
BSI IT-Grundschutz Experts in Germany
to strengthen information security with vetted, available freelancersHire experts who establish information security management systems, perform structural analyses and develop BSI-compliant security concepts. Get precise, fast matching with vetted and available freelancers for audits, implementation and continuous improvement.
Meet FRATCH Experts in Germany, who have recently used BSI IT-Grundschutz
Alwin G.
Last position:
IT Interim Manager & AI Strategist
- Founder of CheironX: AI-supported GRC management (ISO 27001, BSI IT-Grundschutz, TISAX, DORA)
- Strategic focus on Agentic AI and GenAI for modern IT Governance, Risk & Compliance Management
- IT interim management and strategic consulting
Matthias K.
Last position:
Business Owner at AKM
Management of several MFA methods for centralized authentication within a group. Interface between various stakeholders such as support, financial accounting, developers, and security departments. Assessment of compliance requirements such as KRITIS. Budget controlling and monitoring of KPIs and SLAs. Support with internal and external audits on MFA and with connecting new systems. Review of operational documentation. Participation in steering committees and leadership of service review meetings and decision-making committees.
Tools/Frameworks: FIDO, YubiKey, Veridium, BSI IT-Grundschutz, NIST
Frank J.
Last position:
Senior Project Manager / IT Manager - Email Gateway Migration & Information Security at Public Authority
- Strategic planning, detailed technical preparation and operational management of an email gateway migration in a security-critical government environment.
- Preparation of the technical specification and development of technical concepts and migration approaches in line with BSI requirements.
- Technical requirements management with business units, information security and operations.
- Coordination of external service providers, integrators and implementation partners; maintenance of project plans, milestones, resources, risks and dependencies.
- Regular reporting to project management, the program environment and internal stakeholders.
Peter D.
Last position:
Security Consultant at Public-law institution of the city administration
- Requirements management, process planning, interface function, ISMS setup, and documentation
- Setup and establishment of an ISMS according to ISO 27001 and establishment of emergency management / ITSCM
- Coordination of the circumstances with the public-sector IT service provider
- Consideration of KRITIS relevance within the scope and implementation of a B3S
- Development of requirements for document control and the continuous improvement process
- Preparation of relevant project documents
- Analysis of existing processes and preparation of guidelines
- Requirements gathering for ISMS and ITSCM and coordination with the IT service provider, including definition of interfaces
- Analysis of communication processes and escalation paths
- Review of documents for risk management, ISMS, emergency preparedness, and emergency response
- Redesign of the complete documentation and preparation of new relevant documents
- Development of necessary rules, policies, and concepts
- Interface between customer and service provider to ensure document quality
- Coordination of protection needs with specialist departments, particularly regarding KRITIS relevance, and planning of resulting measures
- Development of preventive measures to minimize the risk of data center outages in scenarios such as pandemics or ransomware attacks
- Definition of the test strategy for IT emergency exercises
- Initiation of necessary awareness training measures for specialist departments
- External Information Security Officer
- Introduction of document control
Reza N.
Last position:
Senior IT-Security Expert at Teambank AG
- Completed the integration of log sources into Microsoft Sentinel, including GCP workloads – centralized consolidation of all security-relevant events from Azure and GCP environments for complete end-to-end telemetry and comprehensive compliance evidence
- Developed custom rules and use cases based on the GFG Use-Case Library and the MITRE ATT&CK Matrix to cover company-specific threats and GFG-relevant scenarios with precise, mapped detection rules
- Tuned detection rules to minimize false positives, optimized detection thresholds, and modeled exceptions – enabling the SOC to work with relevant, prioritized alerts while reducing Mean Time to Detect/Respond
- Built SOAR capabilities in Sentinel by developing playbooks to automate recurring response processes such as containment, user and host isolation, and ticketing – shorter response times and 24/7 scalability
- Designed and built a log transformation solution to normalize and enrich incoming raw logs (GeoIP, CMDB, threat intelligence) and convert them into a consistent schema for high-performance KQL queries, use case logic, and correlations
- Managed Azure security through Azure Policies to enforce security and compliance standards, prevent drift, and continuously remediate deviations
- Operated the Defender XDR portal to link endpoint, identity, email, and SaaS signals with Sentinel findings, enable holistic incident triage, and orchestrate measures directly from XDR
Technologies: Microsoft Sentinel, Microsoft Defender XDR, Azure Policy, KQL, GCP, MITRE ATT&CK
Andreas R.
Last position:
Freelance Consultant for Information Security at A-R-C Andreas Rühl Consulting
Development and implementation of tailored information security strategies
Introduction and further development of ISMS according to ISO 27001, BSI baseline protection, and other standards
Risk management and creation of security concepts
Consulting for KRITIS, PCI DSS, TISAX, and VdS 3473/10000
Building and improving security organizations
Creation and implementation of guidelines, policies, work instructions, and process descriptions
Audit support and certification preparation
Conducting trainings, workshops, and awareness campaigns
Selection and consulting on the introduction of IT security solutions such as SIEM, DLP, IDS/IPS, firewalls, and encryption technologies
Conducting penetration tests and vulnerability analyses
Consulting on the selection, integration, and management of security architectures in complex IT environments
Consulting on ITSM and managed security services and SOC
Leading and managing complex projects to improve information security
Process analysis, optimization, and management according to ITIL, ISO 27001, and cybernetics
Introduction and quality assurance of management, documentation, and knowledge management systems
Support in complying with regulatory information security requirements (e.g. GDPR, HIPAA, SOX, GMP, KRITIS)
Development and implementation of risk analysis procedures
Organizing initial response, forensic investigations, and organizational measures in the event of security incidents
Designing and running targeted workshops on topics such as ISMS, IT risks, and current threat scenarios
Awareness campaigns to promote security culture in companies
Special trainings on ISO 27001, BSI baseline protection, KRITIS, and other relevant standards
Simulations and exercises to prepare for information security incidents
Interim management for leading information security projects or IT security organizations
Taking on the role of an external CISO (Chief Information Security Officer)
Support in developing and implementing IT security and corporate strategies
Coaching and mentoring of managers in the field of information security
Building and leading security departments as well as recruiting and qualifying employees
Temporary assumption of management responsibility in critical situations
Jens R.
Last position:
Platform Architect & Senior Developer at Direct client, industrial measurement technology, medium-sized company
- Technical leadership across hardware, firmware, and software teams; scope: hardware/firmware team (4 people) and leadership group (5 people)
- Consolidated and documented a product family that had grown over more than 15 years and aligned it with CRA compliance — from the bare-metal I/O module to the cloud interface.
- Provided the most important customer product with the essential requirements and architecture documentation within two months — for a firmware landscape that had grown over more than 15 years. It now supports the customer’s modernization strategy.
- Established a monthly reporting line to the supervisory board and executive board within three months: nine meetings since 12/2025. The report itself is versioned and built from the CI pipeline; it is based on automatically collected activity and release data instead of assessments.
- Built a container-based CI/CD infrastructure from scratch: cross-compilation, host tests, and documentation builds in one continuous pipeline.
- Introduced declarative QA gates for DevOps and development artifacts — from the start using lefthook instead of pre-commit, executed in a dedicated container image.
Technologies used: arc42, req42, tpo42, docToolchain, PlantUML, ArchiMate, C4 model, ADR, C, C++ (GTest), CMake, Bare Metal (ARM Cortex-M3/M7), OCI containers, Jenkins, lefthook, Prometheus, Grafana, SBOM, CRA, OPC, SCADA, PLC integration, IPv6 migration, Zero Trust, Sociocracy 3.0, Cynefin
Andreas Z.
Last position:
Transformation Architect / Business Analyst at IT Consulting
- Development of a comprehensive transformation model for IT departments and ITSM organizations, from operational stabilization through structuring and optimization to strategic advancement
- Design of a transformation matrix that connects development phases with the implementation activities Position, Focus, Model, Enable, Anchor and Develop
- Development of assessment, maturity and decision-making logic to determine the operational starting point, the appropriate entry point and the prioritized areas of action
- Structuring of an end-to-end approach from current-state assessment and target vision through operating model, roadmap and service modules to implementation and integration into steady-state operations
- Derivation of combinable consulting and implementation modules, including methods, deliverables, role models, governance structures and transformation paths
- Collection, structuring and prioritization of business requirements from the perspectives of IT management, service management and operational roles
- Translation of requirements into target visions, process and role models, decision criteria and traceable deliverables
Environment / Tools: ITIL 4, IT4IT, Operating Model Canvas, SIAM, maturity models Kanban
Rudolf E.
Last position:
Datacenter Engineer, Network & Security Administrator at International insurance group
Operation and further development of the network and security infrastructure.
Monitoring, analysis and resolution of network and security incidents.
Cross-department collaboration with other specialist teams for operations, further development and reporting.
Firewall vulnerability analysis.
Firewall rule approvals.
Troubleshooting IP communication issues in the network and firewall infrastructure.
Security-critical IT infrastructure, processing of personal data, compliance with legal regulations.
Products: Palo Alto Networks Firewalls, Cisco ACI, Checkpoint Firewalls, F5
Technologies: SDN, SDWAN, Cisco EPIC, Cisco ACI
Maciej S.
Last position:
Product Owner at Bundesagentur für Arbeit
- As part of the project, the further development of the identity management system was driven forward. This included a comprehensive refactoring of the interfaces to the connected target systems. In addition, several special systems were successfully connected to the IAM to ensure end-to-end identity and authorization management.
- Technical design and solution proposals for IAM system development
- Requirements analysis and requirements management (IREB, BABOK)
- Alignment of the strategy with the future target architecture (TOGAF)
- Prototyping of solutions
- Documentation of requirements (Innovator)
- Analysis and documentation of requirements and creation of process models (UML, BPMN, ArchiMate)
- Modeling of requirements and system functionalities (OOA/OOD, UML)
- Further development of interfaces (SOAP, REST)
- Carrying out architecture reviews
Jens B.
Last position:
Senior Cyber Security Consultant at Brennscheidt IT Consulting
KEY PROJECTS
Since 05/2023 | Bank | Senior Cyber Security Consultant (external)
- Advising and guiding the system owners in creating and further developing IT security concepts
- Coordinating and tracking the remediation of findings from reviews and audits
- Advising on the implementation of regulatory requirements for information security
10/2023 – 02/2024 | Fintech | Project Manager (external)
- Project management to close various audit gaps in the field of information security
- Conceptual design and implementation of an information security management system based on ISO/IEC 27001
- Creation and further development of ISMS documents and processes
Regina K.
Last position:
Data Protection Consultant at Promotional institute of a federal state (public credit institution)
Industry: Finance/Insurance
- Sparring partner for the data protection team
- Taking over tasks from the data protection backlog
- Updating data protection processes
- Updating TOMs
- Revising template documents (including DPA, data protection guidelines)
- Conducting audits (authorization concept, software development)
- Taking over tasks from day-to-day operations
- Processing data protection reports
- Conducting DPIA and TIA
- Reviewing data processing agreements
- Designing and delivering trainings
- Standard Data Protection Model
- AI and data protection
Result: Successfully supported the data protection team, worked through the data protection backlog, and delivered trainings successfully
Günther E.
Last position:
IT Security & Governance Consulting (DORA & NIS2): at Freelance Assignment
Strategic consulting for the development and strengthening of ISMS structures (ISO 27001 / BSI IT-Grundschutz), including onboarding, gap analyses, and preparation of the IT organization for DORA requirements (ICT third-party risk) and NIS2 compliance. Auditing compliance requirements in a regulated environment.
Burhan D.
Last position:
Enterprise Architect & Solution Architect at DB Netz AG
With project PRIZMA, DB will modernize its infrastructure on the one hand, and develop a fail-safe IT landscape on the other hand, which can be restored quickly and securely in case of a disaster.
- Capture current architectures of existing systems as well as methodical consulting and development of target architectures
- Deepen and maintain the building plan / target IT landscape
- Implement technical architecture concepts & architecture descriptions
- Implement migration concepts for updating and further developing the platform and information systems
- Assess submitted improvement suggestions as part of the project
- Capability management: identify capability gaps, develop target visions, and support transformation planning within the enterprise architecture.
- Create a compatibility matrix of the components in use and compare dependencies of specific versions
- Create an IT concept for extending the platform with the following topics: hardware and software requirements, security, licensing, high availability, load balancing, backup & recovery, update strategy, monitoring integration, etc.
- Coordinate with business architects as well as technical architects from the cross-functional architecture area of the PRISMA program for the topics (backup, Active Directory, monitoring, Citrix, and business applications ...)
- Status meetings and alignment of project planning with the Release Train Engineer / Project Manager
- Advise the Release Train Engineer / Project Manager in identifying project risks
- Advise the System Architect Engineers in steering the implementation of the concept
- Implement the IT concept
- Document the infrastructure
Label: MS Project, LINUX, Windows, ORACLE, Java, REST, SharePoint, Microsoft Exchange, UML, Enterprise Architect, BPMN, AZURE, AWS, V-MODEL, Micro Service, VisualStudio, SAP S/4HANA, SCRUM(SAFE), ESB (TIBCO), Python, Innovator, LeanIX (TOGAF), Ansible, Ansible Tower, Ansible Automation, ROBOT, SpringBoot
Karl-Heinz R.
Last position:
Supporting the further development of a European IT branch service organization (15 countries) at European retail company (discount retailer)
- Documenting the current Incident Management, IT Service Request Management, Problem Management, Change Management and Service Configuration Management processes (including CMDB)
- Conducting maturity assessments for these processes based on the ITIL® 4 Maturity Model
- Analyzing the various service value streams based on the ITIL® 4 value stream model
- Agreeing on maturity levels for the assessed processes
- Developing and approving a roadmap to achieve and measure the respective maturity levels
- Presenting the approach, including milestones, to management for approval
- Managing external service providers in 1st Level Support
Discover over 15,000 top freelancers
Statistics of experts using BSI IT-Grundschutz
Aggregated from the professional profiles of matched freelancers.
Experience
23 years

Position duration
2.6 years

Positions per freelancer
17

Top business areas
Information Technology, Project Management, Operations

Top industries
Information Technology, Professional Services, Banking and Finance

Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
85%
Master's degree or higher
54%
Doctorate
9%

Certifications per freelancer
8

Most common languages
German, English, Spanish

Speak two or more languages
94%
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Discover detailed BSI IT-Grundschutz rate benchmarks:
Explore rate insightsAverage rates of experts in Germany using BSI IT-Grundschutz
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
BSI IT-Grundschutz experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (93%)
- Professional Services (59%)
- Banking and Finance (54%)
- Government and Administration (52%)
- Manufacturing (49%)
- Automotive (40%)
- Insurance (38%)
- Healthcare (37%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
Framework and purpose
BSI IT-Grundschutz is the German Federal Office for Information Security’s method for establishing and improving an information security management system. It combines organisational, personnel, technical and structural safeguards in a repeatable methodology. Companies use it to protect information, services, facilities and business processes against security risks.
Standards and structure
The framework is built around BSI Standards 200-1, 200-2 and 200-3, supported by the IT-Grundschutz Compendium. Professionals work with the methodology for defining the information domain, modelling requirements, assessing risks and selecting suitable safeguards. The approach can support basic, standard or core security protection, depending on an organisation’s scope and objectives.
Typical deliverables
Projects often produce practical documentation and controls rather than isolated recommendations:
- Security concepts aligned with the BSI methodology
- Structural analyses and target definitions
- Protection requirement assessments
- Risk analyses and remediation plans
- Evidence for audits and certification preparation
Tools and adjacent skills
Strong specialists connect IT-Grundschutz with governance, risk and compliance processes. They may use the BSI IT-Grundschutz tool, risk registers, asset inventories and document management systems. Useful adjacent knowledge includes ISO/IEC 27001, data protection, business continuity, incident response, cloud security and identity management.
When companies need support
Companies bring in freelance expertise when a security management system must be created, updated or independently reviewed. This is common during a certification initiative, a major cloud or infrastructure change, an audit, a merger or the expansion of regulated services. In Germany, specialists also help translate business requirements into evidence that internal and external stakeholders can assess.
What good expertise looks like
Experienced professionals understand both the formal BSI language and the operational reality behind each safeguard. They define a clear scope, involve process owners, separate risks from controls and keep documentation usable. For remote collaboration, structured workshops, secure document exchange and clear German or English communication are essential; on-site work can help with facility checks and interviews.
Frequently asked questions
Curious about BSI IT-Grundschutz? Here are the answers that come up again and again.
BSI IT-Grundschutz is used to establish, operate and improve an information security management system. It helps organisations assess protection requirements, identify risks and implement safeguards across processes, people, facilities and technology.
BSI IT-Grundschutz provides a detailed German methodology with concrete implementation guidance through the BSI Standards and IT-Grundschutz Compendium. ISO/IEC 27001 defines requirements for certifying an information security management system, and the two approaches can be combined when a company needs both structured safeguards and an internationally recognised certification path.
A strong BSI IT-Grundschutz specialist often understands ISO/IEC 27001, data protection, business continuity and risk management. Knowledge of cloud environments, identity and access management, incident response and audit evidence is also valuable.
The right BSI IT-Grundschutz professional should have handled a project with a comparable scope, such as an ISMS implementation, a protection requirement assessment or certification preparation. The relevant depth depends on the organisation’s size, complexity, critical services and existing documentation, not on a generic career label.
Yes. BSI IT-Grundschutz can provide detailed methods and safeguards within an existing ISO/IEC 27001 management system. A specialist should map overlapping requirements carefully and avoid duplicating controls, evidence or responsibilities.
Much of BSI IT-Grundschutz work can be completed remotely through workshops, document reviews, interviews and secure evidence exchange. On-site collaboration remains useful for facility inspections, physical safeguards and organisations that require local German-language coordination.
Ask how the BSI IT-Grundschutz professional defines scope, protection requirements, risks and evidence. Review anonymised deliverables, clarify familiarity with the relevant BSI Standards and check whether the person can turn formal requirements into controls that teams can operate.
The IT-Grundschutz Compendium provides building blocks with threats and requirements that support structured security planning. A BSI IT-Grundschutz specialist uses them with the organisation’s information domain and protection requirements, rather than treating the catalogue as a substitute for contextual risk assessment.
The average hourly rate of freelancers in Germany who have used BSI IT-Grundschutz in their recent projects is 116 €, which corresponds to a daily rate of about 928 € based on an 8-hour working day.
Of the freelancers in Germany who have used BSI IT-Grundschutz in their recent projects, 85% hold at least a Bachelor's degree, 54% hold at least a Master's degree, and 9% hold a doctorate.
On average, freelancers in Germany who have used BSI IT-Grundschutz in their recent projects have 23 years of professional experience, with a single engagement typically lasting around 2.6 years.
The most common languages among freelancers in Germany who have used BSI IT-Grundschutz in their recent projects are German (100%), English (93%), and Spanish (15%).
The most common industries among freelancers in Germany who have used BSI IT-Grundschutz in their recent projects are Information Technology (93%), Professional Services (59%), and Banking and Finance (54%).
The most common business areas among freelancers in Germany who have used BSI IT-Grundschutz in their recent projects are Information Technology (99%), Project Management (88%), and Operations (70%).
Main locations of FRATCH Experts, who have recently used BSI IT-Grundschutz
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich
Cologne
Frankfurt
Dusseldorf