Skip to main content
Top expert badge
Recommended expert
Profile header background

Cedric Bergermann-Bißlich-IT / Enterprise Architect (Security & Regulatory)

Cedric Bergermann-Bißlich - IT / Enterprise Architect (Security & Regulatory) - profile avatar
Profile header overlay
Dorsten, Germany

Check rate

Experience

May 2026 - Present
Stuttgart, Germany
Hybrid

Enterprise & Cloud Security Architect

---

Position Summary
Enterprise & Cloud Security Architect at ---
Industries
Insurance
Business Areas
Information Technology
Strategy

Enterprise & Cloud Security Architect supporting the modernization of the SDK application landscape as part of the KVNeo transformation program. Responsible for enterprise architecture, cloud governance, security architecture, and the definition of technical standards for strategic business applications.

Key responsibilities include architecture governance, target architecture development, cloud and integration architecture, security-by-design, and the translation of regulatory requirements into sustainable technical solutions across multiple business domains.

Responsibilities and achievements

  • Designed and reviewed target architectures for strategic insurance applications and enterprise services.
  • Developed architecture documentation based on Arc42 and Architecture Decision Records (ADRs).
  • Defined governance models, architecture principles, and technical guidelines for cross-domain initiatives.
  • Supported the modernization of archive, document management, and output management platforms.
  • Designed integration architectures using REST APIs and event-driven communication patterns.
  • Led architecture discussions with enterprise architects, development teams, product owners, and business stakeholders.
  • Translated regulatory requirements such as DORA and ISO/IEC 27001 into practical architecture decisions.
  • Designed security concepts covering Identity & Access Management, authorization, authentication, auditability, and logging.
  • Supported SIEM integration, security monitoring, and enterprise logging concepts.
  • Evaluated technical risks, technical debt, and architecture improvements while providing decision papers for architecture boards.
  • Established architecture governance processes and contributed to enterprise-wide transformation initiatives.
  • Supported cloud governance activities and the definition of secure cloud architecture standards.
  • Facilitated architecture workshops and coordinated cross-functional stakeholders across business and IT.

Technologies & Methods Microsoft Azure • Arc42 • Architecture Decision Records (ADR) • REST APIs • Event-Driven Architecture • Microsoft Entra ID • Active Directory • IAM • SIEM • Cloud Governance • Enterprise Architecture • Security Architecture • Azure API Management • Jira • Confluence • Draw.io • DORA • ISO/IEC 27001 • Agile • Scrum

Jan 2026 - Present
Zürich, Switzerland

Cyber Security Architect

UBS

Position Summary
Cyber Security Architect at UBS
Industries
Banking and Finance
Business Areas
Audit
Information Technology
Operations
  • Translation of regulatory requirements (especially DORA) into architecture and operational processes
  • Further development of governance structures in a regulatory environment
  • Assessment of IT and integration architectures from a security and compliance perspective
  • Support and assistance with audits
  • Coordination of external service providers in a security context
Oct 2024 - Nov 2025
Essen, Germany

Cyber Security Architect

Nationalbank AG

Position Summary
Cyber Security Architect at Nationalbank AG
Industries
Banking and Finance
Business Areas
Audit
Information Technology
Project Management
  • Functional leadership in the area of cyber security and coordination of cross-functional security initiatives
  • Overall responsibility for implementing and ensuring DORA compliance
  • Development and establishment of an ICT reference architecture taking regulatory requirements into account
  • Support and successful execution of audits (including BaFin, SWIFT, SEPA)
  • Assessment and further development of IT and integration architectures from a security and compliance perspective
  • Definition of security requirements for systems, interfaces, and data flows
  • Management and coordination of cyber security projects in complex IT landscapes
  • Alignment between IT, architecture, business units, and compliance
  • Coordination of external service providers in the context of cyber security and regulatory requirements
  • Building and further developing security governance structures and audit-ready documentation
Jul 2022 - Present
Germany

Freiberuflicher Cyber Security Architekt / Consultant

Selbstständig

Position Summary
Freiberuflicher Cyber Security Architekt / Consultant at Selbstständig
Industries
Banking and Finance
Business Areas
Information Technology
Project Management
  • Design and further development of security and target architectures in complex, highly regulated IT landscapes (banks, insurance companies)
  • Detailed analysis of system, application, and integration landscapes to identify security-critical dependencies and risks
  • Conducting gap analyses between regulatory requirements (DORA, ISO 27001, BAIT) and existing architectures, including deriving concrete measures
  • Translating regulatory requirements into concrete architecture principles, security requirements, and technical guardrails
  • Building and establishing governance structures including policies, control mechanisms, and audit-ready documentation
  • Creating target visions, architecture concepts, and decision foundations for management and architecture committees
  • Functional leadership of transformation and integration projects in complex system landscapes
  • Close coordination with IT, enterprise architecture, compliance, internal audit, and business units
Jul 2022 - Oct 2024
Greven, Germany

Teamleiter Cyber Security / Networking

Finanz Informatik

Position Summary
Teamleiter Cyber Security / Networking at Finanz Informatik
Industries
Banking and Finance
Information Technology
Business Areas
Audit
Information Technology
Operations
Project Management
  • Functional and disciplinary leadership of a team in cyber security and network architecture
  • Coordination and execution of integration and migration projects in complex IT and data center environments
  • Planning and establishment of security architectures and zero-trust approaches
  • Ensuring regulatory requirements and supporting audits (including BaFin, TSI)
  • Responsibility for the secure operation and further development of critical infrastructure (data center, 3000+ systems)
  • Coordination between IT operations, architecture, business units, and external service providers
  • Coordination of external service providers in the context of infrastructure and security projects
  • Building and further developing security standards, processes, and documentation
Mar 2022 - Jun 2022
Greven, Germany

Security Engineer

Finanz Informatik

Position Summary
Security Engineer at Finanz Informatik
Industries
Banking and Finance
Information Technology
Business Areas
Audit
Information Technology
  • Support in the operation and protection of data center and network infrastructures in a banking environment
  • Help with implementing IT security measures and meeting regulatory requirements
  • Support for integration and migration projects in complex system landscapes
  • Analysis and resolution of issues in security-critical IT environments
  • Collaboration with internal teams and external service providers
  • Support in preparing and carrying out audits
Jan 2021 - Nov 2021
Borken, Germany

Security Consulting / Support

Netgo Borken

Position Summary
Security Consulting / Support at Netgo Borken
Industries
Information Technology
Business Areas
Audit
Information Technology
Quality Assurance
  • Network technology / IT security department
  • Security consulting
  • Supporting audits at customer sites
  • Ensuring ISO 27001 certifications for customers
  • Administration of customer servers
  • Remote support for the entire environment
  • Server migrations, etc.
Mar 2019 - Dec 2020
Berlin, Germany

IT Sales, Consulting and Project Management

LT Memory Berlin

Position Summary
IT Sales, Consulting and Project Management at LT Memory Berlin
Industries
Banking and Finance
Information Technology
Tourism
Business Areas
Information Technology
Project Management
Sales
  • Sales, consulting and project management for large customers (2500+ employees)
  • Planning and carrying out large migrations, including for hotels and banks
  • Managing various service providers (IT/building technology)
Aug 2017 - Mar 2019
Geilenkirchen, Germany

1st Lt US Air Force

United States Air Force

Position Summary
1st Lt US Air Force at United States Air Force
Industries
Aerospace and Defense
Business Areas
Audit
Information Technology
  • Stationed at the NATO Airbase in Geilenkirchen (Aachen)
  • Ensuring all required DOD policies and certifications
  • Monitoring service providers
  • Consulting and auditing at the US Consulate in Frankfurt
  • Support and assurance of IT operations for the entire base
  • Providing private households with DSL and mobile services
  • Advising various internal departments on IT security

Industry Experience

See where this freelancer has spent most of their professional time.

Experienced in Banking and Finance, Information Technology, Tourism, and Aerospace and Defense.

Banking and Finance
Information Technology
Tourism
Aerospace and Defense
Profile match chart

Business Area Experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Audit, Project Management, Operations, Sales, and Quality Assurance.

Information Technology
Audit
Project Management
Operations
Sales
Quality Assurance
Profile match chart

Summary

Enterprise & Security Architect with a focus on enterprise architecture, cloud governance, and information security in highly regulated corporate environments. Experience in developing target architectures, governance models, and security concepts, as well as supporting complex transformation initiatives.

Specialized in translating regulatory requirements – especially DORA, ISO/IEC 27001, BAIT, and GDPR – into practical architecture principles, technical guardrails, and sustainable operating models. Strong experience in cloud architecture, identity & access management, privileged access management, API and integration architectures, and security governance.

Regular collaboration with business units, IT, information security, and management to develop solid architecture decisions, technical strategies, and decision foundations. Experience in creating and maintaining architecture documentation (Arc42, ADRs), facilitating architecture workshops, and coordinating cross-functional architecture topics.

Pragmatic, structured, and solution-oriented way of working with the goal of developing secure, scalable, and cost-effective IT architectures that meet both regulatory requirements and the strategic goals of the company.

Skills

Core Skills

  • Enterprise Architecture
  • Cloud Architecture
  • Cyber Security
  • Information Security
  • Solution Architecture
  • It Architecture
  • Security Architecture
  • Cloud Governance
  • It Governance
  • Cyber Risk Management

Cyber Security

  • Identity & Access Management (Iam)
  • Privileged Access Management (Pam)
  • Zero Trust Architecture
  • Security By Design
  • Secure Software Development
  • Threat Modeling
  • Security Assessments
  • Vulnerability Management
  • Security Hardening
  • Network Security
  • Endpoint Security
  • Application Security
  • Cloud Security
  • Data Protection
  • Cyber Resilience

Governance / Compliance

  • Dora
  • Iso/Iec 27001
  • Nis2
  • Gdpr / Dsgvo
  • Bsi It-Grundschutz
  • Tisax
  • Risk Management
  • Security Policies
  • Information Security Management (Isms)
  • Audit Preparation
  • Compliance Management

Identity & Access Management

  • Microsoft Entra Id (Azure Ad)
  • Active Directory
  • Sailpoint Identityiq
  • Okta
  • Beyondtrust Pra
  • Beyondtrust Rs
  • Multi-Factor Authentication (Mfa)
  • Single Sign-On (Sso)
  • Federation
  • Role Based Access Control (Rbac)

Cloud & Microsoft

  • Microsoft Azure
  • Azure Api Management
  • Microsoft Fabric
  • Azure Governance
  • Hybrid Cloud
  • Cloud Migration
  • Cloud Security
  • Microsoft 365 Security

Integration & Architecture

  • Rest Apis
  • Api Design
  • Event-Driven Architecture
  • Microservices
  • Integration Architecture
  • Arc42
  • Architecture Decision Records (Adr)
  • Technical Documentation
  • System Integration

Operations

  • Siem
  • Logging
  • Monitoring
  • Observability
  • High Availability
  • Disaster Recovery
  • Business Continuity
  • Incident Response

Networking

  • Tcp/Ip
  • Dns
  • Vpn
  • Firewalls
  • Network Segmentation

Infrastructure

  • Windows Server
  • Linux
  • Vmware
  • Virtualization

Security Tools

  • Beyondtrust Pra
  • Beyondtrust Rs
  • Sailpoint
  • Okta
  • Tenable Nessus
  • Fortinet Fortimanager
  • Check Point
  • Microsoft Defender

Project & Methods

  • Agile
  • Scrum
  • Kanban
  • Jira
  • Confluence
  • Azure Devops
  • Technical Leadership
  • Stakeholder Management
  • Requirements Engineering
  • Workshop Facilitation

Programming / Scripting

  • Powershell
  • Bash
  • Sql
  • Json
  • Yaml
  • Xml

Top-20 Keywords FüR Maximale Auffindbarkeit Auf Fratch

  • Enterprise Architecture
  • Cloud Architecture
  • Solution Architecture
  • Security Architecture
  • Cyber Security
  • Information Security
  • Microsoft Azure
  • Cloud Governance
  • Dora
  • Iso 27001
  • Arc42
  • Siem
  • Iam
  • Pam
  • Entra Id
  • Active Directory
  • Beyondtrust
  • Sailpoint
  • Okta
  • Api Management

Languages

German
Native
English
Native

Education

Aug 2021 - Sep 2024

GA Tech USA

University · Cyber security / Cyber Privacy · 3,6

Bachelor of Science in Cyber Security and Cyber Privacy Georgia, USA | August 2021 – September 2024

The Bachelor’s degree program in Cyber Security and Cyber Privacy provided a broad and practice-oriented education in the protection of information, IT systems, networks, applications, and digital identities. The program combined technical cybersecurity disciplines with privacy, governance, risk management, and regulatory requirements, creating a strong foundation for working in complex enterprise and cloud environments.

