TISAX Experts in Munich
matched in minutes from over 15,000 CVs with the power of AIHire experts who handle TISAX assessments, gap analysis, and information security controls for automotive supply chains, engineering teams, and supplier onboarding. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Munich, who have recently used TISAX
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Martin Rusnak
Last position:
TECH DUE DILIGENCE FOR PE, VC & FAMILY OFFICES (UNDER NDA) – AI STRATEGY at PE, VC & family office portfolio companies (confidential, under NDA)
Two parallel workstreams: (1) Tech due diligence for acquisitions and portfolio companies. (2) AI strategy certification and AI governance consulting.
Tech assessments for PE/VC acquisitions: code reviews, architecture analysis, scalability evaluation
Tech assessment frameworks and integration roadmaps for portfolio companies
TÜV SÜD certification program: AI governance, EU AI regulation (EU AI Act)
Strategic AI roadmap development for mid-market companies
Delivered several tech DD reports for investment decisions
Developed integration roadmaps for portfolio companies
TÜV SÜD 'AI Strategy & Application Expert' (expected 04/2026)
Andreas Zimmermann
Last position:
ITSM Consultant at Industrial company / Global IT division
- Designed and implemented a new user support tower organization as part of the global IT transformation initiative.
- Created an operating and control model for the central service desk, including downstream support units (field service, VIP support, service points).
- Performed a comprehensive as-is analysis of existing service desk and field service structures and developed a target architecture based on ITIL 4 and SIAM.
- Defined roles, responsibilities, and governance mechanisms for internal IT and external providers.
- Prepared the blueprint document Service Management & Governance Handbook (User Support) to standardize global service processes (incident, request, problem, change, knowledge, ITSCM, CSI).
- Developed a KPI and SLA framework to measure service quality and performance in global user support.
- Defined the reporting and review structure (operations meeting, service review meeting, management steering board).
- Prepared RFP documents for the external tendering of L1/L2 support services, including definition of scope, governance model, process requirements, tool integration (ServiceNow), and KPI/SLA sets.
- Supported procurement and legal departments in evaluating and negotiating vendor proposals and assisted in vendor selection and contract finalization.
- Oversaw the handover to operational support, including knowledge transfer, training of provider teams, and establishment of a continuous improvement process (CSI).
- Methods / framework / tools: ITIL 4 / ITSM, SIAM, IT4IT, ServiceNow, Jira, BPMN, operating model canvas, KPI & SLA design, governance & performance management
Nicolas Neuwirth
Last position:
Senior Project Manager Digital at BKP GmbH / Mercedes-Benz Driving Events
Responsible for the strategic and operational management of digital platforms in the international environment of Mercedes-Benz Driving Events.
- End-to-end leadership of digital event and e-commerce platforms (webshop, microsites, event pages, on-event mobile apps)
- Interface management between marketing, IT, event management, and external tech partners
- Management of external service providers and development resources
- Introduction and implementation of IT security guidelines
- Successful support and execution of the data protection TISAX assessment
- Budget, timeline, and quality responsibility
Joerg Reger
Last position:
Chief Information Officer at CQLT SaarGummi Group
Chief Information Officer with more than two decades of international leadership experience in publicly traded and regulated industrial environments.
Responsible for the structural realignment of complex, long-standing IT organizations to bring transparency, control, and financial stability.
Leading global IT organizations with budgets up to €120 million and up to 320 employees.
Developing and rolling out centrally managed operating models, setting up transparent financial and governance structures, and consistently delivering business-critical platform initiatives (e.g., SAP S/4HANA).
Focused on restoring decision-making, prioritization, and execution power during transformation phases under increased organizational pressure.
Leveraging technology as a strategic tool to increase efficiency, stabilize operations, and support sustainable business development.
Global IT Transformation & Operating Models
SAP S/4HANA & Platform Harmonization
Digital Manufacturing & Industry 4.0
Governance, Compliance & Cyber Resilience
International Organizational Leadership
Sourcing & Location Strategies
Overall responsibility for strategy, governance, budget, and operations of the global IT function with an annual budget of approximately €45 million and an international team of about 95 employees across all locations.
Direct reporting line to the executive management and close strategic coordination with the CFO and COO.
Realigned a historically decentralized IT landscape of 28 legally independent entities and separate budget and control logics into a centrally managed, internationally standardized operating model.
Introduced transparent governance, reporting, and financial structures with clear separation and active management of CapEx and OpEx budgets at the corporate level.
Established group-wide IT financial and performance management with clear investment prioritization, transparent CapEx/OpEx structure, and active portfolio governance to sustainably enhance decision-making at the executive level.
By consistently centralizing, standardizing, and harmonizing platforms (including global rollout of SAP S/4HANA), structural complexity was significantly reduced.
IT cost base was sustainably cut by about 15% while significantly improving performance and service levels and increasing transparency and control for executive management and leadership.
At the same time, strategically expanded the production IT architecture in the context of Industry 4.0 by integrating MES and IoT systems in OEM-related, safety-critical production environments and building audit-ready governance and security structures while meeting regulatory requirements (e.g., automotive standards, TISAX-like frameworks, global compliance rules).
Maintained strict focus on strategically relevant initiatives by clearing parallel projects, reducing redundant structures, and establishing clear responsibilities to noticeably increase speed, commitment, and execution power in the organization.
High international presence with operational responsibility at production sites and an active role as a strategic sparring partner to the executive management.
Klaus Kilvinger
Last position:
Consultant and Trainer, Managing Partner at Opexa Advisory GmbH
- Advising clients on ISO/IEC 27001, TISAX, BSI IT-Grundschutz and GDPR
- Trainer and internal auditor
- Contract management (service and work contracts, framework agreements)
- Coordinating and supporting tender responses
- Developing strategies and measures for clients and new business opportunities (e.g. phishing, online awareness trainings)
- Further developing the governance/risk/compliance offering
- Account management for existing clients and new business acquisition
- Supporting HR with hiring and interviews
Roland Selmeier
Last position:
mediagear GmbH
- Implementation and support of digital transmission of laboratory report data to various practice software systems according to KVB standards
- Ensuring audit-proof archiving of all laboratory reports
- Developing and implementing sustainable optimization measures to increase efficiency in laboratory operations
- Close collaboration with software providers, practice teams, and the Bavarian Association of Statutory Health Insurance Physicians
- Applying agile methods such as Scrum and tools like Jira, Confluence, and MS Office
- Utilizing AI-driven processes to develop innovative solutions
Hans-Peter Ramatschi
Last position:
Interim Director Project Management at Heater and air conditioning equipment manufacturer (non-automotive)
- Improved status and performance of the project management department
- Project management "Project Management Excellence"
- Operational coaching in crisis projects
- Root cause analysis
- Developing and implementing improvement measures
- Reporting to Head of R&D
Philipp Schmidt
Last position:
MS365 Consultant/Solution Architect at Self-employed
- Setup and configuration of an M365 tenant on a hybrid basis
- SSO integration of the existing app infrastructure like Metamost, Huhu, etc.
- License consulting, Entra ID initial configuration, MFA, Conditional Access, Privileged Identity Management
- Intune: initial configuration, Windows 11 Autopilot, iPhone AES
- Takeover of the tenant and preparation of a security audit
- Rollout of iPhones with AES (formerly DEP) as COPE (Corporate Owned, Business Enabled)
- Connecting external customers with enhanced security through Conditional Access
- Consulting on cloud-first strategy and migration to a cloud-only business
- Connecting various apps via SSO/SCIM (e.g. Atlassian, Personio, Adobe)
- On-premises AD: security audit and project management for replacing the local AD (migration of file servers, Navision2016, user clients joined to Entra ID)
- Copilot rollout with connection to external data sources and configuration via Intune
- Support for TISAX and ISO27001 preparation
- Setup and hardening of Entra ID, switching MFA to phishing resistant via Conditional Access
- Intune management for Windows and Apple clients, web enrollment switch to AES, introduction of Autopilot, app management, integration of Microsoft Defender
- Building a device baseline for Windows (COBO) and iOS/Android (BYOD)
- Teams/SharePoint Online: access concepts and integration into Teams
- Maintenance and backup of Entra ID and Intune tenants (drift management)
- M365 backup with Veeam
- Extending Conditional Access policies, introduction of Privileged Identity Management with hardware tokens and an on-premises admin tier concept
- Revision of existing GPOs regarding structure, security, and compliance
- Security audit and hardening of on-premises Active Directory and cloud tenant, SAML VPN, PIM introduction
- Support for the HR department in introducing a booking portal and general system engineering administration & security
- Introduction of Conditional Access and passwordless MFA, platform SSO, Defender for macOS/iOS, macOS compliance with Intune, Code2 signature configuration
Discover over 15,000 top freelancers
Statistics of experts using TISAX
Aggregated from the professional profiles of matched freelancers.
Experience
28 years (Germany: 23 years)
Position duration
1.8 years (Germany: 3.1 years)
Positions per freelancer
16 (Germany: 12)
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Banking and Finance, Manufacturing
Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
63% (Germany: 85%)
Master's degree or higher
25% (Germany: 41%)
Certifications per freelancer
5 (Germany: 7)
Most common languages
German, English, Spanish
Speak two or more languages
78% (Germany: 95%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using TISAX
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What TISAX is
TISAX stands for Trusted Information Security Assessment Exchange. It is the assessment framework many companies in the automotive ecosystem use to prove that their information security controls meet a shared expectation. Strong experts help you prepare evidence, close gaps, and keep assessment scope clear.
Where it is used
TISAX matters for companies that handle sensitive customer data, prototypes, drawings, or production-related information. In Munich, it often comes up in automotive supply chains, mobility firms, software teams, and engineering organizations that work with OEM requirements.
Typical tasks
- Run a readiness review against TISAX requirements
- Map processes, assets, and locations into the right scope
- Prepare policies, evidence, and control descriptions
- Support remediation before the assessment
- Coordinate questions from internal teams and assessors
Skills that matter
Strong TISAX professionals know information security, risk handling, documentation, and stakeholder coordination. They also understand how to translate controls into practical work for IT, operations, and suppliers. Experience with ISO 27001 is often useful because the two topics overlap in daily work.
When freelance help fits
Companies bring in freelance experts when they need focused support for an upcoming assessment, a new supplier requirement, or a difficult scope decision. External specialists are also useful when internal teams know security basics but need help turning them into audit-ready proof and clean documentation.
What good experts deliver
A strong TISAX expert does more than fill out forms. They identify weak points early, align business and security teams, and leave behind documentation that can be reused for future assessments. For Munich teams, remote work is often enough for document reviews and prep, while on-site sessions help with workshops and evidence collection.
Frequently asked questions
Quick answers to the questions that come up most around TISAX.
TISAX is used to show that a company can handle sensitive automotive information in a controlled way. It is common when suppliers, engineering teams, or service providers need to prove security readiness to customers in the automotive sector. In practice, it shapes scoping, policies, evidence, and assessment preparation.
TISAX is an assessment exchange used a lot in the automotive world, while ISO 27001 is a broader information security standard. Many companies work with both because there is overlap in controls and documentation, but TISAX focuses more on customer expectations and assessment scope. A good specialist knows where the frameworks align and where they do not.
You want a TISAX specialist who understands information security controls, evidence collection, and stakeholder coordination. Experience with supplier onboarding, risk reviews, and audit preparation helps a lot. If your environment is complex, look for someone who can work across IT, operations, and business teams.
A strong TISAX professional often brings ISO 27001 knowledge, risk management, and documentation discipline. Familiarity with access control, asset handling, incident response, and third-party management is also useful. For technical environments, experience with security tooling and evidence collection makes the work smoother.
A TISAX project usually needs someone who has already supported preparation, not just read the requirements. The right expert should be able to spot scope issues, explain gaps clearly, and guide teams through remediation without creating extra noise. For a simple gap review, a focused specialist may be enough; for a full assessment cycle, deeper experience helps.
Much of TISAX preparation can be done remotely because it relies on documents, interviews, and process reviews. On-site time helps when workshops need many stakeholders in one room or when the expert has to inspect physical controls and local evidence. For Munich-based teams, a hybrid setup is often practical.
Look for a TISAX expert who can explain the assessment in plain language and turn requirements into concrete actions. Good signs are clear scoping, structured evidence plans, and practical remediation advice. Ask for examples of assessment preparation, supplier coordination, and how they handled weak controls.
No, TISAX is most visible in automotive supply chains, but it can also matter for companies that process sensitive partner data or build services for that ecosystem. In Munich, that can include software, engineering, and service organizations working with automotive clients. If your customers ask for TISAX, you need someone who can prepare the path to compliance and assessment.
The average hourly rate of freelancers in Munich, Germany who have used TISAX in their recent projects is 130 €, which corresponds to a daily rate of about 1,038 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used TISAX in their recent projects, 63% hold at least a Bachelor's degree and 25% hold at least a Master's degree.
On average, freelancers in Munich, Germany who have used TISAX in their recent projects have 28 years of professional experience, with a single engagement typically lasting around 1.8 years.
The most common languages among freelancers in Munich, Germany who have used TISAX in their recent projects are German (100%), English (78%), and Spanish (22%).
The most common industries among freelancers in Munich, Germany who have used TISAX in their recent projects are Information Technology (89%), Banking and Finance (78%), and Manufacturing (78%).
The most common business areas among freelancers in Munich, Germany who have used TISAX in their recent projects are Information Technology (100%), Operations (89%), and Project Management (89%).
Main locations of FRATCH Experts, who have recently used TISAX
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin