ISMS Experts in Dusseldorf
in minutes with vetted specialists and fast AI matchingHire experts who build and run ISMS frameworks, ISO/IEC 27001 documentation, risk treatment plans, internal audits, and security policies. Get matched fast with vetted, available freelancers who can work on-site in Dusseldorf or remotely.
Meet FRATCH Experts in Dusseldorf, who have recently used ISMS
Alwin G.
Last position:
IT Interim Manager & AI Strategist
- AI product development: Design of an AI-supported GRC platform to automate compliance processes.
- AI expertise: Strategic deepening in Agentic AI and GenAI as a core asset for modern IT governance
- IT interim management and strategic consulting
Alicja Wilczek
Last position:
Integrated security and emergency documentation for a 24/7 logistics company at Medium-sized logistics company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, vulnerability management policy, business resilience programme, risk governance plan
- Consolidation into an integrated emergency handbook (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table, and a formal approval structure
- Review of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with documented compensating control
- Review and documentation of NIS2 and HinSchG applicability, including the legal reasoning for non-applicability
Federico Leefhelm
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW.  Developed and implemented a holistic process view covering both technical and organizational aspects  Ensured end-to-end control of all IAM-related technical services  Established clear responsibilities and accountabilities within the IAM landscape  Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security  Introduced and monitored governance policies to ensure compliance and security  Continuously improved IAM processes and systems through regular audits and evaluations  Participated in external audits of the process as part of official ISO audits  Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units  Conceptually advanced the KPI system to measure process quality
Ralph Konitzer
Last position:
Product Owner / Business Owner at AXIS Management Consulting GmbH
- Full product responsibility from a business perspective: requirement analysis, UX design, product strategy, and go-to-market implemented without an internal dev team using fully AI-supported development (Claude Code / Anthropic)
- Technical differentiation: KRITIS-compliant air-gapped deployment (Windows/NSIS), GDT interface for PVS integration, DATEV-LODAS export for payroll
- Managed pilot operation with initial external client (Dormagen medical practice): structured requirement gathering, test support, error analysis, and release management
- Developed rollout and sales strategy for market entry in the segment of private practices and small medical centers
- Human-in-the-Loop development principle: business decision → AI implementation → manual review → approval → release – each sprint documented in Jira (TIME project), every change traceable via co-authored commits
- Product outcome: Tauri/Rust desktop app with GDT watcher, multi-tier model (Starter/Professional/Enterprise), cloud mirror on Hetzner/Traefik, complete ISMS framework based on ISO 27001 and BSI basic protection as product foundation
- Direct method validation for the test manager role: hands-on experience with quality assurance of AI-generated products from a user perspective, review gate discipline, release approval under GDPR and the EU AI Act
Kaliyan Muthukrishnan
Last position:
Techno-Functional Consultant – Digital Lab & Manufacturing Systems at Dynavax Technologies
- Led SampleManager LIMS 21.x & LabWare LIMS v8 implementation, reducing manual lab errors by 40% and improving data traceability.
- Configured LW LIMS & SM LIMS 21.2: workflow design, role-based access control (RBAC), and master data management.
- Designed and configured LES workflows: sample lifecycle management, test assignments, approvals, and result review processes.
- Managed Master Menu and CI configuration, ensuring consistency, data integrity, and regulatory compliance.
- Integrated LIMS 21.2 with MES, ERP, EM, WinKQCL (Lonza MODA), SoftMax Pro, Empower, and Chromeleon CDS via REST APIs and web services.
- Implemented PAS-X MES: architecture design, multi-platform implementation (PAS-X, Siemens Opcenter), and integration with PLC, SCADA, and DCS systems.
- Executed IQ/OQ/PQ qualification protocols and Validation Summary Reports (VSR) for QC analytical and utility systems in aseptic and sterile production environments.
- Developed and reviewed Risk Assessments, Traceability Matrices, and Data Integrity evaluations in accordance with ALCOA+, 21 CFR Part 11, and EU Annex 11.
- Led EMA/FDA/WHO inspection readiness, standardized CQV SOPs, enabled digital CQV integration (LIMS/CDS/MES/SCADA/ERP/SDMS), and ensured 21 CFR Part 11 & Annex 11 compliance.
- Managed secure OT cybersecurity: network configuration and access control.
- Configured NuGenesis SDMS for document/data management, CDS/LIMS integration, workflow automation, and reporting.
Matthias Fitzner
Last position:
Information Security Project Manager at Deutsche Bahn AG
- Introduction of a new Information Security Management System (ISMS) according to ISO/IEC 27001.
- Implementation of the cybersecurity guideline RL CySec-Rail for cross-border rail networks.
Nikolaus Betzler
Last position:
ICT Risk Management and Information Security at B. Metzler seel. Sohn & Co. AG
- Independently develop policies, guidelines, and frameworks for ICT risk management and information security
- Advise business units on ICT risk management and information security
- Further develop the ICT risk management framework that governs the identification, assessment, and control of ICT risks
- Evaluate the Information Security Management System (ISMS) and adjust it for new challenges
- Conduct risk analyses to identify and assess potential ICT risks and information security risks for the Metzler Group
- Advise on defining and implementing measures to reduce risks and improve the resilience of ICT systems
- Advise on ensuring compliance with relevant internal and external regulatory requirements (MaRisk, DORA, BAIT, BSI IT baseline protection, ISMS, ISO 27001, ISO 42001, ISO 27005, BCM ISO 22301)
- Advise on internal and cross-functional projects (SAP DORA compliance, Target2, Section 8a BSI Act)
Melanie Linden
Last position:
IT Consultant at BOVERMANN IT SOLUTIONS GmbH
- Design and development of an information security management system (ISMS) according to DIN EN ISO/IEC 27001
Discover over 15,000 top freelancers
Statistics of experts using ISMS
Aggregated from the professional profiles of matched freelancers.
Experience
24 years (Germany: 21 years)
Position duration
1.8 years (Germany: 2.6 years)
Positions per freelancer
13 (Germany: 14)
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Government and Administration, Healthcare
Certification focus areas
Information Technology, Audit, Legal
Bachelor's degree or higher
83% (Germany: 89%)
Master's degree or higher
67% (Germany: 55%)
Doctorate
17% (Germany: 14%)
Certifications per freelancer
6 (Germany: 8)
Most common languages
German, English, Spanish
Speak two or more languages
88% (Germany: 96%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Dusseldorf are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Dusseldorf using ISMS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
ISMS basics
An ISMS, or information security management system, defines how an organisation protects information in a structured way. It brings policy, risk, controls, and review together in one operating model. Strong experts make it practical, not just compliant.
Common deliverables
- Scope statements and control mapping
- Risk assessment and treatment plans
- Policies, procedures, and records
- Audit preparation and evidence packs
- Continuous improvement plans
These outputs often support ISO/IEC 27001 work, but the ISMS itself is broader than one certificate. It also helps teams align security tasks across IT, legal, procurement, and operations.
Tooling and methods
ISMS specialists usually work with risk registers, policy libraries, asset lists, and evidence trackers. They also need to understand security frameworks, control testing, and incident follow-up. Good experts keep the system easy to maintain after the project ends.
When companies bring help
Companies call in freelance ISMS professionals when a certification effort is starting, an audit is due, or the current system has gaps. They are also useful after growth, supplier reviews, incidents, or a move into regulated markets. In Dusseldorf, this often matters for firms that need clear coordination between local teams and central security functions.
What strong experts do
A strong ISMS specialist turns requirements into working routines. They write clear controls, challenge weak evidence, and keep the scope realistic. They also know how to work with stakeholders who do not speak security language every day.
Where it fits
ISMS work connects to ISO/IEC 27001, data protection, vendor security, business continuity, and internal audit. It is common in finance, healthcare, industrial settings, SaaS, and any company that handles sensitive client or employee data. The best experts can explain trade-offs without making the system heavy.
Frequently asked questions
What clients ask us most about ISMS — answered in short.
A ISMS sets the rules and routines for handling information risk in a consistent way. It helps a company decide what to protect, which controls to apply, and how to review them over time. That makes security management repeatable instead of ad hoc.
No. ISMS is the management system; ISO/IEC 27001 is the standard often used to assess it. Many projects are built around that standard, but a company can still use ISMS principles without treating certification as the only goal.
A ISMS freelancer is often asked to define scope, map risks, write policies, and prepare audit evidence. They may also support control owners, supplier reviews, and corrective actions. The exact task depends on whether the company is building from scratch or improving an existing system.
A strong ISMS specialist usually knows risk management, internal audit, policy writing, and stakeholder coordination. Familiarity with ISO/IEC 27001, vendor assessments, and incident handling is valuable too. Clear documentation skills matter just as much as technical security knowledge.
That depends on scope and maturity. A small gap review may only need one experienced ISMS professional, while a full certification path often needs support across policy, risk, and audit preparation. Companies should look for direct project work, not only theoretical knowledge.
Much of ISMS work can be done remotely because it relies on documents, interviews, and review sessions. On-site time in Dusseldorf helps when teams need workshops, control walkthroughs, or sensitive stakeholder alignment. Many projects use a mix of both.
Look for clear examples of how the ISMS specialist turned requirements into usable processes. Strong signals include practical policy writing, realistic risk treatment, and good audit support. They should also be able to explain why a control exists, not just name the control.
A ISMS focuses on the management system behind security: governance, scope, risk, controls, and review. General cybersecurity consulting may focus more on tools, testing, or incident response. Many companies need both, but the ISMS piece gives the structure that keeps the rest in order.
The average hourly rate of freelancers in Dusseldorf, Germany who have used ISMS in their recent projects is 107 €, which corresponds to a daily rate of about 852 € based on an 8-hour working day.
Of the freelancers in Dusseldorf, Germany who have used ISMS in their recent projects, 83% hold at least a Bachelor's degree, 67% hold at least a Master's degree, and 17% hold a doctorate.
On average, freelancers in Dusseldorf, Germany who have used ISMS in their recent projects have 24 years of professional experience, with a single engagement typically lasting around 1.8 years.
The most common languages among freelancers in Dusseldorf, Germany who have used ISMS in their recent projects are German (100%), English (88%), and Spanish (38%).
The most common industries among freelancers in Dusseldorf, Germany who have used ISMS in their recent projects are Information Technology (88%), Government and Administration (63%), and Healthcare (50%).
The most common business areas among freelancers in Dusseldorf, Germany who have used ISMS in their recent projects are Information Technology (100%), Project Management (88%), and Operations (75%).
Main locations of FRATCH Experts, who have recently used ISMS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich
Cologne
Frankfurt