Information Security Governance and Management. Vulnerability Management, Identity and Access Management, Project & 3rd party Security Assessments
Aktualisiert am 13.11.2024
Profil
Freiberufler / Selbstständiger
Remote-Arbeit
Verfügbar ab: 24.11.2024
Verfügbar zu: 100%
davon vor Ort: 60%
Informationssicherheit
IT-Governance
German
mother tongue
English
good

Einsatzorte

Einsatzorte

Zürich (+10km) Baden (Schweiz) (+20km)
Schweiz
möglich

Projekte

Projekte

10 Jahre 7 Monate
2013-12 - 2024-06

various

Overall information security assuring regulatory compliance and alignment with the group. Setup governance structure and control framework. Act as Data Protection Officer for Swiss Bank.
  • (on request) internally well established and recognized IT security officer and Data Protection Officer
  • Implementation of FINMA 08/21 appendix 3 framework
  • Group GDPR project participation responsible for Swiss Service Centre
  • Strategy and plan for Information Security in Schroders Switzerland
  • Management buy-in and awareness of the InfoSec topic up to Executive Board- level incl. regular reports
  • Establish and run the Information Security Committee
  • Setup roles for role-based access control for major wealth applications and onboard applications to groups IAM platform (Sailpoint Identity IQ)
  • Setup of an Information Security Management System structure
  • Evaluation and overall project lead of data classification and protection (Secure Island IQ Protector/Microsoft ADRMS)
  • Conducted a process-based business impact analysis with key stakeholder from the business
  • Actively work together with group IT security and Data Protection colleagues
  • Run BCM program (BIA, evaluation business recovery options/ requirements, BCP, coordinate workplace recovery exercises, participate in DR testing)

Positions
  • since Sep 2023: Regional Information Security Officer
  • since Oct 2021: Regional Information Security Officer and Data Protection Officer
  • since mid 2015: Head Information Security Officer, BCM Coordinator and Data Protection Officer
Schroder & Co Bank AG Switzerland
11 Monate
2013-01 - 2013-11

Supervision of identity and access management (IAM)

Information Security Officer
Information Security Officer
  • Overseeing identity and access management (IAM), guide way forward and act as the business lead for main initiatives and projects such as:
    • IAM way forward (set new direction)
    • IAM multiple accounts
    • IAM role based access control
  • Constitute role governance and solve open audit findings in the area of IAM
  • Design and implementation of a tool for controlling and reporting granted access rights
Julius Bär
1 Jahr
2012-01 - 2012-12

Ensuring data security

Technical Security Officer
Technical Security Officer
Ensure security for ex ABN AMRO until full integration. Implement and overview security for data extraction and transport to UBP and integration activities at ABN AMRO
  • Data migration transport framework between exABN and UBP (concept, scripts, controls, documentation)
  • User to user file exchange platform because of missing encryption in UBP e-mail system
  • Guide and oversee security in migration project
  • Active participation in network integration (network interconnection design and change management, FW rule base review, web proxy transition to UBP proxies)
  • Participation in end-user mail and data migration
  • Instruct and support data decryption (end user data and application data)
  • Handover of AAB Information Security to UBP
Union Bancaire Privée Switzerland
13 Jahre 2 Monate
1998-11 - 2011-12

Information security in investment and private banking

Information Security Officer and Data Protection Officer
Information Security Officer and Data Protection Officer
Define and implement structure, processes and systems/tools to ensure information security for both Investment and Private Banking for ABN AMRO Switzerland (since one year only Private Banking)
  • Directives and guidelines for information security for Bank staff, projects and outsourcing partners and 3rd parties
  • Oversee and coordinate security with all outsourcing partners (IBM: IT infrastructure, Verizon: Application maintenance and support, TCS: Networks)
  • Participation in relevant tables and steering committees (Operational Risk Management Committee, Swiss Project Steering committee)
  • Coordinate and follow-up on risk assessments and penetration testing
  • Establish and maintain the IS risk register
  • Drive and oversee system security (hardening/ health checking, vulnerability management, patch management, malware detection)
  • Oversee network security (FW management, Intrusion Detection and Prevention)
  • Ensure proper identity and access management (role based access control, provisioning and reconciliation, reviews, monitoring/reporting)
  • Audit fieldwork support and audit finding resolution
  • Ensure compliance with Swiss data protection act and Swiss Banking Secrecy
ABN AMRO Bank Switzerland
10 Monate
1998-02 - 1998-11

Unix Security, Projects and Tools

Head Unix Security, Projects and Tools
Head Unix Security, Projects and Tools
Telekurs Payserv AG
2 Jahre 2 Monate
1996-01 - 1998-02

UNIX Operation and Support

Head UNIX Operation and Support
Head UNIX Operation and Support
Telekurs Payserv AG
9 Monate
1995-04 - 1995-12

different systems

System specialist
System specialist
Telekurs Payserv AG
5 Jahre 3 Monate
1990-02 - 1995-04

EDV-Systemmanagement

EDV-System manager
EDV-System manager
Colenco Power Consulting AG (Motor Columbus AG)
1 Jahr 7 Monate
1987-09 - 1989-03

Software

Software Specialist
Software Specialist
Digital Equipment Corporation (DEC)

Aus- und Weiterbildung

Aus- und Weiterbildung

4 Monate
2005-03 - 2005-06

Nachdiplomskurs Informationssicherheit/ IT Security

Fachhochschule beider Basel
Fachhochschule beider Basel
1 Jahr 6 Monate
1997-04 - 1998-09

Economic Engineer STV Post studies/graduation

Kaderschule St. Gallen
Kaderschule St. Gallen
Specialisation subject in Service management
9 Monate
1987-01 - 1987-09

IT EDV Ergänzungsstudium für HTL Informatik Absolventen

Digital Equipment Corporation AG (DEC)
Digital Equipment Corporation AG (DEC)

Kompetenzen

Kompetenzen

Top-Skills

Informationssicherheit IT-Governance

Produkte / Standards / Erfahrungen / Methoden

Major skills and experiences
  • Broad and in-depth IT, information security and data protection knowledge and experience
  • IT management and governance
  • Conceptual thinking and structured working
  • Risk management
  • Information Security Management System
  • Design and implementation of Identity and Access Management Solutions
  • IT security: Vulnerability management, hardening, malware defence, DLP, DRM, FW/WAF, SIEM, network security, risk management, IAM and privileged access management
  • IS and data protection standards: ISO-2700x, NIST cyber security, GDPR, revFADP
  • Project management
  • Working in international companies
  • Interaction with different management levels
  • Good presentation skills
  • MS Office (word, excel, power point, access, VBA ..), MS SQL ..

General strengths
  • persevering, able to work under pressure, reliable
  • analytical thinking, structured and conceptual working
  • initiative, cool-headed, calm, focused
  • team oriented and collaborative but also independent/self-contained
  • realistic, down to earth, goal setting, value generating

Einsatzorte

Einsatzorte

Zürich (+10km) Baden (Schweiz) (+20km)
Schweiz
möglich

Projekte

Projekte

10 Jahre 7 Monate
2013-12 - 2024-06

various

Overall information security assuring regulatory compliance and alignment with the group. Setup governance structure and control framework. Act as Data Protection Officer for Swiss Bank.
  • (on request) internally well established and recognized IT security officer and Data Protection Officer
  • Implementation of FINMA 08/21 appendix 3 framework
  • Group GDPR project participation responsible for Swiss Service Centre
  • Strategy and plan for Information Security in Schroders Switzerland
  • Management buy-in and awareness of the InfoSec topic up to Executive Board- level incl. regular reports
  • Establish and run the Information Security Committee
  • Setup roles for role-based access control for major wealth applications and onboard applications to groups IAM platform (Sailpoint Identity IQ)
  • Setup of an Information Security Management System structure
  • Evaluation and overall project lead of data classification and protection (Secure Island IQ Protector/Microsoft ADRMS)
  • Conducted a process-based business impact analysis with key stakeholder from the business
  • Actively work together with group IT security and Data Protection colleagues
  • Run BCM program (BIA, evaluation business recovery options/ requirements, BCP, coordinate workplace recovery exercises, participate in DR testing)

Positions
  • since Sep 2023: Regional Information Security Officer
  • since Oct 2021: Regional Information Security Officer and Data Protection Officer
  • since mid 2015: Head Information Security Officer, BCM Coordinator and Data Protection Officer
Schroder & Co Bank AG Switzerland
11 Monate
2013-01 - 2013-11

Supervision of identity and access management (IAM)

Information Security Officer
Information Security Officer
  • Overseeing identity and access management (IAM), guide way forward and act as the business lead for main initiatives and projects such as:
    • IAM way forward (set new direction)
    • IAM multiple accounts
    • IAM role based access control
  • Constitute role governance and solve open audit findings in the area of IAM
  • Design and implementation of a tool for controlling and reporting granted access rights
Julius Bär
1 Jahr
2012-01 - 2012-12

Ensuring data security

Technical Security Officer
Technical Security Officer
Ensure security for ex ABN AMRO until full integration. Implement and overview security for data extraction and transport to UBP and integration activities at ABN AMRO
  • Data migration transport framework between exABN and UBP (concept, scripts, controls, documentation)
  • User to user file exchange platform because of missing encryption in UBP e-mail system
  • Guide and oversee security in migration project
  • Active participation in network integration (network interconnection design and change management, FW rule base review, web proxy transition to UBP proxies)
  • Participation in end-user mail and data migration
  • Instruct and support data decryption (end user data and application data)
  • Handover of AAB Information Security to UBP
Union Bancaire Privée Switzerland
13 Jahre 2 Monate
1998-11 - 2011-12

Information security in investment and private banking

Information Security Officer and Data Protection Officer
Information Security Officer and Data Protection Officer
Define and implement structure, processes and systems/tools to ensure information security for both Investment and Private Banking for ABN AMRO Switzerland (since one year only Private Banking)
  • Directives and guidelines for information security for Bank staff, projects and outsourcing partners and 3rd parties
  • Oversee and coordinate security with all outsourcing partners (IBM: IT infrastructure, Verizon: Application maintenance and support, TCS: Networks)
  • Participation in relevant tables and steering committees (Operational Risk Management Committee, Swiss Project Steering committee)
  • Coordinate and follow-up on risk assessments and penetration testing
  • Establish and maintain the IS risk register
  • Drive and oversee system security (hardening/ health checking, vulnerability management, patch management, malware detection)
  • Oversee network security (FW management, Intrusion Detection and Prevention)
  • Ensure proper identity and access management (role based access control, provisioning and reconciliation, reviews, monitoring/reporting)
  • Audit fieldwork support and audit finding resolution
  • Ensure compliance with Swiss data protection act and Swiss Banking Secrecy
ABN AMRO Bank Switzerland
10 Monate
1998-02 - 1998-11

Unix Security, Projects and Tools

Head Unix Security, Projects and Tools
Head Unix Security, Projects and Tools
Telekurs Payserv AG
2 Jahre 2 Monate
1996-01 - 1998-02

UNIX Operation and Support

Head UNIX Operation and Support
Head UNIX Operation and Support
Telekurs Payserv AG
9 Monate
1995-04 - 1995-12

different systems

System specialist
System specialist
Telekurs Payserv AG
5 Jahre 3 Monate
1990-02 - 1995-04

EDV-Systemmanagement

EDV-System manager
EDV-System manager
Colenco Power Consulting AG (Motor Columbus AG)
1 Jahr 7 Monate
1987-09 - 1989-03

Software

Software Specialist
Software Specialist
Digital Equipment Corporation (DEC)

Aus- und Weiterbildung

Aus- und Weiterbildung

4 Monate
2005-03 - 2005-06

Nachdiplomskurs Informationssicherheit/ IT Security

Fachhochschule beider Basel
Fachhochschule beider Basel
1 Jahr 6 Monate
1997-04 - 1998-09

Economic Engineer STV Post studies/graduation

Kaderschule St. Gallen
Kaderschule St. Gallen
Specialisation subject in Service management
9 Monate
1987-01 - 1987-09

IT EDV Ergänzungsstudium für HTL Informatik Absolventen

Digital Equipment Corporation AG (DEC)
Digital Equipment Corporation AG (DEC)

Kompetenzen

Kompetenzen

Top-Skills

Informationssicherheit IT-Governance

Produkte / Standards / Erfahrungen / Methoden

Major skills and experiences
  • Broad and in-depth IT, information security and data protection knowledge and experience
  • IT management and governance
  • Conceptual thinking and structured working
  • Risk management
  • Information Security Management System
  • Design and implementation of Identity and Access Management Solutions
  • IT security: Vulnerability management, hardening, malware defence, DLP, DRM, FW/WAF, SIEM, network security, risk management, IAM and privileged access management
  • IS and data protection standards: ISO-2700x, NIST cyber security, GDPR, revFADP
  • Project management
  • Working in international companies
  • Interaction with different management levels
  • Good presentation skills
  • MS Office (word, excel, power point, access, VBA ..), MS SQL ..

General strengths
  • persevering, able to work under pressure, reliable
  • analytical thinking, structured and conceptual working
  • initiative, cool-headed, calm, focused
  • team oriented and collaborative but also independent/self-contained
  • realistic, down to earth, goal setting, value generating

Vertrauen Sie auf Randstad

Im Bereich Freelancing
Im Bereich Arbeitnehmerüberlassung / Personalvermittlung

Fragen?

Rufen Sie uns an +49 89 500316-300 oder schreiben Sie uns:

Das Freelancer-Portal

Direktester geht's nicht! Ganz einfach Freelancer finden und direkt Kontakt aufnehmen.