Skip to main content
Top expert badge
Recommended expert
Profile header background

Andreas Rühl-Principal Consultant Information Security

Andreas Rühl - Principal Consultant Information Security - profile avatar
Profile header overlay
Available
Berlin, Germany

Check rate

Experience

Jan 2025 - Present
Germany

Freelance Consultant for Information Security

A-R-C Andreas Rühl Consulting

Position Summary
Freelance Consultant for Information Security at A-R-C Andreas Rühl Consulting
Industries
Information Technology
Professional Services
Business Areas
Information Technology
Project Management
Quality Assurance
  • Development and implementation of tailored information security strategies

  • Introduction and further development of ISMS according to ISO 27001, BSI baseline protection, and other standards

  • Risk management and creation of security concepts

  • Consulting for KRITIS, PCI DSS, TISAX, and VdS 3473/10000

  • Building and improving security organizations

  • Creation and implementation of guidelines, policies, work instructions, and process descriptions

  • Audit support and certification preparation

  • Conducting trainings, workshops, and awareness campaigns

  • Selection and consulting on the introduction of IT security solutions such as SIEM, DLP, IDS/IPS, firewalls, and encryption technologies

  • Conducting penetration tests and vulnerability analyses

  • Consulting on the selection, integration, and management of security architectures in complex IT environments

  • Consulting on ITSM and managed security services and SOC

  • Leading and managing complex projects to improve information security

  • Process analysis, optimization, and management according to ITIL, ISO 27001, and cybernetics

  • Introduction and quality assurance of management, documentation, and knowledge management systems

  • Support in complying with regulatory information security requirements (e.g. GDPR, HIPAA, SOX, GMP, KRITIS)

  • Development and implementation of risk analysis procedures

  • Organizing initial response, forensic investigations, and organizational measures in the event of security incidents

  • Designing and running targeted workshops on topics such as ISMS, IT risks, and current threat scenarios

  • Awareness campaigns to promote security culture in companies

  • Special trainings on ISO 27001, BSI baseline protection, KRITIS, and other relevant standards

  • Simulations and exercises to prepare for information security incidents

  • Interim management for leading information security projects or IT security organizations

  • Taking on the role of an external CISO (Chief Information Security Officer)

  • Support in developing and implementing IT security and corporate strategies

  • Coaching and mentoring of managers in the field of information security

  • Building and leading security departments as well as recruiting and qualifying employees

  • Temporary assumption of management responsibility in critical situations

Jan 2019 - Dec 2024
Germany

Head of Business Unit Security Solutions / Technical Lead Information Security Consulting

Profi Engineering Systems AG

Position Summary
Head of Business Unit Security Solutions / Technical Lead Information Security Consulting at Profi Engineering Systems AG
Industries
Information Technology
Professional Services
Business Areas
Information Technology
Project Management
Strategy
  • Building the Security Solutions business unit
  • Dealing with customer representatives from all functional areas
  • Technical leadership of the employees in the Information Security Consulting team
  • Leading proposal and technical teams from the first idea presentation through contract signing to project completion
  • Active participation in presales
  • Finding solutions in escalation cases
  • Proactive communication and responsibility for projects
  • Strategic development of topics with direct reporting to management
  • Further development and coaching of team members
  • Leadership in line with the company culture
  • Building and expanding the consulting offering
  • Project management and consulting in information security
  • Development of ISMS and audit support
  • Consulting on B3S, NIS2, KRITIS, ISO 27001, BSI baseline protection, PCI DSS, VdS 3473, TISAX
  • Creation and introduction of policies, work instructions, process descriptions, operating documentation, and manuals
  • ITSM and process consulting
  • Consulting on IT and information security strategies and architectures
  • Conducting workshops and seminars
  • IT security technology consulting and selection of suitable tools, processes, and methods
  • Expanding the customer network and contributing to the business unit strategy
  • Point of contact for customers for further questions and ensuring successful project execution
  • Developing strategies and processes around the use of IT staff
  • Supporting the expansion of the Managed Services business area
  • Building the penetration testing business area
  • Supporting departments in analyzing and identifying potential for better control of business processes
  • Recruiting staff and planning further development and qualification
Oct 2017 - Jan 2019
Germany

Principal Consultant Information Security

Profi Engineering Systems AG

Position Summary
Principal Consultant Information Security at Profi Engineering Systems AG
Industries
Information Technology
Professional Services
Business Areas
Audit
Information Technology
Project Management
  • Building information security consulting as a new consulting area
  • Dealing with customer representatives from all functional areas
  • Technical leadership of the employees in the Information Security Consulting team
  • Leading proposal and technical teams from the first idea presentation through contract signing to project completion
  • Active participation in presales
  • Finding solutions in escalation cases
  • Proactive communication and responsibility for projects
  • Strategic development of topics with direct reporting to management
  • Further development and coaching of team members and other employees
  • Leadership in line with the company culture
  • Building and expanding the consulting offering
  • Consulting on information security, project management, ISMS development, and audit support
  • Consulting on KRITIS, ISO 27001, BSI baseline protection, PCI DSS, VdS 3473
  • Creation and introduction of policies, work instructions, process descriptions, operating documentation, and manuals
  • ITSM and process consulting
  • Consulting on IT and information security strategies and architectures
  • Conducting workshops and seminars
  • IT security technology consulting
  • Selection of suitable tools, processes, and methods
  • Expanding the customer network and contributing to the business unit strategy
  • Point of contact for customers for further questions and ensuring successful project execution
  • Developing strategies and processes around the use of IT staff
  • Supporting the expansion of managed services
  • Supporting departments in analyzing and identifying potential for better control of business processes and preparing the analysis results
  • Recruiting staff and planning further development and qualification
Jan 2016 - Apr 2017
Germany

Senior Representative IT and Information Security

Klöckner und Co AG

Position Summary
Senior Representative IT and Information Security at Klöckner und Co AG
Industries
Metals and Mining
Business Areas
Audit
Information Technology
Project Management
  • Managing information security for the Klöckner Group
  • Building the information security organization and ISMS
  • Designing, planning, and reviewing infrastructure measures and managing implementation (IDS/IPS, SIEM, honeypots, firewalls)
  • Preparing and presenting information security topics for the executive board
  • Conducting information security audits
  • Conducting penetration tests and vulnerability scans
  • Consulting and reporting on information and IT security
  • Process analysis, documentation, and design including adaptation to security standards
  • Selection, testing, and introduction of comprehensive security solutions
  • Conducting risk analyses according to ISO 27001 and developing own risk analysis procedures
  • Creation and introduction of an ISMS and the associated policies and guidelines
  • Structural analyses regarding information security
  • Project management for the introduction and implementation of information security policies
  • Serving as the information security officer
  • Managing and monitoring external service providers
  • Forensic and organizational investigation of information security incidents and measures
Apr 2015 - Oct 2015
Germany

Senior Consultant, Auditor and IT Security Engineer Information Security

Kai Viehmeier Consulting GmbH

Position Summary
Senior Consultant, Auditor and IT Security Engineer Information Security at Kai Viehmeier Consulting GmbH
Industries
Information Technology
Professional Services
Business Areas
Audit
Information Technology
Project Management
  • Consultant, committee member, and co-author of the VdS 3473 Cyber Security guideline for SMEs
  • Creation and introduction of ISMS at customer sites
  • Structural and organizational analyses of companies regarding information security and legal requirements
  • Process analysis, documentation, and design including adaptation to security standards
  • Conducting information security audits
  • Conducting penetration tests and vulnerability scans
  • Consulting customers on information and IT security according to ISO 27001, BSI baseline protection, and VdS 3473
  • Conducting risk analyses and developing own risk analysis procedures
  • Project management for the introduction and implementation of the requirements of VdS 3473
  • Serving as the information security officer
  • Configuration and installation of Cisco-based network components
Nov 2013 - Mar 2015
Germany

Manager in the Quality and Training Team

Siemens Healthcare (ISK Personaldienstleistungs GmbH)

