Christian Decker - Managing Director and Senior Consultant
Experience
Managing Director and Senior Consultant
business-security (b-sec®) GmbH
- Conceptual consulting for securing business processes
- Consulting on planning and implementation of IT and IT security projects
- Security and policy checks, process optimizations, emergency planning
- Project management and interim management in IT infrastructure and information security
Overview of relevant projects:
- 2025: Consulting on a DLP concept for Digid GmbH.
- 2025: Consulting a client after a cybersecurity attack that compromised the IT infrastructure and where the attacker obtained M365 tenant admin rights. Investigated the IT infrastructure and restored it. Developed recommendations to improve IT security.
- 2025: Continued the projects listed below for Thyssenkrupp Marine Systems and Norddeutsche Landesbank.
- 2024: Created a DNS concept including advice on DNS strategy and technology, DNS design, DNS security, load balancing, reverse lookup zones, and automation. Created a DHCP concept including advice on DHCP design, a central DHCP management system and automation. Advised on operating the mentioned products, the operational processes, and updated IT documentation and IT service descriptions for Thyssenkrupp Marine Systems.
- 2024: As-is analysis and assessment of the network and security infrastructure established by providers in terms of overall architecture including design and components. Designed solution proposals to improve current operations for performance and security maximization as well as complexity reduction. Presented the results to C-level, their causes and possible solutions including required decision templates. Developed a SASE concept based on a zero-trust architecture for Norddeutsche Landesbank.
- 2024: Continued the projects listed below for Atlas GmbH and Deutsche Vermögensberatung AG.
- 2023: Consulting on resolving findings from an IT security assessment of the IT infrastructure, conducting proofs of concept for DDoS protection and digital experience monitoring (DEM) with Zscaler (ZIA, ZPA & ZDX), creating a new security architecture based on zero trust, redesigning a Cisco ISE implementation, and designing a DNS security solution to protect guests and financial advisors for Atlas GmbH / Deutsche Vermögensberatung AG.
- 2023: Continued the projects listed below for Digid GmbH, Vaillant Group GmbH (until 09/2023), Federal Institute for Geosciences and Natural Resources (until 05/2023), and Union Investment IT-Services GmbH (until 07/2023).
- 2022: Created and reviewed whitepapers for infrastructure and security architectures, and planned new network infrastructures for the German Aerospace Center.
- 2022: Developed a concept for the technical and procedural modernization of a disaster recovery plan for United Nations Volunteers.
- 2022: Developed a concept for migrating measurement data to a cloud environment, introduced network access control, and conducted an awareness training for Digid GmbH.
- 2022: Developed a network segmentation concept for DZ Hyp AG.
- 2022: Developed a network segmentation concept for the Federal Employment Agency.
- 2021: Developed a new load balancer architecture concept for Bundeswehr Fuhrparkservices GmbH.
- 2021: Conducted a vulnerability scan and penetration test of a web frontend including analysis and recommendations for remediation considering risk and likelihood for the client ifi GmbH.
- 2021: Consulting, design, and subproject management for implementing a network access control solution (certificate authentication and MAC address bypass) and macro segmentation (area and zone concept based on dynamic device assignment) in office and production IT for Vaillant Group GmbH.
- 2021: Upgraded and optimized LAN and WLAN infrastructure for United Nations Volunteers.
- 2021: Developed a target concept for modernizing the IT security infrastructure including the DMZ (Cisco switches, firewalls, WSA, ESA, SMA), internet connections, admin and management networks, and the wireless LAN, including overseeing implementation for the Federal Institute for Geosciences and Natural Resources.
- 2021: Created a micro-segmentation concept based on Cisco DNA, SGT, and zero trust for Union Investment IT-Services GmbH.
- 2021: Reviewed and updated ISMS level 3 policies and created procedure instructions for Software AG.
- 2021: Project lead for the global tech refresh project Meraki WLAN 2.0, coordinated the outsourcing of LAN/WLAN infrastructure to a managed service provider, and created a WLAN concept for automated guided vehicles for Heraeus Infosystems GmbH.
- 2021: Project management and technical support for the 'Transition of SIEM/SOC Services' project migrating a client to a shared environment, and took on the interim role of Head of Security Operations at Datagroup SE.
- 2021: Conducted a workshop for the future implementation of mobile device management for Allgeier Experts Go GmbH.
- 2021: Subproject management for implementing a firewall rule management tool and recertifying NAC endpoints based on 802.1x and MAB for Union Investment IT-Services GmbH.
- 2020: Developed a network segmentation concept for two data centers based on Cisco and VMware for Aareon AG.
- Recorded and analyzed the current network architecture including project initiation.
- Designed a micro-segmentation concept in the data center and access network.
- 2020: Infrastructure and security architecture audit for Stuttgarter Versicherung AG.
- Analyzed the IT infrastructure and security architecture regarding network and security component configurations. Also reviewed contracts, process documents, and manuals for completeness. Developed recommendations to improve the stability and operation of the infrastructure. Created a network segmentation concept and led the project to implement the measures from the audit.
- 2020: Consulting on setting up an ISMS-light for Josera foodforplanet GmbH & Co. KG.
- 2020: Security architecture consulting for Datagroup SE.
- Developed a future IT infrastructure and IT security architecture.
- Documented the current IT architecture of all 23 entities.
- Made recommendations to optimize the IT infrastructure and drafted a comparison of a traditional perimeter security concept versus a zero trust model.
- Created a security zone concept.
- Designed an IT infrastructure architecture in coordination with all entities.
- 2018 - 2019: Stream lead in the cybersecurity program at Deutsche Lufthansa AG.
- Responsible for designing and implementing 9 projects in IT security infrastructure and user access management, as well as managing project managers and experts.
- Project area: Network segmentation and access control.
- Project area: Security architecture.
- Project area: Privileged, identity & access management.
- Project area: Simplify user authentication (MFA).
- Project area: Mobile & endpoint security.
- Project area: OT security.
- Project area: E-enabled aircraft.
- 2018: Security architecture consulting for Deutsche Lufthansa AG.
- Project management for the development, evaluation, and management of the company-wide information security architecture.
- Developed a security strategy and a roadmap to align the security architecture with the zero trust model.
- Evaluated market security solutions, services, and tools.
- Defined requirements for RFPs and assessed proposals.
- Developed, maintained, and monitored security architecture artifacts.
- Conducted security assessments of existing and new IT systems and security services.
- 2018: ISMS consulting for GLS IT Services GmbH.
- Advised on implementing and initially operating an ISMS based on ISO27001.
- Audited the IT environments of GLS country subsidiaries.
- Analyzed and assessed IT security risks and derived necessary measures.
- Developed solution proposals in coordination with relevant stakeholders.
- Managed the project and handed over the ISMS to operations.
- 2016 - 2018: Security pre-sales consultant for Cisco Systems GmbH.
- Provided nationwide strategic and conceptual consulting to major enterprise and financial and insurance clients on Cisco and Meraki security products and services such as Firepower, WSA, ESA, Stealthwatch, and ISE.
- 2017 - 2018: Designed and implemented an ISMS for Verivox GmbH.
- Conducted various BIAs and gap analyses.
- Developed security policies based on ISO 2700x.
- Served as interim information security officer.
- 2017: Developed an emergency concept for VPV Lebensversicherungs-AG.
- Reviewed and updated the IT emergency manual.
- 2016: Consulting and project management for designing cloud & hosting services for Vodafone Group Services GmbH.
- Analyzed and optimized the sell-build-run process.
- Created detailed level designs for cloud products.
Freelance IT Infrastructure and IT Security Consultant
christiandecker.net
- 2015 - 2016: Consulting and project management for building an IT security demand management for corporate security at Vodafone Deutschland GmbH.
- Supported the information security officer.
- Proof-of-concept of a WAF integrated with SIEM.
- Security check of the top 10 applications.
- Security review of a cloud solution for an internal DMS.
- Security audit of a data center coupling.
- Migration of the SOC from Kabel Deutschland to Vodafone.
- Defined security parameters for a VDI environment.
- 2015: Created a telephony security concept for VPV Lebensversicherungs-AG.
- 2014 - 2015: Consulting and various IT security project management for corporate security at Kabel Deutschland Vertrieb und Service GmbH.
- Implemented NAC in the corporate network with 4000 endpoints based on Cisco ISE and 802.1x in preparation for TrustSec microsegmentation.
- Implemented a firewall policy tool based on Tufin.
- Optimized processes and SIEM integrations based on ArcSight.
- Implemented a vulnerability scanner based on Tripwire.
- Implemented mobile device management based on SAP Afaria.
- Reviewed and aligned the security policies of both companies.
Head of Infrastructure & Security and Service Desk / Information Security Officer
Commerz Real AG
- Updated Windows Server 2003 to 2008.
- New employee evaluation system.
- Project management for project managers 1 – 4.
- Visualizing and presenting.
Head of Technical Department
Com-Sys Gesellschaft für Netzwerktechnik mbH
- Compared IT security criteria (ITIL, BS2700x).
- Realtech network management and Funkwerk UTM appliance.
Senior Support Engineer
Com-Sys Gesellschaft für Netzwerktechnik mbH
- Avaya advanced 1st and 3rd level support.
- Experience with Enterasys PEN, IDS, IDS-Advanced.
- Experience with Kobil SmartKey, SmartToken, SecOvid, and mIDentity.
- Varysys Packetalarm administrator.
- Experience with Enterasys routing, VPN, UPN, and IDS.
Team Leader IP Network Management
Deutsche Telekom AG
- Team leadership in IP network management using Cisco technologies (ICND, BSCN, BCMSN, BCRAN, CVOICE, CIT, CID, CATM, AOSPF, ABGP, SNAM, CCIE-VB).
Network Planning and Design Staff
Fraport AG
- Airport management.
- Cisco router configurations on IOS-based systems.
- Conflict management, moderating and presenting.
Network Operations Center Staff
Fraport AG
- NOC-Operation-Center Trainee.
- UNIX, migration to Solaris.
- Federal Data Protection Act.
- Basics of Ethernet / Token Ring / ATM.
- Sniffer Network Analyzer.
Network Installation Service Staff
Fraport AG
Vocational training as a communications electronics technician specializing in telecommunications
Fraport AG
- Bosch Integral 22x/E.
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Information Technology, Professional Services, Telecommunication, Banking and Finance, Real Estate, and Transportation.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Customer Service, and Operations.
Summary
- Conceptual consulting for securing business processes
- Consulting on planning and implementation of IT and IT security projects
- Security and policy checks, process optimizations, emergency planning
- Project management and interim management in IT infrastructure and information security
Overview of relevant projects:
- 2025: Consulting on a DLP concept for Digid GmbH.
- 2025: Consulting a client after a cybersecurity attack that compromised the IT infrastructure and where the attacker obtained M365 tenant admin rights. Investigated the IT infrastructure and restored it. Developed recommendations to improve IT security.
- 2025: Continued the projects listed below for Thyssenkrupp Marine Systems and Norddeutsche Landesbank.
- 2024: Created a DNS concept including advice on DNS strategy and technology, DNS design, DNS security, load balancing, reverse lookup zones, and automation. Created a DHCP concept including advice on DHCP design, a central DHCP management system and automation. Advised on operating the mentioned products, the operational processes, and updated IT documentation and IT service descriptions for Thyssenkrupp Marine Systems.
- 2024: As-is analysis and assessment of the network and security infrastructure established by providers in terms of overall architecture including design and components. Designed solution proposals to improve current operations for performance and security maximization as well as complexity reduction. Presented the results to C-level, their causes and possible solutions including required decision templates. Developed a SASE concept based on a zero-trust architecture for Norddeutsche Landesbank.
- 2024: Continued the projects listed below for Atlas GmbH and Deutsche Vermögensberatung AG.
- 2023: Consulting on resolving findings from an IT security assessment of the IT infrastructure, conducting proofs of concept for DDoS protection and digital experience monitoring (DEM) with Zscaler (ZIA, ZPA & ZDX), creating a new security architecture based on zero trust, redesigning a Cisco ISE implementation, and designing a DNS security solution to protect guests and financial advisors for Atlas GmbH / Deutsche Vermögensberatung AG.
- 2023: Continued the projects listed below for Digid GmbH, Vaillant Group GmbH (until 09/2023), Federal Institute for Geosciences and Natural Resources (until 05/2023), and Union Investment IT-Services GmbH (until 07/2023).
- 2022: Created and reviewed whitepapers for infrastructure and security architectures, and planned new network infrastructures for the German Aerospace Center.
- 2022: Developed a concept for the technical and procedural modernization of a disaster recovery plan for United Nations Volunteers.
- 2022: Developed a concept for migrating measurement data to a cloud environment, introduced network access control, and conducted an awareness training for Digid GmbH.
- 2022: Developed a network segmentation concept for DZ Hyp AG.
- 2022: Developed a network segmentation concept for the Federal Employment Agency.
- 2021: Developed a new load balancer architecture concept for Bundeswehr Fuhrparkservices GmbH.
- 2021: Conducted a vulnerability scan and penetration test of a web frontend including analysis and recommendations for remediation considering risk and likelihood for the client ifi GmbH.
- 2021: Consulting, design, and subproject management for implementing a network access control solution (certificate authentication and MAC address bypass) and macro segmentation (area and zone concept based on dynamic device assignment) in office and production IT for Vaillant Group GmbH.
- 2021: Upgraded and optimized LAN and WLAN infrastructure for United Nations Volunteers.
- 2021: Developed a target concept for modernizing the IT security infrastructure including the DMZ (Cisco switches, firewalls, WSA, ESA, SMA), internet connections, admin and management networks, and the wireless LAN, including overseeing implementation for the Federal Institute for Geosciences and Natural Resources.
- 2021: Created a micro-segmentation concept based on Cisco DNA, SGT, and zero trust for Union Investment IT-Services GmbH.
- 2021: Reviewed and updated ISMS level 3 policies and created procedure instructions for Software AG.
- 2021: Project lead for the global tech refresh project Meraki WLAN 2.0, coordinated the outsourcing of LAN/WLAN infrastructure to a managed service provider, and created a WLAN concept for automated guided vehicles for Heraeus Infosystems GmbH.
- 2021: Project management and technical support for the 'Transition of SIEM/SOC Services' project migrating a client to a shared environment, and took on the interim role of Head of Security Operations at Datagroup SE.
- 2021: Conducted a workshop for the future implementation of mobile device management for Allgeier Experts Go GmbH.
- 2021: Subproject management for implementing a firewall rule management tool and recertifying NAC endpoints based on 802.1x and MAB for Union Investment IT-Services GmbH.
- 2020: Developed a network segmentation concept for two data centers based on Cisco and VMware for Aareon AG.
- Recorded and analyzed the current network architecture including project initiation.
- Designed a micro-segmentation concept in the data center and access network.
- 2020: Infrastructure and security architecture audit for Stuttgarter Versicherung AG.
- Analyzed the IT infrastructure and security architecture regarding network and security component configurations. Also reviewed contracts, process documents, and manuals for completeness. Developed recommendations to improve the stability and operation of the infrastructure. Created a network segmentation concept and led the project to implement the measures from the audit.
- 2020: Consulting on setting up an ISMS-light for Josera foodforplanet GmbH & Co. KG.
- 2020: Security architecture consulting for Datagroup SE.
- Developed a future IT infrastructure and IT security architecture.
- Documented the current IT architecture of all 23 entities.
- Made recommendations to optimize the IT infrastructure and drafted a comparison of a traditional perimeter security concept versus a zero trust model.
- Created a security zone concept.
- Designed an IT infrastructure architecture in coordination with all entities.
- 2018 - 2019: Stream lead in the cybersecurity program at Deutsche Lufthansa AG.
- Responsible for designing and implementing 9 projects in IT security infrastructure and user access management, as well as managing project managers and experts.
- Project area: Network segmentation and access control.
- Project area: Security architecture.
- Project area: Privileged, identity & access management.
- Project area: Simplify user authentication (MFA).
- Project area: Mobile & endpoint security.
- Project area: OT security.
- Project area: E-enabled aircraft.
- 2018: Security architecture consulting for Deutsche Lufthansa AG.
- Project management for the development, evaluation, and management of the company-wide information security architecture.
- Developed a security strategy and a roadmap to align the security architecture with the zero trust model.
- Evaluated market security solutions, services, and tools.
- Defined requirements for RFPs and assessed proposals.
- Developed, maintained, and monitored security architecture artifacts.
- Conducted security assessments of existing and new IT systems and security services.
- 2018: ISMS consulting for GLS IT Services GmbH.
- Advised on implementing and initially operating an ISMS based on ISO27001.
- Audited the IT environments of GLS country subsidiaries.
- Analyzed and assessed IT security risks and derived necessary measures.
- Developed solution proposals in coordination with relevant stakeholders.
- Managed the project and handed over the ISMS to operations.
- 2016 - 2018: Security pre-sales consultant for Cisco Systems GmbH.
- Provided nationwide strategic and conceptual consulting to major enterprise and financial and insurance clients on Cisco and Meraki security products and services such as Firepower, WSA, ESA, Stealthwatch, and ISE.
- 2017 - 2018: Designed and implemented an ISMS for Verivox GmbH.
- Conducted various BIAs and gap analyses.
- Developed security policies based on ISO 2700x.
- Served as interim information security officer.
- 2017: Developed an emergency concept for VPV Lebensversicherungs-AG.
- Reviewed and updated the IT emergency manual.
- 2016: Consulting and project management for designing cloud & hosting services for Vodafone Group Services GmbH.
- Analyzed and optimized the sell-build-run process.
- Created detailed level designs for cloud products.
Skills
Operating Systems
- Macos, Ios, Windows, Linux, Unix
Software
- Ms Office Suite Including Outlook, Project, Visio And Jira
Vendors
- Cisco, Meraki, Prtg, Zscaler, Netskope, Aruba, Cyberark, Arcsight, Ping, Beta Systems, Okta, Rsa, Apiida, Duo, Extreme Networks, Juniper, Kobil, Astaro, Mobileiron, Airwatch, Fortinet, Dell, Hp, Radware
Domains
- Security Architecture, Secure Access Service Edge (Sase), Data Loss Prevention (Dlp), Privileged Access Management (Pam), Identity Management (Idm), Identity And Access Management (Iam), Multi-factor Authentication (Mfa, 2fa), Single Sign-on (Sso), Web Application Firewall (Waf), Mobile Device Management (Mdm), Enterprise Mobility Management (Emm), Ddos Protection, Endpoint Security, Network Security, Dns Security, Security Information And Event Management (Siem), Security Operations Center (Soc), Cyber Defence Center (Cdc), Computer Emergency Response Team (Cert), Network Operations Center (Noc), Network Access Control (Nac), Operational Technology (Ot), Internet Of Things (Iot), Macro And Micro Segmentation, Cloud Security, Access Management (Aaa), Vulnerability Management, Patch Management, Information Security Management Systems (Isms), Intrusion Detection And Prevention (Ids/ips), Network Security Management (Nsm), Bsi, Gdpr, Itil, Iso2700x, Critical Infrastructures (Kritis), Request For Information (Rfi), Request For Proposal (Rfp), Vendor Evaluation, Market Analysis, Anti-virus, Advanced Threat Protection, Advanced Malware Protection (Amp), Governance, Risk And Compliance (Grc), Audits And Certifications, Cryptography, Penetration Testing, Configuration Management, Change Management, Incident Management, Business Continuity Management (Bcm), Public Key Infrastructure (Pki)
Languages
Education
Fraport AG
Vocational training as a communications electronics technician, specialization telecommunications · Communications Electronics Technician, Specialization Telecommunications · Frankfurt, Germany
Certifications & licenses
Cisco AMP And Threat Grid Integration With Cisco Email Security
business-security GmbH
Cisco AMP For Endpoints Fundamentals
business-security GmbH
Cisco Advanced Threat Security Domain Fire Jumper Academy
business-security GmbH
Cisco CSS Stealthwatch And SOVA
business-security GmbH
Cisco Cloud, Web And Email Security Domain Fire Jumper Academy
business-security GmbH
Cisco Cyber Security Specialist Stage I Exam
business-security GmbH
Cisco Network Security Domain Fire Jumper Academy
business-security GmbH
Cisco Ransomware Defense Solution
business-security GmbH
Cisco Sales Compliance Phase 2- Compliant Alternatives To Off-book Funds Assessment
business-security GmbH
Cisco Threat Grid Fundamentals
business-security GmbH
Cisco Umbrella Security Sales Training
business-security GmbH
Cisco Umbrella Security Technical Training
business-security GmbH
Cisco Understanding The Umbrella Proposition - Distributor Assessment
business-security GmbH
Cisco Visibility And Enforcement Security Domain Fire Jumper Academy
business-security GmbH
Cisco CMNA Meraki training with certification
christiandecker.net
Cisco Cisco Talos - The Team That Keeps Us Cybersafe
christiandecker.net
Cisco Cisco Tetration Analytics
christiandecker.net
Cisco Compliance: Risk Assessment
christiandecker.net
Cisco Get Some Cisco Spark In Your Life!
christiandecker.net
Cisco My Business Reports Test 1
christiandecker.net
Cisco Power Update - Data And Analytics
christiandecker.net
Cisco Safety Induction Training V2
christiandecker.net
Cisco Sales Compliance Training Assessment
christiandecker.net
Cisco Security Baseline Assessment
christiandecker.net
Cisco The Road To Success With Cloud Networking
christiandecker.net
CISSP training with certification
Commerz Real AG
Astaro Certified Administrator, Engineer, Expert and Sales Expert V7
Com-Sys Gesellschaft für Netzwerktechnik mbH
Enterasys PEN, IDS, IDS-Advanced with certification
Com-Sys Gesellschaft für Netzwerktechnik mbH
Enterasys Routing, VPN, UPN and IDS with certification
Com-Sys Gesellschaft für Netzwerktechnik mbH
Kobil SmartKey, SmartToken, SecOvid and mIDentity with certification
Com-Sys Gesellschaft für Netzwerktechnik mbH
Varysys Packetalarm Administrator
Com-Sys Gesellschaft für Netzwerktechnik mbH
CISCO: ICND, BSCN, BCMSN, BCRAN, CVOICE, CIT, CID, CATM, AOSPF, ABGP, SNAM and CCIE-VB with certification
Deutsche Telekom AG
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Christian based?
What languages does Christian speak?
How many years of experience does Christian have?
What roles would Christian be best suited for?
What is Christian's latest experience?
What companies has Christian worked for in recent years?
Which industries is Christian most experienced in?
Which business areas is Christian most experienced in?
Which industries has Christian worked in recently?
Which business areas has Christian worked in recently?
What is Christian's education?
Does Christian have any certificates?
What is the availability of Christian?
What is the rate of Christian?
How to hire Christian?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Managing Director and Senior Consultant
Nearby freelancers
Professionals working in or nearby Groß-Umstadt, Germany