ISO 27001 Expert in Munich
in minutes from over 15,000 CVs with the power of AI.Work with specialists who design, implement, and audit Information Security Management Systems to secure your corporate data, streamline compliance, and prepare your organization for successful external audits. FRATCH matches you with vetted, available freelance professionals in Munich within hours.
Meet FRATCH Experts in Munich, who have recently used ISO 27001
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Florian Krebs
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Mohamad Dib-Skhni
Last position:
DevOps Engineer & IT-Security-Architect at BMW Group
- Set up Azure Kubernetes clusters (AKS) with network policies, security groups, and RBAC
- Developed Terraform-based infrastructure as code for secure, reproducible deployments in the BMW Azure cloud
- Hardened CI/CD pipelines using Jenkins, SonarQube, Fortify SSC, and Contrast AST
- Integrated SAP BTP/Kyma and ServiceNow GRC
Kai Zimmermann
Last position:
Program and project management; Agile (method) coach; sales/partner manager at Google (in cooperation with Wipro Technologies)
- Strategic consulting for the initiation and management of complex, multidisciplinary projects
- Stakeholder management (project scheduling, requirements management, budget management, risk management) incl. cross-functional communication with implementation partners
- Carrying out analyses and recommendations with the technical team and discussing them at C-level
Paul Webster
Last position:
Agentic AI Solution Architect at Solvd GmbH
As the Solution Architect for Agentic AI in auto claims processing, I led global customer delivery implementations, encompassing solution design and detailing, multi-tenancy, process flows, integration with third-party solutions, and localization requirements.
- Architectural Analysis: Conducted in-depth analysis of business requirements, managing requirements and creating detailed specifications.
- Service Definition: Developed comprehensive technical definitions for services and integration contracts.
- AI Process Management: Automated AI process management, focusing on analysis, optimization, and continuous improvement.
- Requirements Gathering: Facilitated requirement-gathering sessions and analyzed business processes to identify optimization opportunities.
- Agile Collaboration: Employed agile methodologies, working closely with stakeholders to ensure alignment and responsiveness.
- Technical Support: Assisted senior management with technical analyses and deliverability assessments.
Peter Streibel
Last position:
Rollout Manager at Siemens Healthineers
- Cisco SDA LAN network
- Transition and transformation
Martin Rusnak
Last position:
TECH DUE DILIGENCE FOR PE, VC & FAMILY OFFICES (UNDER NDA) – AI STRATEGY at PE, VC & family office portfolio companies (confidential, under NDA)
Two parallel workstreams: (1) Tech due diligence for acquisitions and portfolio companies. (2) AI strategy certification and AI governance consulting.
Tech assessments for PE/VC acquisitions: code reviews, architecture analysis, scalability evaluation
Tech assessment frameworks and integration roadmaps for portfolio companies
TÜV SÜD certification program: AI governance, EU AI regulation (EU AI Act)
Strategic AI roadmap development for mid-market companies
Delivered several tech DD reports for investment decisions
Developed integration roadmaps for portfolio companies
TÜV SÜD 'AI Strategy & Application Expert' (expected 04/2026)
Andreas Zimmermann
Last position:
ITSM Consultant at Industrial company / Global IT division
- Designed and implemented a new user support tower organization as part of the global IT transformation initiative.
- Created an operating and control model for the central service desk, including downstream support units (field service, VIP support, service points).
- Performed a comprehensive as-is analysis of existing service desk and field service structures and developed a target architecture based on ITIL 4 and SIAM.
- Defined roles, responsibilities, and governance mechanisms for internal IT and external providers.
- Prepared the blueprint document Service Management & Governance Handbook (User Support) to standardize global service processes (incident, request, problem, change, knowledge, ITSCM, CSI).
- Developed a KPI and SLA framework to measure service quality and performance in global user support.
- Defined the reporting and review structure (operations meeting, service review meeting, management steering board).
- Prepared RFP documents for the external tendering of L1/L2 support services, including definition of scope, governance model, process requirements, tool integration (ServiceNow), and KPI/SLA sets.
- Supported procurement and legal departments in evaluating and negotiating vendor proposals and assisted in vendor selection and contract finalization.
- Oversaw the handover to operational support, including knowledge transfer, training of provider teams, and establishment of a continuous improvement process (CSI).
- Methods / framework / tools: ITIL 4 / ITSM, SIAM, IT4IT, ServiceNow, Jira, BPMN, operating model canvas, KPI & SLA design, governance & performance management
Patrick Upmann
Last position:
Interim Management | Consulting & Implementation | Data Deletion in SAP at BSR (Berliner Stadtreinigung)
- Topics: Business Analysis, Data Privacy, Data Management, Stakeholder Management, Conceptualization
- This project focuses on developing and implementing a strategic approach for data deletion in SAP systems. The goal is to identify the relevant data and structures during system migration to ensure both data privacy and IT system efficiency. At the same time, downtime should be minimized and regulatory requirements met.
- Development of a comprehensive approach for data deletion in SAP systems, considering data privacy and business requirements.
- Ensuring efficient and structured data transfer to the new system.
- Optimizing system efficiency and reducing downtimes during migration.
- Creating functional and technical concepts to ensure compliant and sustainable data management.
- Topic preparation: Detailed study of the "data deletion" area to lay the foundation for a structured data migration.
- Definition of project structure: Setting roles, interfaces and the project's organizational structure.
- Regulatory requirements: Analysis of data privacy regulations and business requirements to define deletion criteria.
- Approach: Developing possible scenarios and methods for data cleansing and deletion.
- Deletion concepts: Creating functional and technical deletion concepts that structure the implementation and provide clear guidelines.
- Setting deletion criteria: Defining which data and structures to delete or transfer.
- Responsibilities: Clarifying responsibilities within the project team and among stakeholders.
- Analysis of ongoing activities: Identifying and collecting existing activities in the "data deletion" area.
- Effort, cost and timeline planning: Creating estimates for resources, effort and budget.
- Implementation initiatives: Developing and executing concrete measures to apply the defined deletion strategies.
- IT system efficiency: Analyzing the existing IT infrastructure to identify optimization potential for data deletion and transfer.
- Technology trends: Evaluating new technologies and tools that can support the data cleansing process.
- Cost-benefit analysis: Assessing the financial impact of data cleansing and the introduction of new solution approaches.
- Risk management: Identifying potential risks during implementation and developing appropriate mitigation measures.
- This project lays the foundation for a sustainable and compliant data transfer to a new SAP system. With a clear approach to data deletion, it meets data privacy requirements, reduces downtimes and increases the efficiency of the new system. The results and recommendations will help companies develop a future-proof data strategy that meets legal and business needs.
Rupesh Kumar Sendge
Last position:
IT Baseline Compliance Consultant at Consultant
- Baseline compliance verification against MAS audit findings
- Building technical architecture concept for 30 technologies to build hardening standard artifacts
- Identifying and building automation possibilities for given technologies based on CIS
- Building the standard baseline configuration based on internal security standard
- Responsible for building Cloud Native Application Protection Platform (CNAPP) architecture artifacts based on Azure cloud platform
- Responsible for RFQ and RFP for different CNAPP solutions (Qualys Total Cloud, CrowdStrike, Azure Security Center)
- Supporting compliance verification and validation via automated scripts for a sample population of IT devices and instances
- Responsible for complete vulnerability management lifecycle using Nexpose, remediation, reporting and integration of results with Splunk, HPSM and Tableau
- Audit support for MAS
Ould Aly Isselmou
Last position:
Functional Safety Assessor at VW
- Pre-assessments and review of functional safety status for ADAS ECUs and body controller components
- Conduct functional safety audits
- Review the functional safety status of the E3 1.2 in a pre-assessment
- Document interviews
- Document findings and generate internal reports
Methods:
- ISO26262
- Automotive SPICE Level 2, 3
- Agile methods, SAFe
Tools:
- DOORS
- Enterprise Architect
- JIRA & Confluence
- IQ-FMEA
- Isograph
Stephan Krausenegger
Last position:
Migration Coordination at ITZBund
- Analysis and assessment of government business processes with regard to migration capability
- Definition and preparation of the technical framework conditions in the new master data center
- Development and optimization of migration procedures and processes
- Transformation of existing solutions to new technical standards (technology refresh)
- Coordination of architecture and technical cross-cutting topics
Norbert Stilling
Last position:
Self-Employed Consultant and Project Manager at Self-Employed Consultant and Project Manager
- 21 projects ≥ 6 months at large and medium-sized companies
- 13 projects as project or subproject manager
- 6 international projects with English as project language
Alexander Nagy
Last position:
Security Expert at DAK-Gesundheit
- Pentesting of mobile applications
- Code review
- Gematik audit
- Development of secure software development methods
- Creation of security and test concepts
- Penetration testing of software and architecture
- Vulnerability analysis
- Automation and information security
- Use of Confluence and Jira
- Working with databases, J2EE, JavaServer Faces, Liquibase, Apache, Maven, Mercurial, Oracle Financials
- Documentation and creation of security policies
- Management of software systems, SharePoint, PrimeFaces, Git
- Compliance with security regulations and .NET, AWS, API
- Tools: MobSF, Frida, Android Studio, Drozer, Objection, Azure
Klaus Kilvinger
Last position:
Consultant and Trainer, Managing Partner at Opexa Advisory GmbH
- Advising clients on ISO/IEC 27001, TISAX, BSI IT-Grundschutz and GDPR
- Trainer and internal auditor
- Contract management (service and work contracts, framework agreements)
- Coordinating and supporting tender responses
- Developing strategies and measures for clients and new business opportunities (e.g. phishing, online awareness trainings)
- Further developing the governance/risk/compliance offering
- Account management for existing clients and new business acquisition
- Supporting HR with hiring and interviews
Discover over 15,000 top freelancers
Statistics of experts using ISO 27001
Aggregated from the professional profiles of matched freelancers.
Experience
23 years (Germany: 22 years)
Position duration
2 years (Germany: 2.6 years)
Positions per freelancer
16 (Germany: 13)
Top business areas
Information Technology, Project Management, Quality Assurance
Top industries
Information Technology, Professional Services, Banking and Finance
Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
80% (Germany: 88%)
Master's degree or higher
47% (Germany: 54%)
Certifications per freelancer
6
Most common languages
German, English, French
Speak two or more languages
95% (Germany: 97%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using ISO 27001
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Designing a Resilient Information Security Management System
The ISO/IEC 27001 standard provides the global framework for establishing, implementing, maintaining, and continually improving an Information Security Management System. Organizations use this framework to systematically manage risk, protect intellectual property, and secure sensitive customer data. It shifts cybersecurity from a purely IT-centric issue to a broader corporate governance practice.
Key Components of the Compliance Ecosystem
A structured security framework involves coordinating multiple components to ensure alignment with international standards:
- Information Security Management System policies and procedures
- Risk assessment and risk treatment methodologies
- Statement of Applicability detailing selected controls
- Internal audit programs and continuous monitoring tools
- Annex A security controls spanning physical, digital, and organizational domains
Core Deliverables of Information Security Projects
A dedicated specialist handles the end-to-end path to certification. Key milestones include conducting comprehensive gap analyses, drafting necessary policies, training staff members on security awareness, and coordinating with external certification bodies. These activities ensure that security practices are integrated into daily business operations.
When Companies Seek External Certification Expertise
Organizations bring in specialized external professionals when facing upcoming client security audits, entering highly regulated markets, or preparing for formal certification. These situations require deep technical knowledge and objective assessment skills that internal teams often lack. An experienced specialist accelerates the preparation process and avoids costly compliance gaps.
Qualities of Leading Security Compliance Specialists
Outstanding professionals combine technical cybersecurity expertise with strong organizational and auditing skills. They understand how to translate complex compliance requirements into practical, day-to-day business processes. Strong communicators can bridge the gap between technical IT infrastructure teams and executive leadership.
Navigating Munich Compliance Requirements
In Munich, local enterprises must align their security frameworks with both European GDPR standards and specific German federal security regulations like the IT-Grundschutz. Local specialists understand the operational expectations of Bavarian technology hubs and can conduct necessary on-site physical security audits. Their bilingual capabilities ensure smooth communication with German regulatory authorities and international stakeholders.
Frequently asked questions
What clients ask us most about ISO 27001 — answered in short.
While ISO 27001 is a generic international standard for information security across all industries, TISAX is specifically tailored to the automotive supply chain. Many companies in the Munich automotive cluster require TISAX, which is actually based on the ISO standard but adds industry-specific requirements.
A standard ISO 27001 implementation usually takes between six to twelve months depending on the size and maturity of the organization. Engaging an experienced specialist helps streamline the process by utilizing pre-built templates and proven risk assessment methodologies.
Yes, hiring an external freelancer to serve as your interim or part-time ISO 27001 Information Security Officer is a common practice in the Bavarian region. This approach provides immediate access to senior expertise without the long-term overhead of a full-time hire.
The Statement of Applicability is a core document in the ISO 27001 framework that identifies which of the Annex A controls apply to your organization. It justifies the exclusion of any controls and explains how the selected ones are implemented.
While policy drafting and risk assessments can be done remotely, key phases of an ISO 27001 project benefit from on-site presence in Munich. Local physical security audits, staff training sessions, and the final external audit coordination are highly effective when conducted in person.
For projects in Munich, a professional working with ISO 27001 typically needs to be bilingual in German and English. This ensures they can draft policies in the corporate language while effectively communicating with local German auditors and regulatory bodies.
The specialist will conduct a thorough pre-audit gap analysis to ensure all ISO 27001 mandatory clauses and controls are operational. They will also coach your team on how to answer auditor questions and present the required evidence systematically.
Achieving ISO 27001 certification provides a robust technical and organizational foundation that covers many of the data security requirements of the GDPR. While the certification itself does not guarantee full legal compliance, it serves as strong proof to European authorities that customer data is handled securely.
The average hourly rate of freelancers in Munich, Germany who have used ISO 27001 in their recent projects is 117 €, which corresponds to a daily rate of about 936 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used ISO 27001 in their recent projects, 80% hold at least a Bachelor's degree and 47% hold at least a Master's degree.
On average, freelancers in Munich, Germany who have used ISO 27001 in their recent projects have 23 years of professional experience, with a single engagement typically lasting around 2 years.
The most common languages among freelancers in Munich, Germany who have used ISO 27001 in their recent projects are German (100%), English (90%), and French (24%).
The most common industries among freelancers in Munich, Germany who have used ISO 27001 in their recent projects are Information Technology (100%), Professional Services (71%), and Banking and Finance (67%).
The most common business areas among freelancers in Munich, Germany who have used ISO 27001 in their recent projects are Information Technology (100%), Project Management (95%), and Quality Assurance (76%).
Main locations of FRATCH Experts, who have recently used ISO 27001
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Cologne
Frankfurt
Stuttgart
Dusseldorf
Dortmund
Essen