Hire a proven Information Security Manager in Germany in minutes from over 15,000 CVs with our AI-powered matching.
Secure your digital assets with specialists in ISO 27001, TISAX, and BSI IT-Grundschutz. We connect you with vetted, available freelance security experts tailored precisely to your technical environment and compliance needs.
About the role
Protecting Critical Assets in Germany
Information security needs in Germany are shaped by strict regulatory frameworks and a highly specialized industrial landscape. Freelance security experts help businesses navigate these complex compliance environments, protecting intellectual property in manufacturing, automotive, and financial sectors. They align technical safeguards with business strategy to minimize risk.
Key Technical Deliverables
- Structuring and implementing an Information Security Management System (ISMS) according to international standards.
- Conducting comprehensive risk analyses and vulnerability assessments across the IT infrastructure.
- Preparing companies for external audits like ISO 27001 or industry-specific TISAX assessments.
- Defining incident response plans and coordinating disaster recovery simulations.
- Training internal teams on modern security policies and threat awareness.
Driving Compliance and Risk Management
External security specialists are frequently brought in during transitional phases, such as system migrations, cloud adoptions, or corporate restructuring. They act as objective advisors who can quickly identify structural vulnerabilities without internal bias. Their intervention ensures that projects proceed without violating European data protection laws or national IT security acts.
Finding the Right Freelance Expert
A highly qualified professional in this field must possess a strong balance of technical depth and leadership communication. In Germany, fluency in both German and English is often vital for dealing with local regulatory bodies like the BSI while managing international IT teams. The best candidates demonstrate a proven track record of successfully guiding complex organizations through rigorous certification processes.
Meet FRATCH Information Security Managers
Florian Schröder
Information Security Officer / IT Security Architect / Awareness Expert
Last position:
Information Security Officer / Designated InfoSec Officer at Oil Company
- Complete overhaul of the ISMS according to ISO 27001
- Conducted a comprehensive gap analysis
- Reduced ISMS documentation by 30% through consolidation and process optimization
- Introduced a full PDCA cycle for continuous improvement
- Established the ISMS within the company
- Implemented the necessary processes
- Managed and conducted internal and external audits
- Developed and implemented a company-wide risk management system
- Deployed an ISMS tool including process design and training
- KRITIS compliance: Prepared and provided required evidence, liaised with regulatory authorities, planned, documented, and implemented an attack detection system (SIEM), co-led the BCMS/ITSCM implementation subproject
- NIS-2 implementation: Gap analysis, risk assessments, training for executives and staff
- Led a cybersecurity team of 3 members
- Conducted various internal and external audits, managed providers, introduced continuous improvement
- Project consulting: closely coordinated with business and system owners, launched an online shop, a mobile app, and a customer portal
- Redesigned the security architecture, reducing administrative efforts by 20%
- Implemented ITIL processes (e.g., change management)
- Revised service agreements with internal and external providers
- Developed a security awareness strategy, ran social engineering tests, introduced and monitored phishing simulations, created various awareness materials, gave presentations
- Managed a budget of one million euros
Kerstin Glawinski
IT Security Officer with TÜV Rheinland certified qualification
Last position:
Information Security Consulting at CAS AG
Kerstin Glawinski
IT Security Officer with TÜV Rheinland certified qualification
Last position:
Information Security Consulting at CAS AG
Michael Fitschen
Managing Consultant Information Security and Data Protection
Last position:
Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund
- Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
- Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
- Collaborating with the Information Security Officer (ISO)
- Identifying company assets for IT risk management
- Developing a zone concept for IT risk management
- Creating an action plan for B3S
- Developing a template for risk analyses
Michael Fitschen
Managing Consultant Information Security and Data Protection
Last position:
Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund
- Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
- Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
- Collaborating with the Information Security Officer (ISO)
- Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
- Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
- Collaborating with the Information Security Officer (ISO)
- Identifying company assets for IT risk management
- Developing a zone concept for IT risk management
- Creating an action plan for B3S
- Developing a template for risk analyses
- Identifying company assets for IT risk management
- Developing a zone concept for IT risk management
- Creating an action plan for B3S
- Developing a template for risk analyses
Klaus Rheinwald
Senior Project Manager
Last position:
Management Consultant Compliance/Data Protection at Telefónica Germany GmbH & Co. OHG
Consulting on compliance and data protection topics in the telecommunications environment.
Klaus Rheinwald
Senior Project Manager
Last position:
Management Consultant Compliance/Data Protection at Telefónica Germany GmbH & Co. OHG
Consulting on compliance and data protection topics in the telecommunications environment.
Consulting on compliance and data protection topics in the telecommunications environment.
Arndt Schürg
Information Security Officer according to TISAX
Last position:
Information Security Officer according to TISAX at Automotive Supplier
Arndt Schürg
Information Security Officer according to TISAX
Last position:
Information Security Officer according to TISAX at Automotive Supplier
Matthias Fitzner
Information Security Project Manager
Last position:
Information Security Project Manager at Deutsche Bahn AG
- Introduction of a new Information Security Management System (ISMS) according to ISO/IEC 27001.
- Implementation of the cybersecurity guideline RL CySec-Rail for cross-border rail networks.
Matthias Fitzner
Information Security Project Manager
Last position:
Information Security Project Manager at Deutsche Bahn AG
- Introduction of a new Information Security Management System (ISMS) according to ISO/IEC 27001.
- Implementation of the cybersecurity guideline RL CySec-Rail for cross-border rail networks.
- Introduction of a new Information Security Management System (ISMS) according to ISO/IEC 27001.
- Implementation of the cybersecurity guideline RL CySec-Rail for cross-border rail networks.
Gentrit Ajazi
External Information Security Officer
Last position:
External Information Security Officer at Large dairy company
- Align information security objectives with executive management
- Monitor and steer the Information Security Management System (ISMS) in collaboration with the information security team
- Serve as the primary point of contact for all information security matters and advise internal staff and process owners (e.g., Supplier Management, HR)
- Further develop and improve the ISMS and information security policies
- Deliver training and drive ongoing employee awareness
- Hold monthly coordination meetings (jour fixe)
- Conduct risk analyses together with executive management and process owners
- Support audits (e.g., ISO 27001) as well as customer-specific audits
- Structure assessment and handling of information security incidents in cooperation with the information security team
- Support preparation of the annual plan and budget for information security measures
- Plan and conduct internal audits and management reviews
- Integrate the ISMS with other management systems
Gentrit Ajazi
External Information Security Officer
Last position:
External Information Security Officer at Large dairy company
- Align information security objectives with executive management
- Monitor and steer the Information Security Management System (ISMS) in collaboration with the information security team
- Serve as the primary point of contact for all information security matters and advise internal staff and process owners (e.g., Supplier Management, HR)
- Align information security objectives with executive management
- Monitor and steer the Information Security Management System (ISMS) in collaboration with the information security team
- Serve as the primary point of contact for all information security matters and advise internal staff and process owners (e.g., Supplier Management, HR)
- Further develop and improve the ISMS and information security policies
- Deliver training and drive ongoing employee awareness
- Hold monthly coordination meetings (jour fixe)
- Conduct risk analyses together with executive management and process owners
- Support audits (e.g., ISO 27001) as well as customer-specific audits
- Structure assessment and handling of information security incidents in cooperation with the information security team
- Support preparation of the annual plan and budget for information security measures
- Plan and conduct internal audits and management reviews
- Integrate the ISMS with other management systems
- Further develop and improve the ISMS and information security policies
- Deliver training and drive ongoing employee awareness
- Hold monthly coordination meetings (jour fixe)
- Conduct risk analyses together with executive management and process owners
- Support audits (e.g., ISO 27001) as well as customer-specific audits
- Structure assessment and handling of information security incidents in cooperation with the information security team
- Support preparation of the annual plan and budget for information security measures
- Plan and conduct internal audits and management reviews
- Integrate the ISMS with other management systems
Jörg Hoffmann
Managing Director; Data Protection Officer; Information Security Officer
Last position:
Managing Director; Data Protection Officer; Information Security Officer at Datenschutz24 (brand of Sovestro GmbH)
- Drafting company agreements related to data protection
- Acting as a mediator between business interests and data subject rights in a corporate context
- Process analysis and evaluation regarding data protection and information security implications according to GDPR, BDSG, BSI baseline protection
- Support for information security audits according to ISO 27001
- Implementation of change management processes
- Analysis of IT infrastructure and deriving recommendations
- Expert support in legal proceedings and communication with supervisory authorities
- Preparation of data protection impact assessments (DPIAs) and procedure and processing documentation (VVZ)
- Training on corporate data protection and information security
- Cooperation with law firms in legal proceedings
Jörg Hoffmann
Managing Director; Data Protection Officer; Information Security Officer
Last position:
Managing Director; Data Protection Officer; Information Security Officer at Datenschutz24 (brand of Sovestro GmbH)
- Drafting company agreements related to data protection
- Acting as a mediator between business interests and data subject rights in a corporate context
- Process analysis and evaluation regarding data protection and information security implications according to GDPR, BDSG, BSI baseline protection
- Drafting company agreements related to data protection
- Acting as a mediator between business interests and data subject rights in a corporate context
- Process analysis and evaluation regarding data protection and information security implications according to GDPR, BDSG, BSI baseline protection
- Support for information security audits according to ISO 27001
- Implementation of change management processes
- Analysis of IT infrastructure and deriving recommendations
- Expert support in legal proceedings and communication with supervisory authorities
- Preparation of data protection impact assessments (DPIAs) and procedure and processing documentation (VVZ)
- Training on corporate data protection and information security
- Cooperation with law firms in legal proceedings
- Support for information security audits according to ISO 27001
- Implementation of change management processes
- Analysis of IT infrastructure and deriving recommendations
- Expert support in legal proceedings and communication with supervisory authorities
- Preparation of data protection impact assessments (DPIAs) and procedure and processing documentation (VVZ)
- Training on corporate data protection and information security
- Cooperation with law firms in legal proceedings
Mirko Haucke
Cybersecurity Manager
Last position:
Cybersecurity Manager at Joynext GmbH
Cybersecurity for RTCU project for the Stellantis Group.
The management of cybersecurity was strongly criticized by the customer Stellantis, questioning competence. Requirements were missing or incomplete, the architecture for cybersecurity controls was non-existent, and documentation such as cybersecurity plans and concepts were incomplete and formally incorrect.
- Building customer trust and de-escalation
- Sprint planning with the customer based on SAFe
- Task-force management
- Switching planning and control to an agile approach
- Review and update of cybersecurity documents
- Communication and problem solving with suppliers, particularly Rolling Wireless and Autocrypt
- Internal workshops and coordination across various hierarchy levels from developers to CTO
- Coordination of work packages and implementation across locations in Dresden, Ningbo, and Oborniki
- Reporting and support of cybersecurity audits
- Coaching of Joynext cybersecurity managers
- De-escalation of critical customer issues
- Acceleration of requirement creation and release by a factor of 5
- Timely provision of 3rd party components
- Reduction of vulnerability management effort by factor 3
- Creation of cybersecurity documents conformant to existing standards
- Technologies and Methods: V-Modell, ASPICE, IREB, ISTQB, Scrum, Kanban, SAFe, PMP, IPMA, BPMN 2.0, Microsoft Office, Microsoft Project, Jira, Confluence, Siemens Polarion, Dependency Track
Mirko Haucke
Cybersecurity Manager
Last position:
Cybersecurity Manager at Joynext GmbH
Cybersecurity for RTCU project for the Stellantis Group.
The management of cybersecurity was strongly criticized by the customer Stellantis, questioning competence. Requirements were missing or incomplete, the architecture for cybersecurity controls was non-existent, and documentation such as cybersecurity plans and concepts were incomplete and formally
Cybersecurity for RTCU project for the Stellantis Group.
The management of cybersecurity was strongly criticized by the customer Stellantis, questioning competence. Requirements were missing or incomplete, the architecture for cybersecurity controls was non-existent, and documentation such as cybersecurity plans and concepts were incomplete and formally incorrect.
- Building customer trust and de-escalation
- Sprint planning with the customer based on SAFe
- Task-force management
- Switching planning and control to an agile approach
- Review and update of cybersecurity documents
- Communication and problem solving with suppliers, particularly Rolling Wireless and Autocrypt
- Internal workshops and coordination across various hierarchy levels from developers to CTO
- Coordination of work packages and implementation across locations in Dresden, Ningbo, and Oborniki
- Reporting and support of cybersecurity audits
- Coaching of Joynext cybersecurity managers
- De-escalation of critical customer issues
- Acceleration of requirement creation and release by a factor of 5
- Timely provision of 3rd party components
- Reduction of vulnerability management effort by factor 3
- Creation of cybersecurity documents conformant to existing standards
- Technologies and Methods: V-Modell, ASPICE, IREB, ISTQB, Scrum, Kanban, SAFe, PMP, IPMA, BPMN 2.0, Microsoft Office, Microsoft Project, Jira, Confluence, Siemens Polarion, Dependency Track
incorrect.
- Building customer trust and de-escalation
- Sprint planning with the customer based on SAFe
- Task-force management
- Switching planning and control to an agile approach
- Review and update of cybersecurity documents
- Communication and problem solving with suppliers, particularly Rolling Wireless and Autocrypt
- Internal workshops and coordination across various hierarchy levels from developers to CTO
- Coordination of work packages and implementation across locations in Dresden, Ningbo, and Oborniki
- Reporting and support of cybersecurity audits
- Coaching of Joynext cybersecurity managers
- De-escalation of critical customer issues
- Acceleration of requirement creation and release by a factor of 5
- Timely provision of 3rd party components
- Reduction of vulnerability management effort by factor 3
- Creation of cybersecurity documents conformant to existing standards
- Technologies and Methods: V-Modell, ASPICE, IREB, ISTQB, Scrum, Kanban, SAFe, PMP, IPMA, BPMN 2.0, Microsoft Office, Microsoft Project, Jira, Confluence, Siemens Polarion, Dependency Track
Friederike Balaz
Information Security Manager
Last position:
Information Security Manager at Johner Medical GmbH
Friederike Balaz
Information Security Manager
Last position:
Information Security Manager at Johner Medical GmbH
Maxim Ribakowski
Information Security Officer
Last position:
Information Security Officer at Horváth AG
- Managing the Information Security program according to ISO27001:2022, BAIT, BSI 200-1/4
- Creating and updating IT policies and procedures
- Communicating with C-level and the board (weekly, monthly, quarterly reports on incidents, risks, measures, audits, strategic and personnel planning)
- Coordinating external and internal audits (JAP, BAIT, BaFin)
- Risk management (monitoring improvement measures, assessing new risks, planning and reporting countermeasures)
- Incident management (analyzing security-related incidents, monitoring and planning countermeasures and improvements)
- Training employees on incidents, internal policies, and emergency procedures
- Business continuity management (reviewing and updating BIA, emergency plans, recovery concepts, test results)
- Managing communication between departments as a mediator
- Managing and auditing external service providers (IT, cloud services; SOC 1/2, ISAE 3402 Type 1/2, C5 reports, on-site audits)
Maxim Ribakowski
Information Security Officer
Last position:
Information Security Officer at Horváth AG
- Managing the Information Security program according to ISO27001:2022, BAIT, BSI 200-1/4
- Creating and updating IT policies and procedures
- Communicating with C-level and the board (weekly, monthly, quarterly reports on incidents, risks, measures, audits, strategic and personnel planning)
- Coordinating external and internal audits (JAP, BAIT, BaFin)
- Managing the Information Security program according to ISO27001:2022, BAIT, BSI 200-1/4
- Creating and updating IT policies and procedures
- Communicating with C-level and the board (weekly, monthly, quarterly reports on incidents, risks, measures, audits, strategic and personnel planning)
- Coordinating external and internal audits (JAP, BAIT, BaFin)
- Risk management (monitoring improvement measures, assessing new risks, planning and reporting countermeasures)
- Incident management (analyzing security-related incidents, monitoring and planning countermeasures and improvements)
- Training employees on incidents, internal policies, and emergency procedures
- Business continuity management (reviewing and updating BIA, emergency plans, recovery concepts, test results)
- Managing communication between departments as a mediator
- Managing and auditing external service providers (IT, cloud services; SOC 1/2, ISAE 3402 Type 1/2, C5 reports, on-site audits)
- Risk management (monitoring improvement measures, assessing new risks, planning and reporting countermeasures)
- Incident management (analyzing security-related incidents, monitoring and planning countermeasures and improvements)
- Training employees on incidents, internal policies, and emergency procedures
- Business continuity management (reviewing and updating BIA, emergency plans, recovery concepts, test results)
- Managing communication between departments as a mediator
- Managing and auditing external service providers (IT, cloud services; SOC 1/2, ISAE 3402 Type 1/2, C5 reports, on-site audits)
Jörg Iffländer
External Information Security Officer
Last position:
External Information Security Officer at ilink Kommunikationssysteme GmbH
Jörg Iffländer
External Information Security Officer
Last position:
External Information Security Officer at ilink Kommunikationssysteme GmbH
Patrick Günther
Information Security Manager
Last position:
Information Security Manager at IT-Freelancer
- Responsible for computer software validation (CSV) of the IT infrastructure
- Supported the operation and maintenance of the Integrated Management System (IMS)
- Served as interim information security officer (ISMR) for two companies in the medtech industry
- Ensured ISO 27001 compliance within the organization
- Contributed to implementing cybersecurity requirements for health software and networked medical devices according to ISO 81001-1
Patrick Günther
Information Security Manager
Last position:
Information Security Manager at IT-Freelancer
- Responsible for computer software validation (CSV) of the IT infrastructure
- Supported the operation and maintenance of the Integrated Management System (IMS)
- Served as interim information security officer (ISMR) for two companies in the medtech industry
- Responsible for computer software validation (CSV) of the IT infrastructure
- Supported the operation and maintenance of the Integrated Management System (IMS)
- Served as interim information security officer (ISMR) for two companies in the medtech industry
- Ensured ISO 27001 compliance within the organization
- Contributed to implementing cybersecurity requirements for health software and networked medical devices according to ISO 81001-1
- Ensured ISO 27001 compliance within the organization
- Contributed to implementing cybersecurity requirements for health software and networked medical devices according to ISO 81001-1
Stephan Selnerat
IT-Security Manager
Last position:
IT-Security Manager at Large industrial corporation with multiple international locations
- Planning and managing all projects in the context of IT security
- Establishing a Cyber Security Incident Response procedure according to ISO/IEC 27035
- NIS2 readiness: impact analysis, planning and implementation of NIS2 compliance
- Management reporting based on KPIs
Stephan Selnerat
IT-Security Manager
Last position:
IT-Security Manager at Large industrial corporation with multiple international locations
- Planning and managing all projects in the context of IT security
- Establishing a Cyber Security Incident Response procedure according to ISO/IEC 27035
- Planning and managing all projects in the context of IT security
- Establishing a Cyber Security Incident Response procedure according to ISO/IEC 27035
- NIS2 readiness: impact analysis, planning and implementation of NIS2 compliance
- Management reporting based on KPIs
- NIS2 readiness: impact analysis, planning and implementation of NIS2 compliance
- Management reporting based on KPIs
Stefan Laubmeister
Freelance Lecturer
Last position:
Freelance Lecturer at Dr. Stefan P. Laubmeister
- Topic “Organization & Digitization”
Stefan Laubmeister
Freelance Lecturer
Last position:
Freelance Lecturer at Dr. Stefan P. Laubmeister
- Topic “Organization & Digitization”
- Topic “Organization & Digitization”
Discover over 15,000 top freelancers
Information Security Managers statistics
Aggregated from the professional profiles of matched freelancers.
Experience
22 years
Position duration
4.5 years
Positions per freelancer
13
Top business areas
Information Technology, Project Management, Quality Assurance
Top industries
Information Technology, Professional Services, Automotive
Certification focus areas
Information Technology, Audit, Legal
Bachelor's degree or higher
85%
Master's degree or higher
54%
Doctorate
8%
Certifications per freelancer
7
Most common languages
German, English, French
Speak two or more languages
100%
Daily Rate Distribution
The chart shows how the daily rates of freelancers in this role are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Average rates for Information Security Managers & Seniority distribution
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Frequently Asked Questions
Want to learn more? Find helpful information about FRATCH
An Information Security Manager is responsible for designing, implementing, and maintaining policies that protect an organization's digital assets. They assess risks, establish governance frameworks like ISO 27001, and ensure that the entire workforce follows secure data handling practices.
A freelance ISMS Manager provides immediate, highly specialized expertise to resolve specific bottlenecks, such as preparing for an upcoming certification audit. This approach avoids long hiring cycles and offers the flexibility to scale down security resources once the main framework is established.
While a security engineer focuses on configuring firewalls, writing code, and executing technical defenses, an IT Security Officer operates at a strategic level. They align security policies with overall business goals, manage compliance, and direct the technical teams on priority areas.
In Germany, an Information Security Manager must navigate strict national standards, including the IT Security Act and specific guidelines from the BSI. For companies in the automotive supply chain, implementing TISAX compliance is often a mandatory requirement that requires localized expertise.
An interim CISO can execute most strategic tasks, policy writing, and risk analysis remotely. However, critical phases such as physical security audits, initial infrastructure discovery, and crisis response often benefit from occasional on-site presence.
Look for internationally recognized credentials such as CISSP, CISM, or certified lead auditor status for ISO 27001. These certifications demonstrate that the security consultant has a standardized understanding of governance, risk management, and compliance frameworks.
A skilled interim security leader immediately activates the incident response plan, coordinates with IT forensics, and isolates affected systems. They also manage critical communication with stakeholders and regulatory authorities to mitigate reputational and legal damage.
While technical execution can often be handled in English, an information security consultant working with German public authorities or critical infrastructure often needs professional German skills. This ensures clear interpretation of local laws and seamless communication with works councils.
The average hourly rate for Information Security Managers in Germany is 112 €, which corresponds to a daily rate of about 894 € based on an 8-hour working day.
Of the freelancers working as Information Security Managers in Germany, 85% hold at least a Bachelor's degree, 54% hold at least a Master's degree, and 8% hold a doctorate.
On average, freelancers working as Information Security Managers in Germany have 22 years of professional experience, with a single engagement typically lasting around 4.5 years.
The most common languages among freelancers working as Information Security Managers in Germany are German (100%), English (100%), and French (27%).
The most common industries among freelancers working as Information Security Managers in Germany are Information Technology (87%), Professional Services (67%), and Automotive (47%).
The most common business areas among freelancers working as Information Security Managers in Germany are Information Technology (100%), Project Management (87%), and Quality Assurance (87%).
FRATCH Information Security Managers main locations
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a Free Demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
