Top expert badge
Recommended expert
Profile header background

Arndt Schürg

Information Security Officer according to TISAX

Arndt Schürg
Profile header overlay
Ludwigshafen, Germany

Experience

Aug 2025 - Present
8 months

Information Security Officer according to TISAX

Automotive Supplier

Expertise details
Position Summary
Information Security Officer according to TISAX at Automotive Supplier
Industries
Automotive
Business Areas
Information Technology
Quality Assurance
Jan 2023 - Jun 2024
1 year 6 months

Interim CISO

EnBW

Expertise details
Position Summary
Interim CISO at EnBW
Industries
Energy
Business Areas
Information Technology
  • Steering the information security management system with KRITIS relevance according to ISO/IEC 27001 and ISO 27019 in the role of interim CISO/ISB
  • Aligning information security objectives with executive management (management reviews)
  • Coordinating and planning information security with the group CISO and BCM officers
  • Aligning information security in complex group and stakeholder structures
Nov 2021 - Jun 2022
8 months

Security Consultant for Supplier Management and Supplier Audits

Deutsche Bahn

Expertise details
Position Summary
Security Consultant for Supplier Management and Supplier Audits at Deutsche Bahn
Industries
Transportation
Business Areas
Audit
Procurement
  • Advising the supplier management of DB Networks on creating policies in line with ISO 27001 requirements
  • Developing, advancing, and reviewing implementation guidelines
  • Aligning purchasing processes to ensure compliance with corporate policies
  • Evaluating and coordinating supplier self-assessments as a basis for risk assessment
Oct 2021 - Present
4 years 6 months

Lead Auditor Internal Audit ISO/IEC 27001 and ISO/IEC 27019

Gas Network Operator in NRW

Expertise details
Position Summary
Lead Auditor Internal Audit ISO/IEC 27001 and ISO/IEC 27019 at Gas Network Operator in NRW
Industries
Utilities
Business Areas
Audit
  • Planning audits and preparing documents according to ISO 19011
  • Conducting audits by checking the ISMS against ISO/IEC 27001 combined with the requirements of the T-Security Catalog under § 11 (1a) and (1b) EnWG of the Federal Network Agency (BNetzA)
Jul 2021 - Present
4 years 9 months

Trainer and Designer for Incident and Business Continuity Management Trainings

TÜV Süd

Expertise details
Position Summary
Trainer and Designer for Incident and Business Continuity Management Trainings at TÜV Süd
Industries
Professional Services
Business Areas
Information Technology
Quality Assurance
  • Developing a training concept based on ISO 27035 incident management, ISO 22301 business continuity management, and BSI 200-4
  • Continuously updating content according to state-of-the-art and evolving standards
  • Delivering trainings both in-person and online
Jun 2021 - Dec 2022
1 year 7 months

Consultant and subproject manager KRITIS logging IT/OT

Deutsche Bahn

Expertise details
Position Summary
Consultant and subproject manager KRITIS logging IT/OT at Deutsche Bahn
Industries
Transportation
Business Areas
Information Technology
Project Management
  • Capture logging requirements for subsystems
  • Coordinate with system owners on connecting the systems
  • Develop detection patterns/use cases for potential attack scenarios
  • Design and execute tests
  • Coordinate organizational and technical processes with the central SOC
  • Prepare audit-related documentation
Nov 2020 - Present
5 years 5 months

Information Security Officer/ISB

Senftenberg Public Utilities

Expertise details
Position Summary
Information Security Officer/ISB at Senftenberg Public Utilities
Industries
Utilities
Business Areas
Information Technology
  • Manage the information management system based on the IT security catalog ISO/IEC 27001 and ISO 27019 as interim CISO/ISB
  • Align information security objectives with management (management reviews)
  • Identify, categorize, and handle security incidents
  • Serve as the point of contact for stakeholders regarding information security
Sep 2020 - Aug 2021
1 year

Consultant Identity and Access Management

Insurance Company

Expertise details
Position Summary
Consultant Identity and Access Management at Insurance Company
Industries
Insurance
Business Areas
Information Technology
  • Establish IAM monitoring based on a SIEM/Splunk according to VAIT
Jul 2018 - Apr 2019
10 months
Mannheim, Germany

Interim Information Security Officer/CISO

Caterpillar Energy Solutions GmbH

Expertise details
Position Summary
Interim Information Security Officer/CISO at Caterpillar Energy Solutions GmbH
Industries
Energy
Manufacturing
Business Areas
Information Technology
  • Lead information security management
  • Implement and operate the ISMS according to ISO/IEC 27001
  • Advise business units on compliance with KRITIS requirements
Nov 2017 - Feb 2018
4 months

Senior Security Consultant

Local Electricity Provider

Expertise details
Position Summary
Senior Security Consultant at Local Electricity Provider
Industries
Energy
Business Areas
Information Technology
  • Implement the IT security catalog (IT-SiKat)
  • Conduct security analyses and gap analyses
  • Develop technical and organizational security concepts
Jan 2016 - Present
10 years 3 months

ISO 27001 Certification Consultant

Various SMEs

Expertise details
Position Summary
ISO 27001 Certification Consultant at Various SMEs
Industries
Information Technology
Business Areas
Audit
Information Technology
  • Supported SMEs in ISO 27001 certification
  • Developed security policies and technical security concepts
  • Conducted information security trainings and workshops
Feb 2013 - Jul 2015
2 years 6 months
Hanover, Germany

Security Consultant & Project Manager

VW Commercial Vehicles

Expertise details
Position Summary
Security Consultant & Project Manager at VW Commercial Vehicles
Industries
Automotive
Business Areas
Audit
Information Technology
Project Management
  • Advised on the implementation and operation of the ISMS according to ISO/IEC 27001
  • Managed IT security projects
  • Prepared for certifications and conducted audits

Industry Experience

See where this freelancer has spent most of their professional time.

Experienced in Information Technology, Utilities, Professional Services, Automotive, Energy, and Transportation.

Information Technology
Utilities
Professional Services
Automotive
Energy
Transportation
Profile match chart

Business Area Experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Audit, Quality Assurance, Project Management, and Procurement.

Information Technology
Audit
Quality Assurance
Project Management
Procurement
Profile match chart

Summary

Our expert (born 1971) has over 25 years of experience as a consultant and project manager in IT and information security. His main areas include implementing Information Security Management Systems (ISMS), preparing for certifications, conducting ISO 27001 trainings, and performing IT security analyses. He is certified as an ISO 27001 Lead Auditor. His extensive experience in IT and information security is demonstrated by his CISSP certification from ISC2 and as a Certified Security Practitioner from ISACA.

With his diploma in Business Administration (FH) focusing on IT, he has in-depth knowledge of information security in the context of business requirements and processes. His professional practice includes advising companies on introducing and operating ISMS, especially within the framework of legal and regulatory requirements, e.g., under the IT Security Act.

Skills

  • Industries: Kritis, Local Energy Suppliers, Energy Producers, Aggregators, Long-distance Gas Pipeline Operators, Transport And Logistics, Insurance, Consulting, Automotive, Mechanical Engineering, Telecommunications, It Service Providers, Finance.

  • Security: Isms According To Iso 27001, Bsi Basic Protection Approach, B3s District Heating, Nis-2, Cyber Resilience Act, Vda-isa, Data Protection/gdpr, Compliance, Business Continuity, Iec 62443.

  • It Security Audit Tools: Verinice, Vda-isa, Metasploit/icssploit, Wireshark, Owasp, Openvas/nessus, Splunk, Kali, Nmap.

  • Training And Security Awareness: Author And Trainer For Trainings On Incident And Business Continuity Management (Tüv Süd), Trainer For Iso 27001 Foundation, Officer, And Tisax Foundation Personal Certifications (Tüv Süd), Workshops, Trainings, And Events On (It) Security.

  • Software, Frameworks, Skills: Ms Office (Word, Excel, Powerpoint, Access), Ms Visio, Ms Project, Aris Process Modeling (Epk), Adonis, Vmware, Cyberark, Atlassian Jira, Confluence, Bitbucket, Splunk, Elastic Stack, Sap Solution Manager, Crm, Fi, Mm, Xi, Sql, Php, Javascript, Identity & Access Management (Iam/pam).

  • Hardware And Architectures: Pc & System Components, Hardware Architecture, Vpn, Firewall Architecture, And Network Segmentation.

  • Project Management: It Project Management, Project Planning, Project Controlling According To Ipma, Pmbok, Prince2, Kanban, And Scrum.

  • Documentation: Experience With Organizational Structures, Audit Reports According To Iso/iec 27001, Emergency Manuals, Security Policies, Technical Security Concepts, Industry-specific Security Standards (B3s), Operating Manuals, Work Instructions, Process Modeling In Epk, Pap (Aris, Visio, Adonis), Corporate Structures, Smes, Complex Stakeholder Structures, Complex Supplier And Customer Structures (Energy Suppliers).

Languages

German
Native
English
Advanced

Education

Diploma in Business Administration (FH), focus on IT · Business Administration, IT

Certifications & licenses

Compliance Fundamentals according to ISO37301

NIS-2 information sessions by BSI

BSI

Advanced training for trainers at TÜV Süd

TÜV-Süd

Audit Competence according to § 8a (3) BSIG

Trainer for Incident and Business Continuity Management Trainings

TÜV Süd

Accreditation as TISAX Trainer

TÜV Süd

Expert training in IT security for control and automation technology according to IEC 62443

Certified Security Practitioner

ISACA

Accreditation as ISO 27001 Trainer

TÜV Süd

ISO 27001 Lead Auditor

TÜV Rheinland

Data Protection Officer: Fundamentals of Data Protection

CISSP

ISC2

ITIL Foundation

AEVO

Statistics

Experience

Total positions 12
Experience in Information Technology 10 y
Avg length 2 y 9 m
Longest experience 10 y 2 m

Global Experience

Countries worked in 1 (Germany)
Primary country Germany

Expertise

Recent roles Information Security Officer according to TISAX, Interim CISO, Security Consultant for Supplier Management and Supplier Audits
Main industries Information Technology, Utilities, Professional Services
Main business areas Information Technology, Audit, Quality Assurance

Qualifications

Certifications earned 14

Profile

Created
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Frequently asked questions

Do you have questions? Here you can find further information.

Where is Arndt based?

Arndt is based in Ludwigshafen, Germany.

What languages does Arndt speak?

Arndt speaks the following languages: German (Native), English (Advanced).

How many years of experience does Arndt have?

Arndt has at least 13 years of experience. During this time, Arndt has worked in at least 12 different roles and for 11 different companies. The average length of individual experience is 1 year and 1 month. Note that Arndt may not have shared all experience and actually has more experience.

What roles would Arndt be best suited for?

Based on recent experience, Arndt would be well-suited for roles such as: Information Security Officer according to TISAX, Interim CISO, Security Consultant for Supplier Management and Supplier Audits.

What is Arndt's latest experience?

Arndt's most recent position is Information Security Officer according to TISAX at Automotive Supplier.

What companies has Arndt worked for in recent years?

In recent years, Arndt has worked for Automotive Supplier, EnBW, Deutsche Bahn, Gas Network Operator in NRW, and TÜV Süd.

Which industries is Arndt most experienced in?

Arndt is most experienced in industries like Information Technology, Utilities, and Professional Services. Arndt also has some experience in Automotive, Energy, and Transportation.

Which business areas is Arndt most experienced in?

Arndt is most experienced in business areas like Information Technology, Audit, and Quality Assurance. Arndt also has some experience in Project Management and Procurement.

Which industries has Arndt worked in recently?

Arndt has recently worked in industries like Information Technology, Utilities, and Professional Services.

Which business areas has Arndt worked in recently?

Arndt has recently worked in business areas like Information Technology, Audit, and Quality Assurance.

What is Arndt's education?

Arndt attended education in Business Administration, IT.

Does Arndt have any certificates?

Arndt has 14 certificates. Among them, these include: Compliance Fundamentals according to ISO37301, NIS-2 information sessions by BSI, and Advanced training for trainers at TÜV Süd.

What is the availability of Arndt?

Arndt is immediately available full-time for suitable projects.

What is the rate of Arndt?

Arndt's rate depends on the specific project requirements. Please use the Meet button on the profile to schedule a meeting and discuss the details.

How to hire Arndt?

To hire Arndt, click the Meet button on the profile to request a meeting and discuss your project needs.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Market avg: 700-860 €
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.