Skip to main content
Top expert badge
Recommended expert
Profile header background

Mahmoud Q.-Information Security & GRC Expert

Mahmoud Q. - Information Security & GRC Expert - profile avatar
Profile header overlay
Hamburg, Germany

Check rate

Experience

Aug 2026 - Present

Information Security & GRC Expert

GLG (Gerson Lehrman Group)

Position summary
Information Security & GRC Expert at GLG (Gerson Lehrman Group)
Industries
Banking and Finance
Business areas
Information Technology

As a Council Member at GLG (Gerson Lehrman Group), the world’s leading expert network, I provide organizations, investment firms, and consulting companies with expert discussions on demand – wherever specialized knowledge in information security, IT governance, and regulatory compliance is needed.

My assessments are based on many years of practical experience in highly regulated industries: from building and implementing information security management systems (ISMS according to ISO 27001), IT risk and vulnerability management, and business continuity (ISO 22301) to the practical implementation of European regulations such as DORA, NIS2, BAIT, and the Cyber Resilience Act (CRA).

The cooperation is project- and discussion-based. I provide decision-makers with a practical perspective gained from real-world experience on cyber risks, security governance, and operational resilience – exactly when it is needed.

Jan 2025 - Jul 2026

REQUIREMENTS MANAGER

ZAM eG

Position summary
REQUIREMENTS MANAGER at ZAM eG
Industries
Banking and Finance
Information Technology
Business areas
Information Technology
Product Development

Responsible for the functional architecture, requirements modeling, and further development of a multi-tenant SaaS platform for implementing regulatory IT governance and cyber resilience requirements (including DORA, BAIT, MaRisk, ISO 27001) for more than 750 banks in the cooperative financial group.

In this role, I act as the central interface between regulatory departments, software development (Atruvia AG / Forum GmbH), and the connected financial institutions, translating complex regulatory requirements into scalable system architectures and digital platform solutions.

Core responsibilities and contributions:

  • Architecture and end-to-end implementation of information security management systems (ISMS) according to ISO 27001 standards, including the development of assessment logic for protection-needs analyses and IT risk assessments.
  • Leading requirements engineering and the functional architecture of a regulatory platform supporting IT risk management and digital operational resilience in the banking sector
  • Development of complex functional and technical specifications (user stories, functional and technical concepts) for implementing regulatory requirements in scalable backend and frontend architectures
  • Design of the system architecture, including integration interfaces (REST APIs, JSON, CSV) for connecting central banking systems and data integration platforms
  • Design and specification of dynamic workflow mechanisms for managing regulatory processes, including automated escalations, quality gates, and governance controls across multiple platform modules
  • Development of complex data models for mapping ICT assets, business processes, and risk structures, as well as implementation of rule-based assessment logic for protection-needs analyses and risk assessments
  • Integration of regulatory requirements into platform logic according to the Compliance-by-Design principle, including functions for IT emergency management (BIA, RTO/RPO), incident management, and vulnerability management in line with DORA requirements
  • Design of a multi-tenant role and authorization model (RBAC) to ensure regulatory segregation of duties and secure data separation between banks, platform operators, and service providers
  • Functional management of external development service providers within agile development processes, including architecture workshops, solution evaluation, and defect management of complex system and integration issues
Aug 2024 - Dec 2024

Cyber Operations Manager

ING-Diba AG

Position summary
Cyber Operations Manager at ING-Diba AG
Industries
Banking and Finance
Business areas
Information Technology
Project Management

Responsible for the operational management and further development of central cyber security and IT risk management processes within the bank. In this role, I supported the integration of regulatory requirements into operational security processes and provided decision-relevant analyses and reports for the IT Security Control Board and the Chief Information Security Officer (CISO).

