Skip to main content
🇩🇪GDPR-compliant

Find the perfect IT Security Officers in Germany in minutes from 15,000 CVs with the power of AI.

Support for ISO 27001, ISMS governance, risk assessments, and security policies that fit your business. Add incident handling, vendor reviews, and audit preparation, then match with vetted, available freelancers fast and precisely.

About the role

Security scope

An IT Security Officer sets the rules, monitors the controls, and helps the business keep systems, data, and access under control. The work often covers policy design, risk reviews, security awareness, incident coordination, and support for audits or certifications.

  • Define and maintain security policies and standards
  • Review risks in systems, suppliers, and processes
  • Support incident response and root-cause follow-up
  • Prepare evidence for internal and external audits
  • Align security measures with IT and business teams

Typical deliverables

A strong information security officer leaves behind clear, usable outputs. That can mean an ISMS structure, risk registers, control maps, exception handling, and practical guidance for teams that need to follow the rules without slowing delivery.

  • Security policy sets and guidelines
  • Risk treatment plans and action lists
  • Audit-ready documentation and evidence packs
  • Incident procedures and escalation paths
  • Awareness material for employees and managers

Core skills

This role needs a calm view of technical detail and business impact. Good candidates understand identity and access management, endpoint and network security, cloud controls, logging, and how to translate policy into day-to-day practice.

  • Familiarity with ISO 27001 and related governance work
  • Ability to assess technical and organisational risks
  • Clear communication with IT, legal, compliance, and leadership
  • Strong documentation habits and structured thinking
  • Experience working with auditors, vendors, and internal stakeholders

Tools and methods

An IT security consultant or security manager often works with SIEM, IAM, vulnerability management, ticketing, and documentation tools. Just as important are methods like risk workshops, control reviews, security baselines, and incident playbooks that can be used across mixed environments.

When to bring one in

Companies usually hire freelance support when security work needs focused attention, but a permanent role is not the best fit yet. In Germany, this is common for mid-sized firms, regulated sectors, and project-heavy teams that need help before an audit, after a security incident, or during cloud and infrastructure changes.

What good looks like

The best professionals do more than write policies. They know how to make controls usable, spot gaps early, and get people to act on security risks without creating confusion. Strong IT Security Officers keep the message practical, the documentation clean, and the follow-up consistent.

Meet FRATCH IT Security Officers

Florian Schröder

Information Security Officer / IT Security Architect / Awareness Expert

Norderstedt

Last position:

Information Security Officer / Designated InfoSec Officer at Oil Company

  • Complete overhaul of the ISMS according to ISO 27001
  • Conducted a comprehensive gap analysis
  • Reduced ISMS documentation by 30% through consolidation and process optimization
  • Introduced a full PDCA cycle for continuous improvement
  • Established the ISMS within the company
  • Implemented the necessary processes
  • Managed and conducted internal and external audits
  • Developed and implemented a company-wide risk management system
  • Deployed an ISMS tool including process design and training
  • KRITIS compliance: Prepared and provided required evidence, liaised with regulatory authorities, planned, documented, and implemented an attack detection system (SIEM), co-led the BCMS/ITSCM implementation subproject
  • NIS-2 implementation: Gap analysis, risk assessments, training for executives and staff
  • Led a cybersecurity team of 3 members
  • Conducted various internal and external audits, managed providers, introduced continuous improvement
  • Project consulting: closely coordinated with business and system owners, launched an online shop, a mobile app, and a customer portal
  • Redesigned the security architecture, reducing administrative efforts by 20%
  • Implemented ITIL processes (e.g., change management)
  • Revised service agreements with internal and external providers
  • Developed a security awareness strategy, ran social engineering tests, introduced and monitored phishing simulations, created various awareness materials, gave presentations
  • Managed a budget of one million euros
Florian Schröder

Kerstin Glawinski

IT Security Officer with TÜV Rheinland certified qualification

Berlin

Last position:

Information Security Consulting at CAS AG

Kerstin Glawinski

Michael Fitschen

Managing Consultant Information Security and Data Protection

Heeslingen

Last position:

Project Manager Implementation B3S / ISO 27001 at Health Insurance Fund

  • Coordination of the B3S and ISO 27001 implementation project, considering the upcoming KRITIS evidence procedure
  • Providing consulting services in ISO 27001, B3S, KRITIS, and IT baseline protection
  • Collaborating with the Information Security Officer (ISO)
  • Identifying company assets for IT risk management
  • Developing a zone concept for IT risk management
  • Creating an action plan for B3S
  • Developing a template for risk analyses
Michael Fitschen

Andreas Ilias

Senior Cybersecurity Governance & ISMS Consultant

Frankfurt am Main

Last position:

Cybersecurity Specialist Assessor at Bundesnetzagentur

  • Recognition of national notified bodies
  • Preparation of cybersecurity competency reports
  • EU Radio Equipment Directive
Andreas Ilias

Klaus Rheinwald

Senior Project Manager

Hamburg

Last position:

Management Consultant Compliance/Data Protection at Telefónica Germany GmbH & Co. OHG

Consulting on compliance and data protection topics in the telecommunications environment.

