
DORA Experts in Austria
matched in minutes from over 15,000 CVsHire experts who turn the Digital Operational Resilience Act into practical controls, ICT risk processes and tested incident response. Work with vetted, available freelancers matched precisely to your requirements and ready to support regulated organisations across Austria.
Meet FRATCH Experts in Austria, who have recently used DORA
Alexander P.
Last position:
Owner & Lecturer at Own company for AI governance and data products, Vienna
- Consulting and interim management at the interface between IT operations and regulation
- Impact analysis and implementation planning for NISG 2026 and the EU AI Act, including risk management and reporting and evidence processes
- Training for governing bodies and employees on regulatory obligations
- Lectures in Data & Information Management and Human-Machine Interaction at University of Applied Sciences Burgenland, since 2023
- Supervision of master’s theses and participation in the examination board
- Presentations for business and educational institutions
- Design and development of data and AI products, platforms and pipelines
- Privacy-first architectures and zero-knowledge encryption, cloud-native on EU infrastructure
- MLOps and AIOps in live operations
- Own applications under own brand: shared codebase, separate delivery for each target device
- AI-assisted software development (vibe coding), complete agentic pipelines, code generation, implementation, automated testing, CI/CD and release cycles
- Publications on the EU AI Act, NIS2, DORA, CRA and CER as an integrated governance system
- Publications on data sovereignty, cloud economics and industrial image processing
- AI governance / compliance: data quality, Responsible AI, EU AI Act readiness, risk classification, AI ethics
Herbert F.
Last position:
Pentest Center of Excellence - Strategy & Implementation at Cybersecurity & IT Risk Managed Services
- Built board/management business-case scenarios; assessed services, vendors, contracts and financials; defined target operating model, service catalogue, organization, processes and tooling.
- Implemented near-shore CoE in Romania and supported rollout to an international insurance group
Plamen M.
Last position:
Head of Service & Operations Management at Raiffeisen Bank International
- Shaping service management framework as part of head office of RBI
- Service owner overseeing IT cloud services, accountable for overall quality, lifecycle, and success
- Managing customer relationships and satisfaction for 10 business units ensuring smooth business continuity and operations
- Single point of contact and service/process owner providing T-shaped expertise in IT domains, cloud platforms and services (AWS, Azure, Kubernetes, Salesforce, ServiceNow, Jira, Orca, CRM, GitHub, SFMC)
- ITSM/ITIL implementation and mentoring including design, definition, mapping, and execution
- Change and release management, UAT/test assurance, major incident management, SDLC management
- Managing regulatory and audit requirements, DORA, GDPR, ITPF compliance and reporting
- Acting as a point of escalation for complex customer issues, resolving conflicts, fostering a customer-centric culture
- People management: leading and managing service delivery teams, DevOps, vendors, and third-party teams
- Cross-tribe service delivery and contract management: KPIs, SLAs, OLAs, RPO, RTO, BCM/SCM management
- Agile/Scrum process delivery governance, stakeholder communication, and budget/cost management
Zoran J.
Last position:
Technical Writer – Implementation of the BNPP IT PROD SEC Service Catalog at BNP Paribas Germany
Design, authorship and finalization of the IT PROD SEC service catalog with eight standardized security services (S-ID001–S-ID008).
Development of consistent service components & deliverables, RACI assignments and SLA and KPI definitions for each service.
Integration of BaFin document requirements under DORA into the service descriptions.
Coordination with IT, compliance, risk and operations teams to validate all service descriptions.
Specifically for governance & monitoring: definition of governance cadence, evidence delivery processes, audit support and definition of measurable KPIs and measurement methods.
Ensuring that all services are standardized, measurable and documented in an audit-proof manner.
Result: Approved service catalog with eight services as a binding basis for delivery, governance and audits; transparent SLAs/KPIs for each service and DORA/BAIT/MaRisk-compliant documentation with clear responsibilities and evidence trails.
Technologies and tools: Confluence, Jira, ServiceNow, Microsoft PowerPoint, Microsoft Visio, Office 365.
Klaus H.
Last position:
Founder at HoWi Consulting e. U.
- Project management IT & business process design digitalization
- Delivered 10+ successful projects (see project list)
- Business analysis
- Business organization
- Data management
Sascha L.
Last position:
CEO at SEComply
- Founder & creator of a cutting-edge Governance, Risk & Compliance SaaS solution.
- Developing and executing business development strategies to identify new opportunities and expand market presence.
- Providing information security consulting services.
- Specializing in governance, risk, and compliance (GRC) topics such as risk management, ISO 27005, ISO 27001, NIS 2, DORA, PCI DSS, EU-GDPR, and more.
- Past projects:
- Kyndryl Austria GmbH: delivered IAM blueprint, conducted risk assessments, developed transformation strategy and roadmap for client projects, and provided support in pre-sales activities to align solutions with client needs.
- Cashpoint Sportwetten GmbH: conducted ISO 27001:2022 gap analysis, enhanced ISMS processes, updated security training, aligned with ISO 27001:2022 standards, and improved vulnerability management practices through regular assessments and remediation planning.
- Hornbach Baumarkt AG: supported the CISO in achieving ISO 27001 compliance, implementing a secure software development lifecycle (SDLC), strengthening vulnerability management practices, and enhancing risk management frameworks.
- MHP Management- und IT-Beratung GmbH: created and reviewed security concepts aligned with ISO 27001 standards.
- Stromnetz Berlin GmbH: developed a comprehensive security concept based on ISO 27001 requirements.
- dmTech GmbH: conducted IT security training for employees, fostering awareness and adherence to security best practices.
- Finanz Informatik GmbH: managed PCI DSS-related tasks, including compliance assessments and control implementations.
- TIPS Messtechnik GmbH: conducted NIS2 gap analysis, developed a comprehensive compliance roadmap, and provided supportive actions to address identified gaps and ensure alignment with regulatory requirements.
Josef Christian P.
Last position:
Project Manager for Implementing a SIEM Solution at German Armed Forces
- Set up a SIEM solution while following a predefined ITSM process of the German Armed Forces
- Familiarization with the ITSM processes
- Organizational distribution of the project team across Germany
- Taking over an ongoing project until go-live
Hans-Michael M.
Last position:
Project expert, digitalization and strategic consulting at Freelance Consultant
- Project work in IT, banking, insurance and strategy
- Risk management consulting for companies in various industries
Peter K.
Last position:
Sabbatical
Discover over 15,000 top freelancers
Statistics of experts using DORA
Aggregated from the professional profiles of matched freelancers.
Experience
26 years

Position duration
2.1 years

Positions per freelancer
14

Top business areas
Information Technology, Project Management, Business Intelligence

Top industries
Banking and Finance, Information Technology, Professional Services

Certification focus areas
Project Management, Information Technology, Audit
Bachelor's degree or higher
100%
Master's degree or higher
100%

Certifications per freelancer
6

Most common languages
German, English, Russian

Speak two or more languages
100%
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Austria are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Austria using DORA
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
DORA experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Banking and Finance (100%)
- Information Technology (89%)
- Professional Services (67%)
- Insurance (56%)
- Manufacturing (56%)
- Automotive (33%)
- Education (33%)
- Energy (33%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
DORA explained
DORA, the Digital Operational Resilience Act, is the European framework for managing digital operational risk in financial services. It covers ICT risk management, incident handling, resilience testing, information sharing and oversight of critical technology providers. Companies use it to make technology services more resilient, traceable and recoverable.
Where DORA applies
Banks, insurers, investment firms, payment institutions and other financial entities use DORA to structure their operational resilience work. It also affects important ICT suppliers that support these organisations. In Austria, specialists often work across financial services, insurance, payments and group-wide technology functions with local and international stakeholders.
Core workstreams
- Map critical or important functions to ICT services and dependencies
- Build ICT risk management policies, controls and evidence
- Define incident classification, escalation and reporting processes
- Plan resilience testing, including threat-led penetration testing
- Assess ICT third-party risk and contractual requirements
Ecosystem and tooling
DORA work connects governance with security, technology operations, procurement and risk teams. Experts may use GRC platforms, CMDBs, service-management tools, cloud inventories, vulnerability scanners and business continuity systems to collect evidence and track remediation. They also align DORA with ISO 27001, NIS2, EBA guidance and existing risk frameworks without treating those standards as interchangeable.
When companies need support
- DORA readiness needs a clear gap assessment and delivery plan
- ICT inventories or dependency maps are incomplete
- Incident reporting and escalation rules need operational testing
- Third-party contracts lack resilience, audit or exit provisions
- Internal teams need support before an audit or resilience exercise
Freelance experts are useful when a company needs focused capacity without creating a permanent compliance function. Remote collaboration works well for documentation, workshops and evidence reviews; on-site sessions can help with executive alignment and operational exercises in Austria.
What strong experts bring
Strong DORA professionals connect regulatory language to how services actually run. They can interview technology and business teams, identify material dependencies, write usable controls and challenge unsupported evidence. Look for clear deliverables such as a scoped gap assessment, tested incident playbooks, mapped service dependencies, supplier actions and an ownership model that remains workable after the engagement ends.
Frequently asked questions
Before you brief your next project: the most common questions about DORA.
DORA is used to strengthen digital operational resilience in financial services. It gives organisations a common approach to ICT risk management, major incident reporting, resilience testing, information sharing and oversight of critical ICT providers.
DORA is tailored to the operational resilience of financial entities and their ICT ecosystems. ISO 27001 focuses on an information security management system, while NIS2 has broader cybersecurity and entity coverage; organisations may use all of them together, but their controls and reporting duties are not identical.
A strong DORA freelancer usually combines regulatory interpretation with ICT risk, business continuity, information security, supplier risk and incident management. Familiarity with cloud governance, service management, GRC tooling and audit evidence makes the work more practical.
The right level depends on the scope, regulatory status and maturity of the organisation. A readiness review may need focused expertise, while a group-wide implementation benefits from someone who has handled policy design, control ownership, testing and remediation across business and technology teams.
Much of DORA work can be completed remotely, including interviews, control reviews, documentation and evidence analysis. On-site workshops may still help with incident exercises, executive decisions or collaboration across Austrian offices, and language expectations should be agreed before the engagement begins.
A DORA engagement may produce a gap assessment, ICT risk framework, critical service and dependency maps, incident procedures, resilience testing plans and third-party contract requirements. Each deliverable should name owners, evidence sources, remediation priorities and a process for keeping the material current.
DORA requires financial entities to manage the risks of outsourced and other ICT services through due diligence, contractual safeguards, monitoring and exit planning. Critical ICT providers may also fall under direct oversight, so suppliers need clear evidence of resilience, cooperation and continuity capabilities.
Ask a DORA freelancer to explain how a regulatory requirement becomes an operating control and what evidence would prove it works. Strong professionals distinguish critical services from low-impact assets, test incident and recovery assumptions, document decisions clearly and leave teams with maintainable processes.
The average hourly rate of freelancers in Austria who have used DORA in their recent projects is 124 €, which corresponds to a daily rate of about 990 € based on an 8-hour working day.
Of the freelancers in Austria who have used DORA in their recent projects, 100% hold at least a Bachelor's degree and 100% hold at least a Master's degree.
On average, freelancers in Austria who have used DORA in their recent projects have 26 years of professional experience, with a single engagement typically lasting around 2.1 years.
The most common languages among freelancers in Austria who have used DORA in their recent projects are German (100%), English (100%), and Russian (22%).
The most common industries among freelancers in Austria who have used DORA in their recent projects are Banking and Finance (100%), Information Technology (89%), and Professional Services (67%).
The most common business areas among freelancers in Austria who have used DORA in their recent projects are Information Technology (100%), Project Management (100%), and Business Intelligence (67%).
Main locations of FRATCH Experts, who have recently used DORA
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
- Germany
- Austria
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