Core responsibilities and contributions:

  • Preparation and further development of strategic cyber security and IT risk reports for the IT Security Control Board and the CISO to support management decisions in information security
  • Planning, management, and coordination of IT security initiatives and projects to improve security architecture, operational resilience, and regulatory compliance
  • Establishment of structured reporting and monitoring mechanisms to assess the security status of IT systems, processes, and products against current information security standards
  • Supporting the bank in implementing regulatory requirements in the context of European cyber resilience regulation, particularly the Digital Operational Resilience Act (DORA) and bank-specific governance frameworks
  • Conducting comprehensive vulnerability management activities, including planning and managing regular security scans and analyzing identified vulnerabilities to improve the bank’s cyber resilience
  • Analyzing security-relevant system and network data and deriving specific measures to reduce identified cyber risks
  • Close cooperation with IT security, compliance, and infrastructure teams to integrate security and risk requirements into existing operational and governance processes

Selected contributions:

  • Development of high-quality management reports for the CISO and security committees to improve transparency and the basis for decisions in cyber risk management
  • Improvement of vulnerability management processes through structured analysis of security-relevant scan results and derivation of specific risk reduction measures
  • Support for the bank in integrating regulatory requirements into existing security and risk management processes to strengthen digital operational resilience
Jul 2023 - Feb 2024

Senior Security Consultant

BearingPoint GmbH

Position summary
Senior Security Consultant at BearingPoint GmbH
Industries
Banking and Finance
Insurance
Business areas
Information Technology
Product Development

Advised financial institutions and companies on implementing European cyber and IT regulations by developing digital compliance and regulatory technology solutions. In this role, I developed specialized analysis and compliance tools for managing ISMS processes, helping financial institutions assess existing ISO 27001 and BAIT requirements and align them seamlessly with new DORA requirements.

DORA Tool:

  • Development of a comprehensive DORA tool spreadsheet that helps financial institutions assess and improve their compliance with the Digital Operational Resilience Act (DORA). The tool also includes sections helping institutions consider existing BAIT, VAIT, and ISO27001 requirements and align them with DORA. It provides clear guidance for companies that have already implemented BAIT, VAIT, or ISO27001 in order to minimize the additional effort required for DORA compliance.
  • Compliance checklist: A detailed checklist covering key areas such as IT risk management, incident reporting, and third-party risk management. It includes specific sections explaining how existing BAIT, VAIT, and ISO27001 measures can be expanded to meet DORA requirements.
  • Assessment dashboard: A radar chart visualizing the organization’s compliance with DORA requirements, including an overview of BAIT, VAIT, and ISO27001 components that are already covered.
  • Compliance status evaluation: Enables organizations to determine their current position regarding DORA compliance and shows which BAIT, VAIT, and ISO27001 measures have already been integrated.
  • Identification of improvement areas: Helps organizations identify areas where compliance could be strengthened, taking already implemented BAIT, VAIT, and ISO27001 requirements into account.
  • Development planning: Supports the creation of an action plan to improve compliance by showing clear steps for integrating DORA into existing BAIT, VAIT, and ISO27001 frameworks.
  • The tool serves as a valuable instrument for organizations seeking to increase their digital operational resilience without having to start from scratch.
  • It helps identify and mitigate risks and ensures compliance with legal obligations.
  • The spreadsheet provides a framework for managing organizations’ digital operational resilience and facilitates compliance with DORA requirements through targeted integration with existing BAIT, VAIT, and ISO27001 policies.

WEB APPLICATION FOR DORA ITS (Implementing Technical Standards) - REGISTER OF INFORMATION:

  • Development of an advanced digital platform that simplifies and improves the exchange and communication of data between various stakeholders in the financial sector in accordance with the Digital Operational Resilience Act (DORA) and its implementing technical standards (ITS). The web application comprehensively supports all seven DORA domains to ensure that financial institutions fully meet the requirements.
  • The web application was developed using Python, a powerful programming language that enables complex requirements to be implemented efficiently. This development language made a major contribution to creating a robust and adaptable platform.
  • Financial institutions (banks, insurers, charitable organizations): These provide various financial services and need efficient management of their ICT services.
  • Regulatory authorities: Responsible for monitoring compliance with financial regulations.
  • Third-party ICT service providers (e.g. BearingPoint): Ensure the smooth operation and compliance of financial institutions’ IT infrastructure.
  • Auditors and compliance teams: Review compliance of data and processes with the defined standards.
  • Centralized repository: Ensures transparency and compliance in the ICT risk management domain.
  • Optimized information exchange: Supports regulatory oversight and facilitates communication in the incident management domain.
  • Compliance checklists and assessment dashboards: Visualize compliance with DORA requirements and support implementation in the domains of operational resilience testing and third-party risk management.
  • Information Sharing Arrangements: Promote the exchange of threat information and best practices to strengthen information security and cyber resilience measures.
  • The web application aims to create a coherent and efficient environment for all parties involved. It ensures that financial institutions can manage their ICT services in line with DORA standards, while authorities and auditors can effectively monitor and assess operations. This helps reduce risks and ensure digital operational resilience.

NIS2 Directive Tool:

  • The project aims to develop a tool that significantly simplifies implementation of the NIS2 Directive as set out in European Union legislation. The tool is designed in particular to make the complex processes associated with NIS2 compliance more accessible and manageable for organizations.
  • Ease of use: Clear structuring and guidance within the tool provide simple access to the NIS2 guidelines.
  • Compliance monitoring: The tool provides an overview of the steps required to meet NIS2 standards and supports continuous compliance.
  • Companies and organizations within the EU that fall under the NIS2 Directive and must align their processes with the new security standards.
  • Simplification of the NIS2 Directive implementation processes.
  • Improved clarity and manageability of compliance requirements.

CRA Compliance Tool:

  • Development of an innovative tool that enables companies to implement the Cyber Resilience Act (CRA) quickly and efficiently. The tool is designed to help companies understand, assess, and implement the CRA’s complex requirements in order to strengthen their digital resilience and security.
  • Companies in all industries: Specifically designed for organizations offering digital products or services in the EU that must comply with CRA requirements.
  • Compliance and security teams: Supports professionals responsible for complying with cyber security regulations and implementing security measures.
  • IT and cyber security experts: Provides technical support and guidance for implementing security practices according to the CRA.
  • Compliance management dashboard: A user-friendly dashboard providing an overview of CRA compliance status and highlighting areas for improvement.
  • Automated CRA checklist: A comprehensive, automated checklist mapping CRA requirements and guiding companies through the self-assessment process.
  • Risk assessment module: Enables the identification and assessment of risks associated with digital products and services in line with CRA guidelines.
  • Incident management and reporting tool: Provides tools for recording, managing, and reporting security incidents as required by the CRA.
  • Training and awareness modules: Promote understanding of and compliance with the CRA through targeted employee training programs.
  • The CRA compliance tool aims to enable companies in the EU to proactively improve their cyber resilience and simplify CRA compliance. By providing a clear framework and practical tools, it supports organizations in implementing the required security standards, minimizing risks, and preparing for future cyber security challenges.

Professional achievements:

  • Development of compliance assessment tools such as the DORA tool, which supported organizations in assessing and improving their ability to comply with digital security standards.
  • Design of a compliance dashboard that visualizes the current compliance status and highlights areas requiring improvement.
  • Improvement of compliance management by providing interactive tools to support organizations’ security processes.
Dec 2022 - Apr 2023

IT Security Consultant

EDEKA Digital GmbH

Position summary
IT Security Consultant at EDEKA Digital GmbH
Industries
Information Technology
Retail
Business areas
Information Technology

Responsible for the operational management of central cyber security processes and the further development of the security architecture within the company’s digital platform and cloud infrastructure.

In this role, I supported the organization in strengthening its cyber resilience by analyzing security-relevant risks, developing structured security processes, and advising management and security committees on strategic security measures.

Core responsibilities and contributions:

  • Operational management and monitoring of cyber security processes, including incident detection, analysis of security-relevant events, and coordination of response measures as part of a structured 24/7 security operation
  • Design and establishment of a central cyber security war room for effective coordination of security incidents and crisis situations in the event of critical infrastructure failures
  • Conducting security assessments for cloud-based systems and platform projects to ensure compliance with defined security standards and architecture requirements
  • Analysis and continuous improvement of vulnerability management to identify and reduce security-relevant vulnerabilities within the IT infrastructure
  • Development and assessment of IT security policies and security-relevant architecture requirements for platform technologies and IT systems
  • Advising management and security committees (including the Security Board and information security officers) on relevant cyber security measures, risks, and strategic security decisions

Selected contributions:

  • Establishment of a central cyber security war room to improve response capabilities for security-critical events and infrastructure failures
  • Conducting structured security assessments for cloud initiatives to improve the security architecture of the digital infrastructure
  • Improvement of security processes by optimizing vulnerability management and incident response structures
Nov 2021 - Nov 2022

IT Security Consultant

Yanmar GmbH (Avanace Consulting GmbH)

Position summary
IT Security Consultant at Yanmar GmbH (Avanace Consulting GmbH)
Industries
Manufacturing
Business areas
Information Technology

Responsibilities:

  • ISMS & development of information security policies: Establishment and further development of the Information Security Management System (ISMS) in accordance with ISO 27001, as well as formulation of information security policies that serve as the basis for security practices within the company.
  • Risk management: Identification, assessment, and management of information security risks.
  • Vulnerability assessment and threat analysis: Conducting vulnerability analyses and integrating Threat Intelligence to detect potential threats.
  • Cloud security: Implementing security measures to ensure the security of cloud-based services and infrastructures.
  • Incident management: Developing and implementing processes for the effective handling of security incidents.
  • Third-party management: Reviewing and managing the security practices of third parties to minimize risks.
  • Business Continuity Plan: Developing strategies to maintain critical business processes in the event of a security incident or disaster.
  • Disaster recovery planning: Creating contingency plans for the rapid recovery of IT systems and data after an outage.

Professional achievements:

  • Developing new information security policies and implementing them in various systems, which improved organizational security management.
  • Implementing risk management strategies and developing business continuity and system recovery plans, which increased the company's resilience to threats.
Feb 2019 - Nov 2021

IT Security Specialist

ExxonMobil Deutschland GmbH – (SSE Technology)

Position summary
IT Security Specialist at ExxonMobil Deutschland GmbH – (SSE Technology)
Industries
Energy
Business areas
Information Technology

Responsibilities:

  • Development and implementation of security policies: Creating and enforcing policies and procedures for systems security management based on industry best practices, including managing user system access.
  • Disaster recovery plans: Working with IT staff to develop and implement disaster recovery plans for IT systems, with a focus on security aspects.
  • Monitoring and investigation: Leading investigations into unusual activities and ensuring continuous communication with company management.
  • Security assessments: Conducting regular internal security reviews of the IT environment.
  • Review of security controls: Quarterly certification of the effectiveness of information security controls.
  • Vulnerability management: Conducting regular vulnerability analyses and coordinating the remediation of identified risks.
  • SIEM monitoring: Working closely with Managed Security Service Providers (MSSPs) in the daily operation of Security Operations Centers and in monitoring through SIEM solutions.
  • Security training: Conducting regular training sessions for employees to ensure compliance with security policies.

Professional achievements:

  • Implementing recovery plans for systems and data to ensure business continuity.
  • Managing the Security Operations Center (SOC) and analyzing security events with SIEM tools, which improved responsiveness to security incidents.
  • Conducting regular security training for employees to increase cybersecurity awareness within the organization.
Dec 2017 - Jan 2019

Secure Website Developing

Alstercloud GmbH

Position summary
Secure Website Developing at Alstercloud GmbH
Industries
Information Technology
Business areas
Customer Service
Information Technology
Product Development

Responsibilities:

  • Customer support and ticket management: I was the first point of contact for support requests, which I carefully recorded in the service desk system. This included receiving, documenting, and initially analyzing requests.
  • Analysis and classification of support requests: I independently analyzed incoming requests, classified them according to their urgency and complexity, and, where necessary, forwarded them to 3rd-level support for further processing.
  • Securing WordPress and self-programmed websites: When creating new WordPress websites, I was responsible for securing them by installing security plugins and adapting the code to bring security to a higher level. For self-programmed websites, I reviewed the code to ensure that there were no security vulnerabilities. I also regularly reviewed older websites and secured the websites of customers who were specifically seeking security improvements.

Professional achievements:

  • Developing and securing customized websites with WordPress and other programming techniques, which increased the security and reliability of the websites.
  • Providing outstanding technical support and solving complex problems, which contributed to improved customer satisfaction.
Jul 2017 - Dec 2017

IT support: 1st and 2nd level.

Impressive Tech Company

Position summary
IT support: 1st and 2nd level. at Impressive Tech Company
Industries
Information Technology
Business areas
Customer Service
Information Technology
Logistics

Responsibilities:

  • Field and in-house work: Coordinating and working closely with local contacts both within the company and at customer sites to ensure smooth IT service.
  • Service-oriented user support: I provided users with comprehensive support for all IT-related questions to ensure optimal use of IT resources.
  • Logistics and installation: I was responsible for transporting and installing systems at various customer sites, including dismantling old equipment and carrying out setup and maintenance work.
  • Manual software configuration: I individually configured each software solution according to the specific requirements of the customers.
  • On-site support: I provided direct support to users at their workstations to ensure that their IT needs were met efficiently and effectively.
  • Documentation and system maintenance: I was responsible for carefully documenting all processes and regularly maintaining the IT systems to ensure high system availability and performance. These varied tasks required not only technical expertise but also strong organizational skills and a high degree of flexibility to meet different requirements and situations.

Professional achievements:

  • Improving system performance by using tools such as Nagios and SolarWinds for network monitoring and ensuring system stability.
  • Providing direct technical support to employees and resolving technical issues, which reduced system downtime.
May 2016 - Jul 2017

SBB Kompetenz gGmbH

Position summary
Industries
Education
Oct 2015 - Jan 2016
Damascus, Syrian Arab Republic

IT Customer Support for the 1st and 2nd Level

Syriatel Holding, Damascus, Syria

Position summary
IT Customer Support for the 1st and 2nd Level at Syriatel Holding, Damascus, Syria
Industries
Telecommunication
Business areas
Customer Service
Information Technology

Tasks:

  • Initial contact and problem analysis: As the first point of contact for employees' IT requests, I analyzed and classified incoming support tickets to enable quick solutions.
  • Resolving IT issues: I actively handled employees' requests and problems, resolved them independently, or forwarded more complex cases to specialized teams. I used programs such as BMC Remedy for ticket management, SolarWinds for network monitoring, and Active Directory for user and access management.
  • Technical support and consulting: I provided comprehensive technical support and advice to employees to effectively meet their needs and requirements, especially in managing workplace technologies and IT tools.
  • Training and user support: To promote IT skills, I regularly conducted training sessions for employees and supported them in making optimal use of IT resources.
  • Monitoring and maintenance: I monitored the performance of IT systems using tools such as Nagios and performed preventive maintenance to ensure high system availability.
May 2013 - Dec 2015
Damascus, Syrian Arab Republic

Mathematics Teacher for the Tenth and Eleventh Grades

Ibn Al-Haissam High School in Damascus, Syria

Position summary
Mathematics Teacher for the Tenth and Eleventh Grades at Ibn Al-Haissam High School in Damascus, Syria
Industries
Education

Tasks:

  • Conducting lessons: I conducted clearly structured and interactive mathematics lessons aimed at sparking students' interest and enthusiasm for the subject.
  • Promoting critical thinking: I encouraged students to analyze mathematical problems critically and develop independent solutions.
  • Assessment and feedback: I assessed students' performance through regular tests and homework and provided constructive feedback to support and promote their learning.
  • Working with and advising parents: I maintained an open dialogue with parents about their children's progress and advised them on further support opportunities.

Industry experience

See where this freelancer has spent most of their professional time.

Experienced in Education, Information Technology, Banking and Finance, Energy, Manufacturing, and Insurance.

Education
Information Technology
Banking and Finance
Energy
Manufacturing
Insurance
Profile match chart

Business area experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Product Development, Customer Service, Project Management, and Logistics.

Information Technology
Product Development
Customer Service
Project Management
Logistics
Profile match chart

Summary

Information Security, Governance & Compliance Consultant specializing in translating European regulations into robust management systems, controls, and audit-ready evidence structures – in the regulated environments of banks, insurers, critical infrastructure, and industry.

My work follows one guiding principle: A regulatory assessment is only as valuable as its traceable reasoning. A maturity level without evidence, a control without a defined form of evidence, and a contingency plan without tested dependencies can withstand neither an audit nor a real emergency.

This standard runs through my career: At BearingPoint, I converted requirements from DORA, NIS2, and the Cyber Resilience Act into analysis and assessment tools instead of reports. At ZAM eG, this became the functional architecture of a regulatory platform for more than 750 banks – with rule-based assessment logic, quality gates, and audit trails. At ING-DiBa, I was responsible for cyber risk reporting for the CISO and IT Security Control Board.

Professional focus areas: ISMS according to ISO 27001 · IT governance and GRC · DORA, BAIT, VAIT, MaRisk, NIS2, CRA, BSI IT-Grundschutz · Outsourcing and third-party management · Business continuity (ISO 22301, BIA, RTO/RPO) · Vulnerability management · Requirements management at the interface between regulation and IT · AI-supported development and governance of AI systems.

  • Development of compliance assessment tools such as the DORA tool, which supported organizations in assessing and improving their ability to comply with digital security standards.
  • Design of a compliance dashboard that visualizes the current compliance status and highlights areas requiring improvement.
  • Improvement of compliance management by providing interactive tools to support organizations’ security processes.

Skills

  • Isms According To Iso 27001, Iso 27002, Iso 27004, Iso 27005, Iso 27032, Iso 27035 And Iso 27036
  • It Governance And Grc
  • Dora, Dora Its – Register Of Information, Nis2 Directive, Cyber Resilience Act, Bait By Bafin, Vait By Bafin, Marisk, Bsig (Nis2 Implementation), Bsi Kritis And Bsi It-Grundschutz
  • Iso 22301, Iso 31000, Iso 19011, Pci-Dss, Nist, Sans, Gdpr And Dsgvo
  • Eu Ai Act (Vo (Eu) 2024/1689)
  • Ai-Supported Software Development, Prompt Engineering, Context And Rule-Set Design For Llms, Verification Of Ai Results, Mandatory Review Of Generated Code, Data Separation From Models, Eu Ai Act – Risk Classification, Ai Governance In The Isms Context, Prompt Injection And Llm Risks, Sbom And Vulnerability Matching, Deterministic Rule Sets Instead Of Llms, Ai Inventory (Shadow Ai)
  • Python Together With Microsoft Excel For Developing Specialized Tools For It Security And Data Analysis
  • Microsoft Office 365, Windows, Macos, Ios, Kali Linux
  • Bmc Remedy, Solarwinds, Jira Service Management And Servicenow
  • Trello, Jira Software, Microsoft Teams, Zoom, Cisco Webex, Goto Meeting, Teamviewer, Aqua-Cloud, Msra, Ultra Viewer, Asana, Monday, Slack, Zapier, Confluence, Filezilla, Winscp And Cyberduck
  • F-Secure, Crowdstrike, Norton, Mcafee And Kaspersky
  • Symantec 2010 And Veeam
  • Azure And Aws
  • Citrix, Virtualbox And Vmware
  • Fortinet And Palo Alto
  • Visual Studio Code And Notepad++
  • Python, Javascript, Html, Css, Batch Scripting And Powershell Scripting
  • Active Directory, Exchange Server, Sccm, Dhcp, Dns, Group Policy And Windows Server
  • Vlan, Lan, Qos, Acls, Sd-Wan, Mpls, Wlan, Configuration And Wan
  • Solarwinds, Prtg And Zabbix
  • Business Continuity Planning, Disaster Recovery Planning, Risk Management, Defect Management, Test Management And Soc Analysis
  • Backup & Recovery, Capacity Planning, Change Management, Os Security, Patch Management, Installation Checklists, Anti-Virus Updating, License Management, Logging & Auditing, Password Policy, Clock Synchronization, User Access Management, Asset Tagging, Ups & Generator, Spares, Disposal, Internet Access, Technical Vulnerabilities, Incident Management, System Development, Monitoring, Server Room / Data Center
  • Manageengine Endpoint Dlp, Hashcalc, Rapid7, Cryptool.Com, Cyberark, Forum Suit, Fortify And Baramundi
  • Virustotal.Com, Malware Bazaar, Abuseipdb.Com, Phishtank.Org, Alienvault Otx, Bazaar.Abuse.Ch, Seclists, Cve.Mitre.Org, Any.Run, Cyberchef, Deepbluecli And Wireshark
  • Immunity Debugger, Sublist3r, Shodan.Io, Osint Framework, Nmap, Metasploit, Burp Suite, John The Ripper And Threat Modelling
  • Tenable.Sc And Tenable One
  • Ibm Qradar And Splunk
  • Github, Xerox Printers Configuration, Hp Printers Configuration, Sap „Entry Level“, Wordpress, Xampp And Putty
  • Motherboards, Processors (Cpus), Memory (Ram), Storage (Hdds/Ssds), Graphics Cards (Gpus), Power Supplies, Cooling Systems And Laptop-Specific Components
  • Operating System Issues, Software Installation & Updates, Hardware Failures, Network Connectivity, Security And Virus Issues, Driver Conflicts, Data Recovery And Performance Optimization
  • Ability To Communicate Effectively And Clearly With All Levels Of Employees, Stakeholders, And Suppliers.
  • Ability To Lead Initiatives And Manage Them Independently And With Professional Discretion.
  • Ability To Interact With Multiple Vendors To Achieve Integrated Solutions.
  • Ability To Work During The Day, In The Evening, And On Weekends As Required.
  • Ability To Respond At Short Notice Or Without Advance Notice To Urgent Situations Outside Standard Hours.
  • Proven History Of Strong Customer Service For Various Internal And External Stakeholders.
  • Ability To Work In A Team Environment And Maintain Confidentiality.
  • Ability To Conduct Troubleshooting Sessions And Present The Root Cause And Solution To Senior Management And Leadership.
  • Ability To Identify Issues Quickly And Escalate Them When Needed.
  • Excellent Problem-Solving Skills.

Languages

Arabic
Native
German
Advanced
English
Advanced

Education

Dec 2011 - Jul 2015

Faculty of Applied Sciences at the University of Damascus

Bachelor · Applied Mathematics and Information · Damascus, Syrian Arab Republic

Certifications & licenses

AWS Certified Solutions Architekt – Professional

Amazon

PCAP – Certified Associate in Python Programming

Python Institute

Statistics

Experience

Total positions 12
Experience in Education 4 y
Avg length 1 y
Longest experience 2 y 9 m

Global experience

Countries worked in 1 (Syrian Arab Republic)
Primary country Syrian Arab Republic

Expertise

Recent roles Information Security & GRC Expert, REQUIREMENTS MANAGER, Cyber Operations Manager
Main industries Education, Information Technology, Banking and Finance
Main business areas Information Technology, Product Development, Customer Service

Qualifications

Highest degree Bachelor
Certifications earned 7

Profile

Member since
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Frequently asked questions

Have questions? Find more information here.

Mahmoud is based in Hamburg, Germany.

Mahmoud speaks the following languages: Arabic (Native), German (Advanced), English (Advanced).

Mahmoud has at least 12 years of experience. During this time, Mahmoud has worked in at least 10 different roles and for 12 different companies. The average length of individual experience is 1 year. Note that Mahmoud may not have shared all experience and actually has more experience.

Based on recent experience, Mahmoud would be well-suited for roles such as: Information Security & GRC Expert, REQUIREMENTS MANAGER, Cyber Operations Manager.

Mahmoud's most recent position is Information Security & GRC Expert at GLG (Gerson Lehrman Group).

In recent years, Mahmoud has worked for GLG (Gerson Lehrman Group), ZAM eG, ING-Diba AG, BearingPoint GmbH, and EDEKA Digital GmbH.

Mahmoud is most experienced in industries like Education, Information Technology, and Banking and Finance. Mahmoud also has some experience in Energy, Manufacturing, and Insurance.

Mahmoud is most experienced in business areas like Information Technology, Product Development, and Customer Service. Mahmoud also has some experience in Logistics and Project Management.

Mahmoud has recently worked in industries like Banking and Finance, Energy, and Information Technology.

Mahmoud has recently worked in business areas like Information Technology, Product Development, and Project Management.

Mahmoud holds a Bachelor in Applied Mathematics and Information from Faculty of Applied Sciences at the University of Damascus.

Mahmoud has 7 certificates. Among them, these include: AWS Certified Solutions Architekt – Professional, AZ-500 (Azure Security Engineer Associate), and CCNA (Cisco Certified Network Associate).

Mahmoud will be available part-time from November 2026.

Daily rate distribution

0% 25% 50% 75% 100%
20% of experts charge less than €800 per day.
10% of experts charge between €880 and €960 per day.
50% of experts charge between €960 and €1040 per day.
10% of experts charge between €1040 and €1120 per day.
10% of experts charge €1120 or more per day.
<€800 €880-​960 €960-​1040 €1040-​1120 €1120+

The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 952 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 976 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 3 Oct 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.