Jens B.-Senior Information Security Consultant | ISMS | IT GRC | DORA | NIS-2

Check rate
Experience
Senior Cyber Security Consultant
Brennscheidt IT Consulting
KEY PROJECTS
Since 05/2023 | Bank | Senior Cyber Security Consultant (external)
- Advising and guiding the system owners in creating and further developing IT security concepts
- Coordinating and tracking the remediation of findings from reviews and audits
- Advising on the implementation of regulatory requirements for information security
10/2023 – 02/2024 | Fintech | Project Manager (external)
- Project management to close various audit gaps in the field of information security
- Conceptual design and implementation of an information security management system based on ISO/IEC 27001
- Creation and further development of ISMS documents and processes
IT GRC Manager
Barmenia Versicherungen
Conceptual development and continuous improvement of IT GRC management
Creation of policies and provision of methods and tools
Advising on the conceptual and operational implementation of regulatory requirements (including VAIT, DORA)
Delivering training on IT GRC topics (especially VAIT)
Building an IT risk management system and IT governance framework
Risk Manager
Volkswagen Infotainment GmbH
Steering, optimizing, and operationalizing the company-wide risk management process
Structural setup, operationalization, and continuous improvement of the internal control system (ICS)
Planning and running risk workshops
Coordinating, monitoring, and following up on risk treatment measures
Performing effectiveness checks
Building a company-wide internal control system (ICS)
Head of IT Security and Risk Management | IT Security Officer
Polizei NRW (LZPD NRW)
Leading and managing the sub-department and acting as deputy head of department
Advising the department and agency management on IT security issues
Analyzing and assessing the IT security situation
Integrating IT security into organization-wide workflows and processes
Building and optimizing IT security management and existing processes
Developing, adapting, implementing, and controlling IT security policies
Central expert unit for operational information security at the NRW police
Member of the IT Security Commission (KomSi) of the Subcommittee on Information and Communications (UA IuK) of Working Group II (AK II) of the Conference of Interior Ministers
Leading an information security review at another state police force
Establishing a quality management system for security concepts of subordinate authorities
Project lead for the introduction of the ISMS tool HiScout
Project lead for adapting security concepts to BSI Standards 200-X
IT Security Manager
IKB Deutsche Industriebank AG
Advising IT management on IT security issues
Identifying and coordinating the implementation of IT security requirements
Managing IT providers in the IT security environment
Coordinating IT disaster recovery management and carrying out disaster recovery tests
Coordinating the risk management process for the IT area
Operational Risk Manager for the IT area
Project lead for implementing network segmentation in the LAN
Requirement coordination and consulting on the implementation of BAIT requirements
Performing protection needs assessments for the IT area
Senior Consultant Security Management
secunet Security Networks AG
Development of customer-specific security concepts
Carrying out organizational security and risk analyses
Introduction and review of information security management systems
Leading projects for security analyses in the areas of ISMS consulting and Mobile Security
Project work for the certification and accreditation of a provider according to ISO 27001 based on IT Baseline Protection, the De-Mail Act and the Federal Data Protection Act (BDSG)
IT Security Employee
comdirect bank AG
Handling security-related issues
Initiating and supporting IT security projects
Conceptual further development of the security infrastructure
Permanent member of the BdB phishing project group
Deputy Data Protection Officer
Project lead for the introduction of a Web Application Firewall
Project work for the introduction of mobile TAN and 3D Secure (Verified by Visa)
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Information Technology, Government and Administration, Insurance, and Automotive.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Project Management, Quality Assurance, Audit, and Legal.
Summary
I have been working in information security for more than 18 years. My experience includes internal line responsibility, external consulting, and the auditor’s perspective - shaped by roles at several banks, an insurance company, in the security-critical environment of the NRW police, and for operators of critical infrastructure.
My focus is on building, further developing, or stably running information security in regulated companies in a structured way and implementing regulatory requirements so that they work in day-to-day business. My support ranges from consulting assignments and project support to taking on temporary responsibility as an Interim ISB or CISO.
From a professional point of view, I work especially with ISO 27001 and BSI IT Baseline Protection, as well as on implementing regulatory requirements from DORA, NIS-2, and KRITIS. In doing so, I combine the organization’s perspective with the requirements that also have to stand up in an audit later.
I am looking for demanding consulting and interim assignments where information security should be implemented effectively and anchored for the long term.
Skills
My Strengths Are In Building, Further Developing, And Operating Isms Based On Iso 27001 And Bsi It Baseline Protection, As Well As In Implementing Regulatory Requirements From Dora, Nis-2, And Kritis. This Includes Gap Analyses, Audits, Grc Consulting, And Interim Assignments As Isb, Ciso, Or Risk Manager.
What Sets Me Apart Is The Combination Of Internal Line Responsibility, External Consulting, And The Auditor’S Perspective. I Know Both Sides - Implementation In Day-To-Day Business And The Requirements That Really Have To Pass An Audit.
Languages
Education
University of Siegen
Diploma in Computer Science · Applied Computer Science · 1.4
Certifications & licenses
NIS-2 Expert
TÜV
ISO 20000 Foundation
Audit Procedure Competence (§ 39 BSIG, formerly § 8a)
Statistics
Experience
Global experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Jens is based in Bochum, Germany and can operate in on-site, hybrid, and remote work models.
Jens speaks the following languages: German (Native), English (Intermediate).
Jens has at least 18 years of experience. During this time, Jens has worked in at least 7 different roles and for 7 different companies. The average length of individual experience is 3 years and 7 months. Note that Jens may not have shared all experience and actually has more experience.
Based on recent experience, Jens would be well-suited for roles such as: Senior Cyber Security Consultant, IT GRC Manager, Risk Manager.
Jens's most recent position is Senior Cyber Security Consultant at Brennscheidt IT Consulting.
In recent years, Jens has worked for Brennscheidt IT Consulting and Barmenia Versicherungen.
Jens is most experienced in industries like Banking and Finance, Information Technology, and Government and Administration. Jens also has some experience in Insurance and Automotive.
Jens is most experienced in business areas like Information Technology, Project Management, and Quality Assurance. Jens also has some experience in Audit and Legal.
Jens has recently worked in industries like Banking and Finance, Information Technology, and Insurance.
Jens has recently worked in business areas like Information Technology, Audit, and Project Management.
Jens holds a Master in Applied Computer Science from University of Siegen.
Jens has 6 certificates. Among them, these include: NIS-2 Expert, CISM, and ISO 20000 Foundation.
Jens is immediately available part-time for suitable projects.
Daily rate distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 15 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Senior Cyber Security Consultant
Nearby freelancers
Professionals working in or nearby Bochum, Germany
