ISO 27001 Experts in Austria
in minutes from over 15,000 CVs with the power of AI.Hire experts who build ISMS policies, map risks and controls, and prepare audit-ready evidence for ISO/IEC 27001. They support certification work, supplier security checks, and ongoing compliance, with fast, precise matching to vetted, available freelancers.
Meet FRATCH Experts in Austria, who have recently used ISO 27001
Lucas Garzarolli
Last position:
Self-Employed Management Consultant at nospia e.U.
Provided expert consultancy services to a range of clients, supporting their compliance and security objectives across multiple domains. Key projects and responsibilities included:
- Lead consultant for successful ISO 27001 certification projects, including readiness assessments and audit support
- Conducted comprehensive risk reviews and gap analyses to identify and remediate compliance and security vulnerabilities
- Developed, and improved internal and external policies, guidelines, and procedures related to information security and data protection
- Delivered tailored training sessions to employees on security best practices and data protection obligations
- Negotiated and drafted compliance-related contractual clauses, including DPAs and security-related provisions.
- Designed consent management strategies and ensured effective technical implementation of cookie banners in compliance with regulatory requirements
Daniel Schlager
Last position:
AI Automation in E-Commerce at Looops
- AI automation roadmap for a D2C/B2B e-commerce company.
- Customer service bot with RAG over support tickets and product data, OCR pipeline for incoming invoices with writeback to Business Central, lead gen and posting automation.
- Deterministic n8n workflows with EU-hosted models.
- n8n, RAG / Mistral, Qwen/BGE embeddings / Business Central API, HubSpot, Shopify / Scaleway, S3 / Claude Code, OpenCode.
Michael Langer
Last position:
IAM Developer & IT Architect at Internationale Bank
Design and implementation of new functionalities in the areas of Lifecycle Management (LCM), Role Management (RLM) and Access Governance
Adjustment of the company-wide Segregation of Duties (SoD) matrix to ensure regulatory and internal compliance requirements
Further development and configuration of recertification processes
Creation and adaptation of custom workflows, rules and tasks in SailPoint IdentityIQ (BeanShell, XML, Java)
Use of static code analysis with SonarQube to ensure code quality and compliance with defined development standards
Regular code reviews within the development team to ensure quality, share knowledge and follow clean code principles
Work in an agile Scrum team with daily communication, sprint planning and reviews
Coordination with testers, test managers and business departments to ensure quality and smooth production rollout
Active involvement in release planning and deployment coordination, including test preparation, cutover activities and rollback strategies
Analysis and sustainable resolution of issues in the IAM production environment (2nd- and 3rd-level support)
Reproduction of complex errors, identification of root causes and implementation of lasting fixes
Creation of technical analyses and recommendations for operations and further development
Zoran Jovanovic
Last position:
Technical Writer – Implementation of the BNPP IT PROD SEC Service Catalog at BNP Paribas Germany
Design, authorship and finalization of the IT PROD SEC service catalog with eight standardized security services (S-ID001–S-ID008).
Development of consistent service components & deliverables, RACI assignments and SLA and KPI definitions for each service.
Integration of BaFin document requirements under DORA into the service descriptions.
Coordination with IT, compliance, risk and operations teams to validate all service descriptions.
Specifically for governance & monitoring: definition of governance cadence, evidence delivery processes, audit support and definition of measurable KPIs and measurement methods.
Ensuring that all services are standardized, measurable and documented in an audit-proof manner.
Result: Approved service catalog with eight services as a binding basis for delivery, governance and audits; transparent SLAs/KPIs for each service and DORA/BAIT/MaRisk-compliant documentation with clear responsibilities and evidence trails.
Technologies and tools: Confluence, Jira, ServiceNow, Microsoft PowerPoint, Microsoft Visio, Office 365.
Georg Oberdammer
Last position:
CIO / CDO at TroGroup
- Design and execution of the transformation journey of IT & digitization and enablement of the further development of the group
- Development of the global IT & digitization strategy (motto: “ahead of the wave”) based on group standards and USP-driven digital solutions
- Definition of the digital strategy as part of the company’s 2030 strategy with a focus on the value disciplines “operational excellence,” “customer intimacy,” “product leadership”
- Design and implementation of a business-focused, global IT organization, including existing shadow IT parts
- Digital product development with a focus on IoT, data science, AI, software development (DevOps), cloud architecture, and Azure cloud services
- Initiation and ramp-up of the CoE for artificial intelligence and data analytics, including several agentic AI projects
- Definition and global rollout of the enterprise, infrastructure, and application architecture
- Cloud transformation including setup and execution of the global S/4HANA rollout, introducing new capabilities and modules
- Global business process standardization, automation, and end-to-end digitization within and across divisions
- IT/OT integration (shop floor, CAx integration)
- P&L responsibility and further development of digital marketing & sales channels, SEO/SEA, online product configuration, PIM/DAM, eBusiness/eCommerce systems
- Implementation of a global intranet portal and several digital solutions like Workday, Concur, Softconcis, Tacto, xFlow
- Further development of Salesforce beyond CRM into a sales backbone
- Support of M&A and divestiture
- Cyber security excellence, data protection, and NIS2 preparation
- Ramp-up of nearshore and offshore locations (Poland, India)
- Evaluation and implementation of business-value–driven IT innovation like RPA, business process AI, and low-code
- IT budgeting and controlling, KPI reporting, and negotiation of large IT contracts
- Global recruiting, people retention, and development
- Stakeholder management with executive management and heads of divisions
Manuel Kathofer
Last position:
Overall project manager for the global roll-out of a quality and document management system at International medical device company
- Took over overall project leadership after the roll-out was stopped the previous year
- Identified causes and planned a new approach
- Organized and conducted qualification tests of new software versions
- Planned and coordinated all tasks and assignments at six sites worldwide and with the software provider
- Aligned compliance topics with the quality heads at the sites
- Organized and held steering committee meetings to report to management
- Successful go-live in fall 2024
Tobias Franek
Last position:
CTO & Founder at bitminds
Selected projects:
Kiosk platform – hospitality
- Led a 3-person team while hands-on architecting an edge computing infrastructure for over 15 self-service kiosks in Alpine hotels with unstable connectivity
- Designed a Nomad-based cluster with a WireGuard mesh network for fully automated OTA updates, even during local network outages and offline operation
- Integrated physical peripherals (hotel key card readers, thermal printers) into a containerized deployment pipeline
- Reduced on-site maintenance visits by ~40% through a resilient offline-first architecture and Prometheus-based hardware monitoring
- Tech: Nomad, Consul, WireGuard, NestJS, NextJS, Prometheus, Custom Hardware Provisioning
Multi-tenant SaaS platform – insurance claims processing
- Built and operated the Kubernetes infrastructure for a market-leading claims processing platform (acquired by an S&P 500 company) – with strict compliance and availability requirements
- Designed a multi-tenant EKS cluster with tenant isolation, enabling cost-effective single-instance hosting for multiple customers
- Implemented dynamic spot instance node pools, reducing infrastructure costs by ~20%
- Set up fully automated deployment pipelines (Terraform + GitHub Actions) for uninterrupted releases during business hours
- Tech: EKS, Terraform, GitHub Actions, Prometheus/Grafana/Loki, PHP, GraphQL
Legacy ERP integration – construction photo documentation
- Led a 2-person team in designing and implementing a real-time sync bridge between a legacy Microsoft Access ERP (without an API) and a modern mobile photo app for quality control on construction sites
- Developed a PostgreSQL pipeline with real-time listeners that extract data from 1990s Access databases – without disrupting existing workflows
- Built a resilient upload architecture with a circuit breaker pattern for unstable site connections (S3, NFS, Synology NAS)
- Saved each project manager 2–4 hours per week through automated photo sync instead of manual USB/SD card transfers
- Tech: NestJS, PostgreSQL, React Native (Expo), S3, Synology API, offline-first architecture
Sascha Leitner
Last position:
CEO at SEComply
- Founder & creator of a cutting-edge Governance, Risk & Compliance SaaS solution.
- Developing and executing business development strategies to identify new opportunities and expand market presence.
- Providing information security consulting services.
- Specializing in governance, risk, and compliance (GRC) topics such as risk management, ISO 27005, ISO 27001, NIS 2, DORA, PCI DSS, EU-GDPR, and more.
- Past projects:
- Kyndryl Austria GmbH: delivered IAM blueprint, conducted risk assessments, developed transformation strategy and roadmap for client projects, and provided support in pre-sales activities to align solutions with client needs.
- Cashpoint Sportwetten GmbH: conducted ISO 27001:2022 gap analysis, enhanced ISMS processes, updated security training, aligned with ISO 27001:2022 standards, and improved vulnerability management practices through regular assessments and remediation planning.
- Hornbach Baumarkt AG: supported the CISO in achieving ISO 27001 compliance, implementing a secure software development lifecycle (SDLC), strengthening vulnerability management practices, and enhancing risk management frameworks.
- MHP Management- und IT-Beratung GmbH: created and reviewed security concepts aligned with ISO 27001 standards.
- Stromnetz Berlin GmbH: developed a comprehensive security concept based on ISO 27001 requirements.
- dmTech GmbH: conducted IT security training for employees, fostering awareness and adherence to security best practices.
- Finanz Informatik GmbH: managed PCI DSS-related tasks, including compliance assessments and control implementations.
- TIPS Messtechnik GmbH: conducted NIS2 gap analysis, developed a comprehensive compliance roadmap, and provided supportive actions to address identified gaps and ensure alignment with regulatory requirements.
Anton Laza
Last position:
CISO & Interim DPO at Finmatics GmbH
- Built the company’s entire security function from zero to ISO-aligned, audit-ready operation (ISO 27001, GDPR, NIS2).
- Delivered enterprise-grade security posture enabling regulated customer onboarding and due-diligence success.
- Embedded automated security controls (SAST, DAST, secrets, vuln scanning) into CI/CD for a growing SaaS engineering team, removing security as a deployment bottleneck.
- Cut third-party risk exposure by ~70% by replacing manual vendor reviews with an automated, LLM-driven risk scoring and approval pipeline.
- Led board-level security, customer audits, and live incident response.
Michael Selinger
Last position:
Director, IT at Austria Juice GmbH
- Directed IT operations across 13 sites in China, Romania, Poland, Hungary, Germany, Ukraine, and Austria.
- Built and led a new IT team with personnel based in Poland, Hungary, Romania, and Germany.
- Upgraded outdated IT infrastructure at sites in Austria, Germany, Romania, and Poland, enhancing clients, printers, networks, servers, storage, firewalls, and backups.
- Retired the legacy phone system and transitioned to Teams.
- Established and deployed AI tools, including Copilot and Zapier.
- Implemented NIS II readiness and achieved ISO 27001 certification.
- Eliminated inefficient business applications to enhance operational efficiency.
- Developed and executed new processes for operations technology, business process outsourcing, purchasing, human resources, and IT.
- Launched a new SAP Warehouse System.
- Established IT standards across all sites.
- Engaged effectively with internal and external stakeholders.
- Defined and monitored security KPIs, ensuring targets were met.
- Managed budgeting processes, achieving a 15% reduction in operational expenditure.
Heinz Hähnel
Last position:
Project Manager at Industry and trading company
- Development of a planning system (planning of planning) for the entire company.
- Development and implementation of a digital, AI-supported strategic and operational control system for the entire company.
Rene Schakmann
Last position:
Head of Digital Services & IT at reet systems gmbh / THEOPHIL Holding GmbH
- Overall responsibility for IT, software development, and digital services of the company for brands such as Rosenberger, Rosehill, Burger King Austria (approx. 70 companies)
- Built the holding's lakehouse and data analytics platform
- Established and led the software development and IT department
- Established and led the operation (cloud-native AWS) of the B2B platform
- Connected IoT systems and developed models for predictive maintenance and production planning, data lake/lakehouse, and BI
- Preparation for ISO 27001 information security certification
- Technologies: Cloud, AWS, Java, Cypress, Angular, Python, Go
Lukas Kulmitzer
Last position:
Chief Information Security Officer (CISO) at eurofunk Kappacher GmbH
- leading and developing information security team
- responsible for security decisions in customer projects (in sensitive public sector)
- ensuring that sophisticated compliance requirements are adequately met
Gerhard Flachs
Last position:
Head of System Monitoring at AAT Design GmbH
- Organises auditing for compliance with aviation regulations
- Oversees internal procedure compliance at AAT
Discover over 15,000 top freelancers
Statistics of experts using ISO 27001
Aggregated from the professional profiles of matched freelancers.
Experience
24 years
Position duration
2.9 years
Positions per freelancer
18
Top business areas
Information Technology, Project Management, Product Development
Top industries
Information Technology, Manufacturing, Professional Services
Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
92%
Master's degree or higher
67%
Doctorate
17%
Certifications per freelancer
5
Most common languages
German, English, Spanish
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Austria are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Austria using ISO 27001
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What ISO 27001 covers
ISO 27001 is the standard for an information security management system, often called an ISMS. It helps organisations define controls, manage risk, and prove that security is handled in a structured way. Strong experts turn the standard into practical rules that fit the business.
Typical delivery
- Gap analysis against ISO/IEC 27001 requirements
- Risk assessment and Statement of Applicability support
- Security policies, procedures, and control evidence
- Internal audit preparation and corrective actions
These tasks often sit inside certification projects, supplier reviews, and recurring governance work.
Skills that matter
Good professionals know Annex A controls, documentation discipline, and how to work with IT, legal, HR, and operations. They should understand business risk, not just policy text. Familiarity with audit trails, asset inventories, and incident handling is often essential.
When firms bring in help
Companies usually look for freelance support when they need an ISO 27001 roadmap, need to refresh an existing ISMS, or must answer customer security demands quickly. In Austria, this often means working with distributed teams while keeping workshops or final review meetings on-site when needed. Clear English helps; German can be useful for local policy work.
What strong experts deliver
Strong ISO 27001 specialists write documents people can actually use. They align controls with real systems, avoid heavy templates, and keep evidence current.
- practical policies and risk registers
- audit-ready control mapping
- realistic remediation plans
- clear stakeholder communication
Adjacent standards and tools
ISO 27001 work often overlaps with ISO 27002, ISO 22301, GDPR, and security frameworks used for cloud and vendor management. Experts may also work with ticketing systems, document management tools, GRC software, and cloud security logs. The best results come from professionals who can connect process, evidence, and day-to-day operations.
Frequently asked questions
Quick answers to the questions that come up most around ISO 27001.
ISO 27001 is used to set up and run an information security management system, or ISMS. It helps a company define risks, choose controls, and keep security work documented and repeatable. Many firms also use it to support customer trust and certification efforts.
ISO/IEC 27001 is the full standard name, and ISO 27001 is the common short form people search for. They refer to the same core standard for information security management. In projects, the short name is often used in daily conversation, while the full name appears in formal documents.
A ISO 27001 specialist usually handles gap analysis, risk work, control mapping, and policy documentation. They may also prepare the Statement of Applicability, support internal audits, and gather evidence for certification or surveillance reviews. The exact scope depends on how mature the ISMS already is.
ISO 27001 defines the management system and certification requirements, while ISO 27002 is a guidance document for controls. That means 27001 is about how the organisation runs security, not only which technical safeguards it uses. It is often compared with NIST-based frameworks, but the focus is different.
A strong ISO 27001 freelancer usually knows risk management, audit preparation, policy writing, and stakeholder coordination. Useful adjacent skills include GDPR awareness, vendor security review, cloud security basics, and incident response planning. They should also be comfortable turning technical input into clear business language.
A ISO 27001 project does not always need a large team, but it does need someone who has handled the standard in real audits or certification work. Light gap assessments may suit a broad security generalist, while certification readiness or remediation work needs deeper specialist experience. The more fragmented the current documentation, the more valuable seasoned support becomes.
ISO 27001 work is often remote because interviews, document review, and evidence collection do not need a desk in the office. On-site time can still help for workshops, management buy-in, or physical security checks, especially in Austrian organisations with multiple locations. A good specialist can balance both without slowing the project down.
A good ISO 27001 professional asks how the business really works before proposing controls. They can explain Annex A, the Statement of Applicability, and risk treatment in plain language, and they produce documents that match actual operations. Ask for examples of certification support, internal audit work, or remediation plans they have delivered.
The average hourly rate of freelancers in Austria who have used ISO 27001 in their recent projects is 124 €, which corresponds to a daily rate of about 989 € based on an 8-hour working day.
Of the freelancers in Austria who have used ISO 27001 in their recent projects, 92% hold at least a Bachelor's degree, 67% hold at least a Master's degree, and 17% hold a doctorate.
On average, freelancers in Austria who have used ISO 27001 in their recent projects have 24 years of professional experience, with a single engagement typically lasting around 2.9 years.
The most common languages among freelancers in Austria who have used ISO 27001 in their recent projects are German (100%), English (100%), and Spanish (14%).
The most common industries among freelancers in Austria who have used ISO 27001 in their recent projects are Information Technology (79%), Manufacturing (71%), and Professional Services (64%).
The most common business areas among freelancers in Austria who have used ISO 27001 in their recent projects are Information Technology (93%), Project Management (79%), and Product Development (71%).
Main locations of FRATCH Experts, who have recently used ISO 27001
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
