Skip to main content
🇩🇪GDPR-compliant
Hire a proven

Information Security Manager in Germany

in minutes from over 15,000 CVs with our AI-powered matching.

Secure your digital assets with specialists in ISO 27001, TISAX, and BSI IT-Grundschutz. We connect you with vetted, available freelance security experts tailored precisely to your technical environment and compliance needs.

Meet FRATCH Information Security Managers in Germany

Verified expert

Alicja Wilczek

View profile

Lawyer • External Data Protection Officer • IT Security Officer

Düsseldorf
Alicja Wilczek

Last position:

Integrated security and emergency documentation for a 24/7 logistics company at Medium-sized logistics company

  • Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, vulnerability management policy, business resilience programme, risk governance plan
  • Consolidation into an integrated emergency handbook (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table, and a formal approval structure
  • Review of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with documented compensating control
  • Review and documentation of NIS2 and HinSchG applicability, including the legal reasoning for non-applicability
Verified expert

Kerstin Glawinski

View profile

IT Security Officer with TÜV Rheinland certified qualification

Berlin
Kerstin Glawinski

Last position:

Information Security Consulting at CAS AG

Verified expert

Michael Fitschen

View profile

Managing Consultant Information Security and Data Protection

Heeslingen
Michael Fitschen

Last position:

Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund

  • Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
  • Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
  • Collaborating with the Information Security Officer (ISO)
  • Identifying company assets for IT risk management
  • Developing a zone concept for IT risk management
  • Creating an action plan for B3S
  • Developing a template for risk analyses
Verified expert

Frank Mühlenbrock

View profile

Information Security Manager / Data Protection Officer

Ehningen
Frank Mühlenbrock

Last position:

Freelance Security + Data Protection Consultant at Deutsche Bahn

  • Placed via recruiter 1st Solution with Deutsche Bahn. Supported and advised on Audit and Cyber Security matters there
  • Carried out numerous CSAs (Control Self Assessments), with close exchange with application owners and development of possible remediation solutions, and entered them in DB's risk2value tool from vendor GBTEC2
  • Advised on the creation of internal and external security risks
Verified expert

Klaus Rheinwald

View profile

Senior Project Manager

Hamburg
Klaus Rheinwald

Last position:

Management Consultant Compliance/Data Protection at Telefónica Germany GmbH & Co. OHG

Consulting on compliance and data protection topics in the telecommunications environment.

Verified expert

Florian Schröder

View profile

Information Security Officer / IT Security Architect / Awareness Expert

Norderstedt
Florian Schröder

Last position:

Information Security Officer / Designated InfoSec Officer at Oil Company

  • Complete overhaul of the ISMS according to ISO 27001
  • Conducted a comprehensive gap analysis
  • Reduced ISMS documentation by 30% through consolidation and process optimization
  • Introduced a full PDCA cycle for continuous improvement
  • Established the ISMS within the company
  • Implemented the necessary processes
  • Managed and conducted internal and external audits
  • Developed and implemented a company-wide risk management system
  • Deployed an ISMS tool including process design and training
  • KRITIS compliance: Prepared and provided required evidence, liaised with regulatory authorities, planned, documented, and implemented an attack detection system (SIEM), co-led the BCMS/ITSCM implementation subproject
  • NIS-2 implementation: Gap analysis, risk assessments, training for executives and staff
  • Led a cybersecurity team of 3 members
  • Conducted various internal and external audits, managed providers, introduced continuous improvement
  • Project consulting: closely coordinated with business and system owners, launched an online shop, a mobile app, and a customer portal
  • Redesigned the security architecture, reducing administrative efforts by 20%
  • Implemented ITIL processes (e.g., change management)
  • Revised service agreements with internal and external providers
  • Developed a security awareness strategy, ran social engineering tests, introduced and monitored phishing simulations, created various awareness materials, gave presentations
  • Managed a budget of one million euros
Verified expert

Arndt Schürg

View profile

Information Security Officer according to TISAX

Ludwigshafen
Arndt Schürg

Last position:

Information Security Officer according to TISAX at Automotive Supplier

Verified expert

Matthias Fitzner

View profile

Information Security Project Manager

Leverkusen
Matthias Fitzner

Last position:

Information Security Project Manager at Deutsche Bahn AG

  • Introduction of a new Information Security Management System (ISMS) according to ISO/IEC 27001.
  • Implementation of the cybersecurity guideline RL CySec-Rail for cross-border rail networks.
Verified expert

Gentrit Ajazi

View profile

External Information Security Officer

Lappersdorf
Gentrit Ajazi

Last position:

