ISO 27001 Experts in Dusseldorf
matched in minutes from over 15,000 CVs with the power of AI.Hire experts who design, assess, and improve ISO/IEC 27001 information security management systems, close audit gaps, and prepare policies, controls, and evidence packs for certification. Work with vetted, available specialists who know how to fit into local teams in Dusseldorf and deliver fast, precise matching.
Meet FRATCH Experts in Dusseldorf, who have recently used ISO 27001
Alwin G.
Last position:
IT Interim Manager & AI Strategist
- AI product development: Design of an AI-supported GRC platform to automate compliance processes.
- AI expertise: Strategic deepening in Agentic AI and GenAI as a core asset for modern IT governance
- IT interim management and strategic consulting
Alicja Wilczek
Last position:
Integrated security and emergency documentation for a 24/7 logistics company at Medium-sized logistics company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, vulnerability management policy, business resilience programme, risk governance plan
- Consolidation into an integrated emergency handbook (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table, and a formal approval structure
- Review of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with documented compensating control
- Review and documentation of NIS2 and HinSchG applicability, including the legal reasoning for non-applicability
Abdelkader El Moumane
Last position:
Lead Business Analyst (PIM)
- Further development and optimization of the PIM system (e.g. data modeling, interfaces, user experience)
- Analysis, structuring, and professional evaluation of business requirements in close coordination with business units and stakeholders
- Translating business requirements into functional and technical concepts (business & solution design)
- Designing and further developing the target PIM architecture including data models, object structures, versioning, and lifecycle concepts
- Defining interfaces, integration concepts, and data flows between PIM, eCommerce, ERP, and other systems
- Quality assurance in close collaboration with business units and the development team
- Effort estimations for analysis, design, and testing activities
- Agile, Scrum, 4APortal, SAP ERP, SAP eCommerce (Hybris)
Federico Leefhelm
Last position:
Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG
As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW.  Developed and implemented a holistic process view covering both technical and organizational aspects  Ensured end-to-end control of all IAM-related technical services  Established clear responsibilities and accountabilities within the IAM landscape  Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security  Introduced and monitored governance policies to ensure compliance and security  Continuously improved IAM processes and systems through regular audits and evaluations  Participated in external audits of the process as part of official ISO audits  Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units  Conceptually advanced the KPI system to measure process quality
Ralph Konitzer
Last position:
Product Owner / Business Owner at AXIS Management Consulting GmbH
- Full product responsibility from a business perspective: requirement analysis, UX design, product strategy, and go-to-market implemented without an internal dev team using fully AI-supported development (Claude Code / Anthropic)
- Technical differentiation: KRITIS-compliant air-gapped deployment (Windows/NSIS), GDT interface for PVS integration, DATEV-LODAS export for payroll
- Managed pilot operation with initial external client (Dormagen medical practice): structured requirement gathering, test support, error analysis, and release management
- Developed rollout and sales strategy for market entry in the segment of private practices and small medical centers
- Human-in-the-Loop development principle: business decision → AI implementation → manual review → approval → release – each sprint documented in Jira (TIME project), every change traceable via co-authored commits
- Product outcome: Tauri/Rust desktop app with GDT watcher, multi-tier model (Starter/Professional/Enterprise), cloud mirror on Hetzner/Traefik, complete ISMS framework based on ISO 27001 and BSI basic protection as product foundation
- Direct method validation for the test manager role: hands-on experience with quality assurance of AI-generated products from a user perspective, review gate discipline, release approval under GDPR and the EU AI Act
Wolfgang Schenk
Last position:
CIO / CDO / Project Manager AI Academy / Auditor of Operational Processes / Product Owner MS365 at F&P Executive Solutions AG
- Digitalization of accounting, signature/approval, and onboarding processes
- Restructuring of the IT department
- Introduction of a digital sales tool
- Implementation of an AI webinar series
- Introduction and optimization of information security
- Administration and optimization of the MS Office 365 environment
Saba Fazel
Last position:
Lead AI Strategy & Governance Consultant at Public Sector
- Operating Model Design: Designed and rolled out a 3-tier AI Governance Operating Model, defining organizational structures, roles, tooling, guidelines and processes across Corporate, Business Units, and Implementation layers to manage compliance for 200,000+ employees.
- EU AI Act Compliance: Led the strategic screening and risk classification of 3,800+ AI applications, implementing automated assessments for prohibited practices and General Purpose AI (GPAI) requirements.
- Enterprise Roll-out: Orchestrated the deployment of an internal GPT platform and Generative AI tools, defining the value proposition and adoption strategies for 10,000+ users.
- AI Literacy Architecture: Designed a modular AI training framework to transition the workforce from legacy manual workflows to AI-assisted processes.
- Executive Storylining: Developed strategic narratives for the CIO and Board to secure buy-in for AI investments, translating technical model performance into business-value summaries.
- PMO Infrastructure: Built the end-to-end PMO infrastructure using Jira, Confluence, and Azure Boards to track transformation progress and cross-entity dependencies.
Marc Schmöger
Last position:
Consultant / Interim / Freelance at Self-employed
- Hybrid/Remote
- Digitalisation introduction and optimisation of software
- Advice on the introduction of AI
- Data & AI strategy
- Interim / tech consultant
- Product, process & management
- Vendor management
- Compliance management platforms (ISO 27001, GDPR, EU AI Act)
- M&A due diligence & analysis
Kai V. Wulffen
Last position:
Process Manager in Operational Change Management at Jungheinrich AG
- Introduction of a central change process
- Technical support for the operational implementation of changes (ITIL technical change management)
- Co-design and technical implementation of digital processes
Rakesh Lakhani
Last position:
Multi Domain Expert IT Infrastructure at Speira GmbH
- Development and implementation of multi-domain infrastructure strategies to optimize system performance in OT and IT.
- Design of security concepts for multi-domain infrastructures, including IT security management.
- Oversight of incident management, problem management, and change management.
- Managing the entire lifecycle of a strategic project, including planning, execution, delivery, and stabilization.
- Supporting IT governance, IT architecture, and risk management.
- Conducting workshops on IT security and infrastructure.
Natascha Kluike
Last position:
Business Analyst DORA and System Architecture at PSVaG
- DORA consulting and system optimization
- Process analysis of existing business and technically complex processes
- Analysis of individual processes in relevant areas: trading, back office, settlement, custodian bank
- Acting as interface between business areas and IT to understand and define requirements
- Creating a functional specification including adjustments and implementation of software applications and their interfaces to systems
- Preparing a decision paper for the executive board to approve the project
- Setting up and conducting project meetings with relevant stakeholders and documenting them
- Close collaboration with stakeholders
- Coordinating and steering the analysis
- Planning and allocating resources and budget
- Onboarding large banks (Asia and Eastern Europe) for Depot B
- Migrating Depot B holdings (volume around EUR 70-100 million)
Kaliyan Muthukrishnan
Last position:
Techno-Functional Consultant – Digital Lab & Manufacturing Systems at Dynavax Technologies
- Led SampleManager LIMS 21.x & LabWare LIMS v8 implementation, reducing manual lab errors by 40% and improving data traceability.
- Configured LW LIMS & SM LIMS 21.2: workflow design, role-based access control (RBAC), and master data management.
- Designed and configured LES workflows: sample lifecycle management, test assignments, approvals, and result review processes.
- Managed Master Menu and CI configuration, ensuring consistency, data integrity, and regulatory compliance.
- Integrated LIMS 21.2 with MES, ERP, EM, WinKQCL (Lonza MODA), SoftMax Pro, Empower, and Chromeleon CDS via REST APIs and web services.
- Implemented PAS-X MES: architecture design, multi-platform implementation (PAS-X, Siemens Opcenter), and integration with PLC, SCADA, and DCS systems.
- Executed IQ/OQ/PQ qualification protocols and Validation Summary Reports (VSR) for QC analytical and utility systems in aseptic and sterile production environments.
- Developed and reviewed Risk Assessments, Traceability Matrices, and Data Integrity evaluations in accordance with ALCOA+, 21 CFR Part 11, and EU Annex 11.
- Led EMA/FDA/WHO inspection readiness, standardized CQV SOPs, enabled digital CQV integration (LIMS/CDS/MES/SCADA/ERP/SDMS), and ensured 21 CFR Part 11 & Annex 11 compliance.
- Managed secure OT cybersecurity: network configuration and access control.
- Configured NuGenesis SDMS for document/data management, CDS/LIMS integration, workflow automation, and reporting.
Matthias Fitzner
Last position:
Information Security Project Manager at Deutsche Bahn AG
- Introduction of a new Information Security Management System (ISMS) according to ISO/IEC 27001.
- Implementation of the cybersecurity guideline RL CySec-Rail for cross-border rail networks.
Torsten Schneider
Last position:
Managing Director at mac + you GmbH
- CFO of the company
- Consulting in processes and process management
- Consulting in information security ISO 27001
- Consulting Scrum / Agile Management
- Project management for IT projects, especially doctors' practices
- Digitalization projects
- Data protection / data security training
Nikolaus Betzler
Last position:
ICT Risk Management and Information Security at B. Metzler seel. Sohn & Co. AG
- Independently develop policies, guidelines, and frameworks for ICT risk management and information security
- Advise business units on ICT risk management and information security
- Further develop the ICT risk management framework that governs the identification, assessment, and control of ICT risks
- Evaluate the Information Security Management System (ISMS) and adjust it for new challenges
- Conduct risk analyses to identify and assess potential ICT risks and information security risks for the Metzler Group
- Advise on defining and implementing measures to reduce risks and improve the resilience of ICT systems
- Advise on ensuring compliance with relevant internal and external regulatory requirements (MaRisk, DORA, BAIT, BSI IT baseline protection, ISMS, ISO 27001, ISO 42001, ISO 27005, BCM ISO 22301)
- Advise on internal and cross-functional projects (SAP DORA compliance, Target2, Section 8a BSI Act)
Discover over 15,000 top freelancers
Statistics of experts using ISO 27001
Aggregated from the professional profiles of matched freelancers.
Experience
24 years (Germany: 22 years)
Position duration
2.3 years (Germany: 2.6 years)
Positions per freelancer
14 (Germany: 13)
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Automotive, Professional Services
Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
79% (Germany: 88%)
Master's degree or higher
43% (Germany: 54%)
Doctorate
7% (Germany: 10%)
Certifications per freelancer
6
Most common languages
German, English, Spanish
Speak two or more languages
89% (Germany: 97%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Dusseldorf are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Dusseldorf using ISO 27001
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What ISO 27001 covers
ISO 27001 is the international standard for an information security management system, often written as ISO/IEC 27001. It helps companies define how they protect data, manage risk, and prove control over security processes. Strong specialists turn the standard into a working system, not just a set of documents.
Typical work
- Build or refresh the ISMS scope, policies, and risk register
- Map controls to business processes and evidence
- Prepare for certification audits and gap reviews
- Support supplier security, incident handling, and internal audits
- Train teams on security responsibilities and daily routines
Skills that matter
Good ISO 27001 professionals understand Annex A controls, risk treatment plans, statement of applicability, and audit readiness. They also know how to work with legal, IT, operations, and leadership without creating unnecessary complexity. Clear writing and disciplined follow-through matter as much as framework knowledge.
When companies bring help
Many teams look for outside support when certification is new, an audit is approaching, or existing controls no longer match the way the business works. In Dusseldorf, this often matters for companies handling customer data, supplier networks, or regulated services. Freelance experts can join remote, on-site, or hybrid work depending on the review or rollout.
Tooling and deliverables
ISO 27001 work often includes risk workshops, policy sets, control matrices, audit evidence lists, and remediation plans. Professionals may also work with GRC tools, ticketing systems, document repositories, and security logs to keep the system traceable. The best specialists leave behind practical material that teams can maintain.
What strong experts deliver
Strong ISO 27001 experts make security management usable for the business. They reduce friction, align stakeholders, and help turn findings into concrete actions. For hiring teams, that means a cleaner path to certification, steadier governance, and a system that keeps working after the project ends.
Frequently asked questions
Not sure where to start with ISO 27001? These answers cover the essentials.
ISO 27001 is used to build and run an information security management system. It gives a company a structured way to handle risk, define controls, and show that security is managed consistently. Many firms use it to support certification, customer trust, and internal governance.
ISO 27001 is the common short form, while ISO/IEC 27001 is the full standard name. In practice, people usually mean the same framework for an information security management system. The full form appears more often in formal documents and audit material.
ISO 27001 is a certifiable management standard, while NIST is a broader security framework and SOC 2 is an assurance report focused on trust criteria. Companies often choose ISO 27001 when they want a formal system that can be audited against a global standard. A good expert can explain which path fits your customers and internal setup.
A strong ISO 27001 specialist usually brings risk management, audit preparation, policy writing, and basic security governance skills. Familiarity with vendor risk, incident response, and data protection helps a lot too. If the work touches technical controls, cloud and infrastructure awareness is useful.
A ISO 27001 project usually needs someone who has handled the full ISMS lifecycle, not just read the standard. If you are starting from zero, look for someone who has built scope, assessed risks, written controls, and supported an audit. Smaller remediation tasks can be handled by narrower specialists, but the lead should see the whole picture.
Yes, ISO 27001 work is often well suited to remote collaboration because much of it involves reviews, workshops, and document work. On-site time can help when a specialist needs to observe processes, meet stakeholders, or support audit sessions in person. In Dusseldorf, many teams mix both depending on the phase of the project.
Look for someone who can explain ISO 27001 in plain language and turn it into concrete actions. Good signs are clear gap analysis, useful evidence planning, realistic remediation steps, and the ability to work across teams without creating noise. Weak profiles stay abstract or focus only on documentation.
Freelancers working with ISO 27001 should expect to balance structure with pragmatism. Clients want specialists who can adapt the standard to real operations, keep evidence tidy, and communicate well with auditors and business owners. A calm, methodical style matters more than grand claims.
The average hourly rate of freelancers in Dusseldorf, Germany who have used ISO 27001 in their recent projects is 108 €, which corresponds to a daily rate of about 863 € based on an 8-hour working day.
Of the freelancers in Dusseldorf, Germany who have used ISO 27001 in their recent projects, 79% hold at least a Bachelor's degree, 43% hold at least a Master's degree, and 7% hold a doctorate.
On average, freelancers in Dusseldorf, Germany who have used ISO 27001 in their recent projects have 24 years of professional experience, with a single engagement typically lasting around 2.3 years.
The most common languages among freelancers in Dusseldorf, Germany who have used ISO 27001 in their recent projects are German (100%), English (89%), and Spanish (22%).
The most common industries among freelancers in Dusseldorf, Germany who have used ISO 27001 in their recent projects are Information Technology (94%), Automotive (50%), and Professional Services (50%).
The most common business areas among freelancers in Dusseldorf, Germany who have used ISO 27001 in their recent projects are Information Technology (100%), Project Management (89%), and Operations (83%).
Main locations of FRATCH Experts, who have recently used ISO 27001
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Cologne
Frankfurt
Stuttgart
Dortmund
Essen