15.07.2026 aktualisiert


100 % verfügbar
Beraterin & Auditorin für Informationssicherheit, ISO 27001, KRITIS, Cyber Resilience Act
VS-Villingen, Deutschland
Weltweit
Bachelor of Science Wirtschaftsinformatik + MBASkills
Microsoft AzureInformationssicherheitDevOpsGitHubISO / IEC 27001Open SourceScrumSicherheitsanforderungenInformationssicherheits-ManagementsystemISO / IECDevSecOps
Beraterin & Umsetzerin für Informationssicherheit & DevSecOps
Ich unterstütze Unternehmen beim Aufbau und der praktischen Umsetzung eines Informationssicherheitsmanagementsystems (ISMS) sowie bei der sicheren und nachhaltigen Entwicklung von Softwarelösungen. Mit meinem Hintergrund als Product Owner und IT-Security Consultant kombiniere ich methodisches Know-how mit technischer Umsetzungskompetenz – insbesondere in sicherheitsrelevanten Projekten im Cloud- und Softwareumfeld (Azure, DevSecOps, Software Supply Chain Security).
Ich berate praxisnah, strukturiert und zielorientiert – mit dem Ziel, Informationssicherheit als Teil der Produktentwicklung und Unternehmensprozesse zu etablieren.
- Schwerpunkte & Leistungen: ISMS-Aufbau & Sicherheitsprozesse
- Einführung und Weiterentwicklung von ISMS nach ISO/IEC 27001 oder BSI IT-Grundschutz – von der Gap-Analyse über Policies und Risikoanalysen bis hin zur operativen Umsetzung in Projekten.
- Security by Design & Produkt-Security
- Integration von Sicherheitsanforderungen in den Entwicklungsprozess, z. B. durch Secure Development Lifecycles (SDLC), Security-Gates und Threat Modeling.
- DevSecOps & Software Supply Chain Security
- Implementierung sicherer CI/CD-Prozesse, Nutzung von SCA- und SAST-Tools, Aufbau von SBOM-Prozessen (CycloneDX, SPDX) und Begleitung von Open Source Compliance nach ISO/IEC 5230.
- Product Ownership & Umsetzungskompetenz
- Ich übernehme Verantwortung als Product Owner oder Projektleiterin für sicherheitsrelevante Themen – von der initialen Anforderungsklärung über Architekturentscheidungen bis zur Einführung in Betrieb & Organisation.
- Agile Entwicklung & Security-Verankerung
- Einführung agiler Methoden mit Fokus auf Sicherheit und Qualität: z. B. Security Backlog Refinement, Definition of Done mit Security-Kriterien, Security-Champions-Modelle.
- Technisches Know-how:Cloud & Infrastruktur: Microsoft Azure, Azure DevOps
- Security Tools: ScanCode, Syft, FOSSA, Mend, OWASP Dependency-Check
- Prozesse & Integration: GitHub Actions, REST-APIs, PostgresQL, Python, SQL
- Standards & Frameworks: ISO/IEC 27001, BSI IT-Grundschutz, OpenChain ISO/IEC 5230, CRA
Zertifizierungen:
- Zusätzliche Prüfverfahrenskompetenz zur Durchführung der Nachweiserbringung i.S. § 39 BSIG (n.F.)
- Berufene ISO 27001 Auditorin für Zertifizierungsgesellschaften
- ISMS Auditor according to ISO/IEC 27001:2022
- ISMS Security Officer according to ISO/IEC 27001:2022
- IT-Grundschutz-Praktiker gemäß BSI IT-Grundschutz 200-x
- IREB® Certified Professional for Requirements Engineering Foundation Level
- Microsoft Certified: Azure AI Fundamentals
- Certified SAFe® 5 Scrum Master
- Certified ScrumMaster® (CSM®)
- Professional Scrum Product Owner™ II (PSPO II)
- Professional Scrum Master™ I (PSM I)
- Microsoft Certified: Azure Fundamentals
- Professional Scrum Product Owner™ I (PSPO I)
Sprachen
DeutschMutterspracheEnglischverhandlungssicherSpanischGrundkenntnisse
Projekthistorie
- DevSecOps Strategy & Implementation: Defined and implemented a DevSecOps framework aligning with security best practices.
- SCA Tool Selection & Integration: Evaluated and integrated Software Composition Analysis (SCA) tools for OSS license compliance and vulnerability management.
- Secure SDLC & Security-by-Design: Embedded security controls and risk-based security assessments into the Software Development Lifecycle (SDLC).
- Open Source Governance: Strengthened OSS license compliance and automated license management using Open Source tooling.
- SBOM Management & Security Enforcement: Established SBOM workflows to enhance software supply chain security and regulatory alignment.
- Security Automation & Shift-Left Approach: Integrated security controls into CI/CD pipelines for early risk detection and mitigation.
- Stakeholder Collaboration: Worked cross-functionally with Product Security, Engineering, and Compliance Teams to embed security into development lifecycles.
- SCA Tools: [e.g., Black Duck, Snyk, Mend, FOSSA, Dependency-Track]
- CI/CD Pipelines: GitHub Actions, GitLab CI, Jenkins
- SBOM Formats: SPDX, CycloneDX
- Cyber Resilience Act (CRA)
- ISO 5230 (OpenChain) – OSS License Compliance
- ISO/IEC 18974 – Secure Software Development
- Lecture about prototyping several software frameworks
- Hands-on class with many practical examples
- Product Owner for several security systems (e.g.vulnerability management system, PKI services)
- Identify SCA processes and potential vendors
- Develop a software to manage SBOMs
- Defining features and long-term vision for the products
- Creating user stories and wireframes
- Managing the product backlog
- Preparing all sprint events and conducting them
- Support security related activities in the area of PKI and certificate management
Zertifikate
Prüfverfahrenskompetenz § 39 BSIG (n.F.)
ISACA2026
ISMS Auditor according to ISO/IEC 27001:2022
ICO2025
IT-Grundschutz-Praktker gemäß BSI IT-Grundschutz 200-x
ICO-Cert2024