ISMS Experts in Frankfurt
in minutes with vetted specialists and precise AI matching.Hire experts who design, document, and run an ISMS aligned with ISO 27001, risk assessments, internal audits, and security controls. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Frankfurt, who have recently used ISMS
Robert Francia
Last position:
Interim Project Manager at IT services company of a regional energy supplier
- Delivery of various end-customer projects in server and network infrastructure on time, in quality, and within budget.
- Project 1: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall at an automotive supplier.
- Project 2: Migration of file services from dedicated servers at 5 branch locations into a central managed file service, including DHCP, directory, and print services, as well as decommissioning of the old domain controllers.
- Project 3: Renewal of the network infrastructure at the headquarters and branch locations of a logistics company and transition of the LAN, WLAN, and firewall environments into a managed network service.
- Project 4: Network renewal, replacement of the core and access switches at the headquarters of a medical technology company and transition into a managed network service.
- Project 5: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall for a city.
- Environment: ASA and Fortinet firewalls, Cisco network components, ITSM Heat/Ivanti, Confluence.
Najat Diamante
Last position:
Freelance Consultant Microsoft Purview at Bechtlee IT-Systemhaus
- Design and global rollout of sensitivity labels (confidentiality labels) for automated classification and encryption of business-critical data.
- Definition and rollout of Data Loss Prevention (DLP) policies to protect IP and personal data across endpoints, Exchange, SharePoint, Teams, and non-Microsoft clouds.
- Setup of Insider Risk Management policies to detect and contain excessive data leaks and risky user behavior.
- Implementation of GDPR and retention requirements through automated retention policies and structured records management.
- Technical support for legal teams in internal and external investigations using eDiscovery (Standard/Premium) and Content Search.
- Continuous improvement of the security and compliance level by reviewing the Microsoft Compliance Manager and closing gaps (regulations such as ISO 27001, NIS-2)
Günther Eufinger
Last position:
Senior Consultant at ISMS Rollout – Information Security Certification (ISO 27001)
- Built and successfully certified the Information Security Management System (ISMS) according to ISO 27001 in seven country organizations (Ghana, India, Bangladesh, Uzbekistan, Serbia, Kosovo, Albania).
- Full implementation of the ISMS from kick-off phase to certification, including defining the governance structure and process landscape.
- Developed and delivered target-group-specific trainings, workshops, and coaching sessions for local responsible persons on the basics of information security and ISMS operations.
- Designed and continuously improved training concepts and content to increase understanding and acceptance.
- Identified and implemented improvements in processes and tools, including risk management for international projects.
- Optimized central ISMS core processes from the idea through pilot operation and fine-tuning to global rollout.
- Optimized knowledge management, as well as work aids and methods for the global ISMS team.
- Built and moderated cross-functional coordination with key interfaces to the ISMS.
- Microsoft Teams, Excel, SharePoint Lists, Power Apps.
Andreas Ilias
Last position:
Cybersecurity Specialist Assessor at Bundesnetzagentur
- Recognition of national notified bodies
- Preparation of cybersecurity competency reports
- EU Radio Equipment Directive
Marco Trautmann
Last position:
Chief Financial Officer & ExCo Member at Senacor Technologies AG
- Led assessment and preparation for finance and business management transformation including roll-out of SAP S/4 HANA Cloud, Public Edition.
- Enhanced financial and project reporting by streamlining tools and introducing a management dashboard.
- Introduced opportunity management reporting as part of business operations activities.
- Prepared annual financial statements (HGB).
- Directed annual budget development and aligned it with the ExCo.
Dmitrii Shatov
Last position:
IT Risk & Compliance | DORA | IT Regulatory & Operational Resilience Senior Consultant at Jefferies GmbH
Leading Jefferies’ DORA-driven operational resilience programme by strengthening ICT risk governance, control design, and regulatory readiness across key technology and outsourcing domains. Partnering with senior stakeholders to translate regulatory requirements into pragmatic governance, reporting, and assurance processes suitable for a global investment banking environment.
- Developed the Enterprise Register of Information (DORA Art. 28.3) to align with regulatory requirements.
- Defined and embedded ICT Risk Appetite and tolerance levels aligned to the Global Operational Risk Framework, strengthening decision-making and risk acceptance governance.
- Drove audit readiness by reviewing and re-drafting 50+ IT & Information Security policies, improving clarity, ownership, and control alignment.
- Oversaw the Operational Resilience Testing Programme (including penetration testing) and tracked remediation to closure, strengthening control assurance and reducing open findings.
- Aligned 10+ intra-group agreements with DORA regulatory standards.
- Enhanced executive-level decision-making with an enterprise ICT Risk Dashboard featuring KPIs/KRIs.
Peter Weileder
Last position:
ISO 27001 Auditor for health insurance archive system at Health insurance company
The replacement of the existing archive system (document management system – DMS) on a host-based platform is well advanced.
The internal audit is meant to ensure the company's quality standards.
GDPR
ISO 27001 ff.
BSI
DORA
Patient data regulations
Host / Cloud / S3 / Container / highly scalable / Nuxeo
Budget: 50,000
Team: 1
Thoralf Thorson
Last position:
Consultant Digital Operational Resilience Act (DORA) at Swisslife Deutschland GmbH
- Auditing CIS evidence of the SOC providers T-Systems Austria and Cancom GmbH
- Mapping of VAIT, ISO:IEC 27002 and CIS 7.0 requirements for the IT realignment strategy of the German subsidiaries in threat intelligence and zero trust
- Reviewing SIEM evidence, reporting, incident management and security breaches
- Reviewing IT asset management regarding ITSCM and BCM processes
- Employee awareness and compliance training focused on CEO fraud
- Advising the chief information security officer
Discover over 15,000 top freelancers
Statistics of experts using ISMS
Aggregated from the professional profiles of matched freelancers.
Experience
17 years (Germany: 21 years)
Position duration
1.4 years (Germany: 2.6 years)
Positions per freelancer
13 (Germany: 14)
Top business areas
Information Technology, Operations, Project Management
Top industries
Banking and Finance, Information Technology, Professional Services
Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
100% (Germany: 89%)
Master's degree or higher
67% (Germany: 55%)
Certifications per freelancer
7 (Germany: 8)
Most common languages
German, English, Spanish
Speak two or more languages
100% (Germany: 96%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Frankfurt are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Frankfurt using ISMS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
ISMS basics
An ISMS, or Information Security Management System, is the framework a company uses to manage information security in a structured way. It brings policies, risks, controls, and responsibilities together so security work is repeatable and auditable. Strong ISMS work is practical, not theoretical.
What it covers
- Security policies and procedures
- Risk assessments and treatment plans
- Asset, access, and incident management
- Internal audits and continuous improvement
An ISMS usually connects day-to-day operations with compliance goals. In Frankfurt, that often matters for finance, logistics, SaaS, and other businesses that handle sensitive data across many teams.
Common standards
Most companies discuss ISMS work together with ISO 27001, Annex A controls, and Statement of Applicability documentation. You may also hear information security management, security management system, or simply ISMS in project briefs and audits. The exact scope depends on the company’s risks and business model.
Where specialists help
Freelance ISMS experts are often brought in when a company needs to build an ISMS from scratch, prepare for certification, close audit findings, or improve documentation after growth. They also help when security tasks sit across legal, IT, and operations and no one owns the full system.
What strong specialists do
- Translate controls into clear, usable processes
- Write policies that match real operations
- Map risks to practical treatments
- Support evidence collection for audits
Good professionals stay close to how the business actually works. They know how to balance security, governance, and usability without turning the ISMS into shelfware.
Working style
For Frankfurt-based teams, ISMS experts often work well in a hybrid setup. They can join workshops on site when stakeholders need alignment, then handle documentation, gap analysis, and review cycles remotely. Clear communication in English is usually enough, while German helps when policies or audit discussions involve local teams.
Frequently asked questions
Need clarity? These are the questions we hear most often about ISMS.
An ISMS helps a company manage information security in a repeatable way. It defines how risks are identified, how controls are chosen, and how responsibilities are documented. That makes security work easier to run, review, and improve over time.
No, but they are closely related. ISMS is the management system; ISO 27001 is the standard many companies use to design and assess it. A freelancer who knows both can help with scope, controls, policies, and audit readiness.
Bring in a ISMS specialist when you need structure quickly, such as before certification, after audit findings, or during rapid growth. They are also useful when security responsibilities are spread across teams and no one owns the full framework. A freelancer can fill the gap without a long hiring process.
A strong ISMS expert usually knows risk management, policy writing, control mapping, audit preparation, and stakeholder coordination. Familiarity with ISO 27001, evidence collection, and incident handling is especially valuable. They should also be able to explain security in plain language.
A small documentation cleanup may need only one focused ISMS specialist. A full setup, certification push, or remediation program usually needs someone who has handled audits and cross-functional rollout before. The more regulated or complex the environment, the more important that depth becomes.
ISMS is a core part of GRC, but it is narrower and more operational. GRC may cover privacy, legal obligations, third-party risk, and wider governance topics, while ISMS focuses on information security controls and management. Many companies need both, but not always at the same time.
Yes, most ISMS work can be done remotely, especially drafting policies, reviewing risks, and preparing audit evidence. On-site sessions can still help when leadership, IT, and operations need workshops or decision-making. For Frankfurt teams, a mix of remote delivery and in-person meetings often works well.
Look for a ISMS professional who produces clear documents, understands the business context, and can explain trade-offs without jargon. Good work leaves behind usable processes, not just templates. Ask for examples of audit support, risk treatment, and how they keep controls realistic.
The average hourly rate of freelancers in Frankfurt, Germany who have used ISMS in their recent projects is 121 €, which corresponds to a daily rate of about 969 € based on an 8-hour working day.
Of the freelancers in Frankfurt, Germany who have used ISMS in their recent projects, 100% hold at least a Bachelor's degree and 67% hold at least a Master's degree.
On average, freelancers in Frankfurt, Germany who have used ISMS in their recent projects have 17 years of professional experience, with a single engagement typically lasting around 1.4 years.
The most common languages among freelancers in Frankfurt, Germany who have used ISMS in their recent projects are German (100%), English (100%), and Spanish (13%).
The most common industries among freelancers in Frankfurt, Germany who have used ISMS in their recent projects are Banking and Finance (100%), Information Technology (88%), and Professional Services (63%).
The most common business areas among freelancers in Frankfurt, Germany who have used ISMS in their recent projects are Information Technology (100%), Operations (88%), and Project Management (88%).
Main locations of FRATCH Experts, who have recently used ISMS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich
Cologne
Dusseldorf