Position Summary
Manager in the Quality and Training Team at Siemens Healthcare (ISK Personaldienstleistungs GmbH)
Industries
Healthcare
Business Areas
Information Technology
Project Management
Quality Assurance
  • Project management for projects to introduce new services and processes
  • Service Quality Management according to ITIL, ISO 27001, and ISO 9001: design and implementation of the ticket review process, conducting ticket reviews, statistics, analytics, reporting, and initiation of corrective and preventive measures
  • Employee training, certification, and exams
  • Document management according to ITIL, ISO 27001, and ISO 9001: design and implementation, administration, and quality assurance of documents
  • Knowledge Management according to ITIL, ISO 27001, and ISO 9001: design and implementation, administration, and quality assurance of content
  • Process management according to ITIL, ISO 27001, and ISO 9001: recording, documentation, and improvement of various processes (incident, problem, change, knowledge management, employee training)
Jan 2012 - Jul 2013
Germany

Network Administration and IT Security Consultant

Pamec Papp Ingenieurgesellschaft

Position Summary
Network Administration and IT Security Consultant at Pamec Papp Ingenieurgesellschaft
Industries
Healthcare
Information Technology
Business Areas
Information Technology
Operations
Project Management
  • IT security consulting
  • Site-to-site VPN IPsec tunnel configuration and troubleshooting
  • Network configuration and troubleshooting in a global heterogeneous IT infrastructure with Cisco products
  • Firewall and perimeter administration (Cisco ASA, Checkpoint, FortiGate)
  • Network administration and support in customer networks (Cisco, Juniper, Huawei)
  • Technical application, service portal, and customer system support
  • ITIL v3 Service Operation and Continual Service Improvement (CSI)
  • Multilingual 1st- and 2nd-level support in an ISO 27001 organization
  • Incident and problem management
  • Project management
  • Support and configuration of medical systems (CT, MR, AS, HS, DICOM, HL7)
  • Syngo Service software configuration and support
  • System Management support and configuration based on HP OpenView and CA Unicenter
  • Information and data security concepts and principles; PHI/ePHI, HIPAA Security Standard
  • User and knowledge base management
  • Process recording, documentation, and optimization
Jul 2010 - Dec 2011
Austria

IT Security Manager Austria

Sandoz-Novartis International GmbH (Pidas GmbH)

Position Summary
IT Security Manager Austria at Sandoz-Novartis International GmbH (Pidas GmbH)
Industries
Pharmaceutical
Business Areas
Information Technology
Project Management
Quality Assurance
  • IT security management consulting
  • Reporting to the CIO and CISO
  • Project management for IT infrastructure and IT security
  • Creation, review, and adaptation of processes, SOPs, and policies
  • Information Security Officer in Sandoz IT
  • Management of LAN and WAN connections and perimeter security
  • Vulnerability management and penetration testing
  • Single point of contact for suppliers, service providers, and external companies
  • Antivirus and malware management
  • Process documentation, optimization, and introduction according to GxP, SOX, and ITIL
  • IT security incident and problem management
  • Forensics in case of attacks or infections
  • Management of cross-company IT and IT security incidents
  • Audits of third-party companies and partners
  • Encryption of data carriers, network connections, and network storage
  • Adaptation of Sandoz systems for standards compliance in other environments
  • Consulting for hardware and software rollouts as well as execution
  • Consulting on the IT integration of EBEWE into Sandoz/Novartis systems
  • IT quality management
  • Training of the Sandoz help desk
Apr 2010 - Jul 2010
Germany
Remote

Project Network and Rollout Engineer and Network Integration

HWS-Projekt-Engineering

Position Summary
Project Network and Rollout Engineer and Network Integration at HWS-Projekt-Engineering
Industries
Information Technology
Business Areas
Information Technology
  • On-site and remote support for hardware, software, peripheral, and network issues
  • Hardware and software rollouts
  • Active Directory administration and support
  • Software distribution and licensing
Dec 2009 - Jul 2010
Germany

Instructor for Construction and IT Technology

Berufsförderungswerk Weißenburg

Position Summary
Instructor for Construction and IT Technology at Berufsförderungswerk Weißenburg
Industries
Education
  • Teaching construction and IT technology content
  • Preparing teaching materials and practical exercises
Jun 2009 - Dec 2009
Germany
Remote

Network and Systems Project Engineer

Landesgewerbeanstalt (Staff Placement)

Position Summary
Network and Systems Project Engineer at Landesgewerbeanstalt (Staff Placement)
Industries
Information Technology
Business Areas
Information Technology
Operations
Project Management
  • Guidance and onboarding of additional project staff
  • On-site, remote, and phone support (2nd level) for hardware, software, peripheral, and network issues
  • Support and management of hardware and software rollouts
  • Migration from Novell Directory Services to Active Directory as part of the integration into the TÜV Rheinland Group
  • Troubleshooting and onboarding colleagues into processes
  • Network and user administration
  • Team lead for rollouts
May 2008 - May 2009
Germany
Remote

Senior PC Technician Southern Germany, Consultant and Deputy Branch Manager

Arlt Computer GmbH Nuremberg

Position Summary
Senior PC Technician Southern Germany, Consultant and Deputy Branch Manager at Arlt Computer GmbH Nuremberg
Industries
Information Technology
Retail
Business Areas
Customer Service
Information Technology
Sales
  • 1st and 2nd level support (on-site and remote) for hardware, software, and network
  • Warranty processing with manufacturers
  • Installation, configuration, and repair of various operating systems (Windows XP, Vista, 2000, 98, Mac OS X, Linux)
  • Customer consulting and sales in network and server technology, hardware, software, internet technology, and multimedia
  • Working with the inventory management system
  • Internal knowledge transfer and information exchange with Novell GroupWise
  • Training other technicians in internal processes
  • Deputizing for branch management (cash reconciliation, inventory checks, staff management)
Sep 2003 - May 2008
Germany

IT/Network Technician and Consultant for private customers and SMEs

Self-employed

Position Summary
IT/Network Technician and Consultant for private customers and SMEs at Self-employed
Industries
Information Technology
Business Areas
Customer Service
Information Technology
Project Management
  • Network support and setup of TCP/IP networks and internet integration
  • Technical PC support: assembly, setup, expansion, upgrades, troubleshooting, and issue resolution
  • IT consulting: procurement and expansion of hardware, software, and security solutions
  • Support, creation, and organization of websites and web servers (Dreamweaver, Flash, Linux game server)
  • Organization and technical support of LAN parties (10–50 participants)
  • Project management and leadership in integration and rollout projects

Industry Experience

See where this freelancer has spent most of their professional time.

Experienced in Information Technology, Professional Services, Healthcare, Metals and Mining, Pharmaceutical, and Retail.

Information Technology
Professional Services
Healthcare
Metals and Mining
Pharmaceutical
Retail
Profile match chart

Business Area Experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Project Management, Strategy, Customer Service, Quality Assurance, and Audit.

Information Technology
Project Management
Strategy
Customer Service
Quality Assurance
Audit
Profile match chart

Summary

With over 15 years of experience in information security, I support companies in implementing and improving ISMS, based on standards such as ISO 27001. My focus is on developing and implementing IT security strategies, information security audits, and risk analyses to ensure security and compliance.

I currently work as an Information Security and Cybersecurity Consultant and advise clients on topics such as data protection (GDPR), TISAX, and IT project management. With my expertise in leading teams, strategically developing business areas, and communicating proactively, I help create sustainable security solutions.

Skills

  • Strategic Consulting And Project Management, Introduction Of Patch Management
  • Support In Building An Isms According To Bsi It Baseline Protection
  • Revision Of Data Center It Security
  • Introduction Of Identity And Asset Management
  • Revision Of Isms And Introduction According To German Standards When Entering The German Market
  • Security Review And Isms According To Vds 3473 And Introduction Of Isms
  • Implementation Of Iso 27001
  • Handling Cyber Attacks And Advising On Bafin Security Standards
  • Consulting On Iso 27001 And It Security
  • Consulting On Information Security
  • Building A Data Protection Management System
  • Revision Of Internal Guidelines For Kritis
  • Revision Of Internal Guidelines In The Context Of Kritis And Iso 27001
  • Market Analysis Of Siem And Monitoring
  • Handling An Information Security Incident And Closing Security Gaps
  • Gdpr Consulting For The Introduction Of Cloud Solutions
  • Building An It Emergency Handbook
  • Cyber Security Attack
  • Designing And Documenting A Secure Backup Environment
  • Project Management For It Security Projects
  • Consulting And Support For Tisax
  • Consulting And Project Management For Building A Security Operations Center (Soc)
  • Consulting In The Context Of Iso 27001 And Bsi It Baseline Protection In Software Development
  • Audit Of Internal Processes And Subareas Of The It Security Landscape
  • Principal Consultant Information Security

Languages

German
Native
English
Advanced

Education

Sep 2006 - Sep 2007

Georg-Simon-Ohm University of Applied Sciences Nuremberg

Architecture · Nuremberg, Germany

Sep 2004 - Sep 2006

Georg-Simon-Ohm University of Applied Sciences Nuremberg

Civil Engineering · Nuremberg, Germany

Sep 2003 - Sep 2004

Georg-Simon-Ohm University of Applied Sciences Nuremberg

Electrical Engineering · Nuremberg, Germany

...and 6 more

Certifications & licenses

ISMS Officer – ISO 27001

VOREST AG

Cyber Security – Authorization as Auditor and Subject Matter Expert (VdS 3474 / VdS 3473)

VdS Schadenverhütung GmbH · Cologne, Germany

VdS Certified Cyber Security Consultant

VdS Schadenverhütung GmbH

Driving license class: A and B

Statistics

Experience

Total positions 13
Experience in Information Technology 17.5 y
Avg length 1 y 8 m
Longest experience 5 y 11 m

Global Experience

Countries worked in 2 (Germany, Austria)
Primary country Germany

Expertise

Recent roles Freelance Consultant for Information Security, Head of Business Unit Security Solutions / Technical Lead Information Security Consulting, Principal Consultant Information Security
Main industries Information Technology, Professional Services, Healthcare
Main business areas Information Technology, Project Management, Strategy

Qualifications

Highest degree Bachelor
Certifications earned 5

Profile

Created
Last Update

Frequently asked questions

Have questions? Find more information here.

Andreas is based in Berlin, Germany and prefers 100% remote projects.

Andreas speaks the following languages: German (Native), English (Advanced).

Andreas has at least 22 years of experience. During this time, Andreas has worked in at least 13 different roles and for 12 different companies. The average length of individual experience is 2 years and 8 months. Note that Andreas may not have shared all experience and actually has more experience.

Based on recent experience, Andreas would be well-suited for roles such as: Freelance Consultant for Information Security, Head of Business Unit Security Solutions / Technical Lead Information Security Consulting, Principal Consultant Information Security.

Andreas's most recent position is Freelance Consultant for Information Security at A-R-C Andreas Rühl Consulting.

In recent years, Andreas has worked for A-R-C Andreas Rühl Consulting and Profi Engineering Systems AG.

Andreas is most experienced in industries like Information Technology, Professional Services, and Healthcare. Andreas also has some experience in Pharmaceutical, Metals and Mining, and Retail.

Andreas is most experienced in business areas like Information Technology, Project Management, and Strategy. Andreas also has some experience in Customer Service, Quality Assurance, and Audit.

Andreas has recently worked in industries like Information Technology and Professional Services.

Andreas has recently worked in business areas like Information Technology, Project Management, and Strategy.

Andreas holds a Bachelor in Civil Engineering from Georg-Simon-Ohm University of Applied Sciences Nuremberg.

Andreas has 5 certificates. Among them, these include: ISMS Officer – ISO 27001, Cyber Security – Authorization as Auditor and Subject Matter Expert (VdS 3474 / VdS 3473), and VdS Certified Cyber Security Consultant.

Andreas is immediately available full-time for suitable projects.

Andreas's rate depends on the specific project requirements. Please use the Meet button on the profile to schedule a meeting and discuss the details.

To hire Andreas, click the Meet button on the profile to request a meeting and discuss your project needs.

Daily Rate Distribution

0 1 2 3 4
<€640 €640-800 €800-960 €960-1120 €1120-1280 €1280-1440 €1440+

The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.

Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1200
900
600
300
Rate comparison chart
Daily rate avg. 1006 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1200
900
600
300
Rate comparison chart
Median rate 1040 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.