Matthias K.-IT Project Management | IT Security & Governance | ISO 27001 / DORA / BaFin | Stakeholder Management | Workshop Facilitation |

Check rate
Experience
Business Owner
AKM
Management of several MFA methods for centralized authentication within a group. Interface between various stakeholders such as Support, Finance, Developers, and Security departments. Assessment of compliance requirements such as KRITIS. Budget controlling and monitoring of KPIs and SLAs. Support with internal and external audits on MFA topics and with connecting new systems. Review of operational documentation. Participation in steering committees and leadership of service review meetings and decision-making committees.
Tools/Frameworks: FIDO, Yubikey, Veridium, BSI Grundschutz, NIST
Head of MFA Services (Group >100,000 employees)
Context:
Responsibility for group-wide multi-factor authentication services within a security-critical IAM architecture.
Responsibilities:
- Overall responsibility for management, further development, and operation
- Definition of roadmaps and strategic target visions
- Management of stakeholders (Security, IT, Finance, Providers)
- Ensuring compliance requirements (DORA, BAFIN)
- Facilitation of coordination and decision-making meetings
Result / Impact:
- Sustainable increase in the level of security
- Standardization of authentication processes
- Improved manageability through KPI- and SLA-based governance
Tools & Methods: EntralD, PIM, FIDO, YubiKey, SLA/KPI, RASIC, IT-Governance, ISO 27001
IAM Analyst
AKM
Coordination between the individual stakeholders and review of the implementation of all VAIT and DORA requirements concerning PAM. Analysis of access rights, including SoD, RBAC, and requirements for CIF applications. Use and adaptation of AI support for document analysis. Participation in role modeling, taking RBAC and SoD as well as Joiner and Mover processes into account in order to prevent unauthorized duplicate assignment of access rights. Review and management of the access rights structure in One Identity. Adjustment of access rights attribution. Conducting and facilitating workshops with business owners on role modeling, PAM analysis and implementation, and SoD requirements. Comparison and analysis of different systems such as Archer, AdolT, and One Identity, as well as review of the implementation of relevant VAIT and DORA requirements. Reviewing and writing access rights concepts.
IT Security Analyst
APKV
- Support for the CIO during an external audit by BAFIN
- Preparation of recovery plans and presentations for the audit
- Review and resolution of audit findings
- Analysis of recovery after the Crowedstrike incident
Risk Analyst
A-DE
- Review of applications and processes for their risks
- Preparation of risk assessment matrices
Tools/Frameworks: Archer and Presto
PAM Assessment & Security Audit (Group >100.000 MA)
Atech
Context:
Group-wide security assessment to evaluate privileged access and derive measures.
Responsibility:
- Leading the assessment, including the professional management of a team
- Conducting workshops and coordination meetings with specialist departments
- Preparing management reports up to C-level
- Deriving and prioritizing measures
- Documentation for regulatory audits (DORA)
Result / Impact:
- Identification of critical security risks
- Clear basis for management decisions
- Sustainable improvement of IAM and security governance
Tools & methods: One Identity, PAM, SoD, Jira, Archer, ISO 27001, VAIT, risk management
IT Security Expert
metafinanz GmbH
- Industry: Insurance
- Managing several MFA methods for central authentication within a group
- Interface between support, financial accounting, developers, and security departments
- Budget controlling and monitoring of KPIs and SLAs
- Reviewing operational documentation
- Coordinating between individual stakeholders during the introduction of PAM solutions
- Reviewing the implementation of all VAIT and DORA requirements relating to PAM
Project Manager IAM Integration (Public Sector, >14.000 User)
Staatliches Institut
Context:
Migration of a large department to a central IAM platform under high time pressure.
Responsibility:
- Overall project management, including planning and roadmap
- Managing a team (>6 people)
- Facilitating workshops and coordination meetings
- Harmonizing processes across organizational units
- Ensuring implementation on schedule
Result / Impact:
- Successful migration without operational interruption
- Significant improvement in governance and transparency
- High stakeholder acceptance
Tools & methods: One Identity, SAP, process management, stakeholder management, RASIC
IAM Consultant
Computacenter AG & Co. oHG
- Industry: Various
- Integration of a department with over 14.000 users into a new IAM system
- Analysis of all processes of the connected departments and applications
- Comparison and adjustment of processes to the new IAM system
- Coordination of different stakeholders (department heads, interest groups, executive management)
- Test design and testing for a logistics customer: concept for integrating new users into the IAM system, role and permission model, test concepts, test cases, creation of test data, functional test execution, data adjustment and validation in Oracle databases, troubleshooting in Objectbrowser and Manager
- Deployment, test, and project management for a machine manufacturer: reviewing and executing automated test cases, adapting scripts for test automation, documenting test results, coordinating with developers
Test Manager
Demirtag Consulting
- Coordinating and supporting a five-member test team
- Consulting in the area of GDPR and the department's strategic direction
- Managing cross-component tests
- Creating and managing test cases
- Managing a company-wide test environment for mobile testing (including MDM) and X-browser testing
- Sales of test environments and resources
Sub-Project Manager
catenate
- Managing and organizing an integration environment for BMW projects
- Organizing international training sessions and global rollouts
- Introducing PIC processes and quality control for software and projects
- Reviewing and assessing IT security
- Monitoring and controlling the project
- Conducting reviews and contract negotiations
PMO Assistant to the Program Manager
prime force
- PMO in program management at Credit Suisse
- PMO in a project for web content systems at VW
- Creating technical documentation, including in English
- Preparing minutes of meetings
- Analyzing business and technical requirements
- Leading workshops
IT Consultant
sme AG
- 2nd-level support and application management for frontend and backend systems in the automotive sector
- Requirement engineering for frontend and backend systems
- IT design, software engineering, and UML modeling
- System analysis and meeting organization
- Customer support and international training sessions in English
- Application owner and team leader (3–7 people)
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Information Technology, Transportation, Manufacturing, Insurance, Automotive, and Banking and Finance.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Quality Assurance, Project Management, Operations, Audit, and Finance.
Summary
I am a Senior IT Project Manager focused on IT security, governance, and regulatory requirements in complex organizations. I take on the structured planning and management of projects at the interface between IT, business departments, and management. My focus is on implementing security-critical initiatives (IAM, PAM, MFA) in line with ISO 27001, DORA, and BAFIN requirements. I combine classic and agile methods (PRINCE2, Scrum) with a clear focus on transparency, risk, and quality management. I facilitate workshops, structure requirements, and develop actionable roadmaps. In projects, I act as the central communication interface and ensure clear decision-making foundations up to C-level.
Skills
It Project Management & Delivery
End-To-End Management Of Complex It Projects (Time, Budget, Resources)
Roadmap Development And Structured Project Planning
Transparency Through Reporting, Kpis, And Progress Tracking
It Security & Governance
Implementation Of Regulatory Requirements (Iso 27001, Dora, Bafin)
Establishment And Optimization Of Governance And Compliance Structures
Conducting Security Assessments And Preparing For Audits
Stakeholder Management & Communication
Facilitation Of Workshops And Decision-Making Sessions
Management Of Complex Stakeholder Environments Up To C-Level
Translation Between Business Departments, It, And Management
Iam / Security Architecture & Risk
Identity & Access Management (Iam, Pam, Mfa)
Risk Management And Definition Of Concrete Measures
Process Design And Governance In Access Rights Management
Languages
Education
Hochschule München
Bachelor · Wirtschaftsinformatik · Munich, Germany
Robert-Bosch-Fachoberschule für Wirtschaft
Fachoberschule für Wirtschaft
Fliegerhorst Erding (Bundeswehr)
Elektroniker · Elektroniker für Geräte und Systeme · Erding, Germany
Certifications & licenses
Statistics
Experience
Global experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Matthias is based in Schwindegg, Germany and can operate in on-site, hybrid, and remote work models.
Matthias speaks the following languages: German (Native), English (Advanced), Spanish (Advanced).
Matthias has at least 12 years of experience. During this time, Matthias has worked in at least 13 different roles and for 11 different companies. The average length of individual experience is 1 year and 11 months. Note that Matthias may not have shared all experience and actually has more experience.
Based on recent experience, Matthias would be well-suited for roles such as: Business Owner, Head of MFA Services (Group >100,000 employees), IAM Analyst.
Matthias's most recent position is Business Owner at AKM.
In recent years, Matthias has worked for AKM, APKV, A-DE, Atech, and metafinanz GmbH.
Matthias is most experienced in industries like Information Technology, Transportation, and Manufacturing. Matthias also has some experience in Insurance, Automotive, and Banking and Finance.
Matthias is most experienced in business areas like Information Technology, Quality Assurance, and Project Management. Matthias also has some experience in Operations, Audit, and Finance.
Matthias has recently worked in industries like Transportation, Manufacturing, and Insurance.
Matthias has recently worked in business areas like Information Technology, Project Management, and Quality Assurance.
Matthias holds a Bachelor in Wirtschaftsinformatik from Hochschule München.
Matthias has 9 certificates. Among them, these include: Riskoanalyst, BSI Grundschutz Praktiker (ISO27001), and ISMS Lead Auditor nach ISO/IEC 27001.
Matthias is immediately available full-time for suitable projects.
Daily rate distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 28 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Business Owner
Nearby freelancers
Professionals working in or nearby Schwindegg, Germany
