DORA Experts in Dusseldorf
in minutes from over 15,000 CVs with the power of AIHire experts who turn DORA and the Digital Operational Resilience Act into clear controls, documented ICT risk processes, and audit-ready evidence. They help align third-party oversight, incident handling, and policy updates with fast, precise matching from vetted, available freelancers.
Meet FRATCH Experts in Dusseldorf, who have recently used DORA
Alicja Wilczek
Last position:
Integrated security and emergency documentation for a 24/7 logistics company at Medium-sized logistics company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, vulnerability management policy, business resilience programme, risk governance plan
- Consolidation into an integrated emergency handbook (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table, and a formal approval structure
- Review of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with documented compensating control
- Review and documentation of NIS2 and HinSchG applicability, including the legal reasoning for non-applicability
Frank Dostert
Last position:
Project Manager at TEAG Thüringer Energie AG
- Transition of Microsoft Azure operations to BTC AG
- Responsibility: budget of €60k
- Staff: leadership of 5 people
- Tools: Office 365, JIRA, Confluence
Michael März
Last position:
Team Lead / Service Owner 2nd Level & ITIL at Creditreform
- Service owner of the receivables management platform Ikarus
- Management and coordination of external 1st-level service providers
- Team leadership and building ITIL-compliant support structures
- Managing the handover to 3rd-level support (internal & external, incl. vendor/development)
- Stakeholder management between the business unit, IT, and external partners
- Jira ticket automations and maintenance of Confluence documentation
Levent Önder
Last position:
Senior Expert Transformation & Change Management at STC Services (Freelancer in cooperation)
- Developed an IT governance and oversight framework aligned with DORA requirements
- Coordinated and trained external service providers
- Optimized financial processes and performance
Federico Leefhelm
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW.  Developed and implemented a holistic process view covering both technical and organizational aspects  Ensured end-to-end control of all IAM-related technical services  Established clear responsibilities and accountabilities within the IAM landscape  Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security  Introduced and monitored governance policies to ensure compliance and security  Continuously improved IAM processes and systems through regular audits and evaluations  Participated in external audits of the process as part of official ISO audits  Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units  Conceptually advanced the KPI system to measure process quality
Dennis Schelberg
Last position:
Third Party Risk Management at Ergo Group
- Processing entries in the Third Party Risk Management (TPRM) process
- Conducting clean-ups of existing business relationships
- Creating, processing, and documenting requests
- Reviewing entries from process participants based on existing files
- Collaborating with risk SMEs (Subject Matter Experts) and vendor contacts
- Working closely with procurement, information security, and data protection to align business requirements
- Implementing regulatory requirements (VAIT, DORA) and ensuring compliance and risk management
Natascha Kluike
Last position:
Business Analyst DORA and System Architecture at PSVaG
- DORA consulting and system optimization
- Process analysis of existing business and technically complex processes
- Analysis of individual processes in relevant areas: trading, back office, settlement, custodian bank
- Acting as interface between business areas and IT to understand and define requirements
- Creating a functional specification including adjustments and implementation of software applications and their interfaces to systems
- Preparing a decision paper for the executive board to approve the project
- Setting up and conducting project meetings with relevant stakeholders and documenting them
- Close collaboration with stakeholders
- Coordinating and steering the analysis
- Planning and allocating resources and budget
- Onboarding large banks (Asia and Eastern Europe) for Depot B
- Migrating Depot B holdings (volume around EUR 70-100 million)
Nikolaus Betzler
Last position:
ICT Risk Management and Information Security at B. Metzler seel. Sohn & Co. AG
- Independently develop policies, guidelines, and frameworks for ICT risk management and information security
- Advise business units on ICT risk management and information security
- Further develop the ICT risk management framework that governs the identification, assessment, and control of ICT risks
- Evaluate the Information Security Management System (ISMS) and adjust it for new challenges
- Conduct risk analyses to identify and assess potential ICT risks and information security risks for the Metzler Group
- Advise on defining and implementing measures to reduce risks and improve the resilience of ICT systems
- Advise on ensuring compliance with relevant internal and external regulatory requirements (MaRisk, DORA, BAIT, BSI IT baseline protection, ISMS, ISO 27001, ISO 42001, ISO 27005, BCM ISO 22301)
- Advise on internal and cross-functional projects (SAP DORA compliance, Target2, Section 8a BSI Act)
Bernhard Döpper
Last position:
Enterprise Architect. And responsible for the cross-functional architecture as well as all domains with a focus on the sales at Süddeutsche Krankenversicherung
Creation of business and technical concepts as well as support for enterprise architecture management as part of the migration to the Adesso standard insurance solutions and the renewal of surrounding systems
Interface definitions
Business analysis and creation of the business concepts for input management and sales
Creation of architecture guidelines and processes
Processing technical and business decisions in the architecture board
Definition of service processes and system management aspects
Creation of the technical target operating model
Creation of an integration architecture for AI/LLMs from the providers Commasoft and Insiders
CommaSoft (Alan) webpages and web services
Insiders for Smartfix based on web services
Creation of a question catalog for a security/regulatory check.
Analysis of threats using threat modeling / STRIDE incl. creation of a set of measures to secure the systems
System environment: Jira, Confluence, Java, Enterprise Architect, VAIT/DORA, KritisV, GDPR, IT ServiceMgmt, Adesso Ecosphere and Insure Health, DoPIX and successor product, SmartFix, SmartFlow, Zabas, Kolumbus, Clarc archive, BiPRO, AI / LLM, MS Azure, AWS, TOM/FMO
Heinz-Dieter Lühmann
Last position:
Consultant at CH Crypto Group
- Advice on governance and information security topics: BAIT, MaRisk
- Creating governance documents (policies, guidelines)
- Developing emergency manuals
- Based on BSI IT baseline protection standard 200-4 and ISO2700x
Discover over 15,000 top freelancers
Statistics of experts using DORA
Aggregated from the professional profiles of matched freelancers.
Experience
26 years (Germany: 21 years)
Position duration
1.5 years (Germany: 2.3 years)
Positions per freelancer
19 (Germany: 15)
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Insurance, Energy
Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
63% (Germany: 87%)
Master's degree or higher
25% (Germany: 58%)
Certifications per freelancer
5 (Germany: 7)
Most common languages
German, English, Spanish
Speak two or more languages
90% (Germany: 96%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Dusseldorf are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Dusseldorf using DORA
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What DORA covers
DORA, the Digital Operational Resilience Act, sets the rules for ICT risk management in financial services. It focuses on resilience, not theory. Companies use it to harden governance, document controls, and prove they can keep critical services running when technology fails.
Typical work
- ICT risk assessments and control mapping
- Incident reporting workflows and evidence trails
- Third-party and cloud risk reviews
- Business continuity and recovery plans
- Policy updates for DORA readiness
Ecosystem fit
Strong professionals know how DORA connects with existing security, audit, risk, and compliance work. They understand how to translate legal text into practical tasks for IT, operations, procurement, and leadership. In Dusseldorf, this often matters for firms that need structured work across local teams and remote specialists.
When to bring help
Companies usually bring in freelance expertise when deadlines are close, internal teams lack regulatory depth, or the current setup is hard to evidence. That is common during gap assessments, remediation plans, vendor reviews, and audit preparation. The right specialist can stay focused on the controls that matter most.
What good specialists do
Good DORA professionals are precise, calm, and structured. They can read policy language, spot missing evidence, and turn gaps into concrete actions. Look for people who have worked with governance, risk, compliance, security operations, and business continuity in regulated environments.
Dusseldorf projects
Dusseldorf companies often need DORA support that fits existing finance, insurance, and industrial service workflows. A good freelancer can work on-site for workshops and reviews, then continue remotely on documentation, control design, and remediation tracking. Clear communication in English, and sometimes German, helps the work move faster.
Frequently asked questions
Key details about DORA, drawn from the questions we get asked most.
DORA is used to build and prove digital operational resilience in financial services. It helps companies organize ICT risk management, incident handling, resilience testing, and oversight of critical third parties. In practice, it turns regulatory expectations into working controls and evidence.
Yes. DORA is the common abbreviation for the Digital Operational Resilience Act. Many searchers use both names, and strong specialists should be comfortable with the short form and the full legal name.
DORA is more specific than broad security frameworks because it targets operational resilience in regulated financial organizations. ISO 27001 can support the work, but it does not replace DORA requirements. A good freelancer knows how to map existing controls to the regulation without creating duplicate processes.
A strong DORA specialist usually knows ICT risk, incident management, business continuity, vendor risk, and audit support. Familiarity with security governance and cloud oversight is also useful. If the project includes remediation, they should be able to work with policy and control owners as well.
A DORA project needs someone who has worked with regulated environments and can translate rules into evidence-ready controls. For gap assessments or remediation planning, practical experience matters more than broad general knowledge. For early-stage policy work, a focused specialist may be enough if they know the regulatory structure well.
Most DORA work can be done remotely, especially documentation, control mapping, and evidence review. On-site time helps for workshops, stakeholder interviews, and sensitive process reviews. In Dusseldorf, many companies use a mixed setup so local teams and remote specialists can work together smoothly.
A good DORA freelancer explains the regulation in plain language and shows how it affects controls, owners, and evidence. They should ask smart questions about incident flows, vendors, and recovery plans instead of jumping straight to templates. Strong work is specific, traceable, and easy for auditors or internal reviewers to follow.
Many DORA specialists want to know the scope, the current maturity, and whether they are expected to assess, remediate, or both. They also ask who owns risk, compliance, and IT decisions, because that affects delivery speed. Clear access to policies, incidents, vendor lists, and prior audit findings makes the project much easier to run.
The average hourly rate of freelancers in Dusseldorf, Germany who have used DORA in their recent projects is 104 €, which corresponds to a daily rate of about 835 € based on an 8-hour working day.
Of the freelancers in Dusseldorf, Germany who have used DORA in their recent projects, 63% hold at least a Bachelor's degree and 25% hold at least a Master's degree.
On average, freelancers in Dusseldorf, Germany who have used DORA in their recent projects have 26 years of professional experience, with a single engagement typically lasting around 1.5 years.
The most common languages among freelancers in Dusseldorf, Germany who have used DORA in their recent projects are German (100%), English (90%), and Spanish (30%).
The most common industries among freelancers in Dusseldorf, Germany who have used DORA in their recent projects are Information Technology (100%), Insurance (90%), and Energy (70%).
The most common business areas among freelancers in Dusseldorf, Germany who have used DORA in their recent projects are Information Technology (100%), Project Management (100%), and Operations (90%).
Main locations of FRATCH Experts, who have recently used DORA
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Cologne
Frankfurt
Essen