Information Security & Risk Professional · CISO
Senden Sie diesem Kandidaten direkt ein Jobangebot
Information risk and cybersecurity professional with broad experience across crypto, fintech, retail, and banking. Track record of building and running risk, security, and AI governance programs that align with DORA, BaFin, and ISO 27001 expectations, while staying close to the realities of the business. Comfortable shaping policies and at ease with engineers, executives, and regulators.
Looking for a leading role to drive the strengthening of security posture, secure AI adoption, and the harmonization of technical security controls with regulatory and legislative requirements.
SPECIALTY & CREDENTIALS
Specialty: Leading information security and information risk projects. Consulting. Mentoring. Identifying problems and root causes. Defining policies, processes, and procedures. Prioritizing. Simplifying. Increasing awareness. Cultivating cross-functional buy-in to accelerate critical initiatives. Reporting.
Education: BASc in E-Business Certifications: Open FAIR Foundation, CISSP, SSCP, CCSK, ITIL Foundation
Finoa · Berlin, Germany · Startup - crypto-assets service provider
Chief Information Security Officer Jan 2025 - July 2026
Reporting to the Chief Legal and Compliance Officer - Managing Director. Responsible for the governance and control of IT risk management and cybersecurity, executing 2nd line duties.
Principal InfoSec Risk Manager Sep 2021 - Dec 2024
Deputy CISO. Responsible for 2nd line duties, leading the improvements in information security and information risk management. Owned the company's “policy desk” and drove the alignment of internal regulation with regulatory and legislative requirements.
Reporting to the Chief Information Security Officer. Responsible for 2nd line duties, launching the initiatives to strengthen information security and information risk management.
adidas AG · Herzogenaurach, Germany
Senior Manager - Corporate Internal Audit IT Jan 2019 - Jan 2021
Reporting to the Chief Audit Officer. Responsible for 3rd line duties - analyzing the risk universe and enhancing audit methodology and processes. Led multicultural teams across audit and advisory engagements, collaborating with senior directors of Corporate Compliance, Information Security, Enterprise Architecture, Risk, Internal Controls, Procurement, and Legal teams.
Embedded information security into the technical design across waterfall and agile project teams. Reviewed policies and procedures aligning with Corporate Governance, Enterprise Architecture, Risk