Dirk Peter-Freelance Cyber Defense Lead & KRITIS/NIS2 Consultant | AI Security Architect
Check rate
Experience
Freelance Cyber Defense Lead & KRITIS/NIS2 Consultant | AI Security Architect
Self-Employed
Situation: Increasing demand for privacy-compliant AI solutions for clients in the KRITIS and mid-market sector that need to analyze sensitive media content (audio, video, documents) without sending data to public cloud LLMs.
Task: Design, deployment, and secure operation of a fully self-hosted AI infrastructure including a custom-built digital management platform for automated media analysis.
Action: Architected and implemented a multi-tier platform on hardened Proxmox infrastructure with frontend (Nuxt 3, Vue 3, TypeScript, Tailwind 4), backend (Laravel 13, PHP 8.4, Sanctum), data storage (PostgreSQL 16, MongoDB 7), caching/queuing (Redis 7, Laravel Queue), AI workers (Python 3.11, Whisper, DeepFace, Librosa), scheduling (Laravel Scheduler/Cron), and local LLMs (Gemma, DeepSeek, Qwen, Mistral, LLaMA, Phi) via OpenWebUI with segmented network access, API hardening, and audit logging following BSI recommendations.
Result: Fully GDPR-compliant, on-premises AI platform with zero data leakage to third parties.
Task: Overall responsibility as an external Head of Cyber Security / CISO-as-a-Service for the design, implementation, and continuous improvement of ISMS according to ISO 27001, BSI IT-Grundschutz, and NIS2.
Action: Built and managed Cyber Defense Centers (CDC) with SOC operations, integrated SIEM solutions (Splunk, Graylog), established risk-based vulnerability management (Qualys, Nessus, OpenVAS), and conducted regular infrastructure, application, and physical penetration tests.
Result: Audit-ready ISMS for multiple clients and a 60% reduction in critical vulnerabilities within 90 days.
Task: Design and execution of NIS2 assessments and operational roll-out plans for KRITIS operators.
Action: Developed an online assessment tool for automated identification of individual weakness profiles, implemented ISMS optimizations, penetration testing, awareness programs, GRC suite deployment, and delivered C-level presentations.
Result: Accelerated the consulting process by 50% and successfully prepared multiple clients for NIS2 compliance.
Task: Incident commander for crisis response, forensics, and business recovery in ransomware attacks and APT campaigns.
Action: Coordinated with state and federal police (LKA, BKA), performed forensic analysis (OSForensics, Wireshark, Kali Linux), executed disaster recovery and BCM strategies, and developed BTC extortion response strategies.
Result: 100% recovery rate within defined RTO windows and sustainable post-incident security architectures.
Action: Planned, built, and operated a hardened multi-VM infrastructure (Proxmox, 15+ VMs) with web and mail servers, Graylog, OPNsense firewalls, CRM/ERP and LLM instances, network segmentation, DDoS mitigation, automated patch management, and backup strategies.
Result: >99.5% uptime over 20+ years and zero compromises.
Action: Designed coordinated phishing campaigns with five levels of difficulty, developed e-trainings and webinars in a PDCA cycle, and led red and blue teams.
Result: Phishing click rate reduced from 35% to under 5% within three campaign cycles.
Head of Cyber Security
RWT Crowe IT Consulting GmbH
- Overall responsibility for building a new cyber security department, recruiting staff, defining security strategy, technical implementation, and client support within a leading auditing and consulting firm.
- Established offensive/red team and defensive/VM team to full operational capacity.
- Implemented client-specific ISMS based on ISO 2700x, BSI IT-Grundschutz, and ISIS-12 with holistic risk vector analysis.
- Set up RBVM processes, technical and physical penetration tests (network, internet-facing web applications).
- Responded to ransomware attacks as a "digital emergency responder," including disaster recovery and negotiations with BTC extortionists.
- Coordinated phishing campaigns in five difficulty levels with e-trainings and face-to-face workshops.
- Result: Successfully built red and blue team capacities, guided multiple clients through ISO audits, and achieved 100% recovery rate in ransomware incidents.
Senior Security Consultant
Daimler AG (TSS)
- Led project and took full responsibility for the comprehensive security concept of the Germersheim Logistics Center (GLC) focusing on the Warehouse Management System (WMS Cores).
- Developed a holistic security concept covering both organizational and technical aspects.
- Evaluated VMaaS/RBVM processes with Qualys and created a PDCA-based risk-based action plan.
- Launched a cross-department security awareness campaign.
- Result: Delivered a prioritized security concept approved for implementation and successfully executed the awareness campaign as a GLC-wide project.
IT Security Consultant – Corporate Audit Clearing
Daimler AG
- Established vulnerability management processes and information classification as part of a corporate audit.
- Implemented a SIEM solution.
- Conducted penetration tests on dedicated VAN subnets to improve network segmentation.
- Result: Closed all audit findings within the clearing timeframe, SIEM solution in operation, and demonstrated improvements in network segmentation and information classification.
Founder & Managing Director
Carmelyon LLC & Breakpoint LLC
- Founded and managed two companies, each achieving $625K in annual revenue.
- Demonstrated entrepreneurial mindset and international experience.
Portal Development / eTraining Portal Project Management
Lewa GmbH
IT Project Management & Product Development
Pixelpentagon / Daimler AG Global Training
- Setup and operation of international CBT/eTraining platforms on Debian-based infrastructure for Daimler Global Training.
- Full project and budget responsibility, including application administration and IT security.
- Provision of 600+ eTraining topics for 7 international markets (CN, BE, DE, IT, ES, NL, FR) in up to 15 languages.
- Reliable platform operation for over 15 years.
Head of Web & Ad Development
100world.Media AG
IT Infrastructure Migration Project Management
Cherry GmbH
HP-UX Server Installation
Hewlett Packard AG / Leasametric GmbH
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Information Technology, Automotive, Professional Services, Manufacturing, Advertising, and Media and Entertainment.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Product Development, Project Management, Operations, Quality Assurance, and Marketing.
Summary
Results-driven cybersecurity executive with 25+ years of experience in building, operating, and strategically securing complex IT and data center infrastructures. Proven track record as Head of Cyber Security, Incident Commander, and KRITIS/NIS2 consultant for medium-sized businesses, corporations, and critical infrastructures (municipal utilities/providers). Implemented ISMS based on ISO 27001 and BSI IT-Grundschutz with demonstrable audit readiness and reduced critical vulnerabilities by an average of 60% within 90 days through risk-based vulnerability management.
Combines rare end-to-end expertise: offensive security (penetration testing, red teaming), defensive data center operations (20+ years of own hardened multi-VM infrastructure with >99.5% uptime), regulatory compliance (NIS2, GDPR, TISAX®), and as a differentiator, AI security & secure LLM deployment (self-hosted LLM infrastructure with custom-built media analysis platform). Achieved 100% recovery rate in all ransomware incidents handled. Pragmatic, hands-on, and comfortable communicating at C-level.
Skills
- Security Leadership & Governance · Security Architecture & Operations
- Ciso-As-A-Service · Isms (Iso 27001, Bsi It-Grundschutz, Isis-12) · Kritis/Nis2/Dora · Grc · Bcm/Drp · Audit Management · C-Level Reporting · Vpn/Remote Access · Cloud Security · Data Center Operations & Migration · Team Building & Leadership · Infrastructure Hardening · Firewall (Opnsense, Iptables) · Ddos Protection
- Threat Detection, Response & Offensive Security · Soc/Cdc Setup · Siem (Splunk, Graylog) · Risk-Based Vulnerability Management · Penetration Testing · Red Team Operations · Incident Response & Digital Forensics · Ransomware Recovery
- Ai Security & Emerging Tech · Secure Llm Deployment · Self-Hosted Ai Infrastructure · Ai Worker Pipelines (Whisper, Deepface) · Prompt Security · Devsecops · Infrastructure-As-Code · Laravel/Nuxt Secure Coding
Languages
Education
FH Furtwangen
Communication Engineering · Furtwangen, Germany
BK Esslingen
University of Applied Sciences Entrance Qualification · Esslingen, Germany
Certifications & licenses
BSI IT-Grundschutz & ISMS (ISO 27001)
Certified Network-Forensic Professional
Certified PC-Forensic Professional
Certified Security Hacker
EU GDPR Data Protection Officer / Auditor (IHK-certified)
TISAX® Foundation & Professional Examination Assessment
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Freelance Cyber Defense Lead & KRITIS/NIS2 Consultant | AI Security Architect
Nearby freelancers
Professionals working in or nearby Stuttgart, Germany
