ISO 27001 Experts in Switzerland
matched in minutes from over 15,000 CVs with the power of AIHire experts who shape ISO/IEC 27001 programs, ISMS documentation, risk treatment plans, internal audits, and supplier controls. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Switzerland, who have recently used ISO 27001
Klaus Schmitt
Last position:
Senior Financial Consultant and Project Manager at Start Up
- Establishment of a licensing model
- Preparation of investor documents (business plan, cash flow forecast, ROI, etc.)
- Marketing simulation of market development, market potential assessment, etc.
- Definition and implementation of KPIs to measure market entry
- Setting up project planning, project controlling, and business processes
Wolf Preuster-Drews
Last position:
Interim Head of IT POS (GK & SAP) at Depot GDC
- Interim head of IT POS on GK and SAP basis for DEPOT GDC.
- Responsible for the stability and further development of the POS base platform.
- Managing adjustments and rollouts in the POS environment in coordination with the SAP backend.
Jakob Faktorovitch
Last position:
Core Team Member at Jafa Consulting
- SME for operational processes, contract negotiation and product design for the implementation of a SaaS contact center solution & carrier services
- Definition of several operational processes, organizational setup, ITSM application integrations, creation of contract schedules and advising contract negotiation
- Scrum Master with agile tooling (processes & automation)
- Commercial manager to create business cases and closing the sales process
- Increasing impact, trusted relationship, and key team member within a short time
Ralf Ramge
Last position:
Security Architect at Federal Employment Agency
Responsibility for the design, migration, and integration of a security- and audit-critical HashiCorp Vault platform in the trust center of a nationwide authority with system-critical importance.
Analysis and realignment of the existing HashiCorp Vault landscape, including production and planned use cases
Design, proof-of-concept, migration, and integration of HashiCorp Vault Enterprise, taking into account the authority's PKI and operational processes
Design and implementation of an automated certificate and secrets management system for 300 Kubernetes clusters and several thousand certificates in the trust center
Securing the Vault platform using hardware security modules (HSM)
The solution enables a highly available, audit-compliant, and automated operation of certificate and secrets use cases in a highly regulated environment.
Technologies used: HashiCorp Vault Enterprise, Terraform, Ansible, OpenSSL, PKI, HSM
Tomas Hundegger
Last position:
Senior Advisor at Private Equity company
- Support the client in the business integration: technical project management of design & roll out of Corporate Governance & Sox framework / controls for purchase to pay, record to report, procure to pay, order to cash and hire to retire with focus integration of approx. 30 lines of businesses on Business & IT level
- Setup of an Audit & Assurance function & support Finance & HR department with business integration
- Designing and prepare roll-out for: IT Access Management, SoD, ITAC and ITGC
- Establish a Risk Framework (ERM) / Process, introduce risk assessments across the Business, IT and Management
- Establish Compliance function with design and rollout of Whistleblower, ABC, CoC, Fraud and Risk Management framework, ESG, ABC, AML, Sanction
Károly Aczél
Last position:
NIS2 & Risk Strategy Consultant at RRC power solutions GmbH
- Developed a compliant information security management system (ISMS)
- Advanced a modern risk management framework based on NIST for NIS2 compliance
Dieudonné Mbarga
Last position:
External Auditor at SGS Switzerland
- QMS setup according to international standards
- ISO 9001 and ISO 13485 certification audits
- Environmental management audits according to ISO 14001 (training and application)
- Conducting audits in the DACH region (remote and on-site)
- Remote and on-site audit experience (EU, DACH, APAC)
Stefan Berreth
Last position:
Co-Founder at Stealth AI Infrastructure Deep-Tech Venture
- Deep-tech venture in enterprise AI model compression for on-premises and edge deployment.
- Built systematic R&D pipeline, business and technical architecture, early investor pipeline, and design partner network across AI verticals, datacentre operators, and robotics/edge computing — from zero.
- Ventures built concurrently, each in a fundamentally different regulatory and technical domain.
Michael Speller
Last position:
Freelance compliance & IT regulatory consultant at Various financial institutions and regulated companies
- Consulting financial institutions on implementing DORA and NIS2 requirements
- Gap analyses between existing governance structures and new regulatory requirements
- Creation and revision of policies, process descriptions, contract annexes, and technical-organizational measures
- Design of digital operational resilience testing programs (DORA Art. 24–25)
- Third-party risk management: building third-party registers, LEI matching, value chain analysis
- Training internal staff on DORA/NIS2 requirements
- Negotiation and renegotiation of outsourcing contracts according to DORA/NIS2 guidelines
- Use of technologies/frameworks: DORA, NIS2, EBA guidelines, BaFin requirements, NIST CSF, ISO 27001
- Engagements are subject to strict NDAs
Elias Vasiliadi
Last position:
Cloud Architect & Security Advisor at BaFin
- Designing hybrid cloud architectures (on-prem + cloud)
- Implementing cloud governance structures according to NIS2, BSI, ESCB/SMM
- Developing policies for cloud security & access control
- Target designs, management decision frameworks, internal audits & cloud integration
Stefan Laager
Last position:
Senior Manager, Project Manager, Auditor and Consultant at Laager Consulting GmbH
Many years of experience in application development, ICT infrastructures, systems management, hardware and software, telecommunications, ICT strategies, business models, database management, data center consolidations, support and call center setup
Since 1999 independent consultant and project manager: ICT strategies and governance, processes, audits, security, infrastructure (including cloud, DevOps and tools), data and output management, organizational restructurings, business project management and consulting in various industries
Generalist with analytical skills, strong communicator at all hierarchy levels, deployable as manager, coach, project manager or consultant
Yuri Gladkov
Last position:
Senior Security Devops Engineer at Swisscom
- Implementation and maintenance of highly critical IAM solutions for B2B clients (SSO, MFA, SAML/OIDC, Entra ID, PIM/PAM)
- Security administration of Linux systems (CentOS, Red Hat) in Docker and Kubernetes environments
- Migration from Docker Swarm to Kubernetes
- Infrastructure automation with Terraform
- Planning and execution of risk assessments, threat modeling, and compliance reports
- Development and management of B2B applications (Java, REST/SOAP, Angular) and CI/CD pipelines (Python, Ansible, Jenkins, GitLab)
- Leading integration tests and UAT (Cucumber, Selenium, Katalon)
- Implementing monitoring and observability strategies with Grafana, Prometheus, and Splunk
- Integrating SAST tools like Snyk and SonarQube
- Release management and project coordination according to Scrum and SAFe
- Mentoring and technical support of junior team members
Hugo Plüss
Last position:
Supervisory Board Member at 4PL Central Station EE
- Provide independent oversight and advice to the executive board on corporate strategy
- Advise on the effectiveness of digital transformation initiatives, financial performance, and the management of business and enterprise risks
Thorsten Morschheuser
Last position:
Managing Director at Morschheuser Consulting GmbH
- Establishment, development and auditing of ISMS and IAM/IDM structures (SAP & non-SAP).
- Development, optimization and review of authorization concepts, role models and interfaces (including SAP IDM/NetWeaver/S/4HANA, as well as cloud & AD).
- Management and documentation of audit, compliance and certification projects (ISO 27001, TISAX, KRITIS).
Antonis Velalopoulos
Last position:
Security and Audit Consultant at Contractor
Consulting on Cyber Security, Governance, Risk Management, audits, Cloud Security, and compliance in regulated environments.
Discover over 15,000 top freelancers
Statistics of experts using ISO 27001
Aggregated from the professional profiles of matched freelancers.
Experience
23 years
Position duration
3.9 years
Positions per freelancer
10
Top business areas
Information Technology, Project Management, Audit
Top industries
Professional Services, Information Technology, Banking and Finance
Certification focus areas
Information Technology, Quality Assurance, Audit
Bachelor's degree or higher
81%
Master's degree or higher
63%
Doctorate
13%
Certifications per freelancer
4
Most common languages
German, English, French
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Switzerland are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Switzerland using ISO 27001
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
ISO 27001 work
ISO 27001 sets the standard for an information security management system, or ISMS. It helps companies define controls, manage risk, and prove that security is handled in a structured way. Strong specialists turn the standard into clear policies, practical evidence, and audit-ready processes.
What they deliver
- ISMS scope and policy documents
- Risk assessments and treatment plans
- Statement of Applicability support
- Internal audit preparation and follow-up
- Supplier and control reviews
Tooling and methods
ISO/IEC 27001 work often sits beside GRC tools, ticketing systems, document control, and audit evidence trackers. Skilled professionals know how to map controls to business processes and keep records consistent across teams. They also understand how to work with security, legal, IT, and operations without slowing delivery.
When companies bring them in
Companies usually seek outside help when they need certification support, a fresh gap assessment, or help after an audit finding. In Switzerland, this often matters for firms that handle sensitive customer data, work across regulated sectors, or serve international clients that expect formal security assurance. Freelance specialists are useful when the internal team needs focused short-term expertise.
What strong specialists look like
Good ISO 27001 professionals write in plain language and know how to make controls usable. They can translate the standard into tasks that teams will actually follow, not just documents that sit on a shelf. Look for people who can balance compliance, business risk, and day-to-day practicality.
Common delivery topics
ISO 27001 projects often cover policy sets, risk registers, access control reviews, incident handling, supplier due diligence, and audit remediation. Some experts also support ISO/IEC 27001 integration with ISO 27701, SOC 2, or broader privacy and security programs. The best work is specific, documented, and easy to maintain after handover.
Frequently asked questions
Curious about ISO 27001? Here are the answers that come up again and again.
ISO 27001 is used to build and run an information security management system, or ISMS. It helps companies define risk-based controls, assign responsibilities, and keep evidence for internal and external audits. Many organizations also use it to show customers that security is managed in a structured way.
ISO 27001 is a certifiable management standard, while SOC 2 is an assurance report and NIST is a broader framework family. Companies often choose ISO 27001 when they want a formal ISMS and an internationally recognized certification path. A strong specialist can also explain how it lines up with SOC 2 or NIST without forcing the same process on all three.
A good ISO/IEC 27001 freelancer usually brings risk management, audit preparation, policy writing, and supplier security review skills. Useful adjacent knowledge also includes privacy work, incident handling, business continuity, and basic technical security controls. The best professionals can work with both compliance teams and technical teams.
A small gap assessment may only need one experienced ISO 27001 specialist, but a certification program usually needs someone who has handled scope, controls, evidence, and audit questions before. The more complex the environment, the more valuable it is to have prior work with multi-team implementation. Look for real delivery history, not just familiarity with the standard.
Yes, most ISO 27001 work can be done remotely because much of it involves interviews, document review, workshops, and evidence collection. On-site time can still help for process walkthroughs, leadership sessions, or internal audit support. For Switzerland-based teams, English is common, but local language skills can help in larger cross-functional programs.
Ask the ISO 27001 specialist which parts of the ISMS they have led, what audit outcomes they have supported, and how they handle risk and evidence. You should also check how they work with security, IT, legal, and management. Clear answers usually show whether they can deliver practical progress or only draft documents.
Strong ISO/IEC 27001 deliverables are specific, consistent, and easy to maintain. Policies should match real processes, the Statement of Applicability should reflect actual controls, and risk treatment plans should be linked to business decisions. If the documents feel generic or disconnected from operations, the work is probably weak.
A ISO 27001 freelancer will usually ask how mature the ISMS already is, whether the goal is certification or remediation, and who owns decisions. They also need to know what evidence exists, which teams are involved, and how much access they will have. That context helps them plan the work and avoid slow back-and-forth.
The average hourly rate of freelancers in Switzerland who have used ISO 27001 in their recent projects is 133 €, which corresponds to a daily rate of about 1,060 € based on an 8-hour working day.
Of the freelancers in Switzerland who have used ISO 27001 in their recent projects, 81% hold at least a Bachelor's degree, 63% hold at least a Master's degree, and 13% hold a doctorate.
On average, freelancers in Switzerland who have used ISO 27001 in their recent projects have 23 years of professional experience, with a single engagement typically lasting around 3.9 years.
The most common languages among freelancers in Switzerland who have used ISO 27001 in their recent projects are German (100%), English (100%), and French (56%).
The most common industries among freelancers in Switzerland who have used ISO 27001 in their recent projects are Professional Services (83%), Information Technology (78%), and Banking and Finance (61%).
The most common business areas among freelancers in Switzerland who have used ISO 27001 in their recent projects are Information Technology (94%), Project Management (83%), and Audit (67%).
Main locations of FRATCH Experts, who have recently used ISO 27001
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Zurich