security Consultant at Public Institution of the City Administration
- Requirements management, process planning, interface role, ISMS implementation and documentation
- Implementation and establishment of an ISMS according to ISO 27001 as well as setup of emergency management / ITSCM
- Coordination of conditions with the authority-affiliated IT service provider
- Consideration of KRITIS relevance in the scope and implementation of a B3S
- Development of guidelines for document control and the continuous improvement process (KVP)
- Creation of relevant project documents
- Analysis of existing processes and development of guidelines
- Collection of requirements for ISMS and ITSCM and coordination with the IT service provider including definition of interfaces
- Analysis of communication processes and escalation paths
- Review of documents for risk management, ISMS, emergency preparedness and emergency response
- Development of a complete rebuild of all documentation and creation of new relevant documents
- Development of necessary rules, policies and concepts
- Interface function between customer and service provider to ensure document quality
- Coordination of protection needs with departments, especially regarding KRITIS relevance, and planning resulting measures
- Development of preventive measures to minimize data center outages for various scenarios such as pandemics or ransomware attacks
- Defining the test strategy for IT emergency exercises
- Initiation of necessary training measures for raising awareness in departments
- External Information Security Officer (ISB)
- Introduction of document control
Jens G.
Technology & Product Lead
Last position:
CTO & Member Executive Management
- Executive management (C-level)
- End-to-end ownership: IT, Engineering (SDD & Agentic AI), architecture; teams across DE/ES/RO
- Operational responsibility for scalable platforms (nine-digit annual revenue; global marketplace)
- Launched and scaled an AI-powered AdTech service to >€1M daily revenue
- Integration and alignment with group-level processes (Security, BI, Business IT)
- Corporate strategy development and business planning at executive board level
Klaus Rheinwald
Senior Project Manager
Last position:
Management Consultant Compliance/Data Protection at Telefónica Germany GmbH & Co. OHG
Consulting on compliance and data protection topics in the telecommunications environment.
Torsten Schneider
Managing Director
Last position:
Managing Director at mac + you GmbH
- CFO of the company
- Consulting in processes and process management
- Consulting in information security ISO 27001
- Consulting Scrum / Agile Management
- Project management for IT projects, especially doctors' practices
- Digitalization projects
- Data protection / data security training
Henryk Orantek
Security Consultant
Last position:
Security Consultant at Daimler AG
- Development of a cloud security strategy
- Implementation of cloud security governance to comply with ISO/IEC 27017 and the CSA CCM
- Creation of a management system to control cloud security with a focus on process design as well as roles and responsibilities
- Definition of security measures to safeguard cloud solutions
- Conducting requirements analyses and defining the scope for cloud security projects
- Achievements: Established an effective NIS2-compliant cloud security governance that meets industry-specific requirements and effectively minimizes cloud security risks
Dieter Dietz
Senior Consultant IT Service Management / ITIL, Management Coach, Scrum Master
Last position:
Senior Consultant IT Service Management / ITIL, Management Coach, Scrum Master at Schweizer Kantonalbank
Project: Roadmap for implementing the ITIL processes in IT operations according to the guidelines for Operational Excellence per CMMI 4 and the current life cycle management within the frameworks of GRC, SCRUM and DevOps.
- Advising, coordinating and conducting workshops, analyses and gap assessments.
- Determining the current state regarding implementation of IT processes, interfaces, tools used and KPIs with graphical representation of the maturity level.
- Defining the target image of the IT processes, interfaces, tools used and KPIs.
- Designing a set of recommendations for the roadmap for IT operations management in the context of a highly critical and highly available IT infrastructure.
- Supporting the introduction of the central service management tool Jira Service Desk.
- Coordinating and aligning with business units / stakeholders / architecture (Avaloq, SAP, etc.) / security / IAM / BCM, etc.
- Advising on the implementation of IT operations processes: incident, problem, change / release, request and service management (incl. service desk).
Klaus Kilvinger
Consultant and Trainer, Managing Partner
Last position:
Consultant and Trainer, Managing Partner at Opexa Advisory GmbH
- Advising clients on ISO/IEC 27001, TISAX, BSI IT-Grundschutz and GDPR
- Trainer and internal auditor
- Contract management (service and work contracts, framework agreements)
- Coordinating and supporting tender responses
- Developing strategies and measures for clients and new business opportunities (e.g. phishing, online awareness trainings)
- Further developing the governance/risk/compliance offering
- Account management for existing clients and new business acquisition
- Supporting HR with hiring and interviews
Frank Müns
GDPR Consultant
Last position:
Klinikum Stuttgart
- Preparation of DPIA for the implementation of Windows 11 and Co-Pilots
Jörg Iffländer
External Information Security Officer
Last position:
External Information Security Officer at ilink Kommunikationssysteme GmbH
Cristina Bittner
Lawyer, Privacy and AI Consultant and Trainer
Last position:
Privacy consultant at Statutory health insurance / Healthcare / Social data protection (AOK Federal Association and AOK Bayern)
Tasks:
- Privacy consultant for the development and launch of an online portal
- Lead, preparation and support in conducting a data protection impact assessment (DPIA)
- Creation of data protection compliant documentation, especially data protection concept and deletion concepts
- Preparation of decision templates for data protection management, data protection officers (cross-state) and information security
- Acting as liaison between the project and data protection and information security
Manfred Liebetrau
Senior Consultant Information Security
Last position:
Senior Consultant Information Security at Creditplus Bank AG
- Designing the information security process based on ITIL 4
- Designing the ITIL 4 incident and change management processes
- Creating information security policies for the bank
- Support in the project for internal audit findings
- Advising on the setup of the bank's internal control systems (ICS)
- Advising on setting up ICS processes
- Advising and supporting security architecture and risk analysis of the existing IT landscape, including IT security architecture, data management, data compliance & physical security
- Advising and project leadership for the security concept of the bank's assets
- Advising and support in contracts with external service providers to meet the bank's regulatory (BAIT; MaRisk; DORA; NIS2; GDPR) and information security requirements
- Support in planning and implementing a SOC/SIEM and risk management
- Support for the spam email team in analyzing and handling incidents
Bianca-Beata Blaj
Consultant
Last position:
Consultant at Telecommunications company
- Implementation of the NIS 2 directive
- Implementation of measures to prevent and contain cybersecurity incidents
- Response to security incidents
- Adaptation of risk management for AI systems in cybersecurity
- Documentation and containment strategies
- Incident reporting
- Risk analysis and security for information systems
- Maintaining and restoring backup management and crisis management
Andreas Guthier
IT Security Consultant
Last position:
IT Security Consultant at Nuremberg Authority
- Quality assurance of information security documentation
- Advising and coaching departments in creating information security documentation
- Analysis and documentation of information security for various basic services
- Maintaining data in the ISMS
- Identifying vulnerabilities
- Coordinating and tracking vulnerability remediation
- Clarifying data protection questions
- Data protection impact assessment
- Conducting internal IT security audits (review)
- Supporting audit preparation (maturity audit, BSI/ISO 27001 audit, KRITIS audit)
Jamie Crookes
Founder I Data Protection & Compliance Officer
Last position:
Founder I Data Protection & Compliance Officer at Compliant Digital GmbH & Co. KG
Heinz-Dieter Lühmann
Consultant
Last position:
Consultant at CH Crypto Group
- Advice on governance and information security topics: BAIT, MaRisk
- Creating governance documents (policies, guidelines)
- Developing emergency manuals
- Based on BSI IT baseline protection standard 200-4 and ISO2700x
Discover over 15,000 top freelancers
IT Security Officer / Information Security Officer statistics
Typical experience
23 years
Average project duration
2.7 years
Certifications per freelancer
10
Top business areas
Information Technology, Project Management, Legal
Top industries
Information Technology, Professional Services, Automotive
Most common languages
German, English, French
Bachelor's degree or higher
91%
Master's degree or higher
73%
Doctorate
9%
Salary / Daily Rate Distribution
The chart shows how the daily rates of freelancers holding this certification are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Average rates for IT Security Officer / Information Security Officer & Seniority distribution
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Frequently Asked Questions
Curious about FRATCH? Find the answers you need
The IT Security Officer / Information Security Officer (TÜV) certificate shows that a professional understands how to organize and support information security in a company. It focuses on practical security governance, risk handling, awareness, and coordination with IT and management.
In Germany, IT-Sicherheitsbeauftragter is a common search term for this role, and it often refers to the same kind of security responsibility. The exact wording can vary by provider, but the core topic is the same: managing and supporting information security in practice.
The Information Security Officer profile fits people who take responsibility for security processes, policies, and controls. It is a strong match for IT administrators, security coordinators, compliance staff, and consultants who need to connect technical and organizational security work.
A TÜV-certified IT Security Officer typically helps define security rules, assess risks, support incident handling, and keep security measures aligned with business needs. In projects, this often means working on security concepts, awareness programs, supplier questions, and preparation for audits or reviews.
This certificate is usually more focused on practical security coordination than on highly specialized technical or forensic work. Compared with advanced offensive, cryptography, or architecture certifications, IT Security Officer / Information Security Officer is broader and more governance-oriented.
A candidate should be comfortable with basic IT environments, common threats, and the logic of controls, policies, and responsibilities. The TÜV path usually makes the most sense for professionals who already work with security, risk, or compliance and want a recognized qualification for that role.
Yes. Many organizations in Germany use an Information Security Officer both remotely and on site, depending on the project and the need for workshops or stakeholder meetings. German language skills are often helpful because security policies, audits, and internal coordination are frequently handled in German.
Like many professional security qualifications, the value of the IT Security Officer / Information Security Officer certificate depends on staying current with practice, threats, and company requirements. Companies usually look for recent project experience, not just the certificate itself, so continued work in the field matters a lot.
Request a Free Demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
