BSI IT-Grundschutz Experts in Germany
in minutes from over 15,000 CVs with the power of AI.Hire experts who can apply BSI IT-Grundschutz, map controls to your systems, and prepare audit-ready security documentation for German organisations. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used BSI IT-Grundschutz
Andreas Rühl
Last position:
Freelance Consultant for Information Security at A-R-C Andreas Rühl Consulting
Development and implementation of tailored information security strategies
Introduction and further development of ISMS according to ISO 27001, BSI baseline protection, and other standards
Risk management and creation of security concepts
Consulting for KRITIS, PCI DSS, TISAX, and VdS 3473/10000
Building and improving security organizations
Creation and implementation of guidelines, policies, work instructions, and process descriptions
Audit support and certification preparation
Conducting trainings, workshops, and awareness campaigns
Selection and consulting on the introduction of IT security solutions such as SIEM, DLP, IDS/IPS, firewalls, and encryption technologies
Conducting penetration tests and vulnerability analyses
Consulting on the selection, integration, and management of security architectures in complex IT environments
Consulting on ITSM and managed security services and SOC
Leading and managing complex projects to improve information security
Process analysis, optimization, and management according to ITIL, ISO 27001, and cybernetics
Introduction and quality assurance of management, documentation, and knowledge management systems
Support in complying with regulatory information security requirements (e.g. GDPR, HIPAA, SOX, GMP, KRITIS)
Development and implementation of risk analysis procedures
Organizing initial response, forensic investigations, and organizational measures in the event of security incidents
Designing and running targeted workshops on topics such as ISMS, IT risks, and current threat scenarios
Awareness campaigns to promote security culture in companies
Special trainings on ISO 27001, BSI baseline protection, KRITIS, and other relevant standards
Simulations and exercises to prepare for information security incidents
Interim management for leading information security projects or IT security organizations
Taking on the role of an external CISO (Chief Information Security Officer)
Support in developing and implementing IT security and corporate strategies
Coaching and mentoring of managers in the field of information security
Building and leading security departments as well as recruiting and qualifying employees
Temporary assumption of management responsibility in critical situations
Rudolf Eggelbusch
Last position:
Datacenter Engineer, Network & Security Administrator at International insurance group
Operation and further development of the network and security infrastructure.
Monitoring, analysis and resolution of network and security incidents.
Cross-department collaboration with other specialist teams for operations, further development and reporting.
Firewall vulnerability analysis.
Firewall rule approvals.
Troubleshooting IP communication issues in the network and firewall infrastructure.
Security-critical IT infrastructure, processing of personal data, compliance with legal regulations.
Products: Palo Alto Networks Firewalls, Cisco ACI, Checkpoint Firewalls, F5
Technologies: SDN, SDWAN, Cisco EPIC, Cisco ACI
Maciej Sawicki
Last position:
Product Owner at Bundesagentur für Arbeit
- As part of the project, the further development of the identity management system was driven forward. This included a comprehensive refactoring of the interfaces to the connected target systems. In addition, several special systems were successfully connected to the IAM to ensure end-to-end identity and authorization management.
- Technical design and solution proposals for IAM system development
- Requirements analysis and requirements management (IREB, BABOK)
- Alignment of the strategy with the future target architecture (TOGAF)
- Prototyping of solutions
- Documentation of requirements (Innovator)
- Analysis and documentation of requirements and creation of process models (UML, BPMN, ArchiMate)
- Modeling of requirements and system functionalities (OOA/OOD, UML)
- Further development of interfaces (SOAP, REST)
- Carrying out architecture reviews
Regina Körnicke
Last position:
Data Protection Consultant at Promotional institute of a federal state (public credit institution)
Industry: Finance/Insurance
- Sparring partner for the data protection team
- Taking over tasks from the data protection backlog
- Updating data protection processes
- Updating TOMs
- Revising template documents (including DPA, data protection guidelines)
- Conducting audits (authorization concept, software development)
- Taking over tasks from day-to-day operations
- Processing data protection reports
- Conducting DPIA and TIA
- Reviewing data processing agreements
- Designing and delivering trainings
- Standard Data Protection Model
- AI and data protection
Result: Successfully supported the data protection team, worked through the data protection backlog, and delivered trainings successfully
Karl-Heinz Reis
Last position:
Support in the further development of a European IT store service organization (15 countries) at European retail company (discount store)
- Capturing the current processes Incident Management, IT Service Request Management, Problem Management, Change Management, Service Configuration Management (including CMDB)
- Carrying out maturity assessments for these processes based on the ITIL® 4 Maturity Model
- Analyzing the different service value streams based on the ITIL® 4 value stream model
- Agreeing maturity levels for the processes being reviewed
- Developing and approving a roadmap to achieve and measure the respective maturity levels
- Presenting the approach, including milestones, to management for approval
- Managing external service providers in 1st level support
Dirk Peter
Last position:
Freelance Cyber Defense Lead & KRITIS/NIS2 Consultant | AI Security Architect at Self-Employed
Situation: Increasing demand for privacy-compliant AI solutions for clients in the KRITIS and mid-market sector that need to analyze sensitive media content (audio, video, documents) without sending data to public cloud LLMs.
Task: Design, deployment, and secure operation of a fully self-hosted AI infrastructure including a custom-built digital management platform for automated media analysis.
Action: Architected and implemented a multi-tier platform on hardened Proxmox infrastructure with frontend (Nuxt 3, Vue 3, TypeScript, Tailwind 4), backend (Laravel 13, PHP 8.4, Sanctum), data storage (PostgreSQL 16, MongoDB 7), caching/queuing (Redis 7, Laravel Queue), AI workers (Python 3.11, Whisper, DeepFace, Librosa), scheduling (Laravel Scheduler/Cron), and local LLMs (Gemma, DeepSeek, Qwen, Mistral, LLaMA, Phi) via OpenWebUI with segmented network access, API hardening, and audit logging following BSI recommendations.
Result: Fully GDPR-compliant, on-premises AI platform with zero data leakage to third parties.
Task: Overall responsibility as an external Head of Cyber Security / CISO-as-a-Service for the design, implementation, and continuous improvement of ISMS according to ISO 27001, BSI IT-Grundschutz, and NIS2.
Action: Built and managed Cyber Defense Centers (CDC) with SOC operations, integrated SIEM solutions (Splunk, Graylog), established risk-based vulnerability management (Qualys, Nessus, OpenVAS), and conducted regular infrastructure, application, and physical penetration tests.
Result: Audit-ready ISMS for multiple clients and a 60% reduction in critical vulnerabilities within 90 days.
Task: Design and execution of NIS2 assessments and operational roll-out plans for KRITIS operators.
Action: Developed an online assessment tool for automated identification of individual weakness profiles, implemented ISMS optimizations, penetration testing, awareness programs, GRC suite deployment, and delivered C-level presentations.
Result: Accelerated the consulting process by 50% and successfully prepared multiple clients for NIS2 compliance.
Task: Incident commander for crisis response, forensics, and business recovery in ransomware attacks and APT campaigns.
Action: Coordinated with state and federal police (LKA, BKA), performed forensic analysis (OSForensics, Wireshark, Kali Linux), executed disaster recovery and BCM strategies, and developed BTC extortion response strategies.
Result: 100% recovery rate within defined RTO windows and sustainable post-incident security architectures.
Action: Planned, built, and operated a hardened multi-VM infrastructure (Proxmox, 15+ VMs) with web and mail servers, Graylog, OPNsense firewalls, CRM/ERP and LLM instances, network segmentation, DDoS mitigation, automated patch management, and backup strategies.
Result: >99.5% uptime over 20+ years and zero compromises.
Action: Designed coordinated phishing campaigns with five levels of difficulty, developed e-trainings and webinars in a PDCA cycle, and led red and blue teams.
Result: Phishing click rate reduced from 35% to under 5% within three campaign cycles.
Steffen Lotze
Last position:
Consultant for BSI baseline protection and ISO 27701 at Society for International Cooperation
- Support in building and further developing the information security management system
- Cooperation with external consultants in the certification team for the support structure
- Involvement in project planning, identification, and implementation of the necessary measures according to BSI IT baseline protection
- Professional support for in-house subject matter experts in creating the documents required for certifications
- Carrying out the work according to BSI 200-2
Peter Konrad
Last position:
IT Audit Expert at Sparkasse
Support for Internal Audit:
Conducting an audit of the data protection officer and data protection management:
- Preparing an audit program based on the audit field concept
- Requesting the necessary audit documentation
- Carrying out control testing based on the audit program with the following focus:
- Reviewing the relevant PPS processes
- Reviewing the data protection mission statement, data protection policy, and data protection management concept
- Conducting audit interviews with the data protection officer
- Preparing the audit documentation
- Training a junior auditor in the methodology of Internal Audit
- Coordinating the audit documentation with the head of audit
Alexander Petitjean
Last position:
Senior Solution Architect at IT.NRW - The IT service provider of the state of North Rhine-Westphalia
- Responsible for the solution architectures of the eGov solution "e-Akte" for KRITIS authorities of the state of NRW, tailored to the specific needs of the customers, as well as ensuring that these solutions can be operated efficiently and reliably
- Modeling the KRITIS IT architecture (cloud infrastructure, cybersecurity and development) using Archimate
- Ensuring IT governance, compliance, data protection, and the establishment of standards in line with the business strategy
- Managing service providers for the eAkte product nscale from Ceyonic
- EAM and LeanIX, documentation of IT systems, interfaces, technologies
- Solution architecture & stakeholder management, including business units & IT teams
Mario Pucko
Last position:
Senior IT Project Manager / Program Lead – Network Strategy 2030 at ALDB GmbH
- Holistic responsibility for modernizing and expanding federal networks and upgrading critical data center and telecom infrastructure in the high-security agency environment of BDBOS
- Planning and management of the expansion of national BOS network infrastructure in the VS-NfD/KRITIS environment with technical decision authority at the architecture and component level (Cisco, Layer 2/3, WAN redundancy)
- Planning, tendering (EVB-IT/UVgO) and oversight of the upgrade of security-critical telecom infrastructure for emergency call 110/112 (ACD)
- Capacity planning, rack integration, structured cabling, power supply, cooling concept (CRAC/In-Row) and DCIM monitoring for data center expansion
- Building the IT department from scratch: structures, governance, processes, team recruiting, vendor selection and long-term IT strategy
- Planning and managing infrastructure and application migrations: migration strategies, batch planning, hypercare stabilization and rollback concepts
- Creating vendor-neutral specifications (telecom systems, signature solutions) according to EVB-IT and UVgO; contract award and vendor management
- Setting up a secure IT environment according to BSI basic protection, ISO 27001 and VS-NfD; developing IT security concepts and CMDB analyses
- Hands-on program leadership: decision papers for management and steering committees, risk management, reporting and change request control
Christian Enderle
Last position:
IT Consulting / IT Rebuild at IT-Neuaufbau (PF)
- Analysis of requirements and the current situation
- Migration of an old domain structure and Tobit to Exchange 2019 with integration to MS365
- Evaluation of implementation paths and planning for securing sensitive data
- Planning regarding BSI basic protection, the German Federal Data Protection Act (BDSG), and GDPR
- IT governance and IT security backtests
- Support with ERP setup and securing mail transfer
- Hyper-V 2016/2022, Microsoft Terminal Services Cluster, Microsoft Exchange 2019
- Office 365, Microsoft 365, Azure AD, Teams, Salesforce
- Cisco, Zyxel, and HP switches, Sophos firewalls/UTMs, SecurePoint
- Microsoft IIS 2022, IPv4/IPv6, Veeam, Wortmann online backup, NextCloud
- Services: DNS, DHCP, TCP/IP, subnetting, firewalling, routing, VoIP, Group Policy (GPO), SIEM, remote work, home office, high availability, failover, VLAN, PRTG
Thomas Martin
Last position:
Lead AI-/Agentic-Engineering at AI-/Agentic-Engineering (Own research)
AI-supported development and PM acceleration with agentic workflows; deep reinforcement learning; fully automated 24/7 setup.
Wilhelm Haupt
Last position:
Project Manager / Senior Consultant at Anseres GmbH
- Review of BVA sites – compliance checks under VS-NfD conditions
- Application of BSI baseline protection and NdB user obligations
- Carrying out security and compliance checks at sites of the Federal Office of Administration
- Documenting the results in the VS-NfD context
- Representing the client in workshops and meetings with other federal authorities
- Representing the client to the BSI and aligning security requirements
Florian Krebs
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Matthias Weiss
Last position:
DevOps Engineer at Interhyp AG
- Infrastructure management with Puppet and Terraform for consistent environments
- Maintenance and adaptation of Terraform scripts for Azure cloud deployment
- Migration of database systems and services to the Azure cloud
- Introduction of GitOps with ArgoCD for fully automated deployments
- Adaptation and development of GitHub pipelines for CI/CD workflows
- Creation of Helm Charts for standardized deployments
- Migration of repositories from Bitbucket to GitHub
- Operation and performance optimization of an Oracle 19c grid cluster (RAC, Dataguard)
- Setup and management of MongoDB instances (on-premise and Azure Kubernetes)
- Setup of PostgreSQL clusters in on-premise and Azure Kubernetes environments
- Migration of services, master data, and stored procedures from Oracle to PostgreSQL
- Troubleshooting and performance tuning of complex data infrastructures
- Installation, configuration, and upgrade of Tableau in the productive BI environment
- Development of sanity checks to monitor business processes and application logic
- Adaptation of the backup and recovery strategy to new requirements
- Carrying out disaster recovery and point-in-time recovery
- Technologies used: Oracle 19c RAC Grid Dataguard, PostgreSQL 16, MongoDB, MySQL Cluster, Kubernetes (Azure), Tableau, Puppet, Terraform, ArgoCD, GitHub/Bitbucket, CheckMK, Prometheus, Grafana, Icinga2, Ubuntu/RHEL
Discover over 15,000 top freelancers
Statistics of experts using BSI IT-Grundschutz
Aggregated from the professional profiles of matched freelancers.
