Cedric Bergermann-Bißlich-IT / Enterprise Architect (Security & Regulatory)
Check rate
Experience
Enterprise & Cloud Security Architect
---
Enterprise & Cloud Security Architect supporting the modernization of the SDK application landscape as part of the KVNeo transformation program. Responsible for enterprise architecture, cloud governance, security architecture, and the definition of technical standards for strategic business applications.
Key responsibilities include architecture governance, target architecture development, cloud and integration architecture, security-by-design, and the translation of regulatory requirements into sustainable technical solutions across multiple business domains.
Responsibilities and achievements
- Designed and reviewed target architectures for strategic insurance applications and enterprise services.
- Developed architecture documentation based on Arc42 and Architecture Decision Records (ADRs).
- Defined governance models, architecture principles, and technical guidelines for cross-domain initiatives.
- Supported the modernization of archive, document management, and output management platforms.
- Designed integration architectures using REST APIs and event-driven communication patterns.
- Led architecture discussions with enterprise architects, development teams, product owners, and business stakeholders.
- Translated regulatory requirements such as DORA and ISO/IEC 27001 into practical architecture decisions.
- Designed security concepts covering Identity & Access Management, authorization, authentication, auditability, and logging.
- Supported SIEM integration, security monitoring, and enterprise logging concepts.
- Evaluated technical risks, technical debt, and architecture improvements while providing decision papers for architecture boards.
- Established architecture governance processes and contributed to enterprise-wide transformation initiatives.
- Supported cloud governance activities and the definition of secure cloud architecture standards.
- Facilitated architecture workshops and coordinated cross-functional stakeholders across business and IT.
Technologies & Methods Microsoft Azure • Arc42 • Architecture Decision Records (ADR) • REST APIs • Event-Driven Architecture • Microsoft Entra ID • Active Directory • IAM • SIEM • Cloud Governance • Enterprise Architecture • Security Architecture • Azure API Management • Jira • Confluence • Draw.io • DORA • ISO/IEC 27001 • Agile • Scrum
Cyber Security Architect
UBS
- Translation of regulatory requirements (especially DORA) into architecture and operational processes
- Further development of governance structures in a regulatory environment
- Assessment of IT and integration architectures from a security and compliance perspective
- Support and assistance with audits
- Coordination of external service providers in a security context
Cyber Security Architect
Nationalbank AG
- Functional leadership in the area of cyber security and coordination of cross-functional security initiatives
- Overall responsibility for implementing and ensuring DORA compliance
- Development and establishment of an ICT reference architecture taking regulatory requirements into account
- Support and successful execution of audits (including BaFin, SWIFT, SEPA)
- Assessment and further development of IT and integration architectures from a security and compliance perspective
- Definition of security requirements for systems, interfaces, and data flows
- Management and coordination of cyber security projects in complex IT landscapes
- Alignment between IT, architecture, business units, and compliance
- Coordination of external service providers in the context of cyber security and regulatory requirements
- Building and further developing security governance structures and audit-ready documentation
Freiberuflicher Cyber Security Architekt / Consultant
Selbstständig
- Design and further development of security and target architectures in complex, highly regulated IT landscapes (banks, insurance companies)
- Detailed analysis of system, application, and integration landscapes to identify security-critical dependencies and risks
- Conducting gap analyses between regulatory requirements (DORA, ISO 27001, BAIT) and existing architectures, including deriving concrete measures
- Translating regulatory requirements into concrete architecture principles, security requirements, and technical guardrails
- Building and establishing governance structures including policies, control mechanisms, and audit-ready documentation
- Creating target visions, architecture concepts, and decision foundations for management and architecture committees
- Functional leadership of transformation and integration projects in complex system landscapes
- Close coordination with IT, enterprise architecture, compliance, internal audit, and business units
Teamleiter Cyber Security / Networking
Finanz Informatik
- Functional and disciplinary leadership of a team in cyber security and network architecture
- Coordination and execution of integration and migration projects in complex IT and data center environments
- Planning and establishment of security architectures and zero-trust approaches
- Ensuring regulatory requirements and supporting audits (including BaFin, TSI)
- Responsibility for the secure operation and further development of critical infrastructure (data center, 3000+ systems)
- Coordination between IT operations, architecture, business units, and external service providers
- Coordination of external service providers in the context of infrastructure and security projects
- Building and further developing security standards, processes, and documentation
Security Engineer
Finanz Informatik
- Support in the operation and protection of data center and network infrastructures in a banking environment
- Help with implementing IT security measures and meeting regulatory requirements
- Support for integration and migration projects in complex system landscapes
- Analysis and resolution of issues in security-critical IT environments
- Collaboration with internal teams and external service providers
- Support in preparing and carrying out audits
Security Consulting / Support
Netgo Borken
- Network technology / IT security department
- Security consulting
- Supporting audits at customer sites
- Ensuring ISO 27001 certifications for customers
- Administration of customer servers
- Remote support for the entire environment
- Server migrations, etc.
