04.03.2026 aktualisiert

**** ******** ****
verifiziert
Premiumkunde
100 % verfügbar

Senior Information Security & ISMS Consultant | ISO 27001, TISAX, BSI IT-Grundschutz

Berlin, Deutschland
Nur Remote
Fachhochschulreife
Berlin, Deutschland
Nur Remote
Fachhochschulreife

Profilanlagen

Lebenslauf 2026 .pdf
Consultant Profile Andreas Rühl english.pdf

Über mich

I help organizations build and run pragmatic ISMS/GRC programs: ISO 27001 implementations, risk management (ISO 27005/BSI 200-2/200-3), SoA, policies, audits and remediation. Strong in stakeholder alignment and operational rollout across groups/subsidiaries.

Skills

Dokumentation der ProzessePenetration TestingArchitekturAuditsDatensicherungBusiness Continuity And Disaster RecoveryUnternehmensberatungGeschäftskontinuitätBetriebliches KontinuitätsmanagementProzessoptimierungGood Manufacturing PracticesChange ManagementComplianceInformationssicherheitSicherheitskontrollenKontinuierliche QualitätsverbesserungDatensicherheitDokumentenmanagementEDMSNotfall-VerfahrenIncident ResponseMitarbeiterhandbuchSteuerungGovernance-Risikomanagement und ComplianceHost-basierte EinbruchserkennungssystemeHIPAAITILIdentitätsmanagementIncident-ManagementInformationssicherheitsmanagementInterim ManagementInterne DokumentationIntrusion Detection und PreventionVPNIsa99ISO / IEC 27001Iso 2700XNetzwerkarchitekturPci DSSProgramm-ManagementLebensberatungKontrollrahmenRisikoanalyseRisikoappetitRisikomanagement-InformationssystemeSecurity AdministratorSicherheitsanalyseSicherheitsbewusstseinSicherheitsrichtlinienServiceorientierte ArchitekturService ManagementSiemSox-ComplianceAusbildungsaktivitätenVulnerability ManagementTisaxDaten- / DatensatzprotokollierungProzessanalyseProzess ManagementSicherheitssystemeDatenschutzgesetzeDesign-DokumentationSicherheitsauditsInformationssicherheits-ManagementsystemVerwaltungstätigkeitenISO / IECWirkungsanalyseDatenschutzRisikoeinschätzungCyber Threat AnalysisFirewallsDocumentation SystemRisikoberatungSystemadministrationEntwicklung von KonzeptenSicherheitsberatungIt-sicherheitslösungenUnternehmensrichtlinienDSGVOKybernetikCyberkriegRisikomanagementCiscoKpi-Berichterstattung
Information Security / ISMS / GRC

End-to-end ISMS build & run (ISO/IEC 27001): scope, governance, policies, SoA, control implementation, internal audits, management review, continuous improvement (PDCA).
Risk management aligned to ISO/IEC 27005 and BSI 200-2/200-3: asset & process-based risk identification, qualitative/quantitative methods, treatment plans, risk acceptance, tracking and reporting.
Group-wide security operating models: CISO Office setup, local security roles (e.g., LISO), KPI/KRI reporting, security committees, cross-subsidiary rollout.


Compliance & Audits

Audit readiness and execution support for ISO 27001 certification audits (Stage 1/2), surveillance audits and internal audits.
Experience with TISAX and BSI IT-Grundschutz-oriented documentation and implementation approaches.
Regulatory alignment and documentation support (e.g., GDPR interfaces, sector requirements, supplier/customer security questionnaires).


Security Architecture & Controls

Control design and practical implementation guidance for identity & access management, logging/monitoring, vulnerability management, incident response, backup/BCP interfaces, and secure configuration baselines.
Vendor/tool evaluation and rollout support (requirements, selection, PoC, implementation, process integration).


Security Operations & Technical Expertise (selective, as needed)

Security assessments, hardening reviews, network/security architecture workshops.
Hands-on knowledge across common security technologies (SIEM, EDR, DLP, IDS/IPS, firewalls, VPN, encryption) and enterprise environments.


Program / Project Delivery & Enablement

Program management for complex security transformations (multi-stakeholder, multi-entity), roadmap creation, prioritization and execution governance.
Training/awareness, workshops for management and operational teams, documentation templates and playbooks.




Sprachen

DeutschMutterspracheEnglischverhandlungssicherSpanischGrundkenntnisse

Projekthistorie

Freelance Information Security & ISMS Consultant

A-R-C Andreas Rühl Consulting

Internet und Informationstechnologie

< 10 Mitarbeiter

Delivered end-to-end ISO/IEC 27001 ISMS build & run as a freelance consultant: ISMS scope & context, governance/operating model (CISO Office, local security roles), and audit-ready documentation set. Created and maintained policy framework (information security policy, risk management policy, asset management, incident management, access control, supplier security), Statement of Applicability (SoA) incl. control mapping and implementation guidance, and a structured evidence repository. Designed and executed risk management aligned to ISO/IEC 27005 and BSI 200-2/200-3: asset & business-process based risk assessments, risk register, treatment plans, acceptance workflow, KPI/KRI reporting. Built internal audit program (audit plan, checklists, reporting, CAPA tracking) and supported management reviews and continuous improvement (PDCA). Facilitated stakeholder workshops, awareness sessions and leadership enablement; supported third-party security questionnaires and supplier risk processes.

Interim CISO / ISMS Consultant (KRITIS / NIS2 / BSI IT-Grundschutz / ISO 27001)

Company in wastewater a. waste management (critical infrastructure)

Öffentlicher Dienst

500-1000 Mitarbeiter

Further development of the information security organization of a company in the wastewater and waste management sector (critical infrastructure-related) and structured implementation of an ISMS based on BSI IT-Grundschutz.

Focus on translating regulatory requirements (especially NIS2) into practical, auditable measures and establishing sustainable governance and GRC structures.

Close collaboration with business units and management to embed information security into organizational processes and operations.

Result: Significant improvement in audit and compliance readiness and structured preparation for regulatory requirements in a KRITIS/NIS2 context.

Reference available from Information Security Officer.

Principal Consultant (Information Security) | Deputy Business Unit Lead

Profi Engineering Systems AG Darmstadt

Internet und Informationstechnologie

500-1000 Mitarbeiter

Built and scaled the Information Security consulting practice (Security Solutions): portfolio development, delivery governance and strategic advisory. Despite holding a leadership role, I stayed actively involved in client work as senior consultant and engagement lead—conducting ISO/IEC 27001-oriented governance/ISMS advisory, risk assessments, policy/framework design and audit-readiness support, incl. workshops with business and IT stakeholders. Led and mentored teams, ensured delivery quality, and owned presales (solution design, proposals, estimations) with bid-to-delivery handover. Served as primary client interface and escalation point, coordinating stakeholders and delivering pragmatic roadmaps and audit-quality documentation.

Principal Information Security Consultant | Team Lead (Security Consulting)

Profi Engineering Systems AG Darmstadt

Internet und Informationstechnologie

500-1000 Mitarbeiter

Established and developed Information Security Consulting as a new practice area: defining service offerings, delivery standards and reusable templates. Led and mentored the consulting team (technical leadership, onboarding, quality assurance) and supported presales (requirements workshops, solution design, proposals and estimations). Despite the leadership role, I stayed actively involved in client delivery as senior consultant and engagement lead—conducting ISMS/GRC advisory (ISO/IEC 27001-oriented governance), risk assessments, security concepts and implementation roadmaps, and ensuring audit-quality documentation and stakeholder alignment across business and IT.

Information Security Lead (acting CISO function)

Klöckner und Co AG

Industrie und Maschinenbau

5000-10.000 Mitarbeiter

Information Security Lead for corporate group (acting CISO function). Built and operated the information security organization and ISMS foundations: governance and reporting, security policies/standards, risk and control oversight, stakeholder management across business and IT, and alignment of security initiatives with corporate objectives. Planned and led security audits and assessments, managed remediation (prioritization, tracking, follow-up) and drove continuous improvement. Owned third-party/vendor security activities and coordinated penetration tests and technical security reviews (scoping, vendor management, result validation, and closure of findings). Provided management-level reporting, security advisory to stakeholders and supported awareness/communication.

Senior Information Security Consultant | Auditor

Kai Viehmeier Consulting GmbH

Internet und Informationstechnologie

10-50 Mitarbeiter

Consultant and author for the VdS 3473 Cyber Security guideline for SMEs (KMU): translating requirements into practical controls, templates and implementation guidance. Supported clients in building and introducing ISMS foundations (governance, policies, risk assessment approach, control implementation and evidence). Planned and conducted information security audits/assessments, documented findings and managed remediation follow-up. Coordinated and performed penetration tests and technical security reviews (scope definition, execution, reporting and closure of findings), ensuring pragmatic, actionable results for SME environments.

Quality & Training Manager (IT Services)

Siemens Healthcare über ISK Personaldienstleistungs GmbH

Pharma und Medizintechnik

>10.000 Mitarbeiter

Managed service quality and training within an IT services environment. Led projects to introduce new services and operational processes, ensuring consistent delivery standards and measurable quality improvements. Established and maintained a service quality management approach aligned to ITIL practices and ISO-oriented requirements (ISO/IEC 27001 and ISO 9001), including process documentation, control/quality checks and continuous improvement activities. Coordinated training concepts and enablement for teams, supported audits/assessments preparation and ensured that process adherence and quality KPIs were tracked and reported to stakeholders.

Network & IT Security Consultant

Siemens HealthCare über Pamec Papp Ingenieurgesellschaft

Pharma und Medizintechnik

>10.000 Mitarbeiter

Provided network and IT security consulting in an enterprise environment. Designed, configured and troubleshot site-to-site VPN (IPsec) tunnels and secure connectivity between locations. Performed network configuration, incident troubleshooting and operational support. Administered firewall and perimeter security components, including rule management, change implementation and verification of secure communication paths. Collaborated with internal stakeholders to ensure stable, secure network operations and timely resolution of security/network issues.

IT Security Manager (Austria)

Sandoz-Novartis International GmbH über Pidas GmbH

Pharma und Medizintechnik

>10.000 Mitarbeiter

Provided IT security management for the Austria organization in a regulated enterprise environment. Acted as senior security advisor to management and delivered regular reporting to CIO/CISO stakeholders. Managed and coordinated security initiatives across IT infrastructure and operations, including vulnerability management (process, prioritization, tracking and remediation follow-up). Led security-related projects and improvements, aligning requirements, timelines and stakeholders. Coordinated penetration testing and security assessments (scoping, execution oversight, reporting and closure of findings) and supported risk-based decision making for remediation and continuous improvement.

Network Rollout & Integration Engineer (Project)

Cortal Consors über HWS-Projekt-Engineering

Banken und Finanzdienstleistungen

>10.000 Mitarbeiter

Provided in-house and remote support for hardware, software, peripherals and network incidents in an enterprise environment. Delivered coordinated hardware/software rollouts, including preparation, deployment and post-rollout stabilization. Supported network troubleshooting and ensured stable connectivity for end users and sites. Administered and supported Active Directory (user/computer management, access troubleshooting) and collaborated with internal teams to resolve operational issues efficiently.

Freelance Instructor (Construction & IT / Computer Skills)

Berufsförderungswerk Weißenburg

Öffentlicher Dienst

10-50 Mitarbeiter

Delivered vocational training as a freelance instructor in construction-related topics and IT/computer skills. Prepared training materials, ran classroom sessions and practical exercises, and supported learners with hands-on guidance and assessments. Focused on structured knowledge transfer, clear communication and measurable learning outcomes.

Network & Systems Engineer (Project)

Landesgewerbeanstalt (LGA) über Staff Placement

Öffentlicher Dienst

1000-5000 Mitarbeiter

Worked as a project-based Network & Systems Engineer providing 2nd level in-house, remote and telephone support for hardware, software, peripherals and network incidents. Troubleshot and resolved complex user and connectivity issues, ensuring stable operations and timely restoration of services. Onboarded and coached additional project team members and contributed to consistent support processes and knowledge transfer.

Lead PC Technician (Southern Germany) | Deputy Branch Manager

Arlt Computer GmbH Nürnberg

Internet und Informationstechnologie

250-500 Mitarbeiter

Led 1st and 2nd level support for hardware, software and network issues (on-site and remote) and advised customers on solutions and configurations. Performed installation, configuration and repair of various operating systems and end-user environments. Managed warranty/RMA processes with vendors/manufacturers and ensured timely resolution of customer cases. Supported day-to-day branch operations as deputy branch manager and contributed to consistent service quality.


Zertifikate

ISMS Officer – ISO 27001

VOREST AG

2021

VdS 3473 Auditor

VdS Schadenverhütung GmbH (VdS)

2015

VdS 3473 Consultant

VdS Schadenverhütung GmbH (VdS)

2015

ITIL® v3 Foundation (Foundation Examination)

EXIN

2012


Portfolio


Kontaktanfrage

Einloggen & anfragen.

Das Kontaktformular ist nur für eingeloggte Nutzer verfügbar.

RegistrierenAnmelden