DORA Experts in Frankfurt
in minutes from over 15,000 CVs with the power of AI.Hire experts who help with DORA readiness, ICT risk management, incident reporting, resilience testing and third-party oversight in Frankfurt’s financial environment. Match with vetted, available specialists fast and precisely.
Meet FRATCH Experts in Frankfurt, who have recently used DORA
Firas Jradi
Last position:
Interim Management Group Head of IT Governance & IAM at French-German Private Bank
- Head of the group-wide, international, and cross-functional IT Governance & IAM department within the central IT division of a large French-German private banking group. Disciplinary management of around 30 employees at five different locations within the group (Frankfurt, Paris, Tunis, SaarbrĂĽcken, DĂĽsseldorf). Head of IT committees and key role in direct communication with management, the supervisory board, external stakeholders, and regulators.
- Definition and establishment of a state-of-the-art IT strategy process and related IT governance structures for the group's IT department with more than 600 employees (testified by the German Federal Financial Supervisory Authority and the ACPR) and successful process run.
- Establishment of a new future-oriented process framework for IT and necessary governance structures (process squads) for the continuous improvement of IT processes with regard to new regulatory requirements (including DORA, EU AI Act, etc.).
- Establishment of stringent processes to close a historical backlog of findings (> 100 IT findings, 40 overdue findings in 2022) from internal and external auditors (WP, ACPR, BaFin). Successful reduction of stock of overdue findings to 0 at the end of 2025.
- Supporting more than 20 IT audits per year and establishment of regulatory monitoring processes. Introduction of ServiceNow to revolutionize regulatory change and IT compliance processes with advanced AI functionalities.
- Realignment of IT control processes in conjunction with the newly established ICT risk function under DORA and the three lines of defense concept using the TopEase GRC solution.
- Reduction of the application landscape, by systematically analysing the purpose with application and business owners, identifying duplicates while implementing a One-Tool Strategy throughout the group. Successful reduction of one third of the application landscape within the CMDB.
- Onboarding of all group applications into One Identity's group-wide IAM solution, as well as operation and further development of the solution in connection with segregation of duties (SoD), role-based access management (RBAC), etc.
Dustin Dehez
Last position:
External consultant at Deutsche Leasing
2nd LoD/Change the Bank (CtB)
- CtB: External consultant and workstream lead for rectifying findings by BaFin following a special IT audit in the 2nd LoD, management of the work package for revising the ICT Risk Management & ICT Asset Classification in accordance with DORA Chapter 2, the processes for structural analysis, protection requirements, and control assessments (4 FTEs).
Robert Francia
Last position:
Interim Project Manager at IT services company of a regional energy supplier
- Delivery of various end-customer projects in server and network infrastructure on time, in quality, and within budget.
- Project 1: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall at an automotive supplier.
- Project 2: Migration of file services from dedicated servers at 5 branch locations into a central managed file service, including DHCP, directory, and print services, as well as decommissioning of the old domain controllers.
- Project 3: Renewal of the network infrastructure at the headquarters and branch locations of a logistics company and transition of the LAN, WLAN, and firewall environments into a managed network service.
- Project 4: Network renewal, replacement of the core and access switches at the headquarters of a medical technology company and transition into a managed network service.
- Project 5: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall for a city.
- Environment: ASA and Fortinet firewalls, Cisco network components, ITSM Heat/Ivanti, Confluence.
Justina Kmiecik
Last position:
Freelance Consultant for Change & Data Transformation at Freelance Fast Data Consulting
Project, Strategic Consulting – building the Data Strategy and Data Governance Policy for the German branch, client (private bank Julius Bär, headquarters Zurich), March 2026 – present
- Design and negotiation of the data strategy with key stakeholders, including obtaining board sign-off (strategic consulting) – in this context, regulatory advice on data regulations in the EU and specifically for Germany. The data strategy includes: Data Lifecycle Management: data capture, data storage, data usage, data retention policy, data quality incident management
- Definition of milestones and technical feasibility for implementing TOM for the data strategy, data quality checks, metrics, and a metadata inventory to ensure the bank’s compliance with DORA, BCBS239, and MaRisk requirements.
Core project data change, client: (ING Bank, Frankfurt am Main), March – December 2025
- Concept development and solution design for new end-to-end processes including technical interfaces
- Definition of synchronization logic and data flows between legacy and target systems (decommissioning of legacy systems)
- Analysis and validation of data models
- Stakeholder communication with product owners, feature engineers, UX designers, and operational teams for decision-making
- Analytics and impact assessments, e.g. to assess downstream effects and regulatory requirements
- Documentation and comments on technical and business requirements to support implementation in agile squads
Project digitalization of a user group, client: (ING Bank, Frankfurt am Main), as Interim Product Owner, Jan 2025 – present
- Co-shaping key decisions on data architecture and process logic in the context of historized data and user login functionality
- Development of business solution concepts for migration to the target system, including system integration and data flows
- Support with analytics and impact analyses, especially regarding the ability to provide information to law enforcement authorities
- Active coordination with stakeholders from different squads to support decision-making and ensure regulatory requirements are met
- Creation of test scenarios for operational teams and backend systems in the area of API management using Postman and Bruno.
Najat Diamante
Last position:
Freelance Consultant Microsoft Purview at Bechtlee IT-Systemhaus
- Design and global rollout of sensitivity labels (confidentiality labels) for automated classification and encryption of business-critical data.
- Definition and rollout of Data Loss Prevention (DLP) policies to protect IP and personal data across endpoints, Exchange, SharePoint, Teams, and non-Microsoft clouds.
- Setup of Insider Risk Management policies to detect and contain excessive data leaks and risky user behavior.
- Implementation of GDPR and retention requirements through automated retention policies and structured records management.
- Technical support for legal teams in internal and external investigations using eDiscovery (Standard/Premium) and Content Search.
- Continuous improvement of the security and compliance level by reviewing the Microsoft Compliance Manager and closing gaps (regulations such as ISO 27001, NIS-2)
Richard Reynolds
Last position:
Vice President– Head of Claims Operations, Europe at SOMPO International
Managing TPA Manager and a team of 10 Claims Operation Assistants.
Designing and implementing processes and workstreams using Guidewire from the ground up with European claims teams across all lines of business.
Establishing service level agreements (SLAs) and detailed key performance indicators (KPIs) with new business intelligence (BI) reporting, payment and performance analysis.
Developing, steering and analysing 50+ strategic, operational and IT initiatives, driving digital change and AI automation in payments while meeting DORA, GDPR, ACM and BAIT MaRisk regulatory compliance.
Increasing customer satisfaction scores by 80%.
Attracting and mentoring market-leading operational and TPA talent.
Demonstrating strong stakeholder leadership and swift decisional influence.
Andreas Ilias
Last position:
Cybersecurity Specialist Assessor at Bundesnetzagentur
- Recognition of national notified bodies
- Preparation of cybersecurity competency reports
- EU Radio Equipment Directive
Markus Marschollek
Last position:
Project Manager / Senior Consultant (multiple projects) at gkv informatik
- Project manager controlling the update to ISO 27001:2022 (certification from ISO 27002:2013 to ISO 27002:2022) including gap analysis, project planning, preparation of internal and external audits, and creation and maintenance of required documentation.
- Coordination of adjusting existing measures and implementing new measures according to the new standard’s requirements, as well as continuous monitoring and adjustment of these measures.
- Regular reporting to management on progress and risks.
- Senior consultant supporting audit reviews with a focus on critical infrastructures (KRITIS), including resolving findings, creating and updating evidence documents, and amending provider contracts.
- Senior consultant reviewing all deliverables and responsibilities of the IT provider according to the existing contract: identification of over 1500 deliverables & obligations (D&O), setup of a D&O tracker (claim register), and joint expert review with service owners for various service descriptions (e.g. IT service management, workplace and print services, application and desktop services, endpoint management, email including archiving, file services, software packaging, certification, distribution).
- Senior consultant adjusting service scopes in existing service descriptions to enable end-to-end service responsibility of the provider, including identification and analysis of use cases, process analysis and optimization (incident, problem, change), as well as recording and documenting all software products in LeanIX and documenting the contract change.
- Focused services: managed software service, application and desktop service, workplace and print services, web server service, container service, M365, SAP/Oscare, output management systems (OMS), telephony and omnichannel management service.
- Project manager steering a benchmark based on the existing IT contract, including coordination of the entire benchmark process between the benchmarker, IT provider and client, review of benchmark results, and preparation and conduct of price negotiations with the IT provider.
Fabrizio Di Carlo
Last position:
Managing Director at ContrailRisks Germany
- Founded and lead a cybersecurity advisory firm focused on virtual CISO services for financial, SaaS, and critical infrastructure clients.
- Advise executive teams on cyber risk, regulatory compliance (DORA, NIS2, ISO 27001), and incident preparedness.
- Built and executed security programs from scratch, driving measurable maturity improvements.
- Delivered tailored risk assessments, policies, and cloud security guidance (AWS, Azure).
- Scaled the business through client acquisition, partnerships (Vanta, AWS, etc), and a network of senior consultants.
Kurt Rosenberg
Last position:
Lead Solution Architect (AI HealthTech) / interim CTO & Product Co-Owner at Physio-Agil Frankfurt
- General CTO responsibilities (architectural design, operational setup, external runtime product evaluation, investor buy-in, regulatory compliance).
- Software development oversight (implementation on deep-dive-in) plus workflow design.
- Product co-ownership.
- Tech/tools/frameworks: proprietary software (Java, JavaScript), Kubernetes, Postgres, MiniIO, Ollama (internal), several xAI API (external), OpenTofu (Terraform), Keycloak, Kafka, Prometheus, ELK Stack, GitHub, GitHub Workflows, Argo CD, ISO 27001, BSI-ISM, EU AI Act.
Dmitrii Shatov
Last position:
IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH
Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.
- Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
- Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
- Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
- Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
- Aligned 10+ intra-group agreements with DORA regulatory standards.
- Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Olga Lewandowska
Last position:
Business Analyst at Start-up
Analysis and design of functional requirements for an AI-based forecasting model in (XRP) crypto trading to support trading decisions.
Identification, classification, and validation of relevant input sources.
Design and execution of business tests to verify data and model quality.
Analysis of the regulatory environment for using robo-advisors in the crypto sector.
Peter Weileder
Last position:
ISO 27001 Auditor for health insurance archive system at Health insurance company
The replacement of the existing archive system (document management system – DMS) on a host-based platform is well advanced.
The internal audit is meant to ensure the company's quality standards.
GDPR
ISO 27001 ff.
BSI
DORA
Patient data regulations
Host / Cloud / S3 / Container / highly scalable / Nuxeo
Budget: 50,000
Team: 1
Christine Mährle
Last position:
Management Consultant at Self-employed
Support for a global systemically important "Brexit Bank" in applying for a banking license and implementing regulatory requirements in IT and outsourcing, as well as implementing DORA
Local implementation of DORA as part of a group-wide DORA program, focusing on third-party risk management, incident/problem management, and information register
Aligning the regulatory IT requirements of MaRisk/BAIT with the requirements of the "Brexit Bank" group, closing gaps and addressing all IT audit findings
Simone Kopp
Last position:
Consultant at EPSM (European Association of Payment Service Providers for Merchants)
Discover over 15,000 top freelancers
Statistics of experts using DORA
Aggregated from the professional profiles of matched freelancers.
Experience
20 years (Germany: 21 years)
Position duration
1.6 years (Germany: 2.3 years)
Positions per freelancer
16 (Germany: 15)
Top business areas
Information Technology, Operations, Project Management
Top industries
Banking and Finance, Information Technology, Insurance
Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
93% (Germany: 87%)
Master's degree or higher
67% (Germany: 58%)
Doctorate
13% (Germany: 10%)
Certifications per freelancer
7
Most common languages
English, German, Spanish
Speak two or more languages
100% (Germany: 96%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Frankfurt are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Frankfurt using DORA
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What DORA means
DORA is the Digital Operational Resilience Act. It sets clear rules for how financial firms handle ICT risk, incidents, testing and critical suppliers. Strong specialists turn the text into working controls, evidence and repeatable routines.
What projects need it
- DORA gap assessments and remediation plans
- ICT risk management frameworks and control maps
- Incident classification and reporting workflows
- Resilience testing, including scenario-based exercises
- Third-party risk and contract reviews
Where it fits
DORA matters for banks, insurers, payment firms, asset managers and their technology partners. In Frankfurt, it often touches teams that must align compliance, security and operations across regulated services, outsourcing chains and audit demands.
Skills that matter
A strong specialist understands governance, security controls, vendor oversight and documentation discipline. They know how DORA links to NIS2, ISO 27001, business continuity and operational risk, and they can work with legal, compliance, security and infrastructure teams.
Why companies bring in freelancers
Companies bring in freelance experts when they need a focused push for readiness reviews, control design, policy updates or test preparation. They are also useful when internal teams need extra capacity for evidence gathering, remediation tracking or supplier negotiations.
What strong work looks like
- Clear mapping from DORA requirements to existing controls
- Practical fixes that fit real systems and suppliers
- Clean documentation for audits and internal review
- Calm coordination across security, risk and business teams
- Deliverables that stay useful after the project ends
Frequently asked questions
Questions about DORA? Start with the answers below.
DORA is used to improve the operational resilience of financial firms and their ICT suppliers. It helps organizations structure risk management, incident handling, testing and oversight of critical third parties. In practice, it becomes a mix of policies, controls, reporting steps and evidence.
Yes. DORA is the common abbreviation for the Digital Operational Resilience Act. Searchers also use the full name when they want support with compliance, remediation or control design.
DORA is sector-specific and focuses on financial operational resilience, especially ICT risk and third-party oversight. ISO 27001 is broader information security management, while NIS2 is a wider cybersecurity law for essential sectors. Many projects need DORA mapped against those frameworks, not treated as a separate island.
A good DORA specialist often brings knowledge of ICT risk, business continuity, supplier management, audit support and incident processes. Familiarity with security controls, cloud governance and compliance documentation also helps. In larger firms, legal and procurement awareness is useful too.
A DORA project usually needs someone who has worked with regulated environments and can translate requirements into usable controls. The best fit is not only policy knowledge, but also the ability to handle evidence, stakeholder alignment and practical remediation. For complex groups, experience with outsourcing and operating models matters a lot.
Yes. DORA work can often be done remotely because it centers on reviews, workshops and documentation. On-site time can help when teams need access to internal stakeholders, risk committees or sensitive supplier material, especially in Frankfurt’s regulated environment.
A strong DORA freelancer gives you concrete outputs, not just advice. Look for clear mapping to requirements, realistic fixes, good documentation and the ability to work across compliance, security and operations. Good specialists also explain trade-offs and keep evidence organized for future reviews.
With DORA, you should expect gap assessments, action plans, control updates, incident workflows, testing plans and supplier reviews. Depending on the project, you may also need policy drafts, workshop materials and audit-ready evidence packs. The right specialist adapts the deliverables to your operating model and risk profile.
The average hourly rate of freelancers in Frankfurt, Germany who have used DORA in their recent projects is 136 €, which corresponds to a daily rate of about 1,085 € based on an 8-hour working day.
Of the freelancers in Frankfurt, Germany who have used DORA in their recent projects, 93% hold at least a Bachelor's degree, 67% hold at least a Master's degree, and 13% hold a doctorate.
On average, freelancers in Frankfurt, Germany who have used DORA in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 1.6 years.
The most common languages among freelancers in Frankfurt, Germany who have used DORA in their recent projects are English (100%), German (94%), and Spanish (17%).
The most common industries among freelancers in Frankfurt, Germany who have used DORA in their recent projects are Banking and Finance (100%), Information Technology (83%), and Insurance (50%).
The most common business areas among freelancers in Frankfurt, Germany who have used DORA in their recent projects are Information Technology (100%), Operations (89%), and Project Management (89%).
Main locations of FRATCH Experts, who have recently used DORA
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Cologne
Dusseldorf
Essen