ISMS Experts in Munich
in minutes from over 15,000 CVs with the power of AI.Hire experts who build and run Information Security Management Systems, prepare ISO 27001 controls, and support audits, risk work, and security policies. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Munich, who have recently used ISMS
Florian Krebs
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Christoph Koldehoff
Last position:
Project Management/PMO/Multi-Project Management/Program Management at kmc - Koldehoff Management Consulting
- Industry focus: Automotive, IT, Chemicals, Insurance, IT Security
- Project planning & portfolio management with MS Project and cplace
- Implementation and operation of an Information Security Management System (ISMS)
- Process management (modeling & optimization) with BIC
- Delivery of automotive driver assistance systems (ADAS)
- Change management (evaluation to go-live)
- Migration projects and risk management
- IT development (SAP S4Hana, embedded software) using Scrum, Agile and Waterfall
- Data modeling (top-down, bottom-up, re-engineering)
- Master data management (infrastructure, interface, BPM, GPM)
- Customer relationship processes (CRM, ERP)
- Material data management (MDM) regarding consistency and quality
- Digital asset management (content, structure, standard metadata)
- Sales management (service policy, CRM, key account management, vendor management)
Weronika Skarbek-Kozietulska
Last position:
Business & Integration Architecture Specialist at Accenture Technology Solution GmbH
Understanding of bank’s fundamentals throughout analysis and writing specifications
Deep analysis of security measurements to be transferred into new environment
Process design and optimization
Collecting requirements from different areas and processing them into agreement documentation, concepts and process description for internal and external partners
Analysis of data delivery sources and transformation of relevant functions into new environment
Analysis and prioritisation of value and benefits resulting from introducing smart data tools
Mapping and migrating data within Power BI upgrade
Change management support and evaluation
Marketing automation and technology enablement
Executing test and release support
Creating training documentation for the client’s employees to understand value and benefits by using new technologies when acquiring new or creating benefits to their existing customers
Creating a complete database of existing firewalls supporting the security of the client’s infrastructure
Migration and re-architecture of reporting systems from multiple data sources into the cloud environment
Andreas Zimmermann
Last position:
ITSM Consultant at Industrial company / Global IT division
- Designed and implemented a new user support tower organization as part of the global IT transformation initiative.
- Created an operating and control model for the central service desk, including downstream support units (field service, VIP support, service points).
- Performed a comprehensive as-is analysis of existing service desk and field service structures and developed a target architecture based on ITIL 4 and SIAM.
- Defined roles, responsibilities, and governance mechanisms for internal IT and external providers.
- Prepared the blueprint document Service Management & Governance Handbook (User Support) to standardize global service processes (incident, request, problem, change, knowledge, ITSCM, CSI).
- Developed a KPI and SLA framework to measure service quality and performance in global user support.
- Defined the reporting and review structure (operations meeting, service review meeting, management steering board).
- Prepared RFP documents for the external tendering of L1/L2 support services, including definition of scope, governance model, process requirements, tool integration (ServiceNow), and KPI/SLA sets.
- Supported procurement and legal departments in evaluating and negotiating vendor proposals and assisted in vendor selection and contract finalization.
- Oversaw the handover to operational support, including knowledge transfer, training of provider teams, and establishment of a continuous improvement process (CSI).
- Methods / framework / tools: ITIL 4 / ITSM, SIAM, IT4IT, ServiceNow, Jira, BPMN, operating model canvas, KPI & SLA design, governance & performance management
Andreas Türkner
Last position:
Subproject Lead DLD Nearshoring at Bank-Regulated Environment (NDA)
- Analysis and assessment of the approach model
- GAP analyses (sourcing readiness) and process analysis
- Process documentation
- Channeling and evaluation of department requirements
- Monitoring of the service provider/nearshoring partner
Patrick Upmann
Last position:
Interim Management | Consulting & Implementation | Data Deletion in SAP at BSR (Berliner Stadtreinigung)
- Topics: Business Analysis, Data Privacy, Data Management, Stakeholder Management, Conceptualization
- This project focuses on developing and implementing a strategic approach for data deletion in SAP systems. The goal is to identify the relevant data and structures during system migration to ensure both data privacy and IT system efficiency. At the same time, downtime should be minimized and regulatory requirements met.
- Development of a comprehensive approach for data deletion in SAP systems, considering data privacy and business requirements.
- Ensuring efficient and structured data transfer to the new system.
- Optimizing system efficiency and reducing downtimes during migration.
- Creating functional and technical concepts to ensure compliant and sustainable data management.
- Topic preparation: Detailed study of the "data deletion" area to lay the foundation for a structured data migration.
- Definition of project structure: Setting roles, interfaces and the project's organizational structure.
- Regulatory requirements: Analysis of data privacy regulations and business requirements to define deletion criteria.
- Approach: Developing possible scenarios and methods for data cleansing and deletion.
- Deletion concepts: Creating functional and technical deletion concepts that structure the implementation and provide clear guidelines.
- Setting deletion criteria: Defining which data and structures to delete or transfer.
- Responsibilities: Clarifying responsibilities within the project team and among stakeholders.
- Analysis of ongoing activities: Identifying and collecting existing activities in the "data deletion" area.
- Effort, cost and timeline planning: Creating estimates for resources, effort and budget.
- Implementation initiatives: Developing and executing concrete measures to apply the defined deletion strategies.
- IT system efficiency: Analyzing the existing IT infrastructure to identify optimization potential for data deletion and transfer.
- Technology trends: Evaluating new technologies and tools that can support the data cleansing process.
- Cost-benefit analysis: Assessing the financial impact of data cleansing and the introduction of new solution approaches.
- Risk management: Identifying potential risks during implementation and developing appropriate mitigation measures.
- This project lays the foundation for a sustainable and compliant data transfer to a new SAP system. With a clear approach to data deletion, it meets data privacy requirements, reduces downtimes and increases the efficiency of the new system. The results and recommendations will help companies develop a future-proof data strategy that meets legal and business needs.
Rick Grassmann
Last position:
Interim IT Security Analyst at GLS IT Services GmbH
- Risk Management
- Incident Management
- Security Analysis
- Secure Coding
- Information Security Management System (ISMS)
Lukas Braun
Last position:
Project Management Migration Specialist at ADAC
- Data migration strategy consulting for core banking solution - Mainframe to Cloud migration
- Data models evaluation and analysis of value flows for a new cloud-based insurance portfolio system introduction
- High level migration strategy
Michael Lenz
Last position:
Identity & PAM Architect at BfArM
- Implementation of CyberArk OnPremise
- BSI basic protection (high protection needs)
- Breaking Class Strategy
- IdP / Identity Strategy / PIM
- Technologies: PAM, CyberArk OnPremise, KeyCloak
Volker Jung
Last position:
Interim CISO (Germany, Austria, US, APAC), Auditor at Vetter Pharma-Fertigung GmbH & Co. KG
- Planned and initiated BIA/BCM assessment to identify risk mitigation measures and process optimization, and provide risk transparency to the general management
- Evaluated KRITIS/NIS-2 status and implemented requirements
- Created comprehensive digital roadmap and ISO 27001/NIS-2/Data Privacy KRITIS roadmap
- Enhanced crisis management process and documentation
- Integrated information security clauses into customer and supplier contracts to ensure compliance with internal and regulatory requirements
- Ensured organizational readiness for audits by the Landesbehörde für Aufsicht (LBA) and supported audit processes
- Improved asset management processes and classification of sensitive data to strengthen overall security
- Planned and ordered regular penetration tests (internal, external) to identify vulnerabilities and improve security measures
- Performed compliance checks against EU CER requirements and reporting
- Created management status and risk reports to ensure transparent communication of risks and security posture
- Managed registration with the German Federal Office for Information Security (BSI) and provided ongoing status updates
- Conducted risk assessment of supply chain, enhanced evaluation and reporting processes
- Improved IT/OT network segmentation to enhance security and reduce potential audit risks
- Strengthened cyber resilience by proactive measures and enhanced security frameworks and KPI reporting
- Onboarded SIEM/SOC/EDR to improve cybersecurity monitoring and response
- Planned and conducted awareness trainings for employees, administrators, and management
- Enhanced incident reporting processes to ensure timely and accurate reporting of cybersecurity events
- Created AI policy in cooperation with the Legal department to secure use and governance of Artificial Intelligence within the organization
- Scoped and implemented ISO 27001:2022 requirements as part of the Information Security Management System
- Served as interim InfoSec team lead
- Introduced information security to global KAM and Sales organization
- Improved admission and access management including privileged access
- Conducted internal audits in collaboration with internal audit department
Philipp Schmidt
Last position:
MS365 Consultant/Solution Architect at Self-employed
- Setup and configuration of an M365 tenant on a hybrid basis
- SSO integration of the existing app infrastructure like Metamost, Huhu, etc.
- License consulting, Entra ID initial configuration, MFA, Conditional Access, Privileged Identity Management
- Intune: initial configuration, Windows 11 Autopilot, iPhone AES
- Takeover of the tenant and preparation of a security audit
- Rollout of iPhones with AES (formerly DEP) as COPE (Corporate Owned, Business Enabled)
- Connecting external customers with enhanced security through Conditional Access
- Consulting on cloud-first strategy and migration to a cloud-only business
- Connecting various apps via SSO/SCIM (e.g. Atlassian, Personio, Adobe)
- On-premises AD: security audit and project management for replacing the local AD (migration of file servers, Navision2016, user clients joined to Entra ID)
- Copilot rollout with connection to external data sources and configuration via Intune
- Support for TISAX and ISO27001 preparation
- Setup and hardening of Entra ID, switching MFA to phishing resistant via Conditional Access
- Intune management for Windows and Apple clients, web enrollment switch to AES, introduction of Autopilot, app management, integration of Microsoft Defender
- Building a device baseline for Windows (COBO) and iOS/Android (BYOD)
- Teams/SharePoint Online: access concepts and integration into Teams
- Maintenance and backup of Entra ID and Intune tenants (drift management)
- M365 backup with Veeam
- Extending Conditional Access policies, introduction of Privileged Identity Management with hardware tokens and an on-premises admin tier concept
- Revision of existing GPOs regarding structure, security, and compliance
- Security audit and hardening of on-premises Active Directory and cloud tenant, SAML VPN, PIM introduction
- Support for the HR department in introducing a booking portal and general system engineering administration & security
- Introduction of Conditional Access and passwordless MFA, platform SSO, Defender for macOS/iOS, macOS compliance with Intune, Code2 signature configuration
Discover over 15,000 top freelancers
Statistics of experts using ISMS
Aggregated from the professional profiles of matched freelancers.
Experience
19 years (Germany: 21 years)
Position duration
2.2 years (Germany: 2.6 years)
Positions per freelancer
15 (Germany: 14)
Top business areas
Information Technology, Project Management, Marketing
Top industries
Information Technology, Professional Services, Banking and Finance
Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
40% (Germany: 89%)
Master's degree or higher
40% (Germany: 55%)
Certifications per freelancer
5 (Germany: 8)
Most common languages
German, English, French
Speak two or more languages
91% (Germany: 96%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using ISMS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What ISMS covers
An Information Security Management System, often called ISMS, gives a company a structured way to protect information. It connects policies, risks, controls, and evidence into one operating model. Strong specialists turn security from scattered tasks into a clear system that can be reviewed, improved, and audited.
Common deliverables
- Scope definitions and asset inventories
- Risk assessments and treatment plans
- Security policies, procedures, and control sets
- Statement of Applicability for ISO 27001 work
- Audit evidence and management review inputs
Tools and standards
ISMS work often sits around ISO 27001, ISO 27002, and Annex A controls. Experts may also work with risk registers, policy templates, ticketing tools, document control systems, and GRC software. Good professionals know how to adapt the framework to the company, not force the company into the framework.
When companies bring in help
Companies usually need outside support when they start an ISMS, prepare for certification, or need to close gaps after an audit. It also helps when security work spans teams and needs one owner for policies, evidence, and follow-up. In Munich, this often comes up in software firms, industrial businesses, and regulated service providers.
What strong experts do
A strong specialist asks where the real risks are, what evidence exists, and which controls already work. They write clear documents, coordinate with IT and legal teams, and keep the system practical. They also know how to explain ISO 27001, ISMS, and related terms in plain language to managers and auditors.
Fit for remote and on-site work
ISMS projects can be handled remotely when interviews, document reviews, and policy drafting are the main tasks. On-site time helps when workshops, control ownership, or management reviews need direct alignment. For Munich teams, a mix often works best when local coordination and German-language documents matter.
Frequently asked questions
Questions about ISMS? Start with the answers below.
An ISMS helps a company manage information security in a structured way. It defines what must be protected, who owns each control, and how risks are reviewed over time. That makes security work easier to maintain and easier to audit.
An ISMS is the management system behind ISO 27001. ISO 27001 sets the requirements, while the ISMS is the real operating setup of policies, risk treatment, records, and continuous improvement. Many companies use the term ISMS when they are preparing for certification or keeping an existing certification in shape.
A strong ISMS specialist is often compared with someone focused only on technical security controls, privacy, or audit support. The difference is that ISMS work connects all of those areas into one system. If you need policies, scope, risks, and evidence to fit together, ISMS expertise matters.
A good ISMS professional usually understands risk management, internal audits, policy writing, and control mapping. Familiarity with ISO 27001, GDPR, supplier security, and basic IT operations is also useful. The best experts can speak with managers, auditors, and technical teams without losing clarity.
A ISMS project needs someone who has done the work before, not just read the standard. Simple policy updates may need less depth, but a new scope, certification prep, or a corrective action plan needs a specialist who understands the whole lifecycle. The more stakeholders involved, the more important that experience becomes.
Yes, ISMS work is often well suited to remote collaboration. Document reviews, gap analyses, risk workshops, and policy drafting can all be done online. On-site sessions are still useful when you need workshop facilitation, leadership alignment, or local language support in Munich.
Look for a ISMS expert who can explain the scope, the risks, and the control logic without jargon. Good signs are clear deliverables, practical recommendations, and a calm approach to audits and follow-up actions. If the work feels only theoretical, the specialist may not be strong enough for production use.
No, ISMS is useful even without a formal certification goal. Some companies need it to structure security work, support customer requests, or prepare for future growth. Certification is one reason to build an ISMS, but not the only one.
The average hourly rate of freelancers in Munich, Germany who have used ISMS in their recent projects is 112 €, which corresponds to a daily rate of about 893 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used ISMS in their recent projects, 40% hold at least a Bachelor's degree and 40% hold at least a Master's degree.
On average, freelancers in Munich, Germany who have used ISMS in their recent projects have 19 years of professional experience, with a single engagement typically lasting around 2.2 years.
The most common languages among freelancers in Munich, Germany who have used ISMS in their recent projects are German (100%), English (91%), and French (36%).
The most common industries among freelancers in Munich, Germany who have used ISMS in their recent projects are Information Technology (91%), Professional Services (91%), and Banking and Finance (64%).
The most common business areas among freelancers in Munich, Germany who have used ISMS in their recent projects are Information Technology (100%), Project Management (91%), and Marketing (55%).
Main locations of FRATCH Experts, who have recently used ISMS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Cologne
Frankfurt
Dusseldorf