Experience
24 years
Position duration
2.8 years
Positions per freelancer
17
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Professional Services, Government and Administration
Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
86%
Master's degree or higher
56%
Doctorate
10%
Certifications per freelancer
8
Most common languages
German, English, French
Speak two or more languages
94%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using BSI IT-Grundschutz
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What it covers
BSI IT-Grundschutz is Germany’s practical framework for building and checking information security. It helps teams define a security baseline, document risks, and assign safeguards in a clear way. Many companies also refer to it as IT-Grundschutz, BSI Grundschutz, or the IT-Grundschutz-Kompendium.
Where it fits
It is used for security management, audits, and structured documentation across internal IT and critical business services. Strong professionals use it to align processes, systems, and controls with a repeatable method that works for both new setups and existing environments.
Typical work
- Build or update IT-Grundschutz concepts and security policies
- Map systems, applications, and processes to protection needs
- Prepare gap analyses and action plans for remediation
- Support audits, evidence collection, and management reviews
- Translate technical findings into clear documentation for stakeholders
Skills around it
Good experts know the BSI methodology, the structure of the Kompendium, and how to work with related standards such as ISO 27001. They also need strong communication skills, because the work sits between operations, risk, compliance, and leadership. In Germany, this often means clear German documentation and coordination with local teams.
When to bring in help
Companies usually bring in freelance specialists when a project needs focused support for a rollout, a re-certification, or a security review after changes to infrastructure or suppliers. They are also useful when internal teams know the environment but need hands-on help to turn requirements into clean, usable artefacts.
What strong professionals deliver
A strong BSI IT-Grundschutz specialist does more than fill templates. They understand how to assess relevance, choose the right safeguards, and keep documentation consistent across the full scope. The best work is precise, practical, and ready to stand up in a real review.
Frequently asked questions
Curious about BSI IT-Grundschutz? Here are the answers that come up again and again.
BSI IT-Grundschutz is used to build a structured security baseline for organisations and to document how that baseline is applied. It helps teams assess protection needs, choose suitable safeguards, and keep the security model understandable for audits and management reviews.
IT-Grundschutz is often used as a detailed method for implementing security controls, while ISO 27001 is a management standard for running an information security system. Many organisations use them together, especially when they want a practical control catalogue plus a recognised management framework.
Searchers often use BSI Grundschutz, IT-Grundschutz, or the IT-Grundschutz-Kompendium when they mean the same topic. In German-speaking environments, these terms are common shorthand for the BSI method and its control catalogue.
A strong BSI IT-Grundschutz freelancer should be able to assess scope, structure documentation, and turn technical findings into clear measures. They should also know how to work with stakeholders across security, IT operations, and compliance so the result is usable, not just complete.
The amount of experience depends on the task, but this work is rarely a pure template exercise. For a new baseline or a review before an audit, you want someone who has already handled real environments, evidence gathering, and the follow-up work that comes after findings are approved.
IT-Grundschutz often goes together with risk management, asset and process documentation, audit preparation, and knowledge of ISO 27001. Experience with security policies, control mapping, and clear stakeholder communication is also important because the method connects many parts of the organisation.
Most BSI IT-Grundschutz tasks can be done remotely if the expert has access to the right documentation, contacts, and systems information. On-site work can help at the start of a scope review or during workshops with German teams, especially when process owners need quick alignment.
Look for someone who can explain the method plainly and show how they turned it into a working security concept. Good signs are consistent documentation, realistic measures, and clear prioritisation rather than generic text copied from the Kompendium.
The average hourly rate of freelancers in Germany who have used BSI IT-Grundschutz in their recent projects is 117 €, which corresponds to a daily rate of about 937 € based on an 8-hour working day.
Of the freelancers in Germany who have used BSI IT-Grundschutz in their recent projects, 86% hold at least a Bachelor's degree, 56% hold at least a Master's degree, and 10% hold a doctorate.
On average, freelancers in Germany who have used BSI IT-Grundschutz in their recent projects have 24 years of professional experience, with a single engagement typically lasting around 2.8 years.
The most common languages among freelancers in Germany who have used BSI IT-Grundschutz in their recent projects are German (100%), English (93%), and French (16%).
The most common industries among freelancers in Germany who have used BSI IT-Grundschutz in their recent projects are Information Technology (92%), Professional Services (59%), and Government and Administration (50%).
The most common business areas among freelancers in Germany who have used BSI IT-Grundschutz in their recent projects are Information Technology (98%), Project Management (86%), and Operations (70%).
Main locations of FRATCH Experts, who have recently used BSI IT-Grundschutz
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich
Cologne
Frankfurt
Dusseldorf