
DORA Experts in Düsseldorf
for resilient financial systems, matched in minutes with vetted, available freelancersHire experts who prepare DORA compliance programmes, strengthen ICT risk controls and coordinate resilience testing across financial services. FRATCH matches you quickly and precisely with vetted, available freelancers who fit your requirements.
Meet FRATCH Experts in Düsseldorf, who have recently used DORA
Alicja W.
Last position:
Integrated Security and Emergency Documentation for a 24/7 Logistics Company at Medium-Sized Logistics Company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), Access Control Policy, Vulnerability Management Policy, Business Resilience Programme, Risk Governance Plan
- Consolidation into an integrated emergency manual (12 chapters) with immediate-action checklists for six emergency scenarios, a prioritized action table and a formal approval structure
- Review and documentation of the applicability of NIS2 and HinSchG, including the legal justification for non-applicability
Frank D.
Last position:
Project Manager at TEAG Thüringer Energie AG
- Transition of Microsoft Azure operations to BTC AG
- Responsibility: budget of €60k
- Staff: leadership of 5 people
- Tools: Office 365, JIRA, Confluence
Michael M.
Last position:
Team Lead / Service Owner 2nd Level & ITIL at Creditreform
- Service owner of the receivables management platform Ikarus
- Management and coordination of external 1st-level service providers
- Team leadership and building ITIL-compliant support structures
- Managing the handover to 3rd-level support (internal & external, incl. vendor/development)
- Stakeholder management between the business unit, IT, and external partners
- Jira ticket automations and maintenance of Confluence documentation
Natascha K.
Last position:
Business Analyst DORA and System Architecture at PSVaG
- DORA consulting and system optimization
- Process analysis of existing business processes that are complex from both a business and technical point of view
- Analysis of the individual business processes in the relevant business areas Trading, Back Office, Settlement, Custodian Bank
- Interface between the business units and IT to understand and define requirements
- Creation of a business concept incl. adjustments and implementation of software applications and their interfaces to the systems
- Preparation of a decision template for the management board for project approval
- Setting up and running project meetings with the relevant stakeholders and documenting them
- Close collaboration with the stakeholders
- Coordination and control of the analysis
- Creation and planning of resources and budget
- Onboarding of large banks (Asia and Eastern Europe) for Depot B
- Migration of portfolio holdings (volume around EUR 70-100 million)
Levent Ö.
Last position:
Senior Expert Transformation & Change Management at STC Services (Freelancer in cooperation)
- Developed an IT governance and oversight framework aligned with DORA requirements
- Coordinated and trained external service providers
- Optimized financial processes and performance
Arndt M.
Last position:
Project Manager for ServiceNow Vulnerability Response at Union Investment Services & IT GmbH
- Led the subproject for implementing Vulnerability Response as part of DORA
- Documented the current processes in compliance, risk & security
- Created the functional design for introducing application, infrastructure, and cloud vulnerabilities
- Agile management of the integration service provider, the technical department, and the company's cross-functional teams
- Integrated the V scanners Tenable, Qualys and Defender, as well as NVD and CISA/KEV
- Integrated GitLab Ultimate for importing and processing SBOMs
- Developed automation rules to match scan results with CIs in the CMDB, assign vulnerabilities and remediation tasks, handle approvals (false positives, exceptions) and closures
- Calculated multiple risk scores and priorities
- Defined dashboards and reports (Workspaces, Performance Analytics)
- Aligned the new processes, especially to improve the CMDB data quality (according to CSDM)
Federico L.
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW. Developed and implemented a holistic process view covering both technical and organizational aspects Ensured end-to-end control of all IAM-related technical services Established clear responsibilities and accountabilities within the IAM landscape Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security Introduced and monitored governance policies to ensure compliance and security Continuously improved IAM processes and systems through regular audits and evaluations Participated in external audits of the process as part of official ISO audits Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units Conceptually advanced the KPI system to measure process quality
Dennis S.
Last position:
Third Party Risk Management at Ergo Group
- Processing entries in the Third Party Risk Management (TPRM) process
- Conducting clean-ups of existing business relationships
- Creating, processing, and documenting requests
- Reviewing entries from process participants based on existing files
- Collaborating with risk SMEs (Subject Matter Experts) and vendor contacts
- Working closely with procurement, information security, and data protection to align business requirements
- Implementing regulatory requirements (VAIT, DORA) and ensuring compliance and risk management
Nikolaus B.
Last position:
ICT Risk Management and Information Security at B. Metzler seel. Sohn & Co. AG
- Independently develop policies, guidelines, and frameworks for ICT risk management and information security
- Advise business units on ICT risk management and information security
- Further develop the ICT risk management framework that governs the identification, assessment, and control of ICT risks
- Evaluate the Information Security Management System (ISMS) and adjust it for new challenges
- Conduct risk analyses to identify and assess potential ICT risks and information security risks for the Metzler Group
- Advise on defining and implementing measures to reduce risks and improve the resilience of ICT systems
- Advise on ensuring compliance with relevant internal and external regulatory requirements (MaRisk, DORA, BAIT, BSI IT baseline protection, ISMS, ISO 27001, ISO 42001, ISO 27005, BCM ISO 22301)
- Advise on internal and cross-functional projects (SAP DORA compliance, Target2, Section 8a BSI Act)
Bernhard D.
Last position:
Enterprise Architect. And responsible for the cross-functional architecture as well as all domains with a focus on the sales at Süddeutsche Krankenversicherung
Creation of business and technical concepts as well as support for enterprise architecture management as part of the migration to the Adesso standard insurance solutions and the renewal of surrounding systems
Interface definitions
Business analysis and creation of the business concepts for input management and sales
Creation of architecture guidelines and processes
Processing technical and business decisions in the architecture board
Definition of service processes and system management aspects
Creation of the technical target operating model
Creation of an integration architecture for AI/LLMs from the providers Commasoft and Insiders
CommaSoft (Alan) webpages and web services
Insiders for Smartfix based on web services
Creation of a question catalog for a security/regulatory check.
Analysis of threats using threat modeling / STRIDE incl. creation of a set of measures to secure the systems
System environment: Jira, Confluence, Java, Enterprise Architect, VAIT/DORA, KritisV, GDPR, IT ServiceMgmt, Adesso Ecosphere and Insure Health, DoPIX and successor product, SmartFix, SmartFlow, Zabas, Kolumbus, Clarc archive, BiPRO, AI / LLM, MS Azure, AWS, TOM/FMO
Heinz-Dieter L.
Last position:
Consultant at CH Crypto Group
- Advice on governance and information security topics: BAIT, MaRisk
- Creating governance documents (policies, guidelines)
- Developing emergency manuals
- Based on BSI IT baseline protection standard 200-4 and ISO2700x
Discover over 15,000 top freelancers
Statistics of experts using DORA
Aggregated from the professional profiles of matched freelancers.
Experience
26 years (Germany: 21 years)

Position duration
1.6 years (Germany: 2.4 years)

Positions per freelancer
19 (Germany: 16)

Top business areas
Information Technology, Project Management, Operations

Top industries
Information Technology, Insurance, Banking and Finance

Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
67% (Germany: 88%)
Master's degree or higher
33% (Germany: 60%)

Certifications per freelancer
5 (Germany: 7)

Most common languages
German, English, Spanish

Speak two or more languages
91% (Germany: 97%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Düsseldorf are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Düsseldorf using DORA
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
DORA experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (100%)
- Insurance (82%)
- Banking and Finance (73%)
- Energy (64%)
- Manufacturing (64%)
- Professional Services (55%)
- Government and Administration (55%)
- Healthcare (45%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
What DORA covers
DORA, the Digital Operational Resilience Act, is an EU regulation for the digital operational resilience of financial entities and relevant ICT providers. It brings ICT risk management, incident reporting, resilience testing and third-party oversight into one structured framework. Companies use it to make critical technology services more resilient and auditable.
Core compliance work
DORA expertise connects regulatory requirements with practical technology controls. Strong specialists translate business services into risk assessments, policies, evidence and remediation plans that security, IT and compliance teams can maintain.
- Map critical or important functions to ICT services
- Define incident classification and reporting procedures
- Assess ICT third-party and supply-chain risk
- Prepare resilience testing and remediation evidence
Ecosystem and tooling
Projects often involve governance, risk and compliance tools, service management platforms, asset inventories and security monitoring. The work also touches cloud providers, managed services, identity controls, backup design, disaster recovery and business continuity. Familiarity with audit trails and executive reporting is essential.
When companies need specialists
Companies bring in freelance DORA specialists when regulation affects an existing transformation programme, an audit exposes control gaps or a major supplier must be assessed. Düsseldorf-based financial and insurance organisations may value on-site workshops, while distributed teams can collaborate remotely with clear documentation and English-language delivery.
- Establish a DORA implementation roadmap
- Review policies, controls and contractual clauses
- Run a gap assessment against operational resilience requirements
- Coordinate testing with technology and business owners
What strong professionals deliver
The best professionals combine regulatory interpretation with hands-on ICT risk practice. They can explain technical dependencies to compliance stakeholders, challenge weak assumptions and produce evidence that stands up to internal or external review. They also understand proportionality, critical services and the operational impact of proposed controls.
Choosing the right expertise
Look for experience with DORA assessments, ICT incident processes, resilience testing and third-party risk rather than general compliance knowledge alone. Ask for examples of traceable deliverables, stakeholder coordination and remediation ownership. A suitable specialist should adapt the approach to your systems, outsourcing model and governance structure without creating unnecessary process.
Frequently asked questions
Key details about DORA, drawn from the questions we get asked most.
DORA is used to strengthen digital operational resilience across financial entities and relevant ICT providers in the European Union. It covers ICT risk management, incident reporting, resilience testing and oversight of critical technology suppliers.
The Digital Operational Resilience Act focuses specifically on the continuity and resilience of ICT-supported financial services. It goes beyond security controls by connecting incident management, testing, third-party risk, governance and evidence requirements.
A strong DORA specialist usually understands ICT risk, information security, business continuity, disaster recovery and vendor management. Familiarity with cloud services, service management, audit evidence and regulatory reporting is also valuable.
The right DORA experience depends on the scope, complexity and outsourcing model of the organisation. A gap assessment may need focused regulatory and control expertise, while an enterprise programme requires broader experience across governance, testing, incident response and supplier oversight.
DORA projects can often be delivered remotely because much of the work involves workshops, documentation, control reviews and evidence analysis. On-site sessions in Düsseldorf can still help when teams need to map critical services, interview owners or align stakeholders in person.
DORA applies to many types of financial entities and also establishes oversight requirements for certain ICT third-party providers. The exact obligations depend on the organisation’s category, services, size and role in the financial ecosystem.
A capable DORA professional should connect each requirement to a clear owner, control, process and piece of evidence. Ask how they handle ICT dependencies, incident scenarios, resilience testing and supplier risk, and review whether their deliverables are practical for operating teams.
DORA requires financial entities to understand and manage risks arising from ICT third parties, including cloud and managed service relationships. Specialists help review contracts, service dependencies, access rights, incident duties, exit planning and the evidence needed for ongoing oversight.
The average hourly rate of freelancers in Dusseldorf, Germany who have used DORA in their recent projects is 107 €, which corresponds to a daily rate of about 857 € based on an 8-hour working day.
Of the freelancers in Dusseldorf, Germany who have used DORA in their recent projects, 67% hold at least a Bachelor's degree and 33% hold at least a Master's degree.
On average, freelancers in Dusseldorf, Germany who have used DORA in their recent projects have 26 years of professional experience, with a single engagement typically lasting around 1.6 years.
The most common languages among freelancers in Dusseldorf, Germany who have used DORA in their recent projects are German (100%), English (91%), and Spanish (36%).
The most common industries among freelancers in Dusseldorf, Germany who have used DORA in their recent projects are Information Technology (100%), Insurance (82%), and Banking and Finance (73%).
The most common business areas among freelancers in Dusseldorf, Germany who have used DORA in their recent projects are Information Technology (100%), Project Management (100%), and Operations (91%).
Main locations of FRATCH Experts, who have recently used DORA
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Cologne
Frankfurt
Essen