
ISMS Experts in Munich
matched in minutes by AIHire experts who establish security policies, assess risks, prepare ISO 27001 audits and improve incident readiness. FRATCH connects you with vetted, available freelancers whose experience fits your ISMS project quickly and precisely.
Meet FRATCH Experts in Munich, who have recently used ISMS
Andreas Z.
Last position:
Transformation Architect / Business Analyst at IT Consulting
- Development of a comprehensive transformation model for IT departments and ITSM organizations, from operational stabilization through structuring and optimization to strategic advancement
- Design of a transformation matrix that connects development phases with the implementation activities Position, Focus, Model, Enable, Anchor and Develop
- Development of assessment, maturity and decision-making logic to determine the operational starting point, the appropriate entry point and the prioritized areas of action
- Structuring of an end-to-end approach from current-state assessment and target vision through operating model, roadmap and service modules to implementation and integration into steady-state operations
- Derivation of combinable consulting and implementation modules, including methods, deliverables, role models, governance structures and transformation paths
- Collection, structuring and prioritization of business requirements from the perspectives of IT management, service management and operational roles
- Translation of requirements into target visions, process and role models, decision criteria and traceable deliverables
Environment / Tools: ITIL 4, IT4IT, Operating Model Canvas, SIAM, maturity models Kanban
Florian K.
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Christoph K.
Last position:
Project Management/PMO/Multi-Project Management/Program Management at kmc - Koldehoff Management Consulting
- Industry focus: Automotive, IT, Chemicals, Insurance, IT Security
- Project planning & portfolio management with MS Project and cplace
- Implementation and operation of an Information Security Management System (ISMS)
- Process management (modeling & optimization) with BIC
- Delivery of automotive driver assistance systems (ADAS)
- Change management (evaluation to go-live)
- Migration projects and risk management
- IT development (SAP S4Hana, embedded software) using Scrum, Agile and Waterfall
- Data modeling (top-down, bottom-up, re-engineering)
- Master data management (infrastructure, interface, BPM, GPM)
- Customer relationship processes (CRM, ERP)
- Material data management (MDM) regarding consistency and quality
- Digital asset management (content, structure, standard metadata)
- Sales management (service policy, CRM, key account management, vendor management)
Weronika S.
Last position:
Business & Integration Architecture Specialist at Accenture Technology Solution GmbH
Understanding of bank’s fundamentals throughout analysis and writing specifications
Deep analysis of security measurements to be transferred into new environment
Process design and optimization
Collecting requirements from different areas and processing them into agreement documentation, concepts and process description for internal and external partners
Analysis of data delivery sources and transformation of relevant functions into new environment
Analysis and prioritisation of value and benefits resulting from introducing smart data tools
Mapping and migrating data within Power BI upgrade
Change management support and evaluation
Marketing automation and technology enablement
Executing test and release support
Creating training documentation for the client’s employees to understand value and benefits by using new technologies when acquiring new or creating benefits to their existing customers
Creating a complete database of existing firewalls supporting the security of the client’s infrastructure
Migration and re-architecture of reporting systems from multiple data sources into the cloud environment
Andreas T.
Last position:
Subproject Lead DLD Nearshoring at Bank-Regulated Environment (NDA)
- Analysis and assessment of the approach model
- GAP analyses (sourcing readiness) and process analysis
- Process documentation
- Channeling and evaluation of department requirements
- Monitoring of the service provider/nearshoring partner
Patrick U.
Last position:
Interim Management | Consulting & Implementation | Data Deletion in SAP at BSR (Berliner Stadtreinigung)
- Topics: Business Analysis, Data Privacy, Data Management, Stakeholder Management, Conceptualization
- This project focuses on developing and implementing a strategic approach for data deletion in SAP systems. The goal is to identify the relevant data and structures during system migration to ensure both data privacy and IT system efficiency. At the same time, downtime should be minimized and regulatory requirements met.
- Development of a comprehensive approach for data deletion in SAP systems, considering data privacy and business requirements.
- Ensuring efficient and structured data transfer to the new system.
- Optimizing system efficiency and reducing downtimes during migration.
- Creating functional and technical concepts to ensure compliant and sustainable data management.
- Topic preparation: Detailed study of the "data deletion" area to lay the foundation for a structured data migration.
- Definition of project structure: Setting roles, interfaces and the project's organizational structure.
- Regulatory requirements: Analysis of data privacy regulations and business requirements to define deletion criteria.
- Approach: Developing possible scenarios and methods for data cleansing and deletion.
- Deletion concepts: Creating functional and technical deletion concepts that structure the implementation and provide clear guidelines.
- Setting deletion criteria: Defining which data and structures to delete or transfer.
- Responsibilities: Clarifying responsibilities within the project team and among stakeholders.
- Analysis of ongoing activities: Identifying and collecting existing activities in the "data deletion" area.
- Effort, cost and timeline planning: Creating estimates for resources, effort and budget.
- Implementation initiatives: Developing and executing concrete measures to apply the defined deletion strategies.
- IT system efficiency: Analyzing the existing IT infrastructure to identify optimization potential for data deletion and transfer.
- Technology trends: Evaluating new technologies and tools that can support the data cleansing process.
- Cost-benefit analysis: Assessing the financial impact of data cleansing and the introduction of new solution approaches.
- Risk management: Identifying potential risks during implementation and developing appropriate mitigation measures.
- This project lays the foundation for a sustainable and compliant data transfer to a new SAP system. With a clear approach to data deletion, it meets data privacy requirements, reduces downtimes and increases the efficiency of the new system. The results and recommendations will help companies develop a future-proof data strategy that meets legal and business needs.
Rick G.
Last position:
Interim IT Security Analyst at GLS IT Services GmbH
- Risk Management
- Incident Management
- Security Analysis
- Secure Coding
- Information Security Management System (ISMS)
Lukas B.
Last position:
Project Management Migration Specialist at ADAC
- Data migration strategy consulting for core banking solution - Mainframe to Cloud migration
- Data models evaluation and analysis of value flows for a new cloud-based insurance portfolio system introduction
- High level migration strategy
Michael L.
Last position:
Identity & PAM Architect at BfArM
- Implementation of CyberArk OnPremise
- BSI basic protection (high protection needs)
- Breaking Class Strategy
- IdP / Identity Strategy / PIM
- Technologies: PAM, CyberArk OnPremise, KeyCloak
Volker J.
Last position:
Interim CISO (Germany, Austria, US, APAC), Auditor at Vetter Pharma-Fertigung GmbH & Co. KG
- Planned and initiated BIA/BCM assessment to identify risk mitigation measures and process optimization, and provide risk transparency to the general management
- Evaluated KRITIS/NIS-2 status and implemented requirements
- Created comprehensive digital roadmap and ISO 27001/NIS-2/Data Privacy KRITIS roadmap
- Enhanced crisis management process and documentation
- Integrated information security clauses into customer and supplier contracts to ensure compliance with internal and regulatory requirements
- Ensured organizational readiness for audits by the Landesbehörde für Aufsicht (LBA) and supported audit processes
- Improved asset management processes and classification of sensitive data to strengthen overall security
- Planned and ordered regular penetration tests (internal, external) to identify vulnerabilities and improve security measures
- Performed compliance checks against EU CER requirements and reporting
- Created management status and risk reports to ensure transparent communication of risks and security posture
- Managed registration with the German Federal Office for Information Security (BSI) and provided ongoing status updates
- Conducted risk assessment of supply chain, enhanced evaluation and reporting processes
- Improved IT/OT network segmentation to enhance security and reduce potential audit risks
- Strengthened cyber resilience by proactive measures and enhanced security frameworks and KPI reporting
- Onboarded SIEM/SOC/EDR to improve cybersecurity monitoring and response
- Planned and conducted awareness trainings for employees, administrators, and management
- Enhanced incident reporting processes to ensure timely and accurate reporting of cybersecurity events
- Created AI policy in cooperation with the Legal department to secure use and governance of Artificial Intelligence within the organization
- Scoped and implemented ISO 27001:2022 requirements as part of the Information Security Management System
- Served as interim InfoSec team lead
- Introduced information security to global KAM and Sales organization
- Improved admission and access management including privileged access
- Conducted internal audits in collaboration with internal audit department
Philipp S.
Last position:
MS365 Consultant/Solution Architect at Self-employed
- Setup and configuration of an M365 tenant on a hybrid basis
- SSO integration of the existing app infrastructure like Metamost, Huhu, etc.
- License consulting, Entra ID initial configuration, MFA, Conditional Access, Privileged Identity Management
- Intune: initial configuration, Windows 11 Autopilot, iPhone AES
- Takeover of the tenant and preparation of a security audit
- Rollout of iPhones with AES (formerly DEP) as COPE (Corporate Owned, Business Enabled)
- Connecting external customers with enhanced security through Conditional Access
- Consulting on cloud-first strategy and migration to a cloud-only business
- Connecting various apps via SSO/SCIM (e.g. Atlassian, Personio, Adobe)
- On-premises AD: security audit and project management for replacing the local AD (migration of file servers, Navision2016, user clients joined to Entra ID)
- Copilot rollout with connection to external data sources and configuration via Intune
- Support for TISAX and ISO27001 preparation
- Setup and hardening of Entra ID, switching MFA to phishing resistant via Conditional Access
- Intune management for Windows and Apple clients, web enrollment switch to AES, introduction of Autopilot, app management, integration of Microsoft Defender
- Building a device baseline for Windows (COBO) and iOS/Android (BYOD)
- Teams/SharePoint Online: access concepts and integration into Teams
- Maintenance and backup of Entra ID and Intune tenants (drift management)
- M365 backup with Veeam
- Extending Conditional Access policies, introduction of Privileged Identity Management with hardware tokens and an on-premises admin tier concept
- Revision of existing GPOs regarding structure, security, and compliance
- Security audit and hardening of on-premises Active Directory and cloud tenant, SAML VPN, PIM introduction
- Support for the HR department in introducing a booking portal and general system engineering administration & security
- Introduction of Conditional Access and passwordless MFA, platform SSO, Defender for macOS/iOS, macOS compliance with Intune, Code2 signature configuration
Discover over 15,000 top freelancers
Statistics of experts using ISMS
Aggregated from the professional profiles of matched freelancers.
Experience
17 years (Germany: 21 years)

Position duration
2.2 years (Germany: 2.6 years)

Positions per freelancer
11 (Germany: 14)

Top business areas
Information Technology, Project Management, Marketing

Top industries
Information Technology, Professional Services, Banking and Finance

Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
50% (Germany: 88%)
Master's degree or higher
50% (Germany: 54%)

Certifications per freelancer
5 (Germany: 7)

Most common languages
German, English, French

Speak two or more languages
91% (Germany: 97%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using ISMS
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
ISMS experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (91%)
- Professional Services (91%)
- Banking and Finance (64%)
- Automotive (45%)
- Government and Administration (45%)
- Aerospace and Defense (36%)
- Insurance (36%)
- Chemical (27%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
Purpose and scope
An ISMS, or Information Security Management System, is a structured way to govern information security across an organisation. It connects business objectives with policies, risk treatment, controls, responsibilities and continual improvement. An ISMS can support cloud services, internal operations, software products and regulated business processes.
Standards and frameworks
ISO/IEC 27001 is the best-known certification framework for an ISMS. Strong professionals also work with ISO/IEC 27002 controls, ISO 22301 for continuity and the BSI IT-Grundschutz methodology. They translate these frameworks into a practical scope, control set, statement of applicability and audit evidence rather than copying generic templates.
Core workstreams
- Define the ISMS scope, interested parties and security objectives
- Identify assets, threats, vulnerabilities and business risks
- Select controls and document treatment decisions
- Establish incident, access, supplier and continuity processes
- Prepare management reviews and internal audit evidence
The work often includes policy writing, risk registers, control mapping, exception handling and corrective actions. It must remain usable for staff and traceable for auditors.
Tools and interfaces
ISMS specialists combine governance work with practical security knowledge. They may use GRC tools, ticketing systems, document repositories, vulnerability reports, identity platforms and cloud security services. Useful adjacent skills include data protection, third-party risk, business continuity, security awareness, audit management and technical control validation.
When freelance expertise helps
Companies often bring in freelance support before an ISO 27001 certification project, after a major cloud or organisational change, or when internal ownership is unclear. In Munich, local organisations may value German-language workshops and on-site stakeholder sessions, while remote collaboration can work well for evidence reviews, policy drafting and control tracking. The right scope depends on the organisation’s risks and existing processes.
What strong professionals deliver
A capable ISMS professional asks how information flows through the business before proposing controls. They make risks measurable, assign clear owners and connect each requirement to evidence. Look for experience with audits, remediation and management communication, plus the ability to explain security decisions to technical teams, executives and process owners. Quality shows in consistent documentation and controls that people can follow.
Frequently asked questions
Questions about ISMS? Start with the answers below.
An ISMS organises how a company identifies, treats and monitors information security risks. It covers governance, policies, controls, responsibilities, incident handling and continual improvement across defined business activities.
An ISMS is the management system an organisation operates, while ISO/IEC 27001 is the standard used to define requirements and assess conformity. A company can use the standard to build and certify its system, but certification is not the only reason to establish one.
An ISMS freelancer can help when a company lacks internal security governance capacity, is preparing for an audit or needs to address risks after a major change. The engagement may focus on design, implementation, evidence preparation, internal audit or remediation.
A strong ISMS specialist usually understands risk management, ISO/IEC 27001 controls, audit practice and security policies. Experience with data protection, supplier assurance, cloud security, identity management or business continuity is also valuable, depending on the project scope.
An ISMS project needs experience proportionate to its scope, risk profile and audit expectations. A focused policy or gap assessment may need a narrow specialist, while a full implementation benefits from someone who has led risk treatment, stakeholder workshops, control rollout and audit follow-up.
Much ISMS work can be handled remotely through interviews, document reviews, workshops and evidence tracking. On-site sessions in Munich can still help with sensitive process mapping, management alignment and discussions involving teams that prefer German.
Ask an ISMS professional to explain how they define scope, prioritise risks and prove that controls operate in practice. Review sample deliverables such as a risk methodology, control mapping or audit plan, and test whether the person communicates clearly with both leadership and operational teams.
An ISMS may connect with GRC software, ticketing tools, document management, identity systems, vulnerability management and cloud security services. The tool matters less than reliable ownership, version control, evidence retention and workflows that support risk decisions and corrective actions.
The average hourly rate of freelancers in Munich, Germany who have used ISMS in their recent projects is 112 €, which corresponds to a daily rate of about 894 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used ISMS in their recent projects, 50% hold at least a Bachelor's degree and 50% hold at least a Master's degree.
On average, freelancers in Munich, Germany who have used ISMS in their recent projects have 17 years of professional experience, with a single engagement typically lasting around 2.2 years.
The most common languages among freelancers in Munich, Germany who have used ISMS in their recent projects are German (100%), English (91%), and French (27%).
The most common industries among freelancers in Munich, Germany who have used ISMS in their recent projects are Information Technology (91%), Professional Services (91%), and Banking and Finance (64%).
The most common business areas among freelancers in Munich, Germany who have used ISMS in their recent projects are Information Technology (100%), Project Management (91%), and Marketing (45%).
Main locations of FRATCH Experts, who have recently used ISMS
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Cologne
Frankfurt
Dusseldorf