29.11.2025 aktualisiert


100 % verfügbar
Berater Informationssicherheit und Datenschutz
Oberengstringen, Schweiz
Schweiz
Dipl. Oek.Skills
Agile MethodologieAuditsGeschäftskontinuitätInterne KontrollenUnternehmenstransformationComplianceInformationssicherheitGap-AnalyseSteuerungGovernance-Risikomanagement und ComplianceITILInformationssicherheitsmanagementIt OperationsISO / IEC 27001It Service Management
Ich bin diplomierter Oekonom mit über 26 Jahren Erfahrung in IT-Infrastruktur, Service-Management und Informationssicherheit.
Mein Schwerpunkt liegt auf dem Aufbau, der Weiterentwicklung und der Audit-Vorbereitung von Informationssicherheits-Managementsystemen (ISO 27001), Datenschutz-Compliance (DSG / DSGVO) sowie Business Continuity und Cyber Resilience.
Ich entwickle Strukturen, die Sicherheit, Verfügbarkeit, Nachvollziehbarkeit und Effizienz vereinen – pragmatisch, auditfest und nachhaltig.
Kompetenzschwerpunkte & Fachgebiete:
Aufbau, Zertifizierung und Optimierung von ISMS nach ISO 27001, inkl. Risikobewertung, SoA, interne Audits und Management-Reviews
Entwicklung und Einführung von BCM-Strukturen mit Business Impact Analysis (BIA), RTO/RPO-Definition und Testplänen
Umsetzung von Datenschutzanforderungen (DSG / DSGVO), inkl. Gap-Analysen, TOM-Bewertungen und DSFA-Begleitung
Etablierung von Cyber-Resilience- und Incident-Response-Prozessen, um Cyber-Risiken frühzeitig zu erkennen und zu behandeln
Integration von Governance-, Risk- & Compliance-Prozessen (GRC) in Unternehmenssteuerung und Auditfähigkeit
Gestaltung von IT-Service-Management-Prozessen nach ITIL v3 / 4 und Aufbau von Service-Katalogen, KPIs und Reportingstrukturen
Service Integration & Management (SIAM): Steuerung komplexer Provider-Landschaften, SLA-/ OLA-Definition und Eskalationsprozesse
Anwendung von HERMES und agilen Frameworks (SAFe, Scrum) zur strukturierten Umsetzung von Transformationsprojekten
Erfolge & Leistungsausweise:
Aufbau eines vollständigen ISMS nach ISO 27001 inkl. Risikomanagement und Auditstruktur innerhalb eines Jahres
Entwicklung eines organisationweiten Cyber-Resilience-Programms zur Stärkung der operativen Widerstandsfähigkeit
Einführung standardisierter ITSM-Prozesse nach ITIL 4 mit messbarer Steigerung von Effizienz und Servicequalität
Umsetzung von Business Impact Analysen (BIA) und Verankerung von BCM-Massnahmen in den Führungs- und Krisenstrukturen
Aufbau eines Provider-Governance-Modells inkl. SLA-Management, Risikoreporting und Kosten- / Leistungs-Transparenz
Durchführung von Schulungen, Awareness-Kampagnen und Workshops zur Verankerung von Informationssicherheit und Compliance-Kultur
Arbeitsweise & Stärken:
Analytisch | lösungsorientiert | kommunikativ | pragmatisch | audit- und revisionssicher | strategisch denkender Umsetzer
Zertifikate:
ITIL v3 Expert | ITIL 4 Managing Professional | Agile Methods (SAFe, Scrum) | SVEB/ADA FA-M1
Sprachen:
Deutsch | Englisch
Sprachen
DeutschMutterspracheEnglischverhandlungssicher
Projekthistorie
✅ TISAX Assessment Preparation and Implementation (AL2)
- Full responsibility for establishing and implementing an information security management system in accordance with TISAX requirements (Assessment Level 2)
- Initial requirements analysis, maturity assessment, and gap analysis
- Development and implementation of security policies, processes, and technical/organizational measures in line with VDA ISA requirements
- Planning and coordination of the entire project, including stakeholder management and resource planning
- Execution of awareness trainings and internal self-assessments
- Preparation for and support during the official TISAX assessment (AL2) until successful label issuance
- Implementation of continuous improvement measures to maintain TISAX AL2 compliance
✅ ISO 27001 Implementation (Greenfield Approach)
- Full responsibility for the implementation of an ISO 27001-compliant Information Security Management System (ISMS) from scratch
- Requirements gathering, comprehensive gap analysis, and risk assessment
- Development and implementation of all relevant policies, procedures, and technical/organizational controls
- Planning and management of the entire project, including resource allocation and scheduling
- Delivery of security awareness trainings and execution of internal audits
- Preparation for and support during the external certification audit (Stage 1 & Stage 2) leading to successful certification
- Establishment of processes for continuous improvement and long-term compliance
✅ Setup and Integration of a SIAM Operation Unit
- Full responsibility for designing, establishing, and integrating a Service Integration and Management (SIAM) operation unit
- Analysis of existing multi-vendor landscape and definition of SIAM governance model
- Development of processes, roles, and responsibilities for effective service integration and end-to-end accountability
- Design and implementation of performance monitoring, service reporting, and supplier management structures
- Coordination of transition activities and alignment with existing ITSM processes
- Training and onboarding of internal teams and external service providers
- Continuous improvement of collaboration models and operational efficiency within the SIAM framework