Selected Project Experience

Management consulting in ITSM, IT Governance, IT Compliance, and IT Security. Project, program, and multi-project management in banking and critical infrastructure environments.

The following projects reflect over 25 years of consulting experience as a Management Consultant in the disciplines of IT Service Management, IT Governance, IT Compliance, and IT Security – primarily as a project, program, or multi-project manager in highly regulated industries.

Optimization of database activity monitoring using AI-based analytical methods
Company-wide optimization of database activity monitoring using AI-based analytical methods. Development and implementation of a manual database change review framework to strengthen governance, compliance, and operational security. Creation of DPIAs for AI-based security systems.
IT GovernanceISO/IEC 27001Compliance ManagementSecurity Governance
ISMS Setup according to ISO/IEC 27001:2022
Complete establishment of a company-wide Information Security Management System. Gap analysis and structured risk assessment with derivable controls. Creation of audit-proof ISMS documentation (policies, processes, statement of applicability, KPIs). Setup of internal audit and compliance framework for certification readiness.
ITSM/ITILISO/IEC 27001Information Security ManagementAudit-Readiness
Proof of concept for company-wide XDR solution (Crowdstrike)
Conducted proof of concept for company-wide XDR solution (Crowdstrike) with integration of firewall, proxy, WAF, and endpoint data (ZScaler). Documentation of compliance, data protection, and AI usage criteria. Development of target operating model including roles, responsibilities, and approval processes.
ITSM Service DesignTarget Operating ModelISO/IEC 27001Security Incident Management
NSPM Replacement
Time-critical replacement of existing NSPM solution and new implementation based on open-source Cactus Firewall Orchestrator platform. Management of complex vendor escalations with legal and procurement departments. Complete integration into ServiceNow. Management of EU-wide procurement process.
Change & Configuration ManagementVendor GovernanceISO/IEC 27001BAIT/DORA
DORA Readiness
Managed the DORA readiness preparation by identifying all relevant requirements and ensuring ISMS- and DORA-compliant implementation within the existing process landscape. Additionally, coordinated the preparation for BaFin audits (§44 KWG), which included comprehensive evidence management and resulted in a reduction of regulatory findings by over 90%.
ITSM Service OperationCompliance ManagementIT GovernanceDORA
Interim Management Infrastructure & Network Security — Software Defined Network Setup
Setup of software-defined network based on Cisco ACI. Implementation of network automation (Ansible & CI/CD pipeline). Interim management of 20-person specialist team following departure of internal project management. Complete integration into change & release management framework.
Change & Release ManagementAgile MethodenInfrastructure-as-Code
Infrastructure & Network Security — Self-Service & Analytics
Development of multiple Splunk applications: self-service portal for firewall rules for display and recertification, data analytics solution for firewall ruleset optimization. Requirements engineering with business units. Integration into service operation framework.
Service OperationMonitoring & ReportingEvent Management
Infrastructure & Network Security — Process Automation
Complete automation of firewall rule request process using RPA and ServiceNow flows. Optimization of incident & request fulfillment through intelligent workflow automation. Measurable reduction of manual processing steps by over 75%.
Service Design & OperationProcess AutomationIncident Management
Network Security — Recertification & Compliance
Preparation and execution of semi-annual network security rule recertification (CheckPoint & Fortinet). Reconciliation with IAM orders to ensure policy compliance. Establishment of structured change approval framework.
Configuration ManagementChange ControlCompliance Governance
ITSM Process Landscape & Governance Design
Conducted ITSM workshops with IT management. Gap analysis and design of BaFin/BAIT-compliant ITSM process landscape. Process modeling in Camunda and Visio. Development of rollout roadmap and introduction of KPI-based process reviews as part of continual service improvement.
ITIL 4Process DesignSLA/KPI ManagementBAIT/MaRisk
CMDB Optimization & Application Lifecycle Management
Analysis of CMDB architecture with focus on regulatory requirements (MaRisk, BAIT, EBA). Development and rollout of lifecycle management process for application onboarding, recertification, and decommissioning. Development of methodology for identification of critical functions according to EBA guidelines.
Configuration ManagementSACMMaRisk/BAIT/EBA
Dual-Vendor Firewall Integration & Workflow Automation
Planning and implementation of two-stage firewall integration (dual-vendor principle) for strategic partner companies. Coordination of extensive testing phases with business units and partners. Clearance of BaFin findings. Design and development of tool-based recertification processes (JobRouter) for PKI lifecycle management.
Change ManagementCompliance GovernanceProblem Management
Network Security Policy Management — EU Procurement & Implementation
Preparation and execution of EU-wide NSPM procurement (RfP). Market analysis and management of proof-of-concepts with leading vendors (Tufin, FireMon, Algosec). Contract negotiations in coordination with legal, procurement, and procurement authorities. Management of implementation including worldwide escalation management.
Service Design & TransitionVendor GovernanceChange Management
ITSM Turnaround — 24 ITIL Processes & ISO/IEC 20000
Project recovery: time-critical implementation of 24 ITIL processes in IT outsourcing context. Creation of ITIL process manuals including process modeling. Implementation of ITSM tool TOPdesk. Establishment of ISO/IEC 20000 and PCI-DSS compliance. Setup of governance structures and service desk. Successful audit approvals.
ITIL v3/2011ISO/IEC 20000Service DeskPCI-DSS
Windows Rollout — Application Security & Large-Scale Transformation
Development and coordination of application security concept in collaboration with IT security and corporate security. Coordination of release process for central application installation. Management of standard rollout for 8,000 workstations. KPI-based success tracking. Adaptation of ITSM support processes and integration into ServiceNow.
Service Design & OperationChange ManagementApplication Management
IT Annual Audit & Regulatory Compliance
Management of IT audit office as central interface between IT, internal audit, and external auditors. Coordination of all audit inquiries and execution of auditor interviews. Quality assurance of documentation. Support of internal and external audits. Processing and clearance of regulatory findings.
IT GovernanceAudit & ComplianceEvidence ManagementMaRisk/BAIT
Large-Scale Data Provisioning — US Regulatory Monitoring
Coordination, planning, and management of complex mass data provisioning as part of US regulatory monitoring.
Project ManagementComplianceData Governance
Application Management — Compliance Applications
Application responsibility for multiple compliance solutions (Anti Money Laundering, Know Your Customer, Watch List Filtering, NICE Actimize). Product lifecycle management. Problem, risk, and escalation management. Initiation and closure of service level agreements (SLA/OLA). Vendor and license management.
Service OperationIncident & Problem ManagementVendor Governance
Workplace Service Transformation — Application Migration & Packaging
Planning of migration of 1,500 applications for new Windows platforms (application readiness). Management of engineering and packaging team. License validation of 900 commercial products including license management consulting and coordination with strategic suppliers. Design of test and defect management process.
Programme ManagementService Design & TransitionSoftware Asset Management
Workplace Service Transformation — Strategy Development & Provider Procurement
Analysis and maturity assessment of existing workplace processes according to ITIL and COBIT. Requirements gathering from business units. Development of new workplace strategy and target alignment with IT management. Participation in procurement process for future workplace providers: RFI/RFP creation, design of service levels for ITIL operational processes and transition phase.
Service DesignProcess AssessmentService Level ManagementCOBIT
M&A Integration — Service Management Reporting & Provider Management
Development of KPI framework and SLA reporting system for provider management following bank merger. Setup of service management reporting system for senior IT management: aggregation and consolidation of incidents/service requests from multiple ticketing systems. Creation of transparency and management capabilities. Handover to line organization including training.
Service Operation & CSIService Level ManagementKPI-Design
M&A Integration — Interim Management Client IT Support
Interim management of second-level support team focusing on integration processes: brand, file, and email migration (over 60,000 mailboxes to Exchange 2007). Design and coordination of support processes. Setup of problem management to increase first-contact resolution rate. Evaluation and optimization of ITSM processes (ITIL, CMMI for Services, COBIT).
Service Operation & CSIProblem ManagementTeam Coaching
ITIL v3 Process Landscape — Design, Implementation & Shared Service Center
Design and implementation of ITIL v3 processes (incident, change, release, service level management, supplier management). Training of process owners and handover. Management of two migration projects for replacement of obsolete IT infrastructure. Setup of internal shared service provider: creation of service portfolio and catalogs, offers, billing models, service contracts. Execution of service improvement program.
ITIL v3Service Design & OperationContinual Service Improvement
Configuration Management System — Global Setup according to ITIL v3
Design and implementation of service asset and configuration management process including sub-processes. Requirements gathering via management interviews. Creation of configuration management roadmap. Development of Java tool for impact analysis between IT infrastructure components. Management of global developer team. Development of reporting solution (Eclipse BIRT). Consulting and coaching of process owners.
ITIL v3 Configuration ManagementProcess DesignRequirements Engineering
Business Process Management & ITSM Setup
Setup of business process management and process monitoring. Coordination and implementation of ITIL processes (change, release, configuration management). Development and mapping of processes to ITSM tool. Setup of configuration management database (CMDB).
Service Design & OperationChange ManagementConfiguration Management
WLAN Infrastructure Rollout — 330 Locations
Large-scale rollout of wireless LAN infrastructure across 330 locations.
Service DeploymentProject ManagementInfrastructure Management