The curriculum covered the fundamental principles of information security, including confidentiality, integrity, availability, authentication, authorization, accountability, and non-repudiation. A particular focus was placed on understanding how modern cyber threats affect organizations and how technical, organizational, and procedural security measures can be used to reduce risk.

Key areas of study included network and infrastructure security, operating system security, secure system administration, cloud security, application security, identity and access management, cryptography, vulnerability management, incident response, digital forensics, ethical hacking, and security monitoring. The program also addressed the design and evaluation of secure IT architectures, including the implementation of layered security controls and defense-in-depth concepts.

Network security topics included common network protocols, segmentation, firewalls, intrusion detection and prevention systems, virtual private networks, secure remote access, wireless security, and the identification of network-based attacks. The program provided an understanding of how weaknesses in network design, configuration, and access control can be exploited and how these risks can be mitigated through appropriate technical safeguards.

Application and software security were also important components of the degree. This included secure software development principles, common application vulnerabilities, threat modeling, secure coding practices, authentication and authorization mechanisms, input validation, session management, and the protection of application interfaces. Security risks affecting web applications, APIs, databases, and distributed systems were examined from both an attacker’s and a defender’s perspective.

The cloud security component focused on the security challenges associated with modern cloud-based and hybrid IT environments. Topics included shared responsibility models, secure cloud architecture, identity-based access control, encryption, key management, logging, monitoring, secure configuration, and the protection of cloud workloads and data. The program also addressed the importance of governance and standardized security controls when operating services across multiple platforms and environments.

Identity and access management formed another major area of study. The curriculum covered user authentication, authorization models, role-based and attribute-based access control, privileged access, identity lifecycle management, multi-factor authentication, federation, single sign-on, and the principle of least privilege. Particular attention was given to the risks associated with excessive permissions, shared accounts, privileged identities, and insufficient monitoring of access activities.

Cryptography was studied as a fundamental security technology. The program included symmetric and asymmetric encryption, hashing, digital signatures, certificates, public key infrastructures, secure key management, and the practical use of cryptographic mechanisms to protect data both at rest and in transit. Students learned not only how cryptographic techniques work, but also how poor implementation or inadequate key management can undermine otherwise strong security controls.

Cybersecurity risk management and governance were integrated throughout the program. This included identifying assets, threats, vulnerabilities, and potential business impacts; evaluating risks; selecting appropriate controls; and documenting residual risks. Students developed an understanding of how cybersecurity decisions must be aligned with business objectives, legal obligations, operational requirements, and organizational risk appetite.

The Cyber Privacy component focused on the responsible and lawful processing of personal and sensitive information. Areas of study included privacy principles, data minimization, purpose limitation, transparency, consent, retention, access control, privacy by design, privacy by default, and the secure handling of personal data throughout its lifecycle. The program also considered the relationship between privacy, cybersecurity, compliance, ethics, and organizational accountability.

Further topics included security policies, standards, procedures, audits, control frameworks, business continuity, disaster recovery, third-party risk, and security awareness. This provided an understanding of cybersecurity as an organizational responsibility that extends beyond purely technical controls. The course content emphasized the importance of combining people, processes, governance, and technology to establish an effective and sustainable security posture.

Threat analysis and ethical hacking exercises helped develop a practical understanding of common attack methods. These included reconnaissance, social engineering, credential attacks, privilege escalation, exploitation of vulnerabilities, lateral movement, persistence, data exfiltration, and attacks against applications and network services. The objective was to understand attacker behavior in order to design more effective preventive, detective, and responsive security measures.

Vulnerability management topics included asset identification, vulnerability scanning, assessment of technical findings, prioritization based on risk, remediation planning, and verification of implemented measures. Students learned that vulnerability severity alone is not sufficient for effective prioritization and that business criticality, exposure, exploitability, compensating controls, and potential impact must also be considered.