Klaus Rheinwald

Arndt Schürg

Information Security Officer according to TISAX

Ludwigshafen

Last position:

Information Security Officer according to TISAX at Automotive Supplier

Arndt Schürg

Christoph Hennings

Senior IT/OT-Security Specialist

Norderstedt

Last position:

Senior IT/OT-Security Specialist at Aurubis AG

  • Specialized in development and implementation of IT and OT security strategies
  • Conducting risk analyses, vulnerability management and security assessments
  • Administration of Microsoft Cloud and server solutions
  • Establishment and maintenance of ISMS according to ISO 27001, NIS2, BSI and IEC 62443
  • Planning and management of security projects in industrial and production environments
  • Ensuring regulatory compliance with incident response, emergency management and awareness
  • Collaboration with business units, management and external service providers
  • Preparation of IT infrastructure for audits
Christoph Hennings

Benno Zabel

Freelance Data Protection Officer

Windeby

Last position:

Freelance Data Protection Officer at SUMTEC

  • Drafting the data protection concept under EU GDPR including DPIA and implementing TOMs
Benno Zabel

Sebastian Lingenfelter

LLM Evaluation Response Specialist

Munich

Last position:

LLM Evaluation Response Specialist at Translated.com

  • Created and refined technical and compliance-oriented datasets for AI, ensuring high-quality structured documentation.
  • Conducted supervised fine-tuning (SFT) and RLHF tasks, maintaining strict alignment with industry and security guidelines.
  • Produced detailed technical reports and feedback for audits and QA teams.
  • Collaborated with cross-functional teams on documentation strategies for large-scale AI deployments.
Sebastian Lingenfelter

Gentrit Ajazi

External Information Security Officer

Lappersdorf

Last position:

External Information Security Officer at Large dairy company

  • Align information security objectives with executive management
  • Monitor and steer the Information Security Management System (ISMS) in collaboration with the information security team
  • Serve as the primary point of contact for all information security matters and advise internal staff and process owners (e.g., Supplier Management, HR)
  • Further develop and improve the ISMS and information security policies
  • Deliver training and drive ongoing employee awareness
  • Hold monthly coordination meetings (jour fixe)
  • Conduct risk analyses together with executive management and process owners
  • Support audits (e.g., ISO 27001) as well as customer-specific audits
  • Structure assessment and handling of information security incidents in cooperation with the information security team
  • Support preparation of the annual plan and budget for information security measures
  • Plan and conduct internal audits and management reviews
  • Integrate the ISMS with other management systems
Gentrit Ajazi

Jörg Hoffmann

Managing Director; Data Protection Officer; Information Security Officer

Berlin

Last position:

Managing Director; Data Protection Officer; Information Security Officer at Datenschutz24 (brand of Sovestro GmbH)

  • Drafting company agreements related to data protection
  • Acting as a mediator between business interests and data subject rights in a corporate context
  • Process analysis and evaluation regarding data protection and information security implications according to GDPR, BDSG, BSI baseline protection
  • Support for information security audits according to ISO 27001
  • Implementation of change management processes
  • Analysis of IT infrastructure and deriving recommendations
  • Expert support in legal proceedings and communication with supervisory authorities
  • Preparation of data protection impact assessments (DPIAs) and procedure and processing documentation (VVZ)
  • Training on corporate data protection and information security
  • Cooperation with law firms in legal proceedings
Jörg Hoffmann

Mirko Haucke

Cybersecurity Manager

Leimen

Last position:

Cybersecurity Manager at Joynext GmbH

Cybersecurity for RTCU project for the Stellantis Group.

The management of cybersecurity was strongly criticized by the customer Stellantis, questioning competence. Requirements were missing or incomplete, the architecture for cybersecurity controls was non-existent, and documentation such as cybersecurity plans and concepts were incomplete and formally incorrect.

  • Building customer trust and de-escalation
  • Sprint planning with the customer based on SAFe
  • Task-force management
  • Switching planning and control to an agile approach
  • Review and update of cybersecurity documents
  • Communication and problem solving with suppliers, particularly Rolling Wireless and Autocrypt
  • Internal workshops and coordination across various hierarchy levels from developers to CTO
  • Coordination of work packages and implementation across locations in Dresden, Ningbo, and Oborniki
  • Reporting and support of cybersecurity audits
  • Coaching of Joynext cybersecurity managers
  • De-escalation of critical customer issues
  • Acceleration of requirement creation and release by a factor of 5
  • Timely provision of 3rd party components
  • Reduction of vulnerability management effort by factor 3
  • Creation of cybersecurity documents conformant to existing standards
  • Technologies and Methods: V-Modell, ASPICE, IREB, ISTQB, Scrum, Kanban, SAFe, PMP, IPMA, BPMN 2.0, Microsoft Office, Microsoft Project, Jira, Confluence, Siemens Polarion, Dependency Track
Mirko Haucke

Friederike Balaz

Information Security Manager

Schwäbisch Gmünd

Last position:

Information Security Manager at Johner Medical GmbH

Friederike Balaz

Maxim Ribakowski

Information Security Officer

Rüdersdorf

Last position:

Information Security Officer at Horváth AG

  • Managing the Information Security program according to ISO27001:2022, BAIT, BSI 200-1/4
  • Creating and updating IT policies and procedures
  • Communicating with C-level and the board (weekly, monthly, quarterly reports on incidents, risks, measures, audits, strategic and personnel planning)
  • Coordinating external and internal audits (JAP, BAIT, BaFin)
  • Risk management (monitoring improvement measures, assessing new risks, planning and reporting countermeasures)
  • Incident management (analyzing security-related incidents, monitoring and planning countermeasures and improvements)
  • Training employees on incidents, internal policies, and emergency procedures
  • Business continuity management (reviewing and updating BIA, emergency plans, recovery concepts, test results)
  • Managing communication between departments as a mediator
  • Managing and auditing external service providers (IT, cloud services; SOC 1/2, ISAE 3402 Type 1/2, C5 reports, on-site audits)
Maxim Ribakowski

Jörg Iffländer

External Information Security Officer

Wienhausen

Last position:

External Information Security Officer at ilink Kommunikationssysteme GmbH

Jörg Iffländer

Discover over 15,000 top freelancers

IT Security Officers statistics

Aggregated from the professional profiles of matched freelancers.

Experience

21 years

Position duration

4.2 years

Positions per freelancer

13

Top business areas

Information Technology, Project Management, Quality Assurance

Top industries

Information Technology, Professional Services, Energy

Certification focus areas

Information Technology, Audit, Legal

Bachelor's degree or higher

89%

Master's degree or higher

61%

Doctorate

17%

Certifications per freelancer

7

Most common languages

German, English, French

Speak two or more languages

100%

Daily Rate Distribution

0 2 4 6 8
<€720 €720-800 €800-880 €880-960 €960-1040 €1120+

The chart shows how the daily rates of freelancers in this role are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

Average rates for IT Security Officers & Seniority distribution

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 875 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 872 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Try FRATCH GPT

Frequently Asked Questions

Curious about FRATCH? Find the answers you need

An IT Security Officer turns security requirements into day-to-day controls. They define policies, review risks, support incident handling, and help teams prepare for audits or certification work. The role is both technical and organisational, so clear communication matters as much as framework knowledge.

Look for experience with risk assessments, access control, security policies, and audit support. A strong candidate also understands cloud, logging, vulnerability management, and how to work with IT, compliance, and management. If your setup is regulated, ask for direct experience with ISO 27001 or similar governance work.

A cybersecurity specialist or security engineer often focuses more on tools and technical defence. An IT Security Officer usually has a broader governance role: setting rules, coordinating controls, and making sure security is applied across the organisation. In many companies, the titles overlap, but the officer role is usually the clearer ownership point for policy and oversight.

A freelance IT Security Officer is a good fit when you need focused expertise for a project, audit, or gap in coverage. It also works well if your security needs are changing and you want flexibility before committing to a permanent hire. Many companies use a freelancer to stabilise the function and define the next steps.

Most of the work can be done remotely because policies, reviews, and coordination happen in documents, meetings, and shared systems. On-site time helps when you need workshops, stakeholder alignment, or a closer look at local infrastructure and teams. For companies in Germany, a mix of remote and on-site is common, especially in larger or regulated environments.

Expect practical output, not just advice. That usually includes policies, risk registers, control mappings, incident procedures, and audit evidence. If the freelancer is strong, the documents will be usable by your team instead of sitting in a folder.

Good work is visible in fewer open risks, clearer responsibilities, and cleaner audit preparation. A strong IT Security Officer makes security easier to run, not harder, and leaves behind documentation your team can keep using. Ask for examples of how they handled policy rollout, incident follow-up, or cross-team resistance.

In Germany, companies often value experience in manufacturing, industrial groups, SaaS, finance, and other settings where governance and access control matter. German and English communication both help, especially when teams include local operations and international IT. A practical understanding of internal processes is often more valuable than a narrow tool focus.

The average hourly rate for IT Security Officers in Germany is 109 €, which corresponds to a daily rate of about 875 € based on an 8-hour working day.

Of the freelancers working as IT Security Officers in Germany, 89% hold at least a Bachelor's degree, 61% hold at least a Master's degree, and 17% hold a doctorate.

On average, freelancers working as IT Security Officers in Germany have 21 years of professional experience, with a single engagement typically lasting around 4.2 years.

The most common languages among freelancers working as IT Security Officers in Germany are German (100%), English (100%), and French (29%).

The most common industries among freelancers working as IT Security Officers in Germany are Information Technology (86%), Professional Services (76%), and Energy (43%).

The most common business areas among freelancers working as IT Security Officers in Germany are Information Technology (100%), Project Management (86%), and Quality Assurance (81%).

FRATCH IT Security Officers main locations

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a Free Demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO Avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH