Andreas Rühl-Principal Consultant Information Security
Check rate
Experience
Freelance Information Security Consultant
A-R-C Andreas Rühl Consulting
Development and implementation of tailored information security strategies
Introduction and further development of ISMS according to ISO 27001, BSI Baseline Protection, and other standards
Risk management and creation of security concepts
Consulting for KRITIS, PCI DSS, TISAX, and VdS 3473/10000
Building and improving security organizations
Creation and implementation of guidelines, policies, work instructions, and process descriptions
Audit support and certification preparation
Conducting training sessions, workshops, and awareness campaigns
Selection and consulting for the introduction of IT security solutions such as SIEM, DLP, IDS/IPS, firewalls, and encryption technologies
Conducting penetration tests and vulnerability analyses
Consulting on the selection, integration, and management of security architectures in complex IT environments
Consulting on ITSM and managed security services and SOC
Leading and managing complex projects to improve information security
Process analysis, optimization, and management according to ITIL, ISO 27001, and cybernetics
Introduction and quality assurance of management, documentation, and knowledge management systems
Support in meeting regulatory information security requirements (e.g. GDPR, HIPAA, SOX, GMP, KRITIS)
Development and implementation of risk analysis procedures
Organization of initial response, forensic investigations, and organizational measures in security incidents
Design and delivery of focused workshops on topics such as ISMS, IT risks, and current threat scenarios
Awareness campaigns to promote a security culture in companies
Special training on ISO 27001, BSI Baseline Protection, KRITIS, and other relevant standards
Simulations and exercises to prepare for information security incidents
Interim management for leading information security projects or IT security organizations
Taking on the role of an external CISO (Chief Information Security Officer)
Support in developing and implementing IT security and business strategies
Coaching and mentoring of managers in information security
Building and leading security departments as well as recruiting and qualifying employees
Temporary assumption of management responsibility in critical situations
Business Unit Lead Security Solutions / Technical Lead Information Security Consulting
Profi Engineering Systems AG
- Built the Security Solutions business area
- Worked with customer representatives from all functional areas
- Technical lead for the employees in the Information Security Consulting team
- Led offer and technical teams from the first idea presentation through contract signing to project completion
- Active support in presales
- Finding solutions in escalations
- Proactive communication and responsibility for projects
- Strategic development of topics with direct reporting to management
- Further development and coaching of team members
- Leadership in line with the company culture
- Building and expanding the consulting offering
- Project management and information security consulting
- Development of ISMS and audit support
- Consulting on B3S, NIS2, KRITIS, ISO 27001, BSI Baseline Protection, PCI DSS, VdS 3473, TISAX
- Creation and introduction of policies, work instructions, process descriptions, operating documentation, and manuals
- ITSM and process consulting
- Consulting on IT and information security strategies and architectures
- Conducting workshops and seminars
- IT security technology consulting and selection of suitable tools, processes, and methods
- Expansion of the customer network and contribution to the area strategy
- Contact person for customers for further questions and ensuring successful project implementation
- Developing strategies and processes around the use of IT staff
- Supporting the expansion of the Managed Services business area
- Building the penetration testing business area
- Supporting business units in analyzing and identifying potential for better control of business processes
- Recruiting staff and planning further development and qualification
Principal Consultant Information Security
Profi Engineering Systems AG
- Built information security consulting as a new consulting area
- Worked with customer representatives from all functional areas
- Technical lead for the employees in the Information Security Consulting team
- Led offer and technical teams from the first idea presentation through contract signing to project completion
- Active support in presales
- Finding solutions in escalations
- Proactive communication and responsibility for projects
- Strategic development of topics with direct reporting to management
- Further development and coaching of team members and other employees
- Leadership in line with the company culture
- Building and expanding the consulting offering
- Consulting on information security, project management, ISMS development, audit support
- Consulting on KRITIS, ISO 27001, BSI Baseline Protection, PCI DSS, VdS 3473
- Creation and introduction of policies, work instructions, process descriptions, operating documentation, and manuals
- ITSM and process consulting
- Consulting on IT and information security strategies and architectures
- Conducting workshops and seminars
- IT security technology consulting
- Selection of suitable tools, processes, and methods
- Expansion of the customer network and contribution to the area strategy
- Contact person for customers for further questions and ensuring successful project implementation
- Developing strategies and processes around the use of IT staff
- Supporting the expansion of Managed Services
- Supporting business units in analyzing and identifying potential for better control of business processes and preparing analysis results
- Recruiting staff and planning further development and qualification
Senior IT and Information Security Specialist
Klöckner und Co AG
- Management of information security for the Klöckner Group
- Building the information security organization and the ISMS
- Design, planning, and review of infrastructure measures and managing implementation (IDS/IPS, SIEM, honeypots, firewalls)
- Preparing and presenting information security topics for the executive board
- Conducting information security audits
- Conducting penetration tests and vulnerability scans
- Consulting and reporting on information and IT security
- Process analysis, documentation, and design including adjustment to security standards
- Selection, testing, and introduction of broad security solutions
- Conducting risk analyses according to ISO 27001 and developing our own risk analysis procedures
- Creation and introduction of an ISMS and related policies and guidelines
- Structural analyses regarding information security
- Project management for the introduction and implementation of information security policies
- Acting as the information security officer
- Control and monitoring of commissioned service providers
- Forensic and organizational investigation of information security incidents and measures
Senior Consultant, Auditor and IT Security Engineer Information Security
Kai Viehmeier Consulting GmbH
- Consultant, committee member, and co-author of the VdS 3473 cyber security guideline for SMEs
- Creation and introduction of ISMS at customer sites
- Structural and organizational analyses of companies regarding information security and legal requirements
- Process analysis, documentation, and design including adjustment to security standards
- Conducting information security audits
- Conducting penetration tests and vulnerability scans
- Consulting customers on information and IT security according to ISO 27001, BSI Baseline Protection, and VdS 3473
- Conducting risk analyses and developing our own risk analysis procedures
- Project management for the introduction and implementation of the requirements of VdS 3473
- Acting as the information security officer
- Configuration and installation of Cisco-based network components
Manager in the Quality and Training Team
Siemens Healthcare (ISK Personaldienstleistungs GmbH)
- Project management for projects to introduce new services and processes
- Service quality management according to ITIL, ISO 27001, and ISO 9001: design and implementation of the ticket review process, carrying out ticket reviews, statistics, analytics, reporting, initiating corrective and preventive measures
- Employee training, certification, and testing
- Document management according to ITIL, ISO 27001, and ISO 9001: design and implementation, administration, and quality assurance of documents
- Knowledge management according to ITIL, ISO 27001, and ISO 9001: design and implementation, administration, and quality assurance of content
- Process management according to ITIL, ISO 27001, and ISO 9001: recording, documentation, and improvement of various processes (incident, problem, change, knowledge management, employee training)
Network Administration and IT Security Consultant
Pamec Papp Ingenieurgesellschaft
- IT security consulting
- Site-to-site VPN IPsec tunnel configuration and troubleshooting
- Network configuration and troubleshooting in a global, mixed IT infrastructure with Cisco products
- Firewall and perimeter administration (Cisco ASA, Check Point, FortiGate)
- Network administration and support in customer networks (Cisco, Juniper, Huawei)
- Technical application, service portal, and customer system support
- ITIL v3 service operation and continual service improvement (CSI)
- Multilingual 1st- and 2nd-level support in an ISO 27001 organization
- Incident and problem management
- Project management
- Support and configuration of medical systems (CT, MR, AS, HS, DICOM, HL7)
- Syngo service software configuration and support
- System management support and configuration based on HP OpenView and CA Unicenter
- Information and data security concepts and principles; PHI/ePHI, HIPAA security standard
- User and knowledge base management
- Process recording, documentation, and optimization
IT Security Manager Austria
Sandoz-Novartis International GmbH (Pidas GmbH)
- Management consulting for IT security
- Reporting to CIO and CISO
- Project management for IT infrastructure and IT security
- Creation, review, and adjustment of processes, SOPs, and policies
- Information Security Officer in Sandoz IT
- Management of LAN, WAN connections, and perimeter security
- Vulnerability management and penetration testing
- Single point of contact for suppliers, service providers, and external contractors
- Antivirus and malware management
- Process documentation, optimization, and introduction according to GxP, SOX, and ITIL
- IT security incident and problem management
- Forensics in case of attacks or infections
- Management of cross-company IT and IT security incidents
- Audits of third-party companies and partners
- Encryption of data carriers, network connections, and network storage
- Adaptation of Sandoz systems for compliance with standards in other environments
- Consulting for hardware and software rollouts as well as execution
- Consulting on the IT integration of EBEWE into Sandoz/Novartis systems
- IT quality management
- Training of the Sandoz helpdesk
Project Network and Rollout Engineer and Network Integration
HWS-Projekt-Engineering
- On-site and remote support for hardware, software, peripheral, and network issues
- Hardware and software rollouts
- Active Directory administration and support
- Software distribution and licensing
Instructor for Construction and IT Technology
Berufsförderungswerk Weißenburg
- Teaching content in construction and IT technology
- Development of teaching materials and practical exercises
Project Network and System Engineer
Landesgewerbeanstalt (Staff Placement)
- Guidance and training of additional project staff
- In-house, remote, and phone support (2nd level) for hardware, software, peripheral, and network issues
- Support and management of hardware and software rollouts
- Migration from Novell Directory Services to Active Directory as part of the integration into the TÜV Rheinland group
- Troubleshooting and training colleagues in processes
- Network and user administration
- Rollout team lead
Senior PC Technician Southern Germany, Consultant and Deputy Branch Manager
Arlt Computer GmbH Nürnberg
- 1st and 2nd level support (on site and remote) for hardware, software, and network
- Warranty handling with manufacturers
- Installation, configuration, and repair of various operating systems (Windows XP, Vista, 2000, 98, Mac OS X, Linux)
- Customer consulting and sales in network and server technology, hardware, software, internet technology, and multimedia
- Working with the merchandise management system
- Internal knowledge transfer and information exchange with Novell GroupWise
- Training other technicians in internal processes
- Deputy branch management (cash reconciliation, inventory taking, staff management)
IT/Network Technician and Consultant for Private Customers and SMEs
Self-employed
- Network support and setup of TCP/IP networks and internet integration
- Technical PC support: assembly, setup, expansion, upgrades, troubleshooting, and repair
- IT consulting: procurement and expansion of hardware, software, and security solutions
- Support, creation, and organization of websites and web servers (Dreamweaver, Flash, Linux Game Server)
- Organization and technical support of LAN parties (10-50 participants)
- Project management and leadership for integration and roll-out projects
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Information Technology, Professional Services, Healthcare, Metals and Mining, Pharmaceutical, and Retail.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Strategy, Customer Service, Audit, and Quality Assurance.
Summary
With over 15 years of experience in information security, I support companies in implementing and improving ISMS based on standards such as ISO 27001. My focus is on developing and putting into practice IT security strategies, information security audits, and risk analyses to ensure security and compliance.
I currently work as an information security and cybersecurity consultant and advise clients on topics such as data protection (GDPR), TISAX, and IT project management. With my expertise in leading teams, strategically developing business areas, and proactive communication, I help create sustainable security solutions.
Skills
- Strategic Consulting And Project Management, Introducing Patch Management
- Support In Setting Up Isms According To Bsi It Baseline Protection
- Overhaul Of Data Center It Security
- Introduction Of Identity And Asset Management
- Overhaul Of Isms And Introduction According To German Standards When Entering The German Market
- Security Assessment And Isms According To Vds 3473 And Introduction Of Isms
- Implementation Of Iso 27001
- Handling Cyber Attacks And Advising On Bafin Security Standards
- Consulting On Iso 27001 And It Security
- Consulting On Information Security
- Building A Data Protection Management System
- Overhaul Of Internal Policies For Kritis
- Overhaul Of Internal Policies In The Context Of Kritis And Iso 27001
- Siem And Monitoring Market Analysis
- Handling An Information Security Incident And Closing Security Gaps
- Gdpr Consulting For The Introduction Of Cloud Solutions
- Building An It Emergency Handbook
- Cyber Security Attack
- Design And Documentation Of A Secure Backup Environment
- Project Management For It Security Projects
- Consulting And Support For Tisax
- Consulting And Project Management For Building A Security Operations Center (Soc)
- Consulting In The Context Of Iso 27001 And Bsi It Baseline Protection In Software Development
- Audit Of Internal Processes And Parts Of The It Security Landscape
- Principal Consultant Information Security
Languages
Education
Georg Simon Ohm University of Applied Sciences Nuremberg
Architecture · Nuremberg, Germany
Georg Simon Ohm University of Applied Sciences Nuremberg
Civil Engineering · Nuremberg, Germany
Georg Simon Ohm University of Applied Sciences Nuremberg
Electrical Engineering · Nuremberg, Germany
Certifications & licenses
ISMS Officer – ISO 27001
VOREST AG
Cyber Security – Approval as Auditor and Expert (VdS 3474 / VdS 3473)
VdS Schadenverhütung GmbH · Cologne, Germany
VdS Certified Cyber Security Consultant
VdS Schadenverhütung GmbH
Driver's license class: A and B
ITIL v3 certificate
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Freelance Information Security Consultant
Nearby freelancers
Professionals working in or nearby Berlin, Germany
