Peter Konrad-Graduate in Business Administration (FH)

Check rate
Experience
IT Audit Expert
Sparkasse
Support for Internal Audit:
Conducting an audit of the data protection officer and data protection management:
- Preparing an audit program based on the audit field concept
- Requesting the necessary audit documentation
- Carrying out control testing based on the audit program with the following focus:
- Reviewing the relevant PPS processes
- Reviewing the data protection mission statement, data protection policy, and data protection management concept
- Conducting audit interviews with the data protection officer
- Preparing the audit documentation
- Training a junior auditor in the methodology of Internal Audit
- Coordinating the audit documentation with the head of audit
Expert for Information Security, BCM, Outsourcing Management
Sparkasse
Analysis and optimization of various processes in the areas of information security, business continuity management, and outsourcing management
- Recording and analyzing current processes, identifying optimization potential in the area of officer roles (ISB, BCB, outsourcing officer)
- Creating training materials (presentation) to raise awareness among decentralized service managers
- Evaluating data quality in the GRC tool to show further improvements (in information security and outsourcing management)
- Quality assurance of the RMR report according to DORA
- Support in carrying out ISM audits
- Support in optimizing the BIA / RIA
IT Audit Expert
Sparkasse
Support for Internal Audit:
Conducting various audits with a focus on DORA, user and access management, operational information security, data protection, information security (ISMS) and BCM (if applicable, HR and compliance/MaRisk):
- Preparing the audit program based on the relevant audit field concepts
- Comparing business processes with the related (PPS) sub-processes
- Carrying out a follow-up of previous audits in the same audit fields
- Requesting and reviewing various documents and result types
- Conducting audit interviews (opening meeting and follow-up meetings)
- Carrying out tests of functionality and effectiveness
- Evaluating and reviewing documents from bit-Compliance or RiMaGo
- Preparing the audit documentation
- Preparing the audit report
- Conducting the closing meeting and the audit criticism meeting
Expert on DORA topics
Service provider
Handling various issues | Preparing various gap analyses
- Providing an overview of all DORA-relevant topics
- Preparing an overview of DORA-relevant ICT risks
- Assessing the tasks and role of the service provider in serious incidents (including delimitation criteria, information to be provided as part of the initial report, follow-up report, and final report)
- Comparing the report content within the reporting that a service provider has to deliver under DORA
Overall project lead for the DORA project (EU Digital Operational Resilience Act)
Sparkasse
Management of the overall DORA project and its four sub-projects
- Budget planning and control
- Monitoring of project activities in terms of "just in time / budget / quality"
- Status reporting to the client, steering committee, and responsible board member
- Contact person for the Internal Audit department supporting the project
- Quality assurance of the work packages to be implemented for each sub-project
- Running the selection process for additional external project staff
- Preparation and follow-up of various status meetings
- Support and professional development of internal project staff
- Adjusting the project mandate for the project extension
- Various coordination meetings within and outside the project organization
Compliance expert, among others with a focus on DORA (EU Digital Operational Resilience Act) and partial project lead
various savings banks
Consulting on the implementation of DORA requirements
- Support and guidance for the business units in carrying out the GAP analysis to identify existing deviations from the DORA regulation (including the requirements under RTS / ITS)
- Analysis and advice for the responsible owners on the implementation of, among others, the following DSGV short guides:
- classification of the category "critical or important function" derived from the BIA
- strong authentication
- risk management framework (RMR)
- quality assurance of adapted / created strategies, policies and guidelines (2nd LoD) to ensure proper implementation of the DORA requirements
- quality assurance of concepts (1st LoD), for example the cryptography concept, to ensure proper consideration of the DORA requirements
- support for the measures to be carried out within the scope of the following four pillars of the DORA regulation:
- ICT risk management
- reporting of ICT-related incidents
- testing of operational resilience
- ICT third-party risk
Advice to top management on special topics, such as the upcoming Section 44 audit or regulatory requirements for segregation of duties
- quality-assurance review of OHB rules and regulations to identify implausibilities or declining quality at an early stage
- test interviews (coaching) with the responsible owners to point out improper or suboptimal behavior
- assessment and evaluation of the OHB documents with regard to proper implementation of the regulatory requirements in accordance with AT9 MaRisk
- support with the preparatory and implementation measures to ensure a technical mapping of a segregation-of-duties review in the bit-MaRisk application
Expert for rights management & outsourcing management
savings bank
Analysis and optimization of the process approach compared with target measures in rights administration
- Analysis of the approach in rights administration
- Support in processing rights requests within the rights management application KURS
- Development of process optimizations for handling backlog items, especially due to recertification changes
- Identification of process redundancies and inefficiencies
Analysis of service contracts taking into account various risk factors and regulatory requirements in accordance with AT 9 MaRisk
- Carrying out contract and risk analyses and mapping them in the RiMaGo application
- Identification of risks as part of the analysis of contract and service assessments
- Derivation of technical recommendations for action (provider steering measures) for the responsible outsourcing officers
Expert for audit activities in corporate security
building society
Optimization and execution of the audit methodology (internal audits and provider assessments) within information security
- Analysis and assessment of the existing audit methodology
- Optimization of the audit approach based on a robust, risk-oriented approach, including ISO/IEC 27001 controls
- Development of an audit tool (so-called audit guide) to support audits in all phases (preparation/definition of audit focus areas, execution, reporting and follow-up)
- Development of a risk-oriented planning approach for the 5-year plan and the annual audit plan for carrying out provider assessments based on a scoring system
- Creation of a self-assessment questionnaire as a methodological approach for carrying out provider assessments
- Carrying out various provider assessments, including on-site audit activities (data center audits), document reviews and remote interviews
IT audit expert
savings bank
Support for internal audit:
Carrying out the critical follow-up review of open measures with the following focuses:
- Review of completed risk analyses
- Validation of target measure catalogs taking into account "secure IT operations" (SITB)
- Validation of measures within the business and IT strategy
- Validation of closure readiness in rights management (segregation of duties and toxic rights)
- Numerous measures in the IT environment
Carrying out audits with a focus on:
- Proper implementation of service specifications taking into account the regulatory requirements in accordance with AT9 MaRisk
- Design and implementation of the data protection function and the data protection management system, including the following focuses:
- organizational setup and process organization, including internal control system
- handling of data protection impact assessments and data protection incidents
- carrying out employee training and raising awareness among data protection coordinators
- creation and completeness of the record of processing activities
- approach to managing risks
- design of technical and organizational measures
- review of the completeness of confidentiality and/or data protection agreements
IT audit expert
audit firm
Support for the annual financial statement audit of an investment management company:
Planning, execution and documentation of audit procedures with the following focuses:
- outsourcing management and provider steering in accordance with AT9 MaRisk
- business continuity management
- IT strategy and IT governance
- IT operations
- segregation of duties principle and toxic rights within rights management
Execution of quality assurance measures for the audit procedures and results of junior auditors
Compliance expert with focus on outsourcing according to AT 9 MaRisk
Mortgage Bank
advisory support for IT provider management
- Review of contracts regarding compliance with regulatory requirements
- Support in shaping governance, processes and controls in the area of IT provider management
- Support in closing open audit findings
- Coordination of new or adapted contracts to ensure compliance requirements are met
- Coordination meetings with the central outsourcing officer, Internal Audit, Legal, BCM, security officer and data protection officer
- Coordination and alignment of new contract amendments with providers
- Advice and training for internal employees on topics related to data protection, regulatory requirements (MaRisk, BAIT, EBA guidelines), SLAs and KPIs, information security and the issue of bogus self-employment for freelancers
IT Audit Manager
Mortgage Bank and Financial Services Provider
Conducting IT audits with the following focus areas:
Integrated IT/business audits based on COSO II / COBIT 5:
- Review of access rights management at the level of various applications, databases (including Oracle, MS SQL) and operating systems (including Linux, Unix and MS Windows)
- Review of change management at the level of various applications, databases (including Oracle, MS SQL) and operating systems (including Linux, Unix and MS Windows)
- Review of further ITIL-based services, such as problem and incident management, service level management, capacity management, availability management, IT service continuity management, information security management, compliance management, supplier management
- Review of the ERP system SAP ERP 6.0 and the trading system SUMMIT, with focus on
- emergency user management
- user management
- authorization management
- change management
- configuration management
- system integrity at SAP/SUMMIT, DB and OS level
- Review of further audit areas according to IT General Controls (ITGC)
- Validation of the audit results of the ISMS audit according to ISO27.00x
- Teaching audit methodology within the IT audit team
Independent IT audits based on COSO II / COBIT 5:
- Audit of the implemented information security system according to ISO 27.00x and in line with BAIT requirements, with the following focus areas:
- Review of the implementation and effectiveness of the elements of information risk management
- Assessment of the defined and implemented information network and its components and dependencies
- Review of the assessment of protection needs with regard to the relevant protection goals
- Review of the structure and suitability of the target measures (target/target or target/actual comparison)
- Validation of the risk analyses to be carried out regularly
- Review of the implementation and effectiveness of the elements of information security management
- Assessment of the design, completeness, traceability and effectiveness of the rules relevant to the ISMS or the written internal policies (guidelines, policies and work instructions)
- Validation of the organizational structure relevant to the ISMS
- Review of the design and effectiveness of the ISMS internal control system
External data protection expert
Transport financing service provider
advisory support for the data protection officer
- Adaptation of data protection-related regulations (internal documented rules)
- Data protection framework,
- high-level deletion concept,
- rules for data protection impact assessment,
- requirements for data protection incidents
- Advice to business units on data protection issues
- Classification of order processing in the context of an auditor within the meaning of Art. 28 para. 3 GDPR vs. Art. 4 no. 7 GDPR
- Assessment of a request for joint controllership pursuant to Art. 26 GDPR by a service provider
- Support of the data protection audit by Internal Audit
- Advisory support for business units in implementing deletion concepts pursuant to Art. 17 GDPR
- Support for the business unit in carrying out the data protection impact assessment pursuant to Art. 35 GDPR
- Design, optimization and implementation of data protection controls as part of the internal control system
Head of Internal Audit as Interim Manager
IT consulting and software development service provider
Management of Internal Audit and optimization of audit processes:
Leading the audit team and responsible for the following tasks:
- Ensuring the quality, adequacy and timely completion of audits according to the 2019 audit plan
- Leading and managing the audit team consisting of three internal and several external employees (> 10), including one Big4 firm
- Regular reporting to management, the corporate group and customers
- Preparing the risk-based audit plan for 2020
- Audit-compliant advice to business units and management
Consulting and implementation tasks as part of the qualitative optimization of audit processes and ensuring the effectiveness of Internal Audit:
- Revision of the audit manual taking into account the requirements of Audit Standard No. 3 (DIIR) and the principles of proper auditing of internal audit systems (according to IDW PS 983)
- Derivation and implementation of improvement measures according to the audit report of the auditor under IDW PS 983 (principles of proper auditing of internal audit systems)
- Conducting workshops within the audit team to explain the requirements for the effectiveness of an Internal Audit function according to DIIR Audit Standard No. 3 (Audit of Internal Audit Systems (Quality Assessments))
IT Audit Manager
Mortgage Bank and Financial Services Provider
Conducting IT audits with the following focus areas:
Integrated IT/business audits based on COSO II / COBIT 5:
- Review of access rights management at the level of various applications, databases (including Oracle, MS SQL) and operating systems (including Linux, Unix and MS Windows)
- Review of change management at the level of various applications, databases (including Oracle, MS SQL) and operating systems (including Linux, Unix and MS Windows)
- Review of further ITIL-based services, such as problem and incident management, service level management, capacity management, availability management, IT service continuity management, information security management, compliance management, supplier management
- Review of the ERP system SAP ERP 6.0 and the trading system SUMMIT, with focus on
- emergency user management
- user management
- authorization management
- change management
- configuration management
- system integrity at SAP/SUMMIT, DB and OS level
- Review of further audit areas according to IT General Controls (ITGC)
- Validation of the audit results of the ISMS audit according to ISO27.00x
- Teaching audit methodology within the IT audit team
Independent IT audits based on COSO II / COBIT 5:
- Audit of the implemented information security system according to ISO 27.00x and in line with BAIT requirements, with the following focus areas:
- Review of the implementation and effectiveness of the elements of information risk management
- Assessment of the defined and implemented information network and its components and dependencies
- Review of the assessment of protection needs with regard to the relevant protection goals
- Review of the structure and suitability of the target measures (target/target or target/actual comparison)
- Validation of the risk analyses to be carried out regularly
- Review of the implementation and effectiveness of the elements of information security management
- Assessment of the design, completeness, traceability and effectiveness of the rules relevant to the ISMS or the written internal policies (guidelines, policies and work instructions)
- Validation of the organizational structure relevant to the ISMS
- Review of the design and effectiveness of the ISMS internal control system
Senior IT Auditor
Fintech company
Conducted IT audits with the following focus areas:
Data Protection Officer as part of GDPR implementation:
- Appointment of the data protection officer with the supervisory authority
- Organizational and operational structure within the data protection function (data protection management system)
- Organizational framework of the data protection function
- Fulfillment of data subject rights by the controller
- Implementation of the data protection impact assessment
- Structure and content of the record of processing activities
- Proper implementation of risk management as part of technical and organizational measures, the reporting obligation for data protection breaches, and the data protection impact assessment
- Completeness and appropriateness of data processing agreements (DPAs)
- Conducting training sessions as part of GDPR implementation
- Implementation of information obligations at the first collection of personal data
- Completeness of confidentiality agreements for employees and service providers
Data center audit as part of a housing data center service provider:
- Appropriateness of the service contract and monitoring of compliance with service level agreements
- Building and property security of the provider
- Access control and monitoring of access
- Communication and escalation processes between client and contractor
- Reliability of cooling and power supply (redundant supply / UPS)
- Emergency power supply and other measures within business continuity management (diesel generators)
- Early fire detection and smoke alarm systems
- Carrying out regular maintenance activities
- Operations and security control center (confidentiality of deployed staff)
- Cable routing
external data protection officer as interim manager for 11 companies
Leading energy company
external data protection officer
- Preliminary analysis of the current compliance with data protection requirements for the implementation of a data protection management system (DSMS) in order to prepare the company for compliance with the EU General Data Protection Regulation (EU GDPR)
- Processing / advising on data protection-related requests from project and business departments
- Requirements for a privacy policy
- Preparation for anonymization / pseudonymization of data material
- Data protection requirements for the use of customer terminals
- Requirements regarding controlled access to employee email accounts and personal shared drive access
- Advice and support in connection with upcoming data processing on behalf
- Review of work packages within the EU GDPR project
- Requirements for the use of webcams
- Use of profiling and automated individual decision-making
- Review and control of data processing on behalf
- Training and onboarding the future internal data protection officer
- Close cooperation with the legal department
- Compliance with data protection regulations
Senior Engagement Manager
Large bank
Carried out IT audit procedures as part of the following internal audit reviews
- Custody accounts, fund process, marketing & sales
- Validation of the appropriateness of protection needs information in the CMDB of systems relevant to the audit
- Review of the minimum documentation of systems relevant to the audit for completeness and content plausibility
- Conducting audit interviews with the technical and business contacts responsible
- Preparation of the working papers needed for the audit report
- Assessment and categorization of audit findings according to the COSO methodology
Expert for IT Governance / Process and Control Design
Large bank
Implementation project for an Identity & Access Management (IAM)
- Analysis and assessment of the existing control environment
- Adaptation / optimization and implementation of the control environment within the IAM processes
- Analysis / adaptation of existing and design of new IAM processes according to the process modeling methods EPK (event-driven process chain) and BPMN (Business Process Model and Notation) using the process modeling tool BIC
- Conducting workshops with the relevant subject matter experts
- Revision and creation of IAM policies at 1st and 2nd line of defense level
- Presentation of project results
- Deputy for the subproject lead
- Recording, assessment, prioritization and tracking of IAM-relevant (internal and external) audit findings
- Advising project management and the steering committee on security and compliance-related issues
- Coordinator and contact person for other projects as part of the handling of supervisory findings
external data protection officer as interim manager for 11 companies
Leading energy company
external data protection officer
- Preliminary analysis of the current compliance with data protection requirements for the implementation of a data protection management system (DSMS) in order to prepare the company for compliance with the EU General Data Protection Regulation (EU GDPR)
- Processing / advising on data protection-related requests from project and business departments
- Requirements for a privacy policy
- Preparation for anonymization / pseudonymization of data material
- Data protection requirements for the use of customer terminals
- Requirements regarding controlled access to employee email accounts and personal shared drive access
- Advice and support in connection with upcoming data processing on behalf
- Review of work packages within the EU GDPR project
- Requirements for the use of webcams
- Use of profiling and automated individual decision-making
- Review and control of data processing on behalf
- Training and onboarding the future internal data protection officer
- Close cooperation with the legal department
- Compliance with data protection regulations
Senior IT Auditor
Large bank
Co-sourcing of internal audit as an expert in the audit of "Management and monitoring of the IT service provider and its services according to ITIL"
- Significant contribution to the audit planning (especially the IT part)
- Carrying out IT audit procedures in line with the audit plan
- Disaster Recovery
- Configuration Management (CMDB)
- Release Management & Deployment
- Capacity Management
- Security State & Event Management (SIEM)
- Carrying out the audit and preparing the audit documentation in English
- Administrative support for the audit lead
Co-sourcing of internal audit as an expert in various audits on the topic of "Governance within the business policy digitalization strategy in the context of the business bank strategy 2020"
- Significant contribution to the audit planning (risk and control list, audit announcement, audit plan, etc.)
- Carrying out IT audit procedures in line with the audit plan
- Project and program planning
- Compliance with project and development methodology according to
- agile methodology (SCRUM)
- waterfall methodology (QMS)
- Program Governance Framework (PGF)
- Traceability of the strategy transformation from the digitalization strategy into the programs / projects
- Budget and financial compliance
- Project and program control
- Risk and issue management
- Compliance with compliance requirements and involvement of control functions
- Implementation methodology for digitalization initiatives in cooperation with technology partners and start-ups
- Compliance with the requirements of the Software Development Life Cycle (SDLC) in the context of software development
- Compliance with contractual requirements (NDA) when working with partners on joint digitalization projects
- Training new internal employees and other consultants in the audit methodology
- Conducting the audit / interviews and preparing the audit documentation in English
- Administrative support for the audit lead
IT Audit Coordinator and Specialist
State bank
Coordination and execution of IT audits
- Significant contribution to the audit planning (especially the IT part)
- Carrying out IT audits in line with the audit plan (joint audits: BCM, provider management)
- Audit support for a large IT project
- Coordination of audits by the supervisory authority and group audit
- Technical responsibility for carrying out audits in the IT audit team
- Administrative support for the audit management
