
DORA Experts in Berlin
matched in minutes from over 15,000 CVsHire experts who turn the Digital Operational Resilience Act into practical controls, tested processes and clear evidence across ICT risk, incident reporting and third-party oversight. FRATCH matches you quickly and precisely with vetted, available freelancers.
Meet FRATCH Experts in Berlin, who have recently used DORA
Giovanni L.
Last position:
Solution Architect at Nordea Bank
Consumer Cards Solution Architect
- Provided architectural leadership in Consumer Cards Domain establishing best practices and improving architectural transparency and maintainability by designing a structured documentation framework to enable reverse engineering of legacy card systems.
- Standardized architectural artefacts including BIAN Business Capabilities, UML diagrams in draw.io format (Use Case, Component, Sequence), naming conventions, document repository, design templates and blueprints, microservices.
- Produced high-level and low-level designs aligned with enterprise architecture governance processes and artefact standards.
- Provided architectural support to the Strategic Card Simplification Programme, focusing on card product migrations and application decommissioning across all countries. Agile environments (Scrum/SAFe).
- Analysed and designed AI use cases in the architecture domain.
Project: Payment Card Industry Data Security Standards (PCI DSS) Strategic Programme
- Analysed and documented existing data flows across card products and geographic regions to assess PCI DSS compliance.
- Identified areas involving sensitive data at rest and data in motion requiring encryption or masking, ensuring adherence to PCI DSS requirements.
- Collaborated with security, infrastructure, and application teams to align encryption strategies with regulatory and organizational policies.
- Provided strategic advisory services on data strategy, data governance, data management, data quality, data architecture, data mesh, MEGA HOPEX, DAMA-DMBOK, event-driven architecture, end-to-end data flows and card product harmonization models.
- Ensured solution design alignment with regulatory compliance (BCBS 239, DORA, GDPR) and internal policies.
Project: Denmark ATM Outsourcing Project
Objective: Outsource ATM operations and maintenance to a third-party provider while expanding the Denmark ATM fleet, with Nordea retaining ownership of ATMs and cash for the existing and extended infrastructure.
- Led a cross-functional delivery team (project management, business analysis, and architecture) and documented the as-is ATM ecosystem architecture, including end-to-end data flows, integrations, and internal/external application interfaces.
- Designed end-to-end processes for authorization, reconciliation, and settlement, aligning operating model, controls, and compliance requirements across Nordea and the outsourced service provider.
- Produced high-level and low-level solution designs using standardized UML artefacts (Use Case, Component, and Sequence diagrams) to support vendor onboarding, integration planning, and implementation.
- Ensured architectural alignment and decision-making across enterprise stakeholders and third-party providers, managing dependencies and interfaces in the context of the outsourcing initiative.
Daria B.
Last position:
Senior Consultant Strategy, Risk & Resilience Management at Antharas
- Creating guidelines
- Conducting Business Impact Analyses (BIA), assessing risks, and identifying time-critical business processes
- Process management
- Creating emergency plans and crisis management plans, including cyber response and IT emergency plans with special consideration of a cyberattack
- Conducting awareness trainings
- Planning and carrying out tests and exercises
- Developing tailor-made solutions to reduce risks and ensure business continuity
Piet Q.
Last position:
IT Project Manager at no release
Industry: Publishing, media Project management for the concept of a RAG-based archive access solution: a secure on-prem or hybrid compute architecture for LLM and embedding operations, pipeline for transcription and automatic tagging, semantic search across audio and video archives. Use case evaluation and make-or-buy together with editorial team, archive, and legal department, taking into account copyright, broadcasting law, and the AI Act. Differentiator: practical LLM infrastructure experience from two own productive platforms combined with C-level program management in regulated industries.
Flamur A.
Last position:
Fractional Chief Information Security Officer at VR Smart Guide GmbH
- Enhance and develop the Information Security Management System (ISMS) in compliance with ISO 27001 and TISAX standards by continuously updating and refining the ISMS to align with evolving global standards.
- Ensure that security practices and policies are integrated into all business processes to achieve and maintain certifications.
- Lead the effort to identify, evaluate and mitigate risks across the organization, setting benchmarks for security measures.
- Oversee and refine security processes, with an emphasis on incident management and rapid response by developing and enforcing policies for rapid detection, investigation and remediation of security incidents.
- Train and lead the incident response team to handle breaches effectively, minimizing impact and ensuring swift recovery.
- Implement continuous monitoring solutions to detect and respond to threats in real time.
- Conduct comprehensive security assessments for internal and external IT projects, ensuring adherence to GDPR, DORA and other relevant standards.
- Oversee security evaluations for all IT projects to ensure they comply with legal and regulatory requirements.
- Integrate security measures from the planning phase through deployment to ensure all projects uphold the organization’s security standards.
- Collaborate with project teams to address findings and ensure that security risks are managed effectively.
- Serve as the principal security advisor to the IT department and senior management, offering insights on potential security challenges.
- Facilitate a culture of security awareness throughout the organization through training and regular communication.
- Lead security initiatives that align with the organization’s long-term strategic goals.
- Establish and oversee a robust third-party risk management framework to mitigate external security threats by regularly assessing third-party security practices and compliance and developing contingency plans and mitigation strategies.
- Provide regular updates and security briefings to the executive leadership and relevant committees, highlighting recent security incidents, responses, lessons learned and recommending strategic improvements.
Peter M.
Last position:
Managing Partner without operational duties at pt plus GmbH & Co. KG
- full-service marketing agency for global technology companies
Damir H.
Last position:
Founder and Senior Advisor at Harbas & Company
- Advisory for Bank-Verlag GmbH on establishing a risk management and compliance function by defining the DORA strategy, conducting a DORA gap analysis and developing all DORA-relevant policies, supporting the design and roll out of the risk management framework, and providing overall PMO support for all DORA-relevant streams
- Ensured the conceptual and operational setup of a Cyber Defence Center for Vienna Insurance Group AG, including the implementation of regulatory requirements, development of the organizational, tax, and financial structure, including up- & downstream cost allocation model, DORA compliance, outsourcing, data protection, and works council requirements, gap analysis for contracts with regard to DORA, EIOPA, Solvency II and best practices and creation of policies in line with DORA
- Definition of an IT security target operating model for Oldenburgische Landesbank, including definition of processes, responsibilities and interfaces for a new, DORA-compliant IT security operations area that can be integrated into the existing IT organization and that is to be established or expanded
- Implementation of a service management readiness and maturity analysis according to ITIL for Ottobock Group, definition of an ITSM target operating model including processes, organization and governance, and derivation of measures to close identified gaps
- Developed an overarching cloud strategy for the corporate segment of ThyssenKrupp AG, involving all business units and stakeholders while considering business unit specific requirements
- Conducted an IT benchmark for a business unit of ThyssenKrupp AG, including structural analysis of the organizational structure and IT strategy
- Introduced a company-wide business continuity management system for Krieger Group, including identification and assessment of potential crisis scenarios and risks, and establishment of structures
- Developed an S/4HANA transformation strategy for Pfalzwerke AG, including a transformation plan and preliminary project
- Developed a restructuring strategy for Pfalzwerke AG, including the future IT delivery model, transformation plans, and business cases for each scenario
- Conducted an IT cost review for AMS-OSRAM AG, including analysis and optimization of IT costs and budget, as well as planning and implementing a strategy to reduce IT costs.
Gunnar M.
Last position:
Head of IT & Procurement at S-Servicepartner Deutschland GmbH
- Responsibility for IT infrastructure across 8 sites, 2,500 users, 80 systems, 8,000 assets
- Responsibility for IT/non-IT procurement with €18M annual budget
- Central service provider management, digitalization of contracts and procurement
- Project management for scanning solution, site integration, MS SharePoint
- Leadership of 18 FTE across 3 teams
- Agile leadership in implementation of Digital Office and Digital Coach
Volker K.
Last position:
Head of Engineering at Infoniqa
- Led engineering execution: roadmap planning, capacity alignment, risk management, dependencies, and delivery tracking.
- Consolidated multiple payroll product lines into a unified SaaS platform on Dynamics 365 Business Central, enabling scalable post-merger operations and reducing operational complexity across the portfolio.
- Restructured engineering and product teams in a remote-first setting across Germany, Austria and Poland, consisting of five cross-functional units: compliance/enabling, platform, DevOps and two stream-aligned teams with total FTE depending on phase of reorganisation.
- Rebuilt the mid-level leadership layer and mentored engineering leaders, establishing a leadership pipeline and strengthening architectural decision-making across teams for scalable growth, delivery ownership and predictability.
- Designed platform foundations and system boundaries using Team Topologies aligned structures, enabling scalable ownership, clear interfaces and parallel development across distributed teams.
- Spearheaded AI transformation by implementing AI-assisted SDLC practices using SpecKit and GitHub Actions for automated, executable specifications, while delivering agentic product capabilities by securely exposing platform data and services to AI agents and copilots via RAG-based retrieval pipelines and MCP-style extensions.
- Drove modularisation of tightly coupled legacy logic into independently deployable services, improving maintainability, testability and architectural clarity while preserving continuity through targeted, low-risk extraction rather than full rewrites.
- Established observability, CI/CD and DevOps governance as platform capabilities, increasing automated compliance gates from 25% to 75% and improving deployment cadence by 40% across 15+ product versions.
- Improved operational resilience using DORA-aligned practices (lead time ↓50%, SaaS MTTR ↓85%), strengthening reliability and reducing support overhead.
- Coordinated engineering recovery for the German payroll platform during a company-wide P0 ransomware incident; restored platform continuity within 72h, validated data integrity, and rolled out hardened runbooks and automated recovery playbooks.
- Responsible for budget compliance and cost oversight in Engineering, with limited P&L responsibility and participating in the annual COGS/OPEX/CAPEX planning cycle.
Mateusz P.
Last position:
IT Project Manager at Universal Investment
- Led infrastructure and security integration project for Private Equity acquisition, reducing security vulnerabilities through streamlined governance.
- Restructured resource allocation for strategic projects, enhancing governance through automated tracking and reporting to executive stakeholders.
Henryk O.
Last position:
Security Consultant at Daimler AG
- Development of a cloud security strategy
- Implementation of cloud security governance to comply with ISO/IEC 27017 and the CSA CCM
- Creation of a management system to control cloud security with a focus on process design as well as roles and responsibilities
- Definition of security measures to safeguard cloud solutions
- Conducting requirements analyses and defining the scope for cloud security projects
- Achievements: Established an effective NIS2-compliant cloud security governance that meets industry-specific requirements and effectively minimizes cloud security risks
Markus W.
Last position:
KRITIS Consultant at Oil Company
- Preparing an oil company for KRITIS auditing
- KRITIS consulting
- Creating necessary policies, processes, and guidelines in line with KRITIS requirements
- Tools and methodologies used: ISO/IEC 27001, BSI IT Baseline Protection, KRITIS-V
Benjamin Q.
Last position:
Transformation Advisor and Overall Program Manager at Vereinigte Hagelversicherung VVaG
- Transformation management for the renewal of core insurance systems
- Overall management of the transformation program with 10 projects and many subprojects
- Advising the management board
- Designing the new insurance processes
- Ensuring compliance with DORA, GDPR and BaFin
- Program management (multi-project management) based on PMI principles
- Continuous coordination with all service providers and internal stakeholders
- Reporting to all stakeholders
- Preparing and running steering committees
- Detailed task and resource planning
- Tracking effort and budget as well as forecasting
- Decision and escalation management
- Managing the different program phases such as solution design phase, agile implementation phase, test phase, training phase and migration phase
- Building 15 cloud environments in redundant data centers
- Preparing iterative rollouts to European countries
Discover over 15,000 top freelancers
Statistics of experts using DORA
Aggregated from the professional profiles of matched freelancers.
Experience
25 years (Germany: 21 years)

Position duration
2.8 years (Germany: 2.4 years)

Positions per freelancer
18 (Germany: 16)

Top business areas
Information Technology, Project Management, Operations

Top industries
Information Technology, Banking and Finance, Insurance

Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
100% (Germany: 88%)
Master's degree or higher
91% (Germany: 60%)

Certifications per freelancer
7

Most common languages
English, German, French

Speak two or more languages
100% (Germany: 97%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Berlin are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Berlin using DORA
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
DORA experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (83%)
- Banking and Finance (67%)
- Insurance (67%)
- Professional Services (67%)
- Manufacturing (42%)
- Media and Entertainment (42%)
- Education (33%)
- Energy (33%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
What DORA covers
DORA, the Digital Operational Resilience Act, sets requirements for how financial entities manage digital operational risk. It covers ICT risk management, serious incident reporting, resilience testing and oversight of critical technology providers. The framework turns operational resilience into a documented, repeatable discipline.
Core compliance work
Companies use DORA expertise to translate regulatory expectations into controls that fit their systems and operating model.
- Assess ICT risks, control gaps and critical business services
- Define incident classification, escalation and reporting workflows
- Build resilience testing plans and remediation tracking
- Map important ICT providers, contracts and dependencies
Ecosystem and evidence
DORA work connects governance with cloud, security and service management practices. Strong specialists understand risk registers, asset inventories, business continuity, disaster recovery, vulnerability management and third-party assurance. They also work with audit evidence, policy repositories, ticketing systems and reporting workflows.
When companies need support
Freelance expertise helps when a company must prepare for an assessment, integrate DORA into an existing risk framework or coordinate several technology and compliance teams. It is also valuable after a major system change, outsourcing decision or resilience test exposes unclear ownership. In Berlin, specialists may support local teams on-site or collaborate remotely across international organisations.
What strong experts deliver
The best professionals connect regulation with how systems actually run. They ask precise questions about service dependencies, recovery objectives, access controls and supplier responsibilities rather than producing generic policy text. Their deliverables are usable: control mappings, test scenarios, incident playbooks, evidence packs, risk decisions and clear ownership models.
Choosing the right specialist
Look for experience with regulated financial services, ICT risk and operational resilience, plus the ability to work with technical and business stakeholders. Useful adjacent knowledge includes NIS2, ISO 27001, COBIT, ITIL, cloud governance and business continuity. During selection, review anonymised deliverables and ask how the specialist would handle a disputed classification, an unavailable supplier or a failed recovery test.
Frequently asked questions
Key details about DORA, drawn from the questions we get asked most.
DORA is used to strengthen digital operational resilience across financial entities and their important ICT providers. It provides a common approach to ICT risk management, incident reporting, resilience testing and third-party oversight.
DORA is a sector-specific European regulation for financial services and focuses strongly on operational resilience, ICT incidents and critical technology providers. NIS2 has broader cybersecurity scope, while ISO 27001 is a certifiable information security management standard; they can support DORA compliance but do not replace it.
A strong DORA specialist often combines ICT risk, business continuity, cloud governance, incident management and third-party risk skills. Familiarity with NIS2, ISO 27001, COBIT, ITIL and audit evidence can help connect regulatory controls with existing processes.
The right depth depends on the project. A gap assessment may need focused regulatory and risk expertise, while a full implementation benefits from experience across governance, infrastructure, security, supplier management and resilience testing. Ask for examples of comparable deliverables rather than relying on a title alone.
Yes. DORA work is often suitable for remote collaboration because evidence, policies, risk registers and workshops can be managed digitally. On-site sessions in Berlin can still help when teams need to validate system dependencies, ownership or recovery procedures together.
Ask the DORA expert to explain how they would map critical services, classify an ICT incident and prove that a control operates effectively. Good answers link regulatory requirements to real systems, owners, evidence and remediation decisions instead of offering generic checklists.
A DORA freelancer may deliver an ICT risk assessment, control mapping, incident reporting process, resilience test plan, supplier register or remediation roadmap. The exact package should reflect the company’s regulated activities, technology landscape and existing governance.
Bring in DORA expertise when responsibilities are unclear, regulatory evidence is fragmented, a resilience test has revealed weaknesses or a major ICT supplier decision is approaching. External specialists can provide an independent view and help internal teams turn findings into practical actions.
The average hourly rate of freelancers in Berlin, Germany who have used DORA in their recent projects is 150 €, which corresponds to a daily rate of about 1,202 € based on an 8-hour working day.
Of the freelancers in Berlin, Germany who have used DORA in their recent projects, 100% hold at least a Bachelor's degree and 91% hold at least a Master's degree.
On average, freelancers in Berlin, Germany who have used DORA in their recent projects have 25 years of professional experience, with a single engagement typically lasting around 2.8 years.
The most common languages among freelancers in Berlin, Germany who have used DORA in their recent projects are English (100%), German (92%), and French (8%).
The most common industries among freelancers in Berlin, Germany who have used DORA in their recent projects are Information Technology (83%), Banking and Finance (67%), and Insurance (67%).
The most common business areas among freelancers in Berlin, Germany who have used DORA in their recent projects are Information Technology (100%), Project Management (100%), and Operations (75%).
Main locations of FRATCH Experts, who have recently used DORA
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Cologne
Frankfurt
Dusseldorf
Essen