External Information Security Officer at Large dairy company

  • Align information security objectives with executive management
  • Monitor and steer the Information Security Management System (ISMS) in collaboration with the information security team
  • Serve as the primary point of contact for all information security matters and advise internal staff and process owners (e.g., Supplier Management, HR)
  • Further develop and improve the ISMS and information security policies
  • Deliver training and drive ongoing employee awareness
  • Hold monthly coordination meetings (jour fixe)
  • Conduct risk analyses together with executive management and process owners
  • Support audits (e.g., ISO 27001) as well as customer-specific audits
  • Structure assessment and handling of information security incidents in cooperation with the information security team
  • Support preparation of the annual plan and budget for information security measures
  • Plan and conduct internal audits and management reviews
  • Integrate the ISMS with other management systems
Verified expert

Jörg Hoffmann

View profile

Managing Director; Data Protection Officer; Information Security Officer

Berlin
Jörg Hoffmann

Last position:

Managing Director; Data Protection Officer; Information Security Officer at Datenschutz24 (brand of Sovestro GmbH)

  • Drafting company agreements related to data protection
  • Acting as a mediator between business interests and data subject rights in a corporate context
  • Process analysis and evaluation regarding data protection and information security implications according to GDPR, BDSG, BSI baseline protection
  • Support for information security audits according to ISO 27001
  • Implementation of change management processes
  • Analysis of IT infrastructure and deriving recommendations
  • Expert support in legal proceedings and communication with supervisory authorities
  • Preparation of data protection impact assessments (DPIAs) and procedure and processing documentation (VVZ)
  • Training on corporate data protection and information security
  • Cooperation with law firms in legal proceedings
Verified expert

Mirko Haucke

View profile

Cybersecurity Manager

Leimen
Mirko Haucke

Last position:

Cybersecurity Manager at Joynext GmbH

Cybersecurity for RTCU project for the Stellantis Group.

The management of cybersecurity was strongly criticized by the customer Stellantis, questioning competence. Requirements were missing or incomplete, the architecture for cybersecurity controls was non-existent, and documentation such as cybersecurity plans and concepts were incomplete and formally incorrect.

  • Building customer trust and de-escalation
  • Sprint planning with the customer based on SAFe
  • Task-force management
  • Switching planning and control to an agile approach
  • Review and update of cybersecurity documents
  • Communication and problem solving with suppliers, particularly Rolling Wireless and Autocrypt
  • Internal workshops and coordination across various hierarchy levels from developers to CTO
  • Coordination of work packages and implementation across locations in Dresden, Ningbo, and Oborniki
  • Reporting and support of cybersecurity audits
  • Coaching of Joynext cybersecurity managers
  • De-escalation of critical customer issues
  • Acceleration of requirement creation and release by a factor of 5
  • Timely provision of 3rd party components
  • Reduction of vulnerability management effort by factor 3
  • Creation of cybersecurity documents conformant to existing standards
  • Technologies and Methods: V-Modell, ASPICE, IREB, ISTQB, Scrum, Kanban, SAFe, PMP, IPMA, BPMN 2.0, Microsoft Office, Microsoft Project, Jira, Confluence, Siemens Polarion, Dependency Track
Verified expert

Friederike Balaz

View profile

Information Security Manager

Schwäbisch Gmünd
Friederike Balaz

Last position:

Information Security Manager at Johner Medical GmbH

Verified expert

Maxim Ribakowski

View profile

Information Security Officer

Rüdersdorf
Maxim Ribakowski

Last position:

Information Security Officer at Horváth AG

  • Managing the Information Security program according to ISO27001:2022, BAIT, BSI 200-1/4
  • Creating and updating IT policies and procedures
  • Communicating with C-level and the board (weekly, monthly, quarterly reports on incidents, risks, measures, audits, strategic and personnel planning)
  • Coordinating external and internal audits (JAP, BAIT, BaFin)
  • Risk management (monitoring improvement measures, assessing new risks, planning and reporting countermeasures)
  • Incident management (analyzing security-related incidents, monitoring and planning countermeasures and improvements)
  • Training employees on incidents, internal policies, and emergency procedures
  • Business continuity management (reviewing and updating BIA, emergency plans, recovery concepts, test results)
  • Managing communication between departments as a mediator
  • Managing and auditing external service providers (IT, cloud services; SOC 1/2, ISAE 3402 Type 1/2, C5 reports, on-site audits)
Verified expert

Patrick Günther

View profile

Information Security Manager

Kandel
Patrick Günther

Last position:

Information Security Manager at IT-Freelancer

  • Responsible for computer software validation (CSV) of the IT infrastructure
  • Supported the operation and maintenance of the Integrated Management System (IMS)
  • Served as interim information security officer (ISMR) for two companies in the medtech industry
  • Ensured ISO 27001 compliance within the organization
  • Contributed to implementing cybersecurity requirements for health software and networked medical devices according to ISO 81001-1

Discover over 15,000 top freelancers

Information Security Managers statistics

Aggregated from the professional profiles of matched freelancers.

Experience

23 years

Position duration

3.9 years

Positions per freelancer

13

Top business areas

Information Technology, Project Management, Quality Assurance

Top industries

Information Technology, Professional Services, Transportation

Certification focus areas

Information Technology, Audit, Legal

Bachelor's degree or higher

81%

Master's degree or higher

50%

Doctorate

6%

Certifications per freelancer

7

Most common languages

German, English, French

Speak two or more languages

94%

Based on our profile pool as of 6 Sep 2026.

Daily rate distribution

0 2 4 6 8
<€640 €720-​800 €800-​880 €880-​960 €960+

The chart shows how the daily rates of freelancers in this role in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates for Information Security Managers in Germany

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 895 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 880 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 6 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

Information Security Managers experts industry focus

See where the role earns the most, city by city against the national average — every figure is calculated live from the freelancers on FRATCH.

  • Information Technology (89%)
  • Professional Services (72%)
  • Transportation (50%)
  • Manufacturing (50%)
  • Automotive (44%)
  • Banking and Finance (39%)
  • Energy (33%)
  • Healthcare (28%)

Please note that freelancers can work across multiple industries, so percentages overlap.

About the role

Protecting Critical Assets in Germany

Information security needs in Germany are shaped by strict regulatory frameworks and a highly specialized industrial landscape. Freelance security experts help businesses navigate these complex compliance environments, protecting intellectual property in manufacturing, automotive, and financial sectors. They align technical safeguards with business strategy to minimize risk.

Key Technical Deliverables

  • Structuring and implementing an Information Security Management System (ISMS) according to international standards.
  • Conducting comprehensive risk analyses and vulnerability assessments across the IT infrastructure.
  • Preparing companies for external audits like ISO 27001 or industry-specific TISAX assessments.
  • Defining incident response plans and coordinating disaster recovery simulations.
  • Training internal teams on modern security policies and threat awareness.

Driving Compliance and Risk Management

External security specialists are frequently brought in during transitional phases, such as system migrations, cloud adoptions, or corporate restructuring. They act as objective advisors who can quickly identify structural vulnerabilities without internal bias. Their intervention ensures that projects proceed without violating European data protection laws or national IT security acts.

Finding the Right Freelance Expert

A highly qualified professional in this field must possess a strong balance of technical depth and leadership communication. In Germany, fluency in both German and English is often vital for dealing with local regulatory bodies like the BSI while managing international IT teams. The best candidates demonstrate a proven track record of successfully guiding complex organizations through rigorous certification processes.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

What clients ask us most about Information Security Managers — answered in short.

An Information Security Manager is responsible for designing, implementing, and maintaining policies that protect an organization's digital assets. They assess risks, establish governance frameworks like ISO 27001, and ensure that the entire workforce follows secure data handling practices.

A freelance ISMS Manager provides immediate, highly specialized expertise to resolve specific bottlenecks, such as preparing for an upcoming certification audit. This approach avoids long hiring cycles and offers the flexibility to scale down security resources once the main framework is established.

While a security engineer focuses on configuring firewalls, writing code, and executing technical defenses, an IT Security Officer operates at a strategic level. They align security policies with overall business goals, manage compliance, and direct the technical teams on priority areas.

In Germany, an Information Security Manager must navigate strict national standards, including the IT Security Act and specific guidelines from the BSI. For companies in the automotive supply chain, implementing TISAX compliance is often a mandatory requirement that requires localized expertise.

An interim CISO can execute most strategic tasks, policy writing, and risk analysis remotely. However, critical phases such as physical security audits, initial infrastructure discovery, and crisis response often benefit from occasional on-site presence.

Look for internationally recognized credentials such as CISSP, CISM, or certified lead auditor status for ISO 27001. These certifications demonstrate that the security consultant has a standardized understanding of governance, risk management, and compliance frameworks.

A skilled interim security leader immediately activates the incident response plan, coordinates with IT forensics, and isolates affected systems. They also manage critical communication with stakeholders and regulatory authorities to mitigate reputational and legal damage.

While technical execution can often be handled in English, an information security consultant working with German public authorities or critical infrastructure often needs professional German skills. This ensures clear interpretation of local laws and seamless communication with works councils.

The average hourly rate for Information Security Managers in Germany is 112 €, which corresponds to a daily rate of about 895 € based on an 8-hour working day.

Of the freelancers working as Information Security Managers in Germany, 81% hold at least a Bachelor's degree, 50% hold at least a Master's degree, and 6% hold a doctorate.

On average, freelancers working as Information Security Managers in Germany have 23 years of professional experience, with a single engagement typically lasting around 3.9 years.

The most common languages among freelancers working as Information Security Managers in Germany are German (100%), English (94%), and French (22%).

The most common industries among freelancers working as Information Security Managers in Germany are Information Technology (89%), Professional Services (72%), and Transportation (50%).

The most common business areas among freelancers working as Information Security Managers in Germany are Information Technology (100%), Project Management (89%), and Quality Assurance (78%).

FRATCH Information Security Managers main locations

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH