About Carsten
German
Native or bilingual
English
Fluent
Experience
- Veguardex GmbHSenior IT Security Architect & Senior IT Security ConsultantBANKING AND INSURANCEMay 2023 - Today (3 years and 1 month)Kirchardt, GermanyDirect interface between IT security and the various business unitsDirect reporting to IT Management & IT Security ManagementPlanning, coordination, and scheduling of vulnerability scans & compliance scansExecution of vulnerability scans & compliance scansData analysis, preparation, and clustering of vulnerability informationImpact analysis together with system administratorsDeduction of measures for mitigation and remediation of existing vulnerabilitiesReporting of implementation progress and threat landscape to IT Security Managementand various boardsAdvising system administrators in the area of vulnerability remediation &system hardeningCreation of vulnerability management conceptsOptimization of vulnerability managementDevelopment of vulnerability management processesExecution of regular and ad-hoc vulnerability scansFurther development of the current vulnerability scannerCreation of central reports and evaluations (for management andaffected groups / administrators)Creation of instructions for administratorsReview of the patch management infrastructureCreation and optimization of the patch processDevelopment of a new patch policyDevelopment of a new server hardening policyDevelopment of a new vulnerability scanner architectureImplementation of the new vulnerability scanner architectureEvaluation of a new tool for vulnerability scansImplementation of the new tool for vulnerability scans & compliance scansCreation and implementation of processes for patch managementCreation and implementation of processes for vulnerability scans &compliance scansRisk ManagementAsset Management
- Veguardex GmbHSenior IT Security Trainer & Senior IT Security ConsultantEDUCATION AND E-LEARNINGJanuary 2024 - Today (2 years and 5 months)Kirchardt, GermanyIT Security Awareness Training & Education:
- Training and awareness of end-users in the context of basic training &
education- Training and awareness of information security officers & general managers from basic training &
education- Conveying techniques that ensure actual action in addition to understanding IT security & information security
- Creation of further material such as posters or flyers
IT Security Awareness Consulting:- Development & implementation & continuous further development of coordinated information security requirements for the respective company
- Creation, preparation, and execution of phishing campaigns and simulations
- Analysis of results
- Proposal of concrete measures to increase the awareness level
- Development and improvement of processes
- Reporting to Information Security & Management
- Permanent member of various committees
- Direct contact person for all topics related to awareness
- Measurability of the effectiveness of measures
- ROI of awareness-building measures
Microsoft Product Training:- Official Microsoft training
- Customized Microsoft training
- Customized Microsoft workshops
- In-house and company training
- Boot camps and exam preparation
EC-Council Product Training:- EC-Council - Certified Ethical Hacker
- EC-Council - Certified SOC Analyst
- EC-Council - Certified Network Defender
- EC-Council - Certified Hacking Forensics Investigator
- Veguardex GmbHSenior IT Security ManagerAUTOMOBILEAugust 2022 - February 2024 (1 year and 7 months)Kirchardt, GermanyISMS:
- Support in the conception, design, and optimization of the Information Security Management System (ISMS).
- Development of complex ISMS processes and methods
- Documentation of complex ISMS processes and methods
- Execution of general risk assessments
- Consulting on various information security topics and compliance with the ISMS
- Identification, analysis, and evaluation of new developments and trends in information security
- Development of strategic recommendations and analysis of their impact on the value chain
Regulations:- Creation and revision of group-wide information security regulations
- Coordination of content in advance with the responsible information security representatives of the business units
- Preparation, execution, and follow-up of Standard Working Teams
- Preparation & presentation of regulations in committees
- Initiation, leadership, and structuring of content discussions with representatives from business units, cyber security, IT, and security line functions on your subject areas
- Deriving and presenting decision and action options from the results of the committees
- Transferring content discussion results into regulatory texts
- Checking regulatory texts for consistency, plausibility, and conformity with applicable standards (ISO 27001, GDPR)
- Ensuring the uniform format (structure, outline, references, etc.) of information security standards
- Initiation of target group-oriented publication & communication of standards
- Development and design of corresponding communication media
Compliance Checks:- Conception and execution of compliance checks of group-internal information security regulations
- Verification of the effectiveness of implemented ISMS processes
- Creation of meaningful result and final reports, including the derivation of recommendations for action for the business units
Recommendations
Be the first to recommend Carsten
Help this freelancer shine by sharing your experience working together.
These freelancer profiles also match your criteria
Agatha Frydrych
Backend Java Software Engineer
4.7
(3)
2
Baptiste Duhen
Fullstack developer
4.6
(4)
5
Amed Hamou
Senior Lead Developer
4
(2)
7
Audrey Champion
Web developer
4.3
(3)
4