Process Consultant
Automobile manufacturer (OEM)
Design and creation of an interface documentation as part of the procedure documentation for a complex application landscape
- Analysis of the existing metadata within the application landscape
- Structuring of the metadata
- Building a documentation standard taking regulatory and security-related requirements into account
- Creating the documentation
Security and Process Consultant
Automobile manufacturer (OEM)
Implementation project for a provider selection process for cloud computing providers
- Conceptual process development for selecting cloud services and their providers
- Creating service scorecards for each provider
- Analysis of the relevant written policies and procedures
- Adjusting the written policies and procedures and adding cloud computing relevant aspects
- Developing XLS-based tools to support the selection process
- Creating management presentations
- Regular presentation of interim/final results
Senior IT Auditor
Large bank
Co-sourcing of internal audit as an expert in the audit of "Individual data processing"
- Creating the audit program according to the audit standards of DIIR, ISACA, and the German banking supervisory authority
- Conducting interviews in the area of information security
- Analysis of the relevant written policies and procedures
- Assessment of the identified weaknesses in the area of IDV
- Creating an audit report in line with the bank's audit standards
Security and Process Consultant
Large bank
Conceptual development of a Balanced Security Scorecard and a provider management system as part of an ISMS project in accordance with ISO 27.00x
- Analysis of the ISMS structure and process setup
- Conceptual development of an ISMS organization and governance based on the group-wide security requirements
- Adaptation of the security-relevant written policies and procedures
External Data Protection Officer
Mid-sized auditing firm
External data protection officer (in accordance with the German Federal Data Protection Act) for a group of companies
- Compliance with data protection regulations
- Excerpt from the range of responsibilities
- Review of individual data security measures
- Review and monitoring of data processing on behalf of others
- Handling of data subject access requests
- Review of rules for employee monitoring
- Monitoring of data processing programs
- Training of employees
- Maintenance of the record of processing activities
- Carrying out prior checks
Security and Process Consultant
Automotive manufacturer (OEM)
Implementation project of an ISMS in accordance with ISO 27.00x
- Assessment of ISMS-related audit findings using a risk system
- Conducting interviews based on the information security findings
- Development of measures to resolve or reduce existing risks
- Conceptual development and creation of security policies and standards
Process and Organizational Consultant | Senior Auditor
University
Implementation of internal audit
- Analysis of the university's core business processes
- Set-up of an internal audit function based on IIA and DIIR standards
- Set-up of a risk-based audit planning process
- Set-up of a written audit framework (audit strategy and audit manual)
- Conducting IT audits and audits of university-related business processes
Managing Director and Senior Consultant
Mid-sized consulting firm
Building and managing the company
- Building the company's organizational structures
- Building and developing consulting services (IT audit & security, outsourcing services, expert services, business administration, governance/compliance)
- Initiating and closing strategic partnerships with business partners to expand the service portfolio and increase customer potential and revenue
- Conducting sales activities (both cold calling and existing client development)
- Data protection officer for the entire group of companies
- Handling audit assignments according to IDW PS 330 (IT system audit), IDW PS 951 (audit of the internal control system at the service provider), IDW PS 850 (project-related audit) and IDW PS 880 (audit of software products)
Manager IT Audit
Wirtschaftsprüfungsgesellschaft
Coordination and execution of IT audits
- Responsibility for consulting and audit engagements
- Generating new engagements
- Responsible for audit work accompanying a major IT project according to the IDW PS 850 standard
- Regular reporting to internal audit and project management
- Responsibility for conducting the audit
Group Manager IT Audit
Outsourcing service provider with a banking license
Coordination and execution of IT audits
- Responsibility for the overall audit process to ensure the functionality of internal IT audit in line with BaFin MaRisk
- Preparation of audit plans according to IIA (Institute of Internal Auditors) standards
- Organization and coordination of audits
- Responsibility for conducting audits according to IIA and DIIR (German Institute of Internal Auditors) standards
- Conducting IT system audits according to IDW PS 330
- Quality assurance of aligned activities
- Implementation and adaptation of risk- and control-based audit approaches
- Project support for integrating a new business unit (France) into the corporate group according to company standards
- Project responsibility (Germany) for the project "SAP R/3 migration and release change to ECC 6.0" as part of the group-wide consolidation of the heterogeneous SAP R/3 system landscape
Senior IT Audit
Publishing house
Coordination and execution of IT audits
- Conducting IT audits
- Organization and coordination of audits
- Responsibility for conducting audits
- Audit of the security settings and related processes of a card-based Single Sign-On system
- Audit of security systems in the area of debit and credit card production
IT Auditor
Mortgage bank
Coordination and execution of IT audits
- Implementation of a risk-based audit approach when setting up internal IT audit as a sub-area of the overall audit department
- Audit of the group-wide risk management system with a focus on IT risk management
- Advisory support in implementing a risk management process for operational IT risks
- Responsibility for building up internal IT audit as a sub-area of the overall audit department
Senior IT Audit
Insurance company
Coordination and execution of IT audits
- Audit and advisory support for the IT security team in building an Information Security Management System (ISMS) and validation of IT security processes (according to IT baseline protection / ISO 27.001/2)
- Independent execution of various IT audits at different European locations of the company
IT Auditor
Mortgage bank
Coordination and execution of IT audits
- Implementation of a risk-based audit approach when building up an IT audit function as part of the overall audit department
- Audit of the bank-wide risk management system with a focus on IT risk management
- Advisory support in implementing a risk management process for operational IT risks
- Responsibility: building up the IT audit function as part of the overall audit department
IT Manager
Investment company
Responsibility for IT operations and IT organization
- Support and administration of the system landscape
- Building up an IT organization
- Responsible execution of projects during various release changes in the ERP environment
- Implementation of small programming requests in MS Excel / MS Access using VBA
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Banking and Finance, Information Technology, Professional Services, Media and Entertainment, Energy, and Automotive.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Information Technology, Audit, Project Management, Legal, Operations, and Quality Assurance.
Summary
- Specialist expertise in IT audit, IT governance, IT risk, IT compliance, and IT security
- Building up IT-SCAN GMBH with a focus on IT security, IT compliance, and IT audit consulting
- Overall project manager and sub-project manager for compliance and information security projects
- Review of IT application development and IT operations according to best-practice standards based on BSI IT-Grundschutz and CobiT as well as IDW PS 951, IDW PS 850 and IDW PS 330 and "Secure IT Operations" (SITB)
- Building and further developing the audit methodology in line with IDW PS 983 and DIIR Audit Standard No. 3
- Main audit focus in the financial industry with method and application expertise in MaRisk, BAIT, VAIT, KAIT, ZAIT, and KritisV
- Expertise in data protection under BDSG and GDPR in the role of internal/external data protection officer as well as through audit work in the area of data protection
- Establishing the consulting and audit series "ReifegradSCAN" on the topics of implementation maturity of the General Data Protection Regulation (GDPR), implementation maturity of regulatory requirements for outsourcing according to AT9 MaRisk and the EBA Guideline on Outsourcing, as well as gap analysis and implementation of the EU DORA regulation
Skills
Roles
- Project Manager
- Project Lead
- Compliance Expert
- Information Security Expert
- It Auditor
- It Auditor
- It Auditor
- It Risk Manager
- It Governance Consultant
- Data Protection Officer
- Interim Manager Regulatory Requirements
- Gdpr, Bdsg
- Dora
- Marisk
- Eba Guideline On Outsourcing Arrangement
- Eba Guideline Third Party Risk Management
- Nis2
- Supervisory Audit According To §44 Kwg
- Iia Standard
- Diir Audit Standards
- Audit Methodology
- Ai Act
- Ai Regulation Industry Focus
- Financial Services Industry
- Energy Sector
- Public Sector
- Automotive
- Audit Firm
Languages
Education
Ludwigshafen University of Applied Sciences
Graduate in Business Administration (FH) · Business Administration · Ludwigshafen, Germany · Grade 1.9
Focus areas: banking and insurance studies, finance, business information systems
Statistics
Experience
Global Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Daily Rate Distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a IT Audit Expert
Nearby freelancers
Professionals working in or nearby Idar-Oberstein, Germany
