Skip to main content
🇩🇪GDPR-compliant
Find the right

DORA Experts in Frankfurt

from over 15,000 CVs with fast, precise AI matching

Hire experts who prepare financial firms for Digital Operational Resilience Act requirements, strengthen ICT risk management and coordinate third-party oversight. FRATCH matches you quickly with vetted, available freelancers who fit your project.

Meet FRATCH Experts in Frankfurt, who have recently used DORA

Verified expert

Olga L.

View profile

IT Business Analyst/Test Manager

Frankfurt am Main
Olga L.

Last position:

Business Analyst at VisualVest (Union Investment)

  • Analyzed, structured, and documented business requirements for digital investment solutions, such as robo-advisors.
  • Designed applications for new retirement products, including user flows, UX requirements, and functional specifications.
  • Modeled and optimized business processes and coordinated with stakeholders while taking regulatory requirements in the financial sector into account.
Verified expert

Firas J.

View profile

IT Governance & IT Compliance Expert

Friedberg
Firas J.

Last position:

Interim Management Group Head of IT Governance & IAM at French-German Private Bank

  • Head of the group-wide, international, and cross-functional IT Governance & IAM department within the central IT division of a large French-German private banking group. Disciplinary management of around 30 employees at five different locations within the group (Frankfurt, Paris, Tunis, Saarbrücken, Düsseldorf). Head of IT committees and key role in direct communication with management, the supervisory board, external stakeholders, and regulators.
  • Definition and establishment of a state-of-the-art IT strategy process and related IT governance structures for the group's IT department with more than 600 employees (testified by the German Federal Financial Supervisory Authority and the ACPR) and successful process run.
  • Establishment of a new future-oriented process framework for IT and necessary governance structures (process squads) for the continuous improvement of IT processes with regard to new regulatory requirements (including DORA, EU AI Act, etc.).
  • Establishment of stringent processes to close a historical backlog of findings (> 100 IT findings, 40 overdue findings in 2022) from internal and external auditors (WP, ACPR, BaFin). Successful reduction of stock of overdue findings to 0 at the end of 2025.
  • Supporting more than 20 IT audits per year and establishment of regulatory monitoring processes. Introduction of ServiceNow to revolutionize regulatory change and IT compliance processes with advanced AI functionalities.
  • Realignment of IT control processes in conjunction with the newly established ICT risk function under DORA and the three lines of defense concept using the TopEase GRC solution.
  • Reduction of the application landscape, by systematically analysing the purpose with application and business owners, identifying duplicates while implementing a One-Tool Strategy throughout the group. Successful reduction of one third of the application landscape within the CMDB.
  • Onboarding of all group applications into One Identity's group-wide IAM solution, as well as operation and further development of the solution in connection with segregation of duties (SoD), role-based access management (RBAC), etc.
Verified expert

Dustin D.

View profile

Regulatory Risk Executive | Risk Governance & 2nd LoD in Banking | EU AI Act, DORA, MaRisk, NFR | CEO Secori Advisors GmbH

Bad Homburg
Dustin D.

Last position:

External consultant at Deutsche Leasing

2nd LoD/Change the Bank (CtB)

  • CtB: External consultant and workstream lead for rectifying findings by BaFin following a special IT audit in the 2nd LoD, management of the work package for revising the ICT Risk Management & ICT Asset Classification in accordance with DORA Chapter 2, the processes for structural analysis, protection requirements, and control assessments (4 FTEs).
Verified expert

Robert F.

View profile

Interim Project Manager

Kriftel
Robert F.

Last position:

Interim Project Manager at IT services company of a regional energy supplier

  • Delivery of various end-customer projects in server and network infrastructure on time, in quality, and within budget.
  • Project 1: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall at an automotive supplier.
  • Project 2: Migration of file services from dedicated servers at 5 branch locations into a central managed file service, including DHCP, directory, and print services, as well as decommissioning of the old domain controllers.
  • Project 3: Renewal of the network infrastructure at the headquarters and branch locations of a logistics company and transition of the LAN, WLAN, and firewall environments into a managed network service.
  • Project 4: Network renewal, replacement of the core and access switches at the headquarters of a medical technology company and transition into a managed network service.
  • Project 5: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall for a city.
  • Environment: ASA and Fortinet firewalls, Cisco network components, ITSM Heat/Ivanti, Confluence.
Verified expert

Justina K.

View profile

Data Management & Governance Manager

Oberursel
Justina K.

Last position:

Freelance Consultant for Change & Data Transformation at Freelance Fast Data Consulting

Project, Strategic Consulting – building the Data Strategy and Data Governance Policy for the German branch, client (private bank Julius Bär, headquarters Zurich), March 2026 – present

  • Design and negotiation of the data strategy with key stakeholders, including obtaining board sign-off (strategic consulting) – in this context, regulatory advice on data regulations in the EU and specifically for Germany. The data strategy includes: Data Lifecycle Management: data capture, data storage, data usage, data retention policy, data quality incident management
  • Definition of milestones and technical feasibility for implementing TOM for the data strategy, data quality checks, metrics, and a metadata inventory to ensure the bank’s compliance with DORA, BCBS239, and MaRisk requirements.

Core project data change, client: (ING Bank, Frankfurt am Main), March – December 2025

  • Concept development and solution design for new end-to-end processes including technical interfaces
  • Definition of synchronization logic and data flows between legacy and target systems (decommissioning of legacy systems)
  • Analysis and validation of data models
  • Stakeholder communication with product owners, feature engineers, UX designers, and operational teams for decision-making
  • Analytics and impact assessments, e.g. to assess downstream effects and regulatory requirements
  • Documentation and comments on technical and business requirements to support implementation in agile squads

Project digitalization of a user group, client: (ING Bank, Frankfurt am Main), as Interim Product Owner, Jan 2025 – present

  • Co-shaping key decisions on data architecture and process logic in the context of historized data and user login functionality
  • Development of business solution concepts for migration to the target system, including system integration and data flows
  • Support with analytics and impact analyses, especially regarding the ability to provide information to law enforcement authorities
  • Active coordination with stakeholders from different squads to support decision-making and ensure regulatory requirements are met
  • Creation of test scenarios for operational teams and backend systems in the area of API management using Postman and Bruno.
Verified expert

Najat D.

View profile

Data Protection Officer, Auditor and ICT Risk Control Function

Großkrotzenburg
Najat D.

Last position:

Freelance Consultant Microsoft Purview at Bechtlee IT-Systemhaus

  • Design and global rollout of sensitivity labels (confidentiality labels) for automated classification and encryption of business-critical data.
  • Definition and rollout of Data Loss Prevention (DLP) policies to protect IP and personal data across endpoints, Exchange, SharePoint, Teams, and non-Microsoft clouds.
  • Setup of Insider Risk Management policies to detect and contain excessive data leaks and risky user behavior.
  • Implementation of GDPR and retention requirements through automated retention policies and structured records management.
  • Technical support for legal teams in internal and external investigations using eDiscovery (Standard/Premium) and Content Search.
  • Continuous improvement of the security and compliance level by reviewing the Microsoft Compliance Manager and closing gaps (regulations such as ISO 27001, NIS-2)
Verified expert

Christine M.

View profile

Freelance specialist in regulatory affairs & IT in banks

Frankfurt am Main
Christine M.

Last position:

Management consultant at Freelance

  • Delivery of ICT / DORA management training under DORA Article 5(4) at various banking institutions

  • Teaching the key content of DORA requirements with a focus on ICT risks, third-party risk management, incident and problem management, and the information register

  • Deriving implementation measures and recommendations for management and business units

Verified expert

Richard R.

View profile

Vice President– Head of Claims Operations, Europe

Langen (Hessen)
Richard R.

Last position:

Vice President– Head of Claims Operations, Europe at SOMPO International

  • Managing TPA Manager and a team of 10 Claims Operation Assistants.

  • Designing and implementing processes and workstreams using Guidewire from the ground up with European claims teams across all lines of business.

  • Establishing service level agreements (SLAs) and detailed key performance indicators (KPIs) with new business intelligence (BI) reporting, payment and performance analysis.

  • Developing, steering and analysing 50+ strategic, operational and IT initiatives, driving digital change and AI automation in payments while meeting DORA, GDPR, ACM and BAIT MaRisk regulatory compliance.

  • Increasing customer satisfaction scores by 80%.

  • Attracting and mentoring market-leading operational and TPA talent.

  • Demonstrating strong stakeholder leadership and swift decisional influence.

Verified expert

Andreas I.

View profile

Senior Cybersecurity Governance & ISMS Consultant

Frankfurt am Main
Andreas I.

Last position:

Cybersecurity Specialist Assessor at Bundesnetzagentur

  • Recognition of national notified bodies
  • Preparation of cybersecurity competency reports
  • EU Radio Equipment Directive
Verified expert

Markus M.

View profile

Project Manager / Senior Consultant (multiple projects)

Frankfurt am Main
Markus M.

Last position:

Project Manager / Senior Consultant (multiple projects) at gkv informatik

  • Project manager controlling the update to ISO 27001:2022 (certification from ISO 27002:2013 to ISO 27002:2022) including gap analysis, project planning, preparation of internal and external audits, and creation and maintenance of required documentation.
  • Coordination of adjusting existing measures and implementing new measures according to the new standard’s requirements, as well as continuous monitoring and adjustment of these measures.
  • Regular reporting to management on progress and risks.
  • Senior consultant supporting audit reviews with a focus on critical infrastructures (KRITIS), including resolving findings, creating and updating evidence documents, and amending provider contracts.
  • Senior consultant reviewing all deliverables and responsibilities of the IT provider according to the existing contract: identification of over 1500 deliverables & obligations (D&O), setup of a D&O tracker (claim register), and joint expert review with service owners for various service descriptions (e.g. IT service management, workplace and print services, application and desktop services, endpoint management, email including archiving, file services, software packaging, certification, distribution).
  • Senior consultant adjusting service scopes in existing service descriptions to enable end-to-end service responsibility of the provider, including identification and analysis of use cases, process analysis and optimization (incident, problem, change), as well as recording and documenting all software products in LeanIX and documenting the contract change.
  • Focused services: managed software service, application and desktop service, workplace and print services, web server service, container service, M365, SAP/Oscare, output management systems (OMS), telephony and omnichannel management service.
  • Project manager steering a benchmark based on the existing IT contract, including coordination of the entire benchmark process between the benchmarker, IT provider and client, review of benchmark results, and preparation and conduct of price negotiations with the IT provider.
Verified expert

Kurt R.

View profile

CTO / Project Lead & Product Co-Owner

Eschborn
Kurt R.

Last position:

Lead Solution Architect (AI HealthTech) / interim CTO & Product Co-Owner at Physio-Agil Frankfurt

  • General CTO responsibilities (architectural design, operational setup, external runtime product evaluation, investor buy-in, regulatory compliance).
  • Software development oversight (implementation on deep-dive-in) plus workflow design.
  • Product co-ownership.
  • Tech/tools/frameworks: proprietary software (Java, JavaScript), Kubernetes, Postgres, MiniIO, Ollama (internal), several xAI API (external), OpenTofu (Terraform), Keycloak, Kafka, Prometheus, ELK Stack, GitHub, GitHub Workflows, Argo CD, ISO 27001, BSI-ISM, EU AI Act.
Verified expert

Fabrizio D.

View profile

Managing Director

Frankfurt
Fabrizio D.

Last position:

Managing Director at ContrailRisks Germany

  • Founded and lead a cybersecurity advisory firm focused on virtual CISO services for financial, SaaS, and critical infrastructure clients.
  • Advise executive teams on cyber risk, regulatory compliance (DORA, NIS2, ISO 27001), and incident preparedness.
  • Built and executed security programs from scratch, driving measurable maturity improvements.
  • Delivered tailored risk assessments, policies, and cloud security guidance (AWS, Azure).
  • Scaled the business through client acquisition, partnerships (Vanta, AWS, etc), and a network of senior consultants.
Verified expert

Dmitrii S.

View profile

IT Regulatory Compliance & GRC (BCM, IT Risk, DORA, ISO 22301, Outsourcing)

Frankfurt
Dmitrii S.

Last position:

IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH

Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.

  • Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
  • Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
  • Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
  • Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
  • Aligned 10+ intra-group agreements with DORA regulatory standards.
  • Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Verified expert

Peter W.

View profile

Program and Project Manager / Internal Auditor / CISO

Frankfurt am Main
Peter W.

Last position:

ISO 27001 Auditor for health insurance archive system at Health insurance company

  • The replacement of the existing archive system (document management system – DMS) on a host-based platform is well advanced.

  • The internal audit is meant to ensure the company's quality standards.

  • GDPR

  • ISO 27001 ff.

  • BSI

  • DORA

  • Patient data regulations

  • Host / Cloud / S3 / Container / highly scalable / Nuxeo

  • Budget: 50,000

  • Team: 1

Discover over 15,000 top freelancers

Statistics of experts using DORA

Aggregated from the professional profiles of matched freelancers.

Experience

20 years (Germany: 21 years)

DORA experts in Frankfurt have 20 years of professional experience on average. It is 1 year less than in Germany, where the average stands at 21 years.

Position duration

1.8 years (Germany: 2.4 years)

DORA experts in Frankfurt stay in a single position for 1.8 years on average. It is 0.6 years less than in Germany, where the average stands at 2.4 years.

Positions per freelancer

15 (Germany: 16)

DORA experts in Frankfurt have completed 15 positions on average over the course of their careers. It is 1 fewer than in Germany, where the average stands at 16.

Top business areas

Information Technology, Operations, Project Management

DORA experts in Frankfurt have gathered most of their hands-on project experience in Information Technology, Operations, and Project Management.

Top industries

Banking and Finance, Information Technology, Professional Services

DORA experts in Frankfurt are most in demand in Banking and Finance, Information Technology, and Professional Services.

Certification focus areas

Information Technology, Project Management, Quality Assurance

DORA experts in Frankfurt earn their certifications most often in Information Technology, Project Management, and Quality Assurance.

Bachelor's degree or higher

94% (Germany: 88%)

94% of DORA experts in Frankfurt hold at least a Bachelor's degree. It is 6% higher than in Germany, where the rate stands at 88%.

Master's degree or higher

65% (Germany: 60%)

65% of DORA experts in Frankfurt hold at least a Master's degree. It is 5% higher than in Germany, where the rate stands at 60%.

Doctorate

12% (Germany: 9%)

12% of DORA experts in Frankfurt have a doctorate (PhD). It is 3% higher than in Germany, where the rate stands at 9%.

Certifications per freelancer

8 (Germany: 7)

DORA experts in Frankfurt hold 8 professional certifications on average. It is 1 more than in Germany, where the average stands at 7.

Most common languages

English, German, French

DORA experts in Frankfurt most often speak English, German, and French.

Speak two or more languages

100% (Germany: 97%)

100% of DORA experts in Frankfurt speak two or more languages. It is 3% higher than in Germany, where the rate stands at 97%.

Based on our profile pool as of 19 Sep 2026.

Daily rate distribution

0 2 4 6 8
2 of the DORA experts in Frankfurt charge less than €800 per day.
4 of the DORA experts in Frankfurt charge between €800 and €960 per day.
5 of the DORA experts in Frankfurt charge between €960 and €1120 per day.
4 of the DORA experts in Frankfurt charge between €1120 and €1280 per day.
4 of the DORA experts in Frankfurt charge between €1280 and €1440 per day.
One of the DORA experts in Frankfurt charges €1440 or more per day.
<€800 €800-​960 €960-​1120 €1120-​1280 €1280-​1440 €1440+

The chart shows how the daily rates of freelancers in this technology in Frankfurt are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates of experts in Frankfurt using DORA

Rates are based on recent contracts and do not include FRATCH margin.

1200
900
600
300
Rate comparison chart
Daily rate avg. 1059 €
Germany avg. 978 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1200
900
600
300
Rate comparison chart
Median rate 1000 €
Germany median 1000 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

DORA experts industry focus

See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.

  • Banking and Finance (95%)
  • Information Technology (80%)
  • Professional Services (50%)
  • Insurance (45%)
  • Transportation (40%)
  • Government and Administration (40%)
  • Telecommunication (35%)
  • Automotive (30%)

Please note that freelancers can work across multiple industries, so percentages overlap.

About the technology

DORA explained

DORA, the Digital Operational Resilience Act, is an EU framework for digital operational resilience in financial services. It covers ICT risk management, incident reporting, resilience testing, information sharing and oversight of critical technology providers. Companies use DORA to create a consistent way to prevent, withstand and recover from technology-related disruption.

Core requirements

DORA connects governance, security, continuity and supplier management. Strong specialists translate regulatory expectations into practical controls, evidence and operating procedures across business and technology teams.

  • ICT risk management frameworks and policies
  • Major ICT incident classification and reporting
  • Digital operational resilience testing
  • ICT third-party risk and contract reviews
  • Threat-led penetration testing coordination

Where it applies

The framework is relevant to banks, insurers, investment firms, payment providers and other financial entities, as well as important ICT suppliers serving them. In Frankfurt, specialists often support financial organisations with local governance needs while coordinating remote work across European teams. German and English communication may both matter, depending on stakeholders and documentation.

Project triggers

Companies usually bring in freelance DORA expertise when they need to assess readiness, close control gaps or prepare for supervisory review. External specialists are also useful during acquisitions, major cloud changes, incident-response redesigns and supplier assessments. They can add capacity without changing permanent team structures.

  • Map existing controls to DORA obligations
  • Build an ICT risk and resilience roadmap
  • Review cloud and outsourcing arrangements
  • Prepare incident workflows and evidence
  • Design testing and remediation plans

Tools and adjacent skills

DORA work is not limited to legal interpretation. It can involve GRC systems, CMDBs, SIEM platforms, ticketing workflows, business continuity tools and vendor-risk registers. Useful adjacent knowledge includes ISO 27001, NIS2, EBA guidance, GDPR, cloud security, operational risk, audit management and contract governance.

What strong specialists deliver

Effective DORA professionals connect regulation with systems, processes and accountable owners. They produce clear gap assessments, control mappings, risk registers, testing plans, incident playbooks and supplier evidence packs. Look for someone who can explain trade-offs to senior stakeholders, challenge weak assumptions and leave teams with maintainable governance rather than documents that quickly become outdated.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

Questions about DORA? Start with the answers below.

DORA, the Digital Operational Resilience Act, is used to strengthen how financial entities manage ICT risk and technology disruption. It sets expectations for governance, incident reporting, resilience testing, information sharing and ICT third-party risk.

DORA is tailored to digital operational resilience in financial services and includes specific expectations for ICT incidents, testing and critical technology providers. ISO 27001 is a certifiable information security management standard, while NIS2 is a broader EU cybersecurity directive covering designated sectors.

A strong DORA specialist may also understand operational risk, business continuity, cloud security, vendor governance, audit evidence and incident response. Experience with GRC, SIEM, CMDB or workflow tools helps turn requirements into repeatable controls.

The right DORA professional depends on the scope. A focused control review may need a specialist who can assess one domain, while an enterprise readiness programme benefits from someone who has coordinated governance, technology, risk, procurement and compliance stakeholders.

Much of DORA work can be delivered remotely through workshops, document reviews and evidence sessions. On-site meetings in Frankfurt can help with sensitive stakeholder discussions, control walkthroughs or access to teams that work mainly in person.

Before engaging a DORA specialist, gather ICT policies, asset and supplier inventories, incident records, resilience tests, contracts and existing risk assessments. Clear project ownership and access to compliance, security, procurement and technology stakeholders will make the review more useful.

High-quality DORA work links each conclusion to a clear requirement, risk, control owner and piece of evidence. Deliverables should be practical, prioritised and traceable, with realistic remediation actions rather than generic compliance language.

A DORA freelancer can deliver a gap assessment, ICT risk framework, incident classification process, resilience testing plan, third-party risk review, contract requirements and management reporting. They may also create playbooks and evidence structures that internal teams can maintain after the engagement.

The average hourly rate of freelancers in Frankfurt, Germany who have used DORA in their recent projects is 132 €, which corresponds to a daily rate of about 1,059 € based on an 8-hour working day.

Of the freelancers in Frankfurt, Germany who have used DORA in their recent projects, 94% hold at least a Bachelor's degree, 65% hold at least a Master's degree, and 12% hold a doctorate.

On average, freelancers in Frankfurt, Germany who have used DORA in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 1.8 years.

The most common languages among freelancers in Frankfurt, Germany who have used DORA in their recent projects are English (100%), German (95%), and French (20%).

The most common industries among freelancers in Frankfurt, Germany who have used DORA in their recent projects are Banking and Finance (95%), Information Technology (80%), and Professional Services (50%).

The most common business areas among freelancers in Frankfurt, Germany who have used DORA in their recent projects are Information Technology (100%), Operations (95%), and Project Management (90%).

Main locations of FRATCH Experts, who have recently used DORA

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH