Profilbild von Anonymes Profil, IT Consulting CISO ISO 27001 Lead Auditor TISAX IEC 62443 KRITIS B3S NIS2
verfügbar

Letztes Update: 26.01.2024

IT Consulting CISO ISO 27001 Lead Auditor TISAX IEC 62443 KRITIS B3S NIS2

Abschluss: Bachelor of Science - Computer Science IT-Security
Stunden-/Tagessatz: anzeigen
Sprachkenntnisse: deutsch (Muttersprache) | englisch (verhandlungssicher) | französisch (Grundkenntnisse) | russisch (Muttersprache)

Skills

  1. ISMS ISO 27001 Lead Auditor
  2. TISAX, NIS2, BSI IT-Grundschutz, DORA, BAIT, BSIG KRITIS
  3. CISO & ISB
  4. Application Security OWASP
  5. Secure Development Lifecycle (SDL)
  6. Cloud Security
  7. DevSecOps
  8. Secure CI/CD Pipeline
  9. Vulnerability and Patch Management
  10. Bug Bounty Program
  11. Data Loss Prevention
  12. Informationssicherheit
  13. Sicherheitsmanagement
  14. Schwachstellenbewertung
  15. Zugriffssteuerung
  16. Sicherheitsmaßnahmen
  17. Unternehmenssicherheit
  18. Enterprise Risk Management
  19. Incident Management
  20. Penetration Testing
  21. Betriebliches Kontinuitätsmanagement
  22. Informationssicherheitsmanagement
  23. Cloud-Computing
Tools & Technologien
  1. Microsoft Azure
  2. Amazon Web Services (AWS)
  3. Android
  4. iOS
Soziale Kompetenz
  1. Team Lead
Weitere Kenntnisse 
  1. Incident Response
  2. Sicherheitsberatung
  3. Information Security Management System (ISMS)
  4. Business Impact Analysis
  5. Application Security
  6. Cloud Security
  7. ISMS Lead Auditor nach ISO 27001
  8. BSI IT-Grundschutz
  9. TISAX
  10. Threat Modeling
  11. Business Continuity Management
  12. Compliance
  13. Security Development Lifecycle
  14. ISO 27034
  15. TISAX
  16. Forensic
  17. KRITIS
  18. Security Code Review
  19. Container Security
  20. Kubernetes
  21. Mobile Security
  22. ISO 22301
  23. Identity and Access Management (IAM)
  24. Risk Analysis
  25. DevSecOps
  26. Awareness
  27. Security Information and Event Management (SIEM)
  28. Code-Review
  29. Google Cloud

Projekthistorie

Zertifikate

Zusätzliche Prüfverfahrens-Kompetenz für § 8a (3) BSIG
ISACA
2022
Betrieblicher Datenschutzbeauftragter (IHK)
IHK
2021
ISO 27001 Lead Auditor
TÜV Rheinland
2019

Reisebereitschaft

Weltweit verfügbar

Sonstige Angaben

- Senior Manager - Information Security Consulting - CISO - ISO 27001 Lead Auditor - B3S Auditor - BSI IT-Grundschutz - KHZG Establishing information security is like conducting an orchestra.

Book Author – Cloud Security in AWS & Azure

Talks about #kritis, #security, #ransomware, #cyberattack, and #cybersecurity

Top Information Security Skills
Application &
Infrastructure Security
Patch & Vulnerability Management • Penetration Testing • OWASP M/ASVS & MSTG • Security Development Lifecycle • Threat Modeling • Threat Analysis • DevSecOps • DAST • Keys & Secrets Management • Static Source Code Analysis • CWE • Dependency-Checks • Container-Scanning • Bug Bounty Program • SIEM • Security Monitoring • CIS-Benchmarks & Compliance • ISO 27034 • Container • Kubernetes • OpenShift • Secure CI/CD Pipeline • Mobile Security • IoT Security • Web Application & API • Secure Architecture • Deployment Hardening • Logging, Monitoring & Alerting • SIEM & SOAR • SOC – Security Operation Center as a Service • EDR • NDR • oAuth2 • Zero Trust • Endpoint Security • Mobile Device Management • WAF
Information Security Management & Data Privacy
Interim CISO & DPO • ISO 27001 Lead Auditor • BSI IT-Grundschutz • BAIT • SO2 • TISAX • KRITIS • B3S • GDPR • DSGVO • HIPAA • Governance • Program & Project Management • Strategy • Concept • Business Impact Analysis • ISMS Audit & Gap Analysis • Certification • Data Classification – Risks, Requirements and Controls • Data Loss Prevention (DLP) • Asset Management • Risk Assessment • KPIs • IAM • Monitoring • Compliance • Intern Reviews • Operation • Incident Response • Security Awareness • Phishing Campaign • Business Continuity Management System • Disaster Recovery Process • Supplier Relationship Security: Information Security Requirements for Suppliers, Hosting, Software and Hardware as well as for Outsourcing Software Development
Risk Management & Threat Modeling
Risk Analysis • Risk Assessment • Risk Threatment Plan • ISO 27005 • IEC 80001 • Business Impact Analysis • Threat Modeling • STRIDE
Cloud Security
Migration Projects • Posture Management • Identity Protection • Zero Trust • Single-Sign-on • SIEM • Security Audit • Multi-Factor-Authentication • AWS • Azure • Office365 • Licensing • Amazon AWS • IAM • Hardening • Alerting & Reporting • Security & Licensing • CIS Benchmarks • Cloud Conformity
Incident Response & Forensics
Forensics • Crisis Communication • Threat Hunting • IT Fraud • SOC & Threat Intelligence • CEO Fraud • Ransomware • Cryptojacking • Phishing • Log Analysis • Memory Analysis • File System Analysis • SIEM & SOAR • SOC – Security Operation Center as a Service • EDR • NDR • Cloud Forensics • Azure • Office365 • Short-term Security Measures • Long-term Risk Mitigations • Crisis Exercise
Profilbild von Anonymes Profil, IT Consulting CISO ISO 27001 Lead Auditor TISAX IEC 62443 KRITIS B3S NIS2 IT Consulting CISO ISO 27001 Lead Auditor TISAX IEC 62443 KRITIS B3S NIS2
Registrieren