Skip to main content
Top expert badge
Recommended expert
Profile header background

Enrique Gallardo-Data Security

Enrique Gallardo
Profile header overlay
Hamburg, Germany

Check rate

Experience

Jan 2022 - Feb 2026
Berlin, Germany

Security Architect

Capgemini

Position Summary
Security Architect at Capgemini
Industries
Aerospace and Defense
Energy
Healthcare
Manufacturing
Pharmaceutical
Business Areas
Information Technology
Operations
Strategy

I implemented a Zero-Trust architecture for robust, military-grade maritime container mini data centers based on VMware & Tanzu to support containerized GIS workloads for ground forces. The main focus was on securing communications, workload protection, and data access in contested electronic battle environments affected by jamming, interception, signal manipulation, and constantly changing operational conditions. I designed and architected use cases so that every element of workload, identity, and system could continue to operate independently and securely even in degraded or disrupted scenarios. In parallel, I defined the enterprise and solution security architecture with LeanIX, Bizzdesign, and HOPEX as enterprise architecture, repository, and governance platforms to maintain architecture inventory, relationships, traceability, target pictures, and security governance in complex environments. For the architectural designs, I used Sparx Enterprise Architect to describe formal architecture views, interfaces, trust boundaries, and system architecture in both IT and OT environments. IriusRisk was used for threat modeling of the solution to identify architecture-driven risks, derive security requirements, and detect countermeasures and design gaps directly from the solution models. Risk and compliance management was supported with Archer. Architecture decisions, control gaps, and operational risks were translated into controlled governance and auditable compliance measures. For documentation, collaboration, and visual design, I used Confluence to maintain Architecture Decision Records, Security Blueprints, and workflows. I used Lucidchart and draw.io to create design artifacts tailored to stakeholders. I also defined OT security concepts with support from electrical and mechanical engineers in the areas of oil, vehicle onboard systems, rail, power plants, pharma, gas turbines, and nuclear technology. I created the end-to-end OT security strategy, starting with global policy, developed into standards and procedures, and finally aligned with Bell-LaPadula, Purdue Model, SABSA, TOGAF ADM, CENELEC 50701, IEC 62443, and NIST standards. In addition, I worked with engineering team leads to identify critical KBP assets and place them under protective measures that segmented SCADA, PLC, and HMI assets. I drove collaboration between Security, IT, and OT teams to create standardized workflows and use cases for the OT security solution catalog, while integrating Defense-in-Depth and Zero-Trust principles into operational environments. A key part of my work was integrating multidisciplinary engineering, security, and operations stakeholders into a unified security blueprinting strategy and ensuring that architecture, threat modeling, governance, and documentation were technically strong and operationally practical.

Aug 2019 - Jan 2022
Switzerland

Lead Security Architect

Sopra Steria

Position Summary
Lead Security Architect at Sopra Steria
Industries
Information Technology
Business Areas
Information Technology
Operations
Project Management
Strategy

Governance and control:

  • I used reliable methods to monitor risk appetite and maintain strong controls by reporting metrics to governance and risk management stakeholders.
  • I led digital forensics according to ISO 27035 and delivered root cause analysis reports that helped close systemic gaps.
  • I worked on data governance models and access control policies to ensure that business, regulatory, and architectural requirements were taken into account in the design of security controls, workflows, and processes across Security Operations, Engineering, and Advisory.

Strategy:

  • I developed and maintained functions to deliver a security strategy aligned with business goals, control frameworks, used technologies, milestones, critical paths, risks, regulators, key stakeholders, and customers.
  • I helped define the target state of IT security engineering and align it with regulatory requirements, performance constraints, and vendor limitations.
  • I planned and managed the migration from VPN solutions to Secure Access Service Edge platforms and supported zero-trust onboarding and lifecycle procedures for operations teams.
  • I worked on data governance as well as identity, privileged identity, and privileged user access management, making sure all access scenarios were aligned with new Zero-Trust use cases.
  • I created artifacts such as Statements of Work, HLD and LLD designs, and operating manuals.
  • I performed risk analyses and defined processes based on ISO 27001, CIS 20, BaFin, KRITIS, and MaRisk; all processes were documented and the governance team was supported in implementing the Archer Enterprise GRC tool and its compliance module.

Leadership skills:

  • I trained colleagues and shared knowledge as a subject matter expert for strategic and operational security management.
  • I supervised daily and ad hoc activities and provided mentoring, training, and support to retain cyber talent.
  • I was responsible for the day-to-day business of the security operations team and delivered technical and strategic goals for identifying, assessing, quantifying, reporting, communicating, and reducing threats; I also strengthened threat management, modeling, and vectoring and developed use cases for security monitoring reports, dashboards, and metrics.

Technical goals:

  • I worked across threat intelligence, vulnerability management, and detection and response capabilities and drove automation and orchestration in the threat event landscape.
  • I monitored and analyzed Microsoft Security Central SIEM alerts to identify security issues for remediation, investigated events and incidents, and optimized rules and thresholds to improve alert fidelity.
  • I created security operations reports that analyzed and presented results from security monitoring and penetration testing technologies such as Defender ATP Endpoint Detection and Response, Palo Alto Networks Extended Detection and Response, and Endgame.
  • I applied the MITRE ATT&CK framework to identify attacker tactics, techniques, and procedures with the AttackIQ simulation solution.
  • I ran scenarios with split-brain policy enforcement points and used APIs to integrate policy enforcement components into the security orchestration, automation, and response platform.
  • I delivered microsegmentation and SD perimeter solutions from two different vendors, processed telemetry, threat intelligence, and risk signals from various platforms, and connected SDNs and Zero Trust to enable secure internal workloads and a unified secure architecture.
  • I monitored and investigated network traffic with Splunk Enterprise Security, RSA Security Operations, Sourcefire, FireEye, NetScout, and Wireshark.
  • I investigated and handled incidents around identity and privileged access, access revocation, and session tracking, created custom integrations for automated monitoring, and carried out cloud investigations.
  • I tracked attacker tactics, techniques, procedures, and indicators of compromise, simulated intrusions, and applied Cyber Kill Chain and Advanced Persistent Threat techniques.
  • I architected a hardened hybrid cloud infrastructure using Infrastructure as a Service and Software as a Service; the technical depth I gained there helped me identify, analyze, and mitigate advanced threats effectively.
Sep 2015 - Jul 2019
Hamburg, Germany

Security and Data Protection Consultant

Fujitsu

Position Summary
Security and Data Protection Consultant at Fujitsu
Industries
Information Technology
Business Areas
Information Technology
Legal
Project Management

Governance and control:

  • I applied NIST 800-53 and 800-122 controls to privacy assessments.
  • I reviewed privacy risks related to systems of records and legal agreements such as Memoranda of Understanding and Cooperative Research and Development Agreements.
  • I developed data retention and media sanitization policies and created privacy handbooks that complied with CCPA, GDPR, and other requirements.
  • I initiated a privacy data mapping exercise to discover PII in databases and was responsible for data mapping frameworks as well as records of processing activities under Article 30.
  • I coordinated the migration of perimeter devices, ensured the devices met updated security controls, developed project documentation for each project phase, maintained repositories, and reviewed evidence to make sure cloud providers corrected audit findings; I also translated scan results from ACAS, SCAP, and HP Fortify into vulnerability and compliance context.
  • In addition, I carried out cloud governance compliance activities with more than seventy cloud providers, worked on fixing audit findings, assessed cloud service providers, and took part in Microsoft Office 365 and Enterprise Mobility Suite transitions with a focus on reducing cyber risk.
  • I supported a program of industrial security audits, including hardening and vulnerability reviews, and established a unified governance policy in cloud and on-premises environments that was audit-ready.

Strategy:

  • I designed and maintained privacy and risk management approaches aligned with privacy regulations, security frameworks, and business goals. This included building data mapping and privacy information mapping frameworks to create a consolidated view of where personal and sensitive data is stored, as well as defining and developing retention and cleanup policies and mapping them to regulatory and contractual duties.
  • I organized the new security strategy so that existing perimeter controls and the retirement of older perimeter configurations were compatible with newer architectures such as cloud services and web application security.
  • Findings from vulnerability management, audits, and industrial security assessments were fed back into the improvement cycle for policies, standards, and technical baselines so that governance remained practical and not just academic.

Leadership skills:

  • I also served as Data Protection Officer and was responsible for privacy impact assessments, response workflows for data subject access requests, and security questionnaires such as SIG and CAIQ.
  • I updated Role Responsibility Assignment Matrices and ensured role alignment with the legal framework as well as implementation of the BYOD policy.
  • I modeled processes, logged obligations, and supported audit processes under European and international regulations.
  • I built and defined a security monitoring team with workflows, procedures, and SIEM-related rules.
  • I helped restore a professional and cooperative relationship between internal audit and IT, and coordinated project planning, status reporting, and stakeholder communication.
  • I managed remediation activities with compliance analysts, CIOs, and business owners.
  • I supported incident response teams and discussed and documented penetration test results directly with technical teams to close security gaps.

Technical goals:

  • I worked with encryption, tokenization, data masking, and lifecycle controls for cloud storage, as well as system hardening using toolkits such as OpenSCAP, Lynis, Tripwire, logging, and privilege controls.
  • I used DISA Security Technical Implementation Guides and Security Requirements Guides to build baselines and audit them through SCAP.
  • I designed and implemented container security for microservices and deployed data loss prevention with Symantec technologies.
  • I successfully replaced antivirus software with Carbon Black, CrowdStrike, and open-source alternatives and used large volumes of log data to fine-tune remediation measures.
  • I developed and adapted security appliances such as Tufin, F5 Application Security Module, Barracuda Appliances, IBM Guardium, and Imperva Web Application Firewall.
  • I rebuilt existing perimeter setups with Application Security Modules, F5 load balancing devices, and Layer 3 firewalls.
  • I was responsible for security in public cloud environments, including web application firewalls in Docker, runtime application self-protection such as Twistlock and Wazuh, and Ansible automation in a DevSecOps model.
  • I carried out in-depth penetration tests for web applications and networks, migrated legacy proxy gateways to cloud-based DLP and CASB solutions, deployed QRadar for SIEM, and rolled out Carbon Black for endpoint protection.
  • I configured AAA and Privilege Management (PIM) with CyberArk and Cisco ISE for wired and wireless networks; I enforced network access control agent checks to require antivirus and endpoint detection and response; I managed virtual infrastructure in VMware environments and improved quality assurance performance.
  • I conducted penetration tests, OSINT-based fraud simulations, and evasion tests against web application firewalls.
  • I performed full-scope red team assessments including physical and infrastructure testing, which gave me hands-on experience in identifying and closing real security exposures.
Apr 2010 - Aug 2015
Offenbach, Germany

Security Project and Governance Consultant

Computerfutures

Position Summary
Security Project and Governance Consultant at Computerfutures
Industries
Banking and Finance
Business Areas
Audit
Information Technology
Operations
Project Management
Strategy

Governance and control:

  • I led the centralization of security for all European branches and carried out the migration into a new data center with a centralized model to reduce costs and improve control.
  • I built a complete security policy program based on NIST and ISO guidelines and designed and implemented security standards in AWS/Azure with a focus on IAM, encryption, network controls, and more.
  • I developed security policy documents for Office 365, CASB integration, and data exfiltration controls.
  • I developed and revised policies, standards, and procedures to support privacy and information security programs and created contingency plans to ensure continuity and recovery plans during network disruptions such as high availability outages or DDoS attacks.
  • I supported reviews of SOPs, action plans, milestones, and other internal compliance documentation.
  • I worked with stakeholders in audits and assessments and gave recommendations beyond baseline controls where risk appetite and regulation allowed it.
  • I developed a comprehensive risk and control matrix that mapped GAPP controls to risks from control failures, and I was heavily involved in SOC 2 audits, where I managed and supported audit activities to meet the Trust Principles.

Strategy:

  • I structured the central security model so that the migration of security from branches to a shared model, the data center migration, and cloud adoption with AWS and Azure were implemented on a logical roadmap that addressed cost reduction, operational control, and regulatory standards.
  • I made sure cloud security standards, Office 365 security policies, and data exfiltration controls were integrated into the overall risk and control framework and were not handled as separate projects.
  • I developed emergency and continuity plans that linked network outages, perimeter changes, and intrusion prevention migrations with practical contingency plans.
  • I used the risk and control matrix to connect audit, governance, and technical controls and to provide risk-based justification for decisions on technology, architecture, and processes.

Leadership skills:

  • I built a SOC from the ground up, including hiring and training new team members and developing runbooks, incident procedures, and a SIEM solution.
  • I provided input to Office 365 strategy development and led development, improvement, and design support workflows.
  • I coordinated cloud migrations from on-premises environments to Azure and AWS and led cross-functional initiatives to implement Zero-Trust principles and VPN architectures.
  • I worked under CISOs, supported SOC 2 Type I readiness assessments, and optimized security operations activities by managing workflows, procedures, and SIEM rules while driving improvements in security service delivery.
  • I balanced multiple projects, including intrusion prevention system migration, while also acting as a senior analyst, giving feedback on existing security issues and supporting continuous improvement.
  • Writing internal policies required advanced communication skills to present and explain requirements to cross-functional teams.

Technical goals:

  • I implemented Zero Trust and microsegmentation with VMware NSX-T and Palo Alto Panorama and built Splunk correlation rules for business impact analysis use cases.
  • I designed and managed cloud identity provider infrastructure, including directories, databases, and certificate services, and worked with identity and access management, key management services, and secure shell key management.
  • I deployed web and next-generation firewalls in Azure, redesigned cloud-to-on-premises VPNs, updated security controls, carried out monitoring and logging, and designed and protected large-scale hybrid and cloud-native systems.
  • I implemented a transparent web application firewall running in kernel reverse mode for a large bank. Here I implemented this Imperva firewall in my collaboration platform and tried to prevent data exfiltration and control document-sharing approvals at scale; after that, I carried out vulnerability assessments with the usual tools and additional tools. These included: Nessus, Rapid7 Nexpose, AppDetective, Cenzic Hailstorm, WebInspect, Metasploit, and Acunetix.
  • I migrated intrusion prevention systems from McAfee IntruShield to Cisco Firepower and managed and tuned SIEM rules and detection logic as part of my security operations responsibilities.
May 2007 - Mar 2010
Stockholm, Sweden

Cybersecurity Auditor

Randstad

Position Summary
Cybersecurity Auditor at Randstad
Industries
Information Technology
Business Areas
Audit
Information Technology
Project Management

Governance and control:

  • I was a founding member of the IS Governance, Risk and Compliance Committee, where I translated regulatory, industry-specific, and contractual requirements into internal security policies, frameworks, and procedures.
  • I created a complete security lifecycle roadmap for the organization, built a security plan at director level, and carried out gap analyses.
  • I was responsible for implementing the Information Assurance Vulnerability Management (IAVM) process as well as creating and maintaining POA&Ms and the vulnerability management program, which included continuous scanning, monitoring, remediation, and reporting.

Organizational leadership and soft skills:

  • I led the planning and delivery of more than 20 security projects, including commercial and open-source tools such as OpenDNS, SIEM, MDM, and IOC scanners.
  • I worked closely with SOC leadership to define use cases for integrating the WAF into the SIEM.
  • I supported the SOC by proposing new detection strategies and retention filters to meet data regulations.
  • I also initiated IT systems for inventory, asset management, classification, and labeling.

Technical topics:

  • I examined web application logs for vulnerabilities, identity issues, and threat patterns.
  • I provided RFIs and RSIs for data lake applications to enable secure data integration.
  • I re-engineered the network topology together with the WAF-IDS architecture.
  • I installed and configured a high-availability cluster with 200 DAMs and 100 WAF clusters and integrated everything into ArcSight SIEM.
  • I worked with FireMon to perform perimeter reviews and suggest actionable improvements.
  • I also implemented a DMS with open-source tools.
  • On the SIEM side, I built multi-layer filters to comply with ISP data retention laws.
  • I scanned, correlated, and prioritized vulnerabilities with tools such as Qualys, Nessus, Rapid7, Retina, Sofia, Burp Suite, Nmap, and Joval to remediate findings.
  • By integrating STIGs, SRGs, and industry best practices into mobility strategies, I delivered a secure modern work environment.
Feb 2004 - Apr 2007
Barcelona, Spain

Senior Consultant, Governance

Ernst & Young

Position Summary
Senior Consultant, Governance at Ernst & Young
Industries
Information Technology
Professional Services
Business Areas
Audit
Information Technology
Project Management

Governance and control:

  • I ensured that all security methodologies matched NIST-compliant frameworks, including 800-53, RMF, and POAM.
  • I was responsible for implementing Security Plans, writing Security Directives, performing in-depth risk and business impact analyses, creating and maintaining action plans and milestones, and carrying out risk remediation across numerous locations.
  • I administered PCI-DSS Self Assessment Questionnaires and supported ISO-27000 evidence audits.

Organizational leadership and soft skills:

  • I led the consolidation of the entire security policy program by designing a new structure and updating technical and process policies. This included identifying compliance gaps and aligning them with internal and external requirements.
  • I worked closely with IT, Finance, and Legal to resolve open issues around information security and vendor risk.
  • I also led third-party risk assessments for new implementations and upgrades.
  • In addition, I was involved in pre-sales activities, preparing proposals, statements of work, and staffing estimates for privacy projects.
  • Reporting to C-level executives and preparing a SWOT analysis were also part of my tasks.

Technical topics:

  • I analyzed customers' security engineering capabilities and created remediation plans to meet NIST requirements.
  • I reviewed penetration testing and vulnerability scan results and fixed gaps with support from InfoSec.
  • I deployed a network behavior analysis solution with ArcSight SIEM and deep packet inspection tools such as Solera.
  • I implemented access controls using authentication tools combined with IPS, IDS, NAC, and antivirus technologies.
  • I implemented DLP with IronPort, McAfee Webwasher, Blue Coat, GTB, RSA NetWitness, and NetBeholders.
  • I managed data quality anomalies and user activity anomalies that required in-depth analysis of data patterns and violations.
Jun 2002 - Jan 2004
Madrid, Spain

Cybersecurity Incident Handler

Accenture

Position Summary
Cybersecurity Incident Handler at Accenture
Industries
Banking and Finance
Government and Administration
Business Areas
Customer Service
Information Technology
Operations

Governance and control:

  • I managed Managed Security Services (MSS) for most banks in Spain and was directly responsible for implementing anti-phishing solutions and managing perimeter defenses.
  • I made sure that the services were aligned with customers' compliance and governance requirements.
  • I also maintained and provisioned SLAs and made sure we consistently met contractual obligations and service metrics.

Organizational leadership and soft skills:

  • The main task of my role was coordinating support, sales, and engineering teams in delivering MSS. This was especially challenging and required strong communication, planning, and alignment skills across departments.
  • It also involved a lot of customer contact, especially in banking organizations, where I had to maintain close relationships and provide clear, consistent feedback.
  • I was responsible for VIP customer support and escalation management in a calm and competent way under significant pressure.

Technical topics:

  • I worked directly hands-on with the Verisign Teraguard SIEM system, which gave me broad experience in log analysis and event correlation.
  • I also provided operational support for the Andalusian government corporate network with more than 7,000 network points; the underlying technologies were ATM and MPLS. This included extensive troubleshooting and proactive maintenance.
  • I worked directly with transmission and radio technologies such as SDH, PDL, and DWDM, and with hardware from different vendors, including major companies in this field: Lucent, Alcatel, Cisco, Pirelli, Ericsson, Motorola, and Juniper.
  • In addition, I provided Level-2 support for VIP customers, where fast resolution and accuracy were essential.

Industry Experience

See where this freelancer has spent most of their professional time.

Experienced in Information Technology, Banking and Finance, Aerospace and Defense, Energy, Healthcare, and Manufacturing.

Information Technology
Banking and Finance
Aerospace and Defense
Energy
Healthcare
Manufacturing
Profile match chart

Business Area Experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Project Management, Operations, Strategy, Audit, and Legal.

Information Technology
Project Management
Operations
Strategy
Audit
Legal
Profile match chart

Summary

More than 20 years of industry experience as a Security Architect in cloud, on-premises, IT, and ICS/OT environments.

Focus on designing Zero Trust, Defense-in-Depth, and network segmentation.

Expertise in GRC, risk management, and security implementations.

Very experienced in architecture for Security Blueprints as well as operational security modeling.

Specialist in SOP modernization, improving detection, and audit readiness.

Connects architecture with operations and governance to deliver secure results at scale.

Skills

  • Information Security

  • Cyber

  • Infosec

  • Data Security

  • Grc, Risk Management And Security Implementations

  • Zero Trust, Defense-In-Depth And Network Segmentation

  • Security Blueprints And Operational Security Modeling

  • Sop Modernization, Detection Improvement And Audit Readiness

  • Enterprise And Solution Architecture: Leanix Eam, Archimate, Adm, Draw.Io, Miro, Whimsical, Graphviz, Jira, Azure Devops Boards, Confluence, Servicenow Secops, Log4brains, Ibm Doors, Polarion Alm, Codebeamer, Windchill, Isograph Reliability Workbench, Faulttree+, Cafta, Riskspectrum, Ansys Medini Analyze, Opencontrol, Compliance Masonry, Aws Audit Manager, Azure Policy, Open Policy Agent Rego, Auth0 Attack Protection Playbooks, Varonis Datadvantage Maps, Purview Data Lineage, Syft, Grype, Cyclonedx, Spdx, Dependency Track, Renovate, Dependabot, Structurizr C4, Plantuml, Iriusrisk, Terraform, Checkov, Opa, Prowler, Scoutsuite, Opentelemetry, Grafana, Loki, Aws Well-Architected, Azure Advisor

  • Threat Modeling And Attack Simulation: Microsoft Threat Modeling Tool, Iriusrisk, Owasp Threat Dragon, Securicad, Pasta, Threatspec, Pytm, Mitre Att&Ck, Ebios, Fair, Octave, Mehari, Magerit, Cwe Top 25, Capec, Rams, Fmeca, Fmea, Fmeda, Fta, Eta, Hazop, Hazid, Pha, Sha, Fha, Bow-Tie Analysis, Sil Assessment, Lopa, Alarp / Sfairp, Qra, Safety Case Development, Common Cause Failure Analysis, Safety Case

  • Perimeter It Network Security And Microsegmentation: Guardicore, Claroty Ctd, Claroty Sra, Armis, Vectra, Nozomi Networks, Nanolock, Verve Industrial, Microsoft Defender For Iot, Tenable Ot, Prisma Cloud, Rsa Netwitness, Imperva Waf, Fortinet, Juniper, Palo Alto Networks Ngfw, Dns Sinkholing, Dns Behavior Analysis, Microsoft Defender Stack, Darktrace

  • Endpoint Security: Crowdstrike, Carbon Black, Red Cloak, Microsoft Defender For Endpoint, Wazuh, Elk, Thor, Loki, Hips, Fim, Sandboxing, Detonation, Recovery Tooling, Ollydbg, Ida Pro

  • Database Security: Ibm Guardium, Imperva Db Firewall, Check Point Cloudguard, Trend Micro Cloud One

  • Identity & Access Management: Okta, Pingid, Microsoft Entra Id, Active Directory, Cisco Ise, Tacacs, Radius, Nac, Mfa, Conditional Access

  • Logging & Forensics: Rsa Envision, Splunk Enterprise Security, Wazuh, Elk, Netwrix, Microsoft Defender Xdr, Microsoft Sentinel, Qradar, Maltego, Insightidr Ti, Volatility, Autopsy, Helix, Ftk, Sans Sift

  • Threat Intelligence: Misp, Maltego, Spiderfoot Hx, Bitsight, Zerofox, Securityscorecard, Cycognito, Faraday, Recorded Future, Insight Ti, Censys, Spycloud, Data Or Api Discovery

  • Dlp: Microsoft Purview Dlp, Gtb Dlp, Forcepoint Dlp, Netskope Dlp, Fidelis Dlp, Trellix Dlp, Zscaler Dlp, Symantec Dlp, Mimecast Dlp

  • Cloud Security: Cnapp Microsoft Defender For Cloud, Prisma Cloud, Aqua Security, Wiz, Check Point Cloudguard; Cspm Crowdstrike Cloud, Tenable Cloud Security, Qualys Cloudview, Rapid7 Insightcloudsec; Cwpp Sysdig Secure, Crowdstrike Falcon Cloud Security, Vmware Carbon Black Cloud; Ciem Microsoft Entra Permissions Management, Cyberark, Saviynt, Prisma Cloud Iam; Easm Censys, Cycognito, Bitsight, Securityscorecard, Rapid7 Ti, Hadrian; Casb Microsoft Defender For Cloud Apps, Netskope, Zscaler Casb, Skyhigh; Sspm Obsidian, Adaptive Shield, Grip Security; Piam/Pim/Puam/Pam Cloud Identity And Access Security: Microsoft Entra Id, Okta Workforce Identity Cloud, Ping Identity, Cyberark Identity, Beyondtrust, Sailpoint; Iac Security Tenable Cloud Security, Aqua Trivy; Container And Kubernetes Security Sysdig, Aqua, Falco, Anchore; Key Management Aws Kms, Cloud Hsm, Azure Key Vault, Thales Ciphertrust, Hashicorp Vault

  • Vulnerability Management: Nozomi, Qualys, Nessus, Tenable, Rapid7, Greenbone, Retina, Coreimpact, Intune Defender Asr

  • Secure Software Development And Application Security: Black Duck, Veracode, Checkmarx, Sonarqube, Burp Suite Pro, Invicti, Netsparker, Acunetix, Qualys Web App Scanning, Rapid7 Appspider, Nmap, Nikto, Greenbone Openvas, Vega, Metasploit, Core Impact, Invicti Enterprise, Gitlab Secure, Jenkins Security Plugins, Circleci Pipelines With Sast, Dast, Regression And Smoke Security Testing, Microsoft Defender For Devops, Aqua Trivy, Tenable Web App Scanning, Selenium, Postman, Testrail, Katalon, Browserstack

Languages

Spanish
Native
English
Advanced
German
Intermediate

Education

Oct 1999 - Jun 2003

University Madrid

B.Sc. · Telecommunication Engineering · Madrid, Spain

Certifications & licenses

AWS Certified Security – Specialty

CSP Cloud Security Professional

Carbon Black Protection / Response (EDR)

Palo Alto Networks Prisma Cloud - Essentials

Zscaler Cloud DLP

CCSK Cloud Security

CISA Information Security Auditor

CrowdStrike EDR

IBM QRadar - Administration

EC Security Analyst

AlgoSec - Administrator

Barracuda Web Application Firewall - Administrator

FireEye Helix - Administration

Imperva SecureSphere - WAF, DAM, FIM, SharePoint

Palo Alto Networks - Security Engineer

Micro Focus ArcSight - Solution Engineer

Barracuda Email Security Gateway - Administrator

Fortinet Network Security Expert (NSE)

EC Certified Ethical Hacker

EC Forensic investigator

CISSP Certified Information Systems Security Professional

ISO 27001 and ISO20000 Leading auditor

ITIL Foundations

Statistics

Experience

Total positions 7
Experience in Information Technology 12.5 y
Avg length 3 y 4 m
Longest experience 5 y 4 m

Global Experience

Countries worked in 4 (Germany, Spain, Switzerland, Sweden)
Primary country Germany

Expertise

Recent roles Security Architect, Lead Security Architect, Security and Data Protection Consultant
Main industries Information Technology, Banking and Finance, Aerospace and Defense
Main business areas Information Technology, Project Management, Operations

Qualifications

Highest degree Bachelor
Certifications earned 23

Profile

Created

Frequently asked questions

Have questions? Find more information here.

Enrique is based in Hamburg, Germany.
Enrique speaks the following languages: Spanish (Native), English (Advanced), German (Intermediate).
Enrique has at least 24 years of experience. During this time, Enrique has worked in at least 7 different roles and for 7 different companies. The average length of individual experience is 3 years and 5 months. Note that Enrique may not have shared all experience and actually has more experience.
Based on recent experience, Enrique would be well-suited for roles such as: Security Architect, Lead Security Architect, Security and Data Protection Consultant.
Enrique's most recent position is Security Architect at Capgemini.
In recent years, Enrique has worked for Capgemini and Sopra Steria.
Enrique is most experienced in industries like Information Technology, Banking and Finance, and Aerospace and Defense. Enrique also has some experience in Energy, Healthcare, and Manufacturing.
Enrique is most experienced in business areas like Information Technology, Project Management, and Operations. Enrique also has some experience in Strategy, Audit, and Legal.
Enrique has recently worked in industries like Aerospace and Defense, Energy, and Healthcare.
Enrique has recently worked in business areas like Information Technology, Operations, and Strategy.
Enrique holds a Bachelor in Telecommunication Engineering from University Madrid.
Enrique has 23 certificates. Among them, these include: AWS Certified Security – Specialty, CSP Cloud Security Professional, and Carbon Black Protection / Response (EDR).
Enrique is immediately available part-time for suitable projects.
Enrique's rate depends on the specific project requirements. Please use the Meet button on the profile to schedule a meeting and discuss the details.
To hire Enrique, click the Meet button on the profile to request a meeting and discuss your project needs.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1200
900
600
300
Rate comparison chart
Market avg: 864-1024 €
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.