Incident response and digital forensics covered the identification, analysis, containment, eradication, and recovery phases of security incidents. The program addressed the importance of logging, evidence preservation, documentation, communication, and post-incident analysis. Students gained an understanding of how technical evidence can be collected and evaluated while maintaining integrity and traceability.

Security monitoring and detection topics included the collection and analysis of logs, event correlation, identification of suspicious behavior, security information and event management, alert handling, and the development of appropriate detection and response processes. The course content highlighted the importance of visibility, traceability, and reliable audit information in modern IT environments.

The program used practical exercises, laboratories, case studies, research assignments, and project-based work to connect theoretical cybersecurity concepts with real-world scenarios. These activities required the analysis of security problems, evaluation of alternative solutions, documentation of risks and recommendations, and presentation of findings to both technical and non-technical audiences.

Throughout the degree, emphasis was placed on structured analytical thinking, independent research, problem-solving, and the ability to assess security requirements from different perspectives. Technical solutions were evaluated not only in terms of security effectiveness, but also with regard to usability, operational feasibility, scalability, cost, compliance, and business impact.

The program also strengthened communication and documentation skills. Students were required to explain complex technical risks in a clear and understandable manner, create structured reports, justify security decisions, and develop recommendations for different stakeholder groups. This included translating technical findings into business-relevant risks and supporting informed decision-making.

By completing the program, I developed a comprehensive understanding of cybersecurity and privacy across technical, organizational, and regulatory dimensions. The degree prepared me to evaluate security risks, design and assess security architectures, support governance and compliance initiatives, improve identity and access controls, analyze vulnerabilities, and contribute to the protection of enterprise systems, cloud environments, applications, data, and digital identities.

The combination of technical cybersecurity expertise and privacy-focused education provided a strong basis for roles in cybersecurity architecture, cloud security, information security governance, identity and access management, risk management, security engineering, and enterprise IT architecture.

Aug 2013 - Jun 2017

Sandy Creek High School

Fachabitur IT, Highschool Abschluss · IT · Tyrone, United States

Statistics

Experience

Total positions 9
Experience in Banking and Finance 6 y
Avg length 1 y 5 m
Longest experience 4 y

Global Experience

Countries worked in 2 (Germany, Switzerland)
Primary country Germany

Expertise

Recent roles Enterprise & Cloud Security Architect, Cyber Security Architect, Freiberuflicher Cyber Security Architekt / Consultant
Main industries Banking and Finance, Information Technology, Tourism
Main business areas Information Technology, Audit, Project Management

Qualifications

Highest degree Bachelor

Profile

Created

Frequently asked questions

Have questions? Find more information here.

Cedric is based in Dorsten, Germany and can operate in on-site, hybrid, and remote work models.
Cedric speaks the following languages: German (Native), English (Native).
Cedric has at least 9 years of experience. During this time, Cedric has worked in at least 8 different roles and for 8 different companies. The average length of individual experience is 1 year and 11 months. Note that Cedric may not have shared all experience and actually has more experience.
Based on recent experience, Cedric would be well-suited for roles such as: Enterprise & Cloud Security Architect, Cyber Security Architect, Freiberuflicher Cyber Security Architekt / Consultant.
Cedric's most recent position is Enterprise & Cloud Security Architect at ---.
In recent years, Cedric has worked for ---, UBS, Nationalbank AG, Selbstständig, and Finanz Informatik.
Cedric is most experienced in industries like Banking and Finance, Information Technology, and Tourism. Cedric also has some experience in Aerospace and Defense and Insurance.
Cedric is most experienced in business areas like Information Technology, Audit, and Project Management. Cedric also has some experience in Operations, Sales, and Quality Assurance.
Cedric has recently worked in industries like Banking and Finance, Information Technology, and Insurance.
Cedric has recently worked in business areas like Information Technology, Audit, and Project Management.
Cedric holds a Bachelor in Cyber security / Cyber Privacy from GA Tech USA.
Cedric is immediately available part-time for suitable projects.
Cedric's rate depends on the specific project requirements. Please use the Meet button on the profile to schedule a meeting and discuss the details.
To hire Cedric, click the Meet button on the profile to request a meeting and discuss your project needs.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Market avg: 720-880 €
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.