
BSI IT-Grundschutz Experts in Dusseldorf
with precise AI matching, vetted and available freelancersHire experts who establish information security management systems, perform structural analyses and prepare organizations for BSI audits. FRATCH matches you quickly and precisely with vetted, available freelancers who fit your requirements.
Meet FRATCH Experts in Dusseldorf, who have recently used BSI IT-Grundschutz
Rudolf E.
Last position:
Datacenter Engineer, Network & Security Administrator at International insurance group
Operation and further development of the network and security infrastructure.
Monitoring, analysis and resolution of network and security incidents.
Cross-department collaboration with other specialist teams for operations, further development and reporting.
Firewall vulnerability analysis.
Firewall rule approvals.
Troubleshooting IP communication issues in the network and firewall infrastructure.
Security-critical IT infrastructure, processing of personal data, compliance with legal regulations.
Products: Palo Alto Networks Firewalls, Cisco ACI, Checkpoint Firewalls, F5
Technologies: SDN, SDWAN, Cisco EPIC, Cisco ACI
Alicja W.
Last position:
Integrated Security and Emergency Documentation for a 24/7 Logistics Company at Medium-Sized Logistics Company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), Access Control Policy, Vulnerability Management Policy, Business Resilience Programme, Risk Governance Plan
- Consolidation into an integrated emergency manual (12 chapters) with immediate-action checklists for six emergency scenarios, a prioritized action table and a formal approval structure
- Review and documentation of the applicability of NIS2 and HinSchG, including the legal justification for non-applicability
Olaf R.
Last position:
DevOps Architect / Consultant at Authority with increased security requirements
- Identification of requirements (legal, organizational, and technical)
- Design of solution architectures
- Evaluation of concepts and technologies
- Preparation of decision templates
- Architectural Decision Records (ADR)
- Coordination of implementation
- Review of implementations
- Documentation
Federico L.
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW.  Developed and implemented a holistic process view covering both technical and organizational aspects  Ensured end-to-end control of all IAM-related technical services  Established clear responsibilities and accountabilities within the IAM landscape  Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security  Introduced and monitored governance policies to ensure compliance and security  Continuously improved IAM processes and systems through regular audits and evaluations  Participated in external audits of the process as part of official ISO audits  Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units  Conceptually advanced the KPI system to measure process quality
Wolfgang S.
Last position:
CIO / CDO / Project Manager AI Academy / Auditor of Operational Processes / Product Owner MS365 at F&P Executive Solutions AG
- Digitalization of accounting, signature/approval, and onboarding processes
- Restructuring of the IT department
- Introduction of a digital sales tool
- Implementation of an AI webinar series
- Introduction and optimization of information security
- Administration and optimization of the MS Office 365 environment
Ralph K.
Last position:
Product Owner / Business Owner at AXIS Management Consulting GmbH
- Full product responsibility from a business perspective: requirement analysis, UX design, product strategy, and go-to-market implemented without an internal dev team using fully AI-supported development (Claude Code / Anthropic)
- Technical differentiation: KRITIS-compliant air-gapped deployment (Windows/NSIS), GDT interface for PVS integration, DATEV-LODAS export for payroll
- Managed pilot operation with initial external client (Dormagen medical practice): structured requirement gathering, test support, error analysis, and release management
- Developed rollout and sales strategy for market entry in the segment of private practices and small medical centers
- Human-in-the-Loop development principle: business decision → AI implementation → manual review → approval → release – each sprint documented in Jira (TIME project), every change traceable via co-authored commits
- Product outcome: Tauri/Rust desktop app with GDT watcher, multi-tier model (Starter/Professional/Enterprise), cloud mirror on Hetzner/Traefik, complete ISMS framework based on ISO 27001 and BSI basic protection as product foundation
- Direct method validation for the test manager role: hands-on experience with quality assurance of AI-generated products from a user perspective, review gate discipline, release approval under GDPR and the EU AI Act
Nikolaus B.
Last position:
ICT Risk Management and Information Security at B. Metzler seel. Sohn & Co. AG
- Independently develop policies, guidelines, and frameworks for ICT risk management and information security
- Advise business units on ICT risk management and information security
- Further develop the ICT risk management framework that governs the identification, assessment, and control of ICT risks
- Evaluate the Information Security Management System (ISMS) and adjust it for new challenges
- Conduct risk analyses to identify and assess potential ICT risks and information security risks for the Metzler Group
- Advise on defining and implementing measures to reduce risks and improve the resilience of ICT systems
- Advise on ensuring compliance with relevant internal and external regulatory requirements (MaRisk, DORA, BAIT, BSI IT baseline protection, ISMS, ISO 27001, ISO 42001, ISO 27005, BCM ISO 22301)
- Advise on internal and cross-functional projects (SAP DORA compliance, Target2, Section 8a BSI Act)
Bernhard D.
Last position:
Enterprise Architect. And responsible for the cross-functional architecture as well as all domains with a focus on the sales at Süddeutsche Krankenversicherung
Creation of business and technical concepts as well as support for enterprise architecture management as part of the migration to the Adesso standard insurance solutions and the renewal of surrounding systems
Interface definitions
Business analysis and creation of the business concepts for input management and sales
Creation of architecture guidelines and processes
Processing technical and business decisions in the architecture board
Definition of service processes and system management aspects
Creation of the technical target operating model
Creation of an integration architecture for AI/LLMs from the providers Commasoft and Insiders
CommaSoft (Alan) webpages and web services
Insiders for Smartfix based on web services
Creation of a question catalog for a security/regulatory check.
Analysis of threats using threat modeling / STRIDE incl. creation of a set of measures to secure the systems
System environment: Jira, Confluence, Java, Enterprise Architect, VAIT/DORA, KritisV, GDPR, IT ServiceMgmt, Adesso Ecosphere and Insure Health, DoPIX and successor product, SmartFix, SmartFlow, Zabas, Kolumbus, Clarc archive, BiPRO, AI / LLM, MS Azure, AWS, TOM/FMO
Heinz-Dieter L.
Last position:
Consultant at CH Crypto Group
- Advice on governance and information security topics: BAIT, MaRisk
- Creating governance documents (policies, guidelines)
- Developing emergency manuals
- Based on BSI IT baseline protection standard 200-4 and ISO2700x
Holger G.
Last position:
IT at Holger Grittner Consulting
Discover over 15,000 top freelancers
Statistics of experts using BSI IT-Grundschutz
Aggregated from the professional profiles of matched freelancers.
Experience
26 years (Germany: 23 years)

Position duration
2.2 years (Germany: 2.6 years)

Positions per freelancer
21 (Germany: 17)

Top business areas
Information Technology, Operations, Project Management

Top industries
Information Technology, Healthcare, Government and Administration

Certification focus areas
Information Technology, Audit, Project Management
Bachelor's degree or higher
50% (Germany: 85%)
Master's degree or higher
33% (Germany: 54%)

Certifications per freelancer
6 (Germany: 8)

Most common languages
German, English, Spanish

Speak two or more languages
80% (Germany: 94%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Dusseldorf are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Dusseldorf using BSI IT-Grundschutz
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
BSI IT-Grundschutz experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (100%)
- Healthcare (90%)
- Government and Administration (70%)
- Banking and Finance (60%)
- Insurance (50%)
- Manufacturing (50%)
- Professional Services (50%)
- Energy (40%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
What IT-Grundschutz covers
BSI IT-Grundschutz is the German Federal Office for Information Security methodology for establishing and improving information security. It combines organizational, personnel, technical and structural safeguards in a repeatable security process. Companies use it to protect information, services, facilities and business processes against realistic threats.
Standards and methodology
The approach is based on the BSI Standards, including BSI Standard 200-1 for information security management, BSI Standard 200-2 for the IT-Grundschutz methodology and BSI Standard 200-3 for risk analysis. Specialists work with the IT-Grundschutz Compendium, protection requirements, information domains and security concepts. They also align the method with ISO 27001 where certification or international compatibility matters.
Typical project work
- Define the information security organization and scope
- Create structural analyses, modeling and protection requirements
- Assess risks and document suitable safeguards
- Prepare security concepts, audit evidence and remediation plans
- Support certification preparation and ongoing improvement
These deliverables can cover data centers, cloud services, applications, networks, workplaces and business processes. The method is relevant to public bodies, regulated organizations and companies handling sensitive customer or operational information.
When specialists help
Companies often bring in freelance expertise when they need an independent assessment, must formalize an information security management system or are preparing for an audit. External specialists can accelerate a first IT-Grundschutz assessment, close documentation gaps and coordinate security work across business and IT teams. In Dusseldorf, on-site workshops may complement remote analysis for organizations with distributed locations.
Skills around the method
Strong professionals combine BSI IT-Grundschutz with information security governance, risk management, business continuity and data protection. Useful adjacent knowledge includes ISO 27001, cloud security, identity and access management, network protection, incident response and audit management. They can translate the Compendium's requirements into controls that teams can operate and prove.
What distinguishes strong professionals
A capable specialist separates documented intent from verifiable implementation. They ask precise questions about assets, dependencies, threats and responsibilities, then produce clear models, risk decisions and actionable measures. Look for experience with evidence collection, management communication and audit findings, plus the ability to explain BSI terminology in plain language. German-language work is often important for local policies, authorities and audit documentation, while remote collaboration can work well with structured workshops and shared evidence repositories.
Frequently asked questions
Everything clients usually want to know about BSI IT-Grundschutz, in one place.
BSI IT-Grundschutz is used to build, operate and improve an information security management system based on the BSI methodology. It helps organizations model their information, processes and systems, assess protection requirements and implement suitable safeguards.
BSI IT-Grundschutz provides a detailed methodology, modeling approach and catalog of safeguards for creating an information security management system. ISO 27001 defines internationally recognized management system requirements and supports certification; many organizations combine both approaches rather than treating them as direct substitutes.
A strong BSI IT-Grundschutz specialist often also understands ISO 27001, risk management, data protection, business continuity and audit preparation. Depending on the assignment, cloud security, network architecture, identity management and incident response are valuable additions.
The right level depends on the scope and maturity of the organization. A focused gap assessment may need a specialist who can work independently with existing documentation, while a full information security management system or certification program calls for experience in governance, modeling, risk analysis and stakeholder coordination.
BSI IT-Grundschutz work can often be performed remotely through structured interviews, document reviews and online workshops. On-site sessions in Dusseldorf are useful for inspecting facilities, validating physical safeguards and aligning teams that handle sensitive information. German-language communication may be important for policies, authorities and audit evidence.
A BSI IT-Grundschutz project may deliver a defined scope, structural analysis, modeling, protection requirements, risk assessments and a security concept. It can also include a safeguard implementation plan, audit evidence, management decisions and documentation of open findings.
Ask the BSI IT-Grundschutz specialist to explain how they move from business processes and information to models, risks, safeguards and evidence. Good professionals distinguish between planned and implemented controls, document assumptions clearly and adapt the method to the organization instead of producing generic paperwork.
A capable BSI IT-Grundschutz freelancer should work confidently with the BSI Standards, especially BSI Standard 200-1, BSI Standard 200-2 and BSI Standard 200-3. Familiarity with the IT-Grundschutz Compendium, audit guidance and current BSI publications helps keep assessments and security concepts consistent with the methodology.
The average hourly rate of freelancers in Dusseldorf, Germany who have used BSI IT-Grundschutz in their recent projects is 114 €, which corresponds to a daily rate of about 910 € based on an 8-hour working day.
Of the freelancers in Dusseldorf, Germany who have used BSI IT-Grundschutz in their recent projects, 50% hold at least a Bachelor's degree and 33% hold at least a Master's degree.
On average, freelancers in Dusseldorf, Germany who have used BSI IT-Grundschutz in their recent projects have 26 years of professional experience, with a single engagement typically lasting around 2.2 years.
The most common languages among freelancers in Dusseldorf, Germany who have used BSI IT-Grundschutz in their recent projects are German (100%), English (80%), and Spanish (30%).
The most common industries among freelancers in Dusseldorf, Germany who have used BSI IT-Grundschutz in their recent projects are Information Technology (100%), Healthcare (90%), and Government and Administration (70%).
The most common business areas among freelancers in Dusseldorf, Germany who have used BSI IT-Grundschutz in their recent projects are Information Technology (100%), Operations (90%), and Project Management (90%).
Main locations of FRATCH Experts, who have recently used BSI IT-Grundschutz
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich
Cologne
Frankfurt