Skip to main content
Top expert badge
Recommended expert
Profile header background

Federico (F.) Leefhelm-ISO – Senior Consultant Quality & Information Security

Federico (F.) Leefhelm - ISO – Senior Consultant Quality & Information Security - profile avatar
Profile header overlay
Düsseldorf, Germany

Check rate

Experience

Jun 2025 - Nov 2025
Karlsruhe, Germany
Hybrid

Senior IAM Manager & Single Point of Contact for Information Security

EnBW Energie Baden-Württemberg AG

Expertise details
Position Summary
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
Industries
Energy
Business Areas
Information Technology

As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW.  Developed and implemented a holistic process view covering both technical and organizational aspects  Ensured end-to-end control of all IAM-related technical services  Established clear responsibilities and accountabilities within the IAM landscape  Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security  Introduced and monitored governance policies to ensure compliance and security  Continuously improved IAM processes and systems through regular audits and evaluations  Participated in external audits of the process as part of official ISO audits  Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units  Conceptually advanced the KPI system to measure process quality

Sep 2024 - Mar 2025
Hybrid

Senior PMO for the CDC Project of Global IT

Daimler Truck Financial Services (DTFS)

Expertise details
Position Summary
Senior PMO for the CDC Project of Global IT at Daimler Truck Financial Services (DTFS)
Industries
Banking and Finance
Insurance
Business Areas
Information Technology
Project Management

Daimler Truck Financial Services is moving from traditional data centers to the Azure Cloud. As part of the Cloud Data Center project (CDC), DTFS is migrating traditional data centers in Europe (EMEA), Asia & South Africa (APAC), Canada, South, Central and North America (NAFTA) and transferring the service to the Azure Cloud. DTFS supports the global sale of Daimler commercial vehicles through leasing, financing and insurance and is, with a contract volume of 25.4 billion euros, one of the world's largest financial service providers for commercial vehicles [link]  Worked as Senior PMO and Senior Management Consultant with the Global IT Director and Head of Innovation Projects  Worked as Senior PMO and Management Consultant with international PM and PO teams (Project Management/Project Owner)  Created a master plan based on MS Project for the CDC project, which allowed DTFS to gain a clear overview and transparency of the project after one year  The master plan provided management and teams with clear and accurate information about the status of the overall project and each subproject, both by region and by country  The reports from the master plan enabled management and teams to take measures to correct deviations so that the project could be completed on time, on budget, and on quality  Regular reporting of project progress to the Global IT Director and PM teams  Handed over the CDC master plan to the DTFS PM at the end of the contract period

Oct 2023 - Jun 2024
Germany

ISO – Senior Consultant Quality & Information Security

Gemeinsame Klassenlotterie der Länder (GKL)

Expertise details
Position Summary
ISO – Senior Consultant Quality & Information Security at Gemeinsame Klassenlotterie der Länder (GKL)
Industries
Professional Services
Government and Administration
Business Areas
Information Technology
Project Management
Quality Assurance
  • Responsible for implementing the QMS & ISMS on behalf of the partner company ModernX GmbH & Co. KG
  • Responsible for benchmarking and future rollout of an ISO tool for centralized management of all management systems
  • Responsible for implementing a Quality Management System (QMS) according to ISO 9001:2015
  • Responsible for implementing an Information Security Management System (ISMS) according to ISO 27001:2022
  • Preparation and creation of relevant measures (scope, SoA, policies, security concepts, procedures, SOPs, etc.) to build a QMS and ISMS
  • Risk management: identification, assessment, and treatment of critical and potential attack scenarios
  • Risk analysis, risk treatment, determination of protection needs, and vulnerability analysis of the IT infrastructure
Jul 2023 - Apr 2024
Hamburg, Germany

ISO – Senior Consultant Cyber- & Information Security

Northland Power Europa GmbH

Expertise details
Position Summary
ISO – Senior Consultant Cyber- & Information Security at Northland Power Europa GmbH
Industries
Energy
Business Areas
Information Technology
  • Northland Power is a developer, operator and owner of clean wind power plants
  • Member of the security team, co-responsible for the cyber & information security of the wind power plants
  • Responsible for creating all documentation and measures (policies, security concepts, cryptography, key management) to deploy SzA according to BSI IT-SiG 2.0 and EnWG
  • Preparation and creation of measures (policies, SOP, ISMS manual, BCM, IT emergency concepts, IAM, backup & recovery, MDM, supplier, password, patch, asset & configuration, network management) to build an ISMS according to ISO 27001:2022
  • Identification, assessment, and treatment of critical and potential attack scenarios for the wind power plants in risk management
  • Risk analysis, risk treatment, determination of protection needs, and vulnerability analysis of the IT/OT infrastructure
  • Creation of IT/OT emergency concepts, incident response processes & rebuilding of IT/OT systems as part of BCM (BIA, RIA & DRP)
  • The project was stopped early because the wind turbines were sold and the company was closed in Germany
Feb 2023 - Aug 2023
Velbert, Germany

CISO ad Interim & Senior Management Consultant ISMS, BCM & IAM

Huf Hülsbeck & Fürst GmbH & Co. KG

Expertise details
Position Summary
CISO ad Interim & Senior Management Consultant ISMS, BCM & IAM at Huf Hülsbeck & Fürst GmbH & Co. KG
Industries
Automotive
Business Areas
Information Technology
Project Management
  • Led and managed the project to implement a Business Continuity Management (BCM) according to ISO 22301
  • Defined the scope, created a BCM policy, Business Impact Analysis (BIA), Risk Impact Analysis (RIA), and Disaster Recovery Plan (DRP)
  • Developed IT emergency concepts, vulnerability analysis, incident response processes & rebuilding of IT systems
  • Conducted the first review of the Corporate Identity and Access Management process (IAM) and identified improvement measures
  • Contributed to the continuous improvement process of the TISAX and ISMS certification according to ISO 27001
  • The BCM project was not completed due to budget planning
Dec 2022 - Jul 2024
Düsseldorf, Germany

ISO, Sr. Management Consultant and Sr. PMO

University Hospital Düsseldorf (UKD)

Expertise details
Position Summary
ISO, Sr. Management Consultant and Sr. PMO at University Hospital Düsseldorf (UKD)
Industries
Healthcare
Business Areas
Information Technology
Project Management
Quality Assurance
  • UKD is the largest hospital in the state capital and one of the key medical centers in North Rhine-Westphalia.
  • Operator of critical infrastructures (KRITIS according to §8a BSIG) with an ISMS certified to ISO 27001:2022.
  • Working directly as Senior Management Consultant to the IKMT (CIO) division head and leader of innovation projects.
  • Responsible for the entire IT department in information security as ISO.
  • Developing, maintaining, and improving ISMS policies and SOPs.
  • Conducting training and awareness for IT staff in IT security, incident response processes, and rebuilding IT systems.
  • Creating and being the main contact for the new IT strategy at UKD, plus a BIA and DRP for rebuilding IT systems.
  • Preparing for the next implementation of business continuity management according to ISO 22301 for the IKMT division and UKD.
  • Developing an IT cyber security strategy and roadmap for implementing additional tools and solutions for UKD's cyber security.
  • Developing an IT emergency plan (as part of the DRP), IT security concept, incident response, and related supporting plans (data protection, antivirus, cryptography, configuration and hardening measures, asset & configuration management, patch management, roles and rights (IAM), IT disaster recovery, etc.).
  • Contributing to defining measures to make IDS (intrusion detection systems) compliant with BSI IT Security Act 2.0.
  • Developing a security concept, conducting a proof of concept (PoC), evaluating and assessing up to procurement and implementation of a medical device monitoring security system.
  • Setting up a security operations center (SOC) with a working concept and definitions for preventive measures, threat detection, and incident response.
  • Building a security information and event management (SIEM) system using Splunk.
  • Senior PMO of the division management since February 2023, responsible for overseeing all IT-related projects (>2K projects).
  • Creating and managing Gantt charts for all IT-related projects (IT & healthcare, IT security, SAP, etc.).
  • Developing a patch management security concept & processes and standard operating procedures (SOP).
  • Contributing to the continuous improvement process (CIP) of the certified ISMS in preparation for the first surveillance audit.
  • Regular reporting of project progress to the division management and board.
May 2022 - Dec 2022
Munich, Germany

Senior Management Consultant BCM, Compliance & Information Security

Bitmarck Consulting GmbH

Expertise details
Position Summary
Senior Management Consultant BCM, Compliance & Information Security at Bitmarck Consulting GmbH
Industries
Professional Services
Business Areas
Information Technology
Project Management
Quality Assurance
  • Leading and managing the project for introducing business continuity management (BCM) according to ISO 22301 and BSI IT-Grundschutz Standard 200-4.
  • Defining the scope, developing a BCM policy, and conducting a business impact analysis (BIA) and risk impact analysis (RIA).
  • Developing IT emergency plans, vulnerability analysis, incident response processes, and rebuilding IT systems (DRP).
  • Creating a project Gantt chart and preparing all necessary certification documents.
  • The BCM project was not completed due to budget planning.
May 2022 - Jul 2022
Germany

CISO as a Service – Chief Information Security Officer

EUROVIA Services GmbH

Expertise details
Position Summary
CISO as a Service – Chief Information Security Officer at EUROVIA Services GmbH
Industries
Construction
Business Areas
Information Technology
  • Preparing and conducting awareness training for the company and its subsidiaries.
  • Reviewing penetration test (PenTest) results and creating a list of measures to address identified vulnerabilities.
  • Optimizing IT processes to support business operations.
  • Contributing to ensuring the availability of IT services.
  • Reviewing existing ISMS documents for as-is assessment and gap analysis to implement an ISMS according to ISO 27001.
Mar 2021 - Jun 2023
Wilhelmshaven, Germany

Security Engineer, ISO, Senior Management Consultant Cyber & Information Security

Thales Germany GmbH Naval

Expertise details
Position Summary
Security Engineer, ISO, Senior Management Consultant Cyber & Information Security at Thales Germany GmbH Naval
Industries
Aerospace and Defense
Business Areas
Information Technology
  • Member of the F126 team and co-responsible for the cyber and information security of the new F126 ships for the German Navy according to the German Military Security Accreditation Authority.
  • Leading the implementation of the largest Thales innovation project in information security for the German Navy.
  • Identifying, assessing, and addressing critical and potential attack scenarios of the new F126 ships.
  • Risk management, risk analysis, risk treatment, determining protection requirements, IT emergency plans, vulnerability analysis, incident response processes, and rebuilding IT infrastructure systems.
  • Developing, adjusting, and improving policies, hardening and security concepts, and SOPs.
  • Developing, managing, and documenting information security and emergency concepts in compliance with ISO 27001, BSI IT-Grundschutz & compendium, and regulations of the German Military Security Accreditation Authority (ZDV A-960/1).
  • Contributing to the information security of the Digital Communication Network (DKN), Ship Entry Point (SEP), and satellite communication (SATCOM) systems.
  • Advising and collaborating with departments on conflicts between technical implementation and information security requirements.
  • Applying the ISO/IEC 27001 standard according to BSI IT-Grundschutz & compendium and Bundeswehr IT-Grundschutz for ISMS.
  • Participating in workshops with the German Navy and other contractors in German and English.
  • Collaborating with information security teams from France and the Netherlands.
Jun 2019 - Mar 2020
Wiesbaden, Germany

ISO & Senior Management Consultant Compliance & Information Security

Federal Criminal Police Office (BKA)

Expertise details
Position Summary
ISO & Senior Management Consultant Compliance & Information Security at Federal Criminal Police Office (BKA)
Industries
Government and Administration
Business Areas
Audit
Information Technology
  • Responsible for the certification (attestation) of the new cloud services of the Police Service Platform (PSP) to the international C5 standard.
  • Conducting gap analysis and contributing to building and improving an ISMS according to ISO 27001, IT-Grundschutz, and the new BSI compendium.
  • Developing and adapting policies and SOPs for the entire federal office (BCM, BIA, RIA, DRP, IT emergency plans).
  • Developing and improving information security (SiKo) and IT emergency plans for IT operations and cloud services (IAM, backup & recovery, patch management, crypto & key management, asset & configuration management).
  • Collaborating with the SOC team to update the threat landscape.
  • Conducting internal trainings, workshops, and awareness activities.
  • BKA security review SÜ2.
  • The project was terminated early due to the COVID-19 pandemic.
Feb 2019 - Jul 2019
Düsseldorf, Germany

CISO & Senior Management Consultant Compliance & Information Security

Dr. Glinz COViS GmbH

Expertise details
Position Summary
CISO & Senior Management Consultant Compliance & Information Security at Dr. Glinz COViS GmbH
Industries
Professional Services
Business Areas
Information Technology
Legal
Strategy
  • Development of security concepts (SiKo) for the company and different software products.
  • Conducting a pre-audit regarding EU GDPR, resulting in over 90% compliance.
  • Strategic development of IT security, continuous improvement process (CIP), and maintenance of the ISMS according to ISO 27001.
  • Introduction of an event handling concept and improvement of the SOC system.
  • Conducting security assessments (pen tests & vulnerability scans) to eliminate vulnerabilities.
  • Developing new compliance services for clients and conducting workshops on ISMS and GDPR.
  • Creating new policies, especially for using cloud services as a CSP and CSC.
May 2018 - Dec 2018
Mannheim, Germany

Lead Auditor & Sr. Management Consultant Compliance & Information Security

TÜV SÜD

Expertise details
Position Summary
Lead Auditor & Sr. Management Consultant Compliance & Information Security at TÜV SÜD
Industries
Professional Services
Business Areas
Audit
Legal
  • Conducting ISO 27001 audits for various clients.
  • Conducting EU GDPR workshops and pre-audits for TÜV SÜD Munich and its clients.
Apr 2018 - Jan 2019
Walldorf, Germany

Lead Auditor & Sr. Management Consultant Compliance & Information Security

SAP AG

Expertise details
Position Summary
Lead Auditor & Sr. Management Consultant Compliance & Information Security at SAP AG
Industries
Information Technology
Business Areas
Audit
Information Technology
Quality Assurance
  • International lead audit manager in quality management and information security for ISO 9001, ISO 27001, ISO 22301, SOC, SOX, C5, PCI-DSS & SIEM.
  • Focus on cloud network delivery (CND) and global SAP cloud services.
  • Collaborating with enterprise compliance, audit, and SOC teams on threat lifecycle management (TLM).
  • Reviewing and improving the information security concepts for all SAP cloud services.
  • Contributing to the development of innovation projects in information security.
  • Single point of contact between cloud network delivery, users, and global compliance teams.
  • Compliance project manager for CND (Cisco switches in global data centers).
Feb 2016 - Jun 2018
Karlsruhe, Germany

CISO & Division Manager Compliance Services & Solutions

Makro Factory GmbH & Co. KG

Expertise details
Position Summary
CISO & Division Manager Compliance Services & Solutions at Makro Factory GmbH & Co. KG
Industries
Information Technology
Professional Services
Business Areas
Information Technology
Legal
Quality Assurance
  • Planning, expansion, and establishment of the new Compliance Services & Solutions division.
  • Advising clients on implementing ISMS (ISO 27001), BCM (ISO 22301), IT baseline protection, BaFin & MaRisk requirements.
  • Successfully implementing and dual-certifying an ISMS (ISO 27001) and a BCM (ISO 22301) within 14 months.
  • Achieving ISO 27017 / ISO 27018 certification to protect personal data as a cloud service provider (CSP).
  • Conducting IT security assessments (pen tests, vulnerability scans) and developing IT emergency plans.
  • Conducting seminars, training sessions, and workshops on GDPR and information security.
  • Conducting information security audits according to ISO 27001, ISO 27006, and ISO 19011.
Nov 2015 - Jan 2016
Düsseldorf, Germany

Senior Management Consultant Compliance & Information Security

Stadtsparkasse Düsseldorf

Expertise details
Position Summary
Senior Management Consultant Compliance & Information Security at Stadtsparkasse Düsseldorf
Industries
Banking and Finance
Business Areas
Business Intelligence
Information Technology
Legal
  • Conducting banking security consulting regarding BaFin and MaRisk AT 8.2 compliance.
  • Advising on IT requirements and secure IT operations measures (SITB).
  • Advising on network service outsourcing under the German Banking Act (KWG 25a/b).
  • Adapting incident management for the change of network provider to Finanz Informatik (FI) in line with MaRisk AT 9 outsourcing.
  • Business analysis, modeling, and adjustment for outsourcing processes.
Mar 2013 - Jun 2015
Santiago, Chile

Strategic ITSCM, CISO, Business & eGRC Senior Management Consultant

Self-Employed Entrepreneur

Expertise details
Position Summary
Strategic ITSCM, CISO, Business & eGRC Senior Management Consultant at Self-Employed Entrepreneur
Industries
Banking and Finance
Insurance
Information Technology
Metals and Mining
Retail
Business Areas
Business Intelligence
Information Technology
Project Management
Strategy
  • Senior Project Manager, Business Analyst and Senior PMO as an interim manager for banks, insurance companies, retail and industry.
  • Technical rollout and change management for an international mining company during the introduction of new ERP systems.
  • Strategic further development of ITSCM, IT services and IT security as interim CISO.
  • Implementation of ISMS according to ISO 27001 and BCM according to ISO 22301 in Chile, Argentina and Brazil.
  • Interim Business Development Manager for various IT companies.
  • Business Analyst and interpreter for IT projects (Spanish/German/English).
Jul 2010 - Feb 2013
Santiago, Chile

Regional eRCP Manager & Senior PMO for all of Latin America

Zürich Shared Services – Insurance Company

Expertise details
Position Summary
Regional eRCP Manager & Senior PMO for all of Latin America at Zürich Shared Services – Insurance Company
Industries
Insurance
Business Areas
Information Technology
Project Management
Quality Assurance
  • Responsible for Enterprise Release, Configuration & Promotion (deployment) within the global Growing Market Platform (GMP) project.
  • Rollout of a new core insurance system for all Latin American business units of Zurich Insurance.
  • Building, training and leading an eRCP team in Chile, Brazil and India.
  • Regional problem, incident, change, release and crisis management across the entire application lifecycle.
  • Single point of contact for Latin American users and collaboration with regional Change Advisory Boards (CAB).
  • QA approval of software releases and development of test cases.
  • Reviewing and adjusting contracts for external service providers (Accenture, CSC, Everis, Wipro).
  • Personnel responsibility for over 80 employees worldwide.
  • Senior PMO for all non-core applications (legacy systems) in Latin America.
Jul 2008 - Jul 2010
Santiago, Chile

Interim CISO & interim manager for IT and information security

INE, Chilean Statistics Office

Expertise details
Position Summary
Interim CISO & interim manager for IT and information security at INE, Chilean Statistics Office
Industries
Government and Administration
Business Areas
Information Technology
Project Management
  • Responsible for preparing, programming and securing wireless solutions for digital data collection for the 2011-2012 census.
  • Conducting training sessions for external staff on digital data collection.
  • Strategic development of ITSCM, IT services and IT security and leadership of all innovation projects.
  • Restructuring the IT department and negotiating with management and the works council.
  • Introducing policies in line with ISO 27001, ISO 22301, ITIL, COBIT and OECD.
  • Setting up and launching the first SOC with a SIEM platform for automated Threat Lifecycle Management (TLM).
  • Introducing PMO, development and project methodologies (PMI, CMMI, CMMN).
  • Leading the cross-border improvement of the telecommunications network (RFP).
  • Interim personnel responsibility for over 50 employees.
Mar 2002 - Jun 2008
Santiago, Chile

CEO & Owner; Managing Director, CISO & Senior Consultant

ATNet Latin America Management Consulting GmbH

Expertise details
Position Summary
CEO & Owner; Managing Director, CISO & Senior Consultant at ATNet Latin America Management Consulting GmbH
Industries
Banking and Finance
Information Technology
Professional Services
Business Areas
Information Technology
Product Development
  • Founder and managing director of an international IT management consulting firm.
  • Specializing in IT governance, risk & compliance, information security and electronic invoicing processes.
  • Implementation and certification of ISMS (ISO 27001) and BCM (ISO 22301) at financial institutions in South America.
  • Setting up SOCs with SIEM platforms for banks in Chile.
  • Developing and marketing an application for electronic invoicing with asymmetric cryptography.
  • Lecturer for the Ministry of Economy and the Santiago Chamber of Commerce on strategic and technological aspects of cryptography.
  • Automating workflows for foreign trade processes for a Brazilian bank.
  • Consolidation of networks and server platforms to reduce TCO at a local bank.
  • Introducing IT security guidelines and reorganizing the IT department at Chile's largest mining and steel company.
  • Personnel responsibility for over 120 employees.
May 2000 - Feb 2002
Santiago, Chile

CIO & COO – IT & Operations Manager

Chipkarten AG (ETISA)

Expertise details
Position Summary
CIO & COO – IT & Operations Manager at Chipkarten AG (ETISA)
Industries
Banking and Finance
Business Areas
Finance
Information Technology
Operations
  • Introduction of an electronic money card (eWallet) using smart card technology as a subsidiary of the banks.
  • Managing the technology platform for eWallet administration as an open innovation project.
  • Licensing the money card with Mondex International (MasterCard).
  • Introducing and leading an interbank committee for operational and technology topics.
  • Developing the model for production, operation and settlement of electronic money in collaboration with banking regulators and the central bank.
  • Developing the financial model for investment and profit distribution considering money market stability.
  • Acting as the interface (Business Analyst) between banks for project implementation.
  • Personnel responsibility for over 20 employees.
Jul 1998 - May 2000
Santiago, Chile
Remote

Manager of Technological Remote Channels

Banco Crédito Inversiones (BCI)

Expertise details
Position Summary
Manager of Technological Remote Channels at Banco Crédito Inversiones (BCI)
Industries
Banking and Finance
Business Areas
Information Technology
Project Management
  • Operational management of technological remote channels: web, mobile banking, telephone banking, and ATMs.
  • Designed and defined the project to launch the first Chilean transactional banking website.
  • Introduced mobile digital banking.
  • Led and controlled external service providers.
  • Managed over 40 employees.
Oct 1994 - Jul 1998
Santiago, Chile

Senior Consultant Electronic Banking

Banco Crédito Inversiones (BCI)

Expertise details
Position Summary
Senior Consultant Electronic Banking at Banco Crédito Inversiones (BCI)
Industries
Banking and Finance
Business Areas
Information Technology
Product Development
  • Developed, implemented, and managed all electronic banking products for the corporate sector.
  • Developed and introduced e-commerce solutions for the bank.
  • Advised on secure development of e-commerce and EDIFACT in Chile.
Jul 1992 - Sep 1994
Santiago, Chile

R&D Manager, Research and Technological Development

Banco Crédito Inversiones (BCI)

Expertise details
Position Summary
R&D Manager, Research and Technological Development at Banco Crédito Inversiones (BCI)
Industries
Banking and Finance
Business Areas
Information Technology
Product Development
Research and Development
  • Introduced EDIFACT (Electronic Data Interchange) for the bank.
  • Advised on the establishment of an EDI subsidiary for the banks.
  • Developed and launched the first drive-in car banking branch.
  • Managed over 10 employees.
Jul 1991 - Jun 1992
Frankfurt, Germany

Senior Consultant & Deputy Manager of International Banking

Digital Equipment Corporation (DEC)

Expertise details
Position Summary
Senior Consultant & Deputy Manager of International Banking at Digital Equipment Corporation (DEC)
Industries
Banking and Finance
Business Areas
Information Technology
Project Management
  • Responsible for COMEX, Financial EDIFACT, and e-commerce for German and European banks.
  • Responsible for the financial institutions sector at CeBIT.
  • Developed and promoted e-commerce among German banks.
  • Member of the European interbank committees in Frankfurt, Paris, and London.
  • Led an e-commerce project between commercial banks and the State Central Bank (LZB) in Frankfurt.
Jul 1983 - Jun 1991
Frankfurt, Germany

CIO and Authorized Officer

Société Générale

Expertise details
Position Summary
CIO and Authorized Officer at Société Générale
Industries
Banking and Finance
Business Areas
Information Technology
Project Management
  • Conducted benchmarking and procured the SWIFT-ST400 system for the entire bank.
  • Planned, rolled out, and provided training for the SWIFT system in all German branches.
  • Introduced the first wide area network (WAN) from Frankfurt to all national branches using analog multiplexers.
  • Designed and implemented the new data center in Frankfurt.
  • Managed over 40 employees.
  • Career progression within the bank: promoted to CIO and Authorized Officer (1988), CTO (1986), Deputy CIO (1984), Team Lead Software Engineering (1983).

Industry Experience

See where this freelancer has spent most of their professional time.

Experienced in Banking and Finance, Information Technology, Professional Services, Insurance, Government and Administration, and Aerospace and Defense.

Banking and Finance
Information Technology
Professional Services
Insurance
Government and Administration
Aerospace and Defense
Profile match chart

Business Area Experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Project Management, Product Development, Quality Assurance, Legal, and Strategy.

Information Technology
Project Management
Product Development
Quality Assurance
Legal
Strategy
Profile match chart

Summary

Diplom-Ingenieur with a focus on Business Informatics from TU Santiago, Chile. In my career I have held various positions in Germany, Chile and other Latin American countries (CEO, CIO, COO, CTO, CISO, ISO, Sr. PM, Sr. PMO, etc.). My experiences as CEO include founding and leading my own IT services company, where over a period of 6 years I employed over 120 engineers and completed large projects successfully. My leadership style has always been based on a holistic talent management approach. Because of my German and Chilean citizenship, my wife and I lived in the Federal Republic of Germany for the first time from April 1981 to the end of June 1992. After that we returned to Chile, became parents there, and 23 years later (June 2015) we returned to Germany. In 2016, as ISO at an IT services company in Karlsruhe, I achieved a dual certification in Information Security and Business Continuity Management within 14 months, my first ISO certifications in Germany. In addition to these activities I worked on the EU General Data Protection Regulation (GDPR). My entrepreneurial spirit led me back to self-employment, and since 2018 I have been a freelance Senior Management Consultant for Information Security and Business Continuity. To this end I was certified by a recognized German company as an ISMS Lead Implementer and ISMS Lead Auditor, also for organizations or institutions in the field of critical infrastructures (KRITIS).

Summary of successful projects and key results:  Makro Factory in Karlsruhe: As CISO I implemented and certified an ISMS and a BCMS for the CSP and IT services company within 14 months  SAP in Walldorf: As international Lead Audit Manager I enabled the Cloud Network Delivery area to pass all audits successfully (ISO 9001, ISO 27001, ISO 22301, C5, SOC, SOX and PCI-DSS)  COViS in Düsseldorf: The software development company had an oversized ISMS and IT staff worked almost exclusively on it, which led to dissatisfaction, friction and frustration among users. After aligning with the CEO and senior management, I adjusted the ISMS to the real needs. Since then the IT colleagues can satisfy their users and their needs  Federal Criminal Police Office in Wiesbaden (BKA): As ISO I helped the organization achieve certification of the new cloud services of the Police Service Platform to the international C5 standard and assisted in building and improving an ISMS according to ISO 27001 and the BSI IT-Grundschutz compendium  TÜV SÜD in Munich and Mannheim: Through my consulting and workshops on the EU GDPR, the company was able to start offering data protection services  German Navy via Thales Naval Kiel: As Security Engineer and ISO I helped certify the cyber & information security of the new frigates (F126) of the German Navy according to the German Military Security Accreditation Authority  University Hospital Düsseldorf: As ISO I (among other things) created the new IT strategy of UKD plus a security concept (BIA & DRP) for rebuilding IT systems; also prepared and successfully carried out a surveillance and recertification audit of the ISMS according to ISO 27001. As PMO; developed a security concept, conducted a proof of concept, evaluation, analysis up to procurement and implementation of a medical device monitoring security system to know which, how many and in what security state medical devices were connected to the campus network and to avoid further threats or attacks via the network  Daimler Truck Financial Services: As Senior PMO I created a master plan for the Cloud Data Center project, which enabled the company to have a clear overview of the project after one year  EnBW Energie Baden-Württemberg in Karlsruhe: As Senior IAM Specialist I work on improving the overall IAM concept and processes of the whole company

Skills

  • Information Security Governance, Risk & Compliance: Consulting & Management For The Implementation Of An Information Security Management System According To Iso 27001, A Business Continuity Management System According To Iso 22301 (Bia, Ria, Drp & Bsi It-gs 100-4 / 200-4), Dora And Nis2 Compliant

  • Gdpr Compliant With Use Of An Isms According To Iso 27001:2022 Plus Iso 27701

  • Bafin: Dora, Macomp & Xait Compliant; Marisk, Bait, Vait, Zag, Zait, Kait

  • Bsi: It-grundschutz & Compendium As The German Basis For Information Security

  • C5:2020 & Information Security: Cloud Computing Compliance Criteria Catalogue And Escloud

  • Setup, Rollout & Services Of Security Operation Center (Soc) & Siem, Ueba & Soar Platforms

  • Iam: Identity & Access Management, Cryptography & Key Management (Symmetric/asymmetric)

  • Information Security Audits According To Iso 27001, 27006, 19011, Gdpr & Bsi-gs

  • Audits For Energy Supply Companies (So-called Kritis), According To Bnetza Under § 11 Art. 1a Enwg

  • Project Management & Control Methods For Projects (Pgmp & Pmo According To Project Management Institute)

  • Itscm (Iso 27031), Itsm (Iso 20000), Sla, Crisis, Patch, Security Logging & Monitoring, Event, Incident, Problem Management, Etc.

  • Ercp Management: Enterprise Release, Configuration & Promotion/deployment, As Well As Release & Change Management (According To Itil & Cobit)

  • Strong Hands-on Mentality, High And Fast Analytical, Conceptual, Abstract And Logical Thinking

  • Service And Solution Oriented, Conceptual, Strategic, Self-driven, Goal-oriented And Highly Structured Working Style Based On The Pestel Framework

  • High Sense Of Responsibility, Self-motivation, Flexibility And Reliability

  • Creativity And Courage To Present And Drive New Ideas, Following The Open Innovation Principle

  • Strong Assertiveness And Convincing Communication With Users As A Contact Person

  • High Cooperation And Team Skills

  • Strong Process Thinking In The Overall Concept And Modeling Of Business Processes

  • Very Good And Strong Communication Skills And Social Competence

  • Confident And Convincing Presence

  • Experience Leading International Project Teams, Project Management, Pmo, Etc.

  • Audits In The European General Data Protection Regulation (Gdpr)

  • Information Security Egrc – Enterprise Governance, Risk Management & Compliance According To Iso/iec 2700x Series, Iso 22301, Iso 27031, Bsi It-grundschutz, Gdpr, Bdsg-new And According To "Deumilsaa" German Military Security Accreditation Authority (Zdv A-960/1, Etc.)

  • Bcm, Business Continuity Management According To Iso 22301, Iso 27031 (Bia, Ria, Drp) And Bsi It-grundschutz Standard 100-4/200-4, It-service Continuity Management (Itscm According To Iso 27031). Disaster Recovery Plans, Business Continuity Plans, It Emergency Concepts, Etc.

  • Kritis: Bsig § 8a(1a) And The Use Of Detection Systems For Attacks (Sza), Early Detection Of Cyber Attacks, Incident Response Management & Rebuilding Of It Systems

  • C5 & Escloud: Security Concepts For Using Cloud Services (Csp & Csc)

  • Iam: Identity And Access Management (Identity And Access Management)

  • Bafin: Dora, Macomp And Xait Compliant (Bait, Vait, Zait, Kait); Management Consulting For Credit Institutions, Marisk, Zag

  • Audits According To Iso 9001, Iso 27000, Iso 27001, Iso 27006, Iso 19011, Iso 22301, Soc, Sox, C5, Pci-dss And As Per Kritis Regulation Under § 11, Art. 1a Enwg And Bsi It-gs

  • Irbc According To Iso 27031; It Readiness For Business Continuity To Minimize Business-threatening It Risks And Implement Effective Countermeasures

  • Pm & Pmo According To Pmi, It-service Continuity Management According To Iso 20000 & Itil, Cobit, Cmmi

Languages

German
Native
Spanish
Native
English
Advanced
French
Advanced
Italian
Intermediate
...and 1 more

Education

Oct 1977 - Jun 1982

TU Santiago

Diplom-Ingenieur (TH/TU), major in Business Informatics · Business Informatics · Santiago, Chile

Certifications & licenses

CISA/CISM: Certified Information Systems & Security Lead Auditor according to ISO 27000 TÜV SÜD series and ISO 19011

TÜV SÜD

CISO: Chief Information Security Officer / Professional according to ISO 2700X series

TÜV SÜD

Certified ISMS Lead Auditor according to the IT Security Catalog of the Federal Network Agency (BNetzA)

Federal Network Agency (BNetzA)

Certified ISMS Lead Implementer according to ISO/IEC 2700X series

TÜV SÜD

Statistics

Experience

Total positions 25
Experience in Banking and Finance 28 y
Avg length 1 y 9 m
Longest experience 7 y 11 m

Global Experience

Countries worked in 2 (Germany, Chile)
Primary country Germany

Expertise

Recent roles Senior IAM Manager & Single Point of Contact for Information Security, Senior PMO for the CDC Project of Global IT, ISO – Senior Consultant Quality & Information Security
Main industries Banking and Finance, Information Technology, Professional Services
Main business areas Information Technology, Project Management, Product Development

Qualifications

Highest degree Master
Certifications earned 4

Profile

Created
Last Update
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Frequently asked questions

Do you have questions? Here you can find further information.

Where is Federico based?

Federico is based in Düsseldorf, Germany and prefers 100% remote projects.

What languages does Federico speak?

Federico speaks the following languages: German (Native), Spanish (Native), English (Advanced), French (Advanced), Italian (Intermediate), Portuguese (Intermediate).

How many years of experience does Federico have?

Federico has at least 41 years of experience. During this time, Federico has worked in at least 24 different roles and for 23 different companies. The average length of individual experience is 2 years and 7 months. Note that Federico may not have shared all experience and actually has more experience.

What roles would Federico be best suited for?

Based on recent experience, Federico would be well-suited for roles such as: Senior IAM Manager & Single Point of Contact for Information Security, Senior PMO for the CDC Project of Global IT, ISO – Senior Consultant Quality & Information Security.

What is Federico's latest experience?

Federico's most recent position is Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG.

What companies has Federico worked for in recent years?

In recent years, Federico has worked for EnBW Energie Baden-Württemberg AG, Daimler Truck Financial Services (DTFS), Gemeinsame Klassenlotterie der Länder (GKL), Northland Power Europa GmbH, and Huf Hülsbeck & Fürst GmbH & Co. KG.

Which industries is Federico most experienced in?

Federico is most experienced in industries like Banking and Finance, Information Technology, and Professional Services. Federico also has some experience in Insurance, Government and Administration, and Aerospace and Defense.

Which business areas is Federico most experienced in?

Federico is most experienced in business areas like Information Technology, Project Management, and Product Development. Federico also has some experience in Quality Assurance, Legal, and Strategy.

Which industries has Federico worked in recently?

Federico has recently worked in industries like Aerospace and Defense, Healthcare, and Professional Services.

Which business areas has Federico worked in recently?

Federico has recently worked in business areas like Information Technology, Project Management, and Quality Assurance.

What is Federico's education?

Federico holds a Master in Business Informatics from TU Santiago.

Does Federico have any certificates?

Federico has 4 certificates. Among them, these include: CISA/CISM: Certified Information Systems & Security Lead Auditor according to ISO 27000 TÜV SÜD series and ISO 19011, CISO: Chief Information Security Officer / Professional according to ISO 2700X series, and Certified ISMS Lead Auditor according to the IT Security Catalog of the Federal Network Agency (BNetzA).

What is the availability of Federico?

Federico is immediately available full-time for suitable projects.

What is the rate of Federico?

Federico's rate depends on the specific project requirements. Please use the Meet button on the profile to schedule a meeting and discuss the details.

How to hire Federico?

To hire Federico, click the Meet button on the profile to request a meeting and discuss your project needs.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Market avg: 824-984 €
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.