IT Sales, Consulting and Project Management
LT Memory Berlin
- Sales, consulting and project management for large customers (2500+ employees)
- Planning and carrying out large migrations, including for hotels and banks
- Managing various service providers (IT/building technology)
1st Lt US Air Force
United States Air Force
- Stationed at the NATO Airbase in Geilenkirchen (Aachen)
- Ensuring all required DOD policies and certifications
- Monitoring service providers
- Consulting and auditing at the US Consulate in Frankfurt
- Support and assurance of IT operations for the entire base
- Providing private households with DSL and mobile services
- Advising various internal departments on IT security
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Information Technology, Tourism, and Aerospace and Defense.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Audit, Project Management, Operations, Sales, and Quality Assurance.
Summary
Enterprise & Security Architect with a focus on enterprise architecture, cloud governance, and information security in highly regulated corporate environments. Experience in developing target architectures, governance models, and security concepts, as well as supporting complex transformation initiatives.
Specialized in translating regulatory requirements – especially DORA, ISO/IEC 27001, BAIT, and GDPR – into practical architecture principles, technical guardrails, and sustainable operating models. Strong experience in cloud architecture, identity & access management, privileged access management, API and integration architectures, and security governance.
Regular collaboration with business units, IT, information security, and management to develop solid architecture decisions, technical strategies, and decision foundations. Experience in creating and maintaining architecture documentation (Arc42, ADRs), facilitating architecture workshops, and coordinating cross-functional architecture topics.
Pragmatic, structured, and solution-oriented way of working with the goal of developing secure, scalable, and cost-effective IT architectures that meet both regulatory requirements and the strategic goals of the company.
Skills
Core Skills
- Enterprise Architecture
- Cloud Architecture
- Cyber Security
- Information Security
- Solution Architecture
- It Architecture
- Security Architecture
- Cloud Governance
- It Governance
- Cyber Risk Management
Cyber Security
- Identity & Access Management (Iam)
- Privileged Access Management (Pam)
- Zero Trust Architecture
- Security By Design
- Secure Software Development
- Threat Modeling
- Security Assessments
- Vulnerability Management
- Security Hardening
- Network Security
- Endpoint Security
- Application Security
- Cloud Security
- Data Protection
- Cyber Resilience
Governance / Compliance
- Dora
- Iso/Iec 27001
- Nis2
- Gdpr / Dsgvo
- Bsi It-Grundschutz
- Tisax
- Risk Management
- Security Policies
- Information Security Management (Isms)
- Audit Preparation
- Compliance Management
Identity & Access Management
- Microsoft Entra Id (Azure Ad)
- Active Directory
- Sailpoint Identityiq
- Okta
- Beyondtrust Pra
- Beyondtrust Rs
- Multi-Factor Authentication (Mfa)
- Single Sign-On (Sso)
- Federation
- Role Based Access Control (Rbac)
Cloud & Microsoft
- Microsoft Azure
- Azure Api Management
- Microsoft Fabric
- Azure Governance
- Hybrid Cloud
- Cloud Migration
- Cloud Security
- Microsoft 365 Security
Integration & Architecture
- Rest Apis
- Api Design
- Event-Driven Architecture
- Microservices
- Integration Architecture
- Arc42
- Architecture Decision Records (Adr)
- Technical Documentation
- System Integration
Operations
- Siem
- Logging
- Monitoring
- Observability
- High Availability
- Disaster Recovery
- Business Continuity
- Incident Response
Networking
- Tcp/Ip
- Dns
- Vpn
- Firewalls
- Network Segmentation
Infrastructure
- Windows Server
- Linux
- Vmware
- Virtualization
Security Tools
- Beyondtrust Pra
- Beyondtrust Rs
- Sailpoint
- Okta
- Tenable Nessus
- Fortinet Fortimanager
- Check Point
- Microsoft Defender
Project & Methods
- Agile
- Scrum
- Kanban
- Jira
- Confluence
- Azure Devops
- Technical Leadership
- Stakeholder Management
- Requirements Engineering
- Workshop Facilitation
Programming / Scripting
- Powershell
- Bash
- Sql
- Json
- Yaml
- Xml
⸻
Top-20 Keywords FüR Maximale Auffindbarkeit Auf Fratch
- Enterprise Architecture
- Cloud Architecture
- Solution Architecture
- Security Architecture
- Cyber Security
- Information Security
- Microsoft Azure
- Cloud Governance
- Dora
- Iso 27001
- Arc42
- Siem
- Iam
- Pam
- Entra Id
- Active Directory
- Beyondtrust
- Sailpoint
- Okta
- Api Management
Languages
Education
GA Tech USA
University · Cyber security / Cyber Privacy · 3,6
Bachelor of Science in Cyber Security and Cyber Privacy Georgia, USA | August 2021 – September 2024
The Bachelor’s degree program in Cyber Security and Cyber Privacy provided a broad and practice-oriented education in the protection of information, IT systems, networks, applications, and digital identities. The program combined technical cybersecurity disciplines with privacy, governance, risk management, and regulatory requirements, creating a strong foundation for working in complex enterprise and cloud environments.
The curriculum covered the fundamental principles of information security, including confidentiality, integrity, availability, authentication, authorization, accountability, and non-repudiation. A particular focus was placed on understanding how modern cyber threats affect organizations and how technical, organizational, and procedural security measures can be used to reduce risk.
Key areas of study included network and infrastructure security, operating system security, secure system administration, cloud security, application security, identity and access management, cryptography, vulnerability management, incident response, digital forensics, ethical hacking, and security monitoring. The program also addressed the design and evaluation of secure IT architectures, including the implementation of layered security controls and defense-in-depth concepts.
Network security topics included common network protocols, segmentation, firewalls, intrusion detection and prevention systems, virtual private networks, secure remote access, wireless security, and the identification of network-based attacks. The program provided an understanding of how weaknesses in network design, configuration, and access control can be exploited and how these risks can be mitigated through appropriate technical safeguards.
Application and software security were also important components of the degree. This included secure software development principles, common application vulnerabilities, threat modeling, secure coding practices, authentication and authorization mechanisms, input validation, session management, and the protection of application interfaces. Security risks affecting web applications, APIs, databases, and distributed systems were examined from both an attacker’s and a defender’s perspective.
The cloud security component focused on the security challenges associated with modern cloud-based and hybrid IT environments. Topics included shared responsibility models, secure cloud architecture, identity-based access control, encryption, key management, logging, monitoring, secure configuration, and the protection of cloud workloads and data. The program also addressed the importance of governance and standardized security controls when operating services across multiple platforms and environments.
Identity and access management formed another major area of study. The curriculum covered user authentication, authorization models, role-based and attribute-based access control, privileged access, identity lifecycle management, multi-factor authentication, federation, single sign-on, and the principle of least privilege. Particular attention was given to the risks associated with excessive permissions, shared accounts, privileged identities, and insufficient monitoring of access activities.
Cryptography was studied as a fundamental security technology. The program included symmetric and asymmetric encryption, hashing, digital signatures, certificates, public key infrastructures, secure key management, and the practical use of cryptographic mechanisms to protect data both at rest and in transit. Students learned not only how cryptographic techniques work, but also how poor implementation or inadequate key management can undermine otherwise strong security controls.
Cybersecurity risk management and governance were integrated throughout the program. This included identifying assets, threats, vulnerabilities, and potential business impacts; evaluating risks; selecting appropriate controls; and documenting residual risks. Students developed an understanding of how cybersecurity decisions must be aligned with business objectives, legal obligations, operational requirements, and organizational risk appetite.
The Cyber Privacy component focused on the responsible and lawful processing of personal and sensitive information. Areas of study included privacy principles, data minimization, purpose limitation, transparency, consent, retention, access control, privacy by design, privacy by default, and the secure handling of personal data throughout its lifecycle. The program also considered the relationship between privacy, cybersecurity, compliance, ethics, and organizational accountability.
Further topics included security policies, standards, procedures, audits, control frameworks, business continuity, disaster recovery, third-party risk, and security awareness. This provided an understanding of cybersecurity as an organizational responsibility that extends beyond purely technical controls. The course content emphasized the importance of combining people, processes, governance, and technology to establish an effective and sustainable security posture.
Threat analysis and ethical hacking exercises helped develop a practical understanding of common attack methods. These included reconnaissance, social engineering, credential attacks, privilege escalation, exploitation of vulnerabilities, lateral movement, persistence, data exfiltration, and attacks against applications and network services. The objective was to understand attacker behavior in order to design more effective preventive, detective, and responsive security measures.
Vulnerability management topics included asset identification, vulnerability scanning, assessment of technical findings, prioritization based on risk, remediation planning, and verification of implemented measures. Students learned that vulnerability severity alone is not sufficient for effective prioritization and that business criticality, exposure, exploitability, compensating controls, and potential impact must also be considered.
Incident response and digital forensics covered the identification, analysis, containment, eradication, and recovery phases of security incidents. The program addressed the importance of logging, evidence preservation, documentation, communication, and post-incident analysis. Students gained an understanding of how technical evidence can be collected and evaluated while maintaining integrity and traceability.
Security monitoring and detection topics included the collection and analysis of logs, event correlation, identification of suspicious behavior, security information and event management, alert handling, and the development of appropriate detection and response processes. The course content highlighted the importance of visibility, traceability, and reliable audit information in modern IT environments.
The program used practical exercises, laboratories, case studies, research assignments, and project-based work to connect theoretical cybersecurity concepts with real-world scenarios. These activities required the analysis of security problems, evaluation of alternative solutions, documentation of risks and recommendations, and presentation of findings to both technical and non-technical audiences.
Throughout the degree, emphasis was placed on structured analytical thinking, independent research, problem-solving, and the ability to assess security requirements from different perspectives. Technical solutions were evaluated not only in terms of security effectiveness, but also with regard to usability, operational feasibility, scalability, cost, compliance, and business impact.
The program also strengthened communication and documentation skills. Students were required to explain complex technical risks in a clear and understandable manner, create structured reports, justify security decisions, and develop recommendations for different stakeholder groups. This included translating technical findings into business-relevant risks and supporting informed decision-making.
By completing the program, I developed a comprehensive understanding of cybersecurity and privacy across technical, organizational, and regulatory dimensions. The degree prepared me to evaluate security risks, design and assess security architectures, support governance and compliance initiatives, improve identity and access controls, analyze vulnerabilities, and contribute to the protection of enterprise systems, cloud environments, applications, data, and digital identities.
The combination of technical cybersecurity expertise and privacy-focused education provided a strong basis for roles in cybersecurity architecture, cloud security, information security governance, identity and access management, risk management, security engineering, and enterprise IT architecture.
Sandy Creek High School
Fachabitur IT, Highschool Abschluss · IT · Tyrone, United States
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Enterprise & Cloud Security Architect
Nearby freelancers
Professionals working in or nearby Dorsten, Germany
