Andreas Ilias - Senior Cybersecurity Governance & ISMS Consultant
Experience
Cybersecurity Specialist Assessor
Bundesnetzagentur
- Recognition of national notified bodies
- Preparation of cybersecurity competency reports
- EU Radio Equipment Directive
Cybersecurity Trainer
Provadis Bildung und Beratung GmbH
- IT Security Act, BSI Act, BSI Kritis V, NIS2, DORA, GDPR
- ISO/IEC 27001, BSI IT Baseline Protection, NIST Cyber Security Framework
- Ethical hacking basics (Kali Linux, Metasploit Framework)
- Hacking techniques & tools (port scans, password cracking, injections)
- Development of supplementary training and course materials
Cybersecurity Project Manager (Data Loss Prevention)
HSBC Continental Europe, Germany
- DLP infrastructure migration, SIEM integration, IAM concept
- Implementation of DLP print monitoring and data-at-rest scanning
- DLP roll-out (4,000 users), DLP SharePoint, DLP ISM reporting
Cybersecurity Program Manager (Vulnerability Remediation)
ADIDAS AG
- End-to-end coordination of vulnerability management (VRM)
- Program status reporting for CISOs & steering committees (SteerCo)
IT Security Lecturer
Hochschule Fresenius GmbH
- Fundamentals: cybersecurity and information security
- Information security management (ISO/IEC 27001)
- Cybersecurity legislation & regulation (IT-SiG, BSI KritisV)
- Governance, risk & compliance, ISMS audit management
- Co-development and design of IT security curricula
- Development of exam papers and grading of exams
Cybersecurity Project Lead (Governance & Control)
Deutsche Bank AG
- Technical project lead for global InfoSec management reporting
- Stakeholder level: CIOs, CISOs, ExCo, SteerCo, auditors, and regulators
- Developed "Path-to-Green" action recommendations for CISOs & CIOs
- Close collaboration with the central Regulatory Compliance team
- Automation of the entire ISM reporting (savings: approx. 100h/month)
- Subject-matter representative in external ISO/IEC 27001 recertification audits
Senior IT Service & Test Manager
Deutsche Bank AG
- Management and coordination of global UATs (approx. 135,000 end users)
- Optimized and automated test management processes
- Close collaboration with engineering and release management
- Co-managed an offshore testing team of 20 FTEs
- In total, approx. 750 successfully transitioned software releases
Senior Server Administrator
Deutsche Bank AG
- Coordination and management of request-for-service processes
- Close collaboration with service design, transition, and operations
- Interface work with Unix, storage, virtualization, and DBA teams
- Reviewed service design packages and created change requests
- 2nd level Windows Server support in a 24/7 European operations center
- Event management, incident management, and request fulfillment
- Server provisioning, maintenance, and security patching
- Print server administration and data restorations
IT Specialist, focus on system integration
Deutsche Telekom AG
- User helpdesk, 1st level support, roll-out, and IMAC
- Software distribution, Windows XP migration, and security patching (approx. 300 users)
- Two-month internship abroad at DB Schenker Canada, Toronto
- 1st level support, Notes, VPN remote access, and print server admin
- Implemented a VDI infrastructure for test and training purposes
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Education, Professional Services, Transportation, Telecommunication, and Government and Administration.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Quality Assurance, and Operations.
Summary
Senior Cybersecurity & ISMS consultant with 15 years of experience in regulated and security-critical environments, especially in financial services, the public sector and critical infrastructure contexts. Focus on audit preparation according to ISO/IEC 27001 and BSI-KritisV, development of ISMS and governance structures, regulatory implementation mandates, as well as data loss prevention and audit-compliant information security senior management reporting to auditors and regulators.
Skills
- Infosec Management Reporting
- Infosec Management Systems
- Infosec Risk Management
- Cybersecurity Regulation
- It Process Automation
- It Enterprise Governance
- It Service Management
- It Project Management
- It Report Creation
- Information Security Management (Iso/iec 27001:2022)
- Nist Cyber Security Framework (Csf) 2.0
- It Service Management (Iso/iec 20000:2011 / Itilv3)
- Enterprise It-governance (Cobit5)
- Requirements Engineering & Software Testing (Istqb)
- Bait (Banking Supervisory Requirements For It | Bafin)
- Nis2 (Network And Information Security | Eu-2022/2555)
- Dora (Digital Operational Resilience Act | Eu-2022/2554)
- Use Case Modelling (Systems, Actors, Relationships)
- Requirements Engineering (Functional/non-functional)
- Classical Development Models (Waterfall Model, V-model Xt)
- Relational Database Systems (Oracle, Mysql, Mssql)
- Erm Modelling (Entity Relationship Modelling)
- Sql Crud Statements (Create, Read, Update, Delete)
- C, C++, Java
- Visual Basic For Applications (Vba)
- Frontend Development: Html, Css, Javascript, Jquery
- Backend Development: Ajax, Php, Mysql, Laravel
- Content Management Systems: Joomla, Wordpress
- Api Data Formats: Rest (Json And Xml Based)
- Network Technologies: Hubs, Switches, Layer 3 Switches, Routers, Mpls
- Primary, Secondary, And Tertiary Cabling
- Network Protocols: Tcp, Udp, Http(s), (S)ftp, Smtp, Dns, Dhcp, Pop3
- Storage Technologies: Das, Nas, San, Fibre Channel, Iscsi
- Server Virtualization (Vmware Esxi, Vsphere, Vcenter)
- Desktop Virtualization (Citrix Xen Desktop)
- Tableau / Microsoft Power Bi (Big Data Analytics & Visualisation)
- Sap Businessobjects (Reporting, Queries And Analysis)
- Splunk (Log Management, Monitoring, Reporting)
- Microsoft Windows 10/11 Professional
- Microsoft Windows Server 2016/2019 Standard Edition
- Red Hat Linux, Opensuse, Ubuntu, Mint, Kali Linux
- Encryption: Microsoft Bitlocker, Veracrypt
- End-point Security (Anti-virus, Anti-malware Solutions)
- Data Leakage Prevention (Infrastructure, Agents, Policies)
- Vulnerability Scanners: Owasp, Nessus, Openvas
- Penetration Testing: Kali Linux, Metasploit Framework
- Siem/soar Solutions: Ibm Resilient, Splunk Phantom
- Firewalls: Network (Plesk, Iptables), Host (Illumio)
Languages
Education
Deutsche Telekom AG, T-Systems International
State-certified IT specialist (IHK) · IT specialist, system integration · Germany · Grade average: 1.8
Award: Top young talent 2009
Certifications & licenses
ISO/IEC 42001 (AI Management System)
mITSM · Munich, Germany
BSI IT Baseline Protection Practitioner
Federal Office for Information Security (BSI) · Frankfurt, Germany
ISO/IEC 27001:2022 Update-Training
TÜV Süd Academy · Munich, Germany
BISG e.V. certified IT expert
Federal Association of IT Experts and Assessors (BISG) · Memmingen, Germany
Certified Information Systems Security Professional (CISSP)
International Information System Security Certification Consortium (ISC²) · Munich, Germany
M_o_R Risk Management Practitioner
Axelos · Bad Homburg, Germany
TÜV Data Protection Officer (GDPR)
TÜV Süd Academy · Bad Homburg, Germany
ISO/IEC 27001:2013 ISMS Auditor
TÜV Süd Academy · Frankfurt, Germany
ISO/IEC 27001:2013 Info Sec Officer
TÜV Süd Academy · Frankfurt, Germany
PRINCE2 Foundation (Project Management)
Axelos · Bad Homburg, Germany
COBIT 5 Implementer (IT Governance)
APMG · Bad Homburg, Germany
ISO/IEC 20000:2011 ITSM Manager/Auditor
TÜV Süd Academy · Bad Homburg, Germany
ITIL V3 Expert
Axelos · Bad Homburg, Germany
Six Sigma Green Belt Process Manager
Telekom Training · Bonn, Germany
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Andreas based?
What languages does Andreas speak?
How many years of experience does Andreas have?
What roles would Andreas be best suited for?
What is Andreas's latest experience?
What companies has Andreas worked for in recent years?
Which industries is Andreas most experienced in?
Which business areas is Andreas most experienced in?
Which industries has Andreas worked in recently?
Which business areas has Andreas worked in recently?
What is Andreas's education?
Does Andreas have any certificates?
What is the availability of Andreas?
What is the rate of Andreas?
How to hire Andreas?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Cybersecurity Specialist Assessor
Nearby freelancers
Professionals working in or nearby Frankfurt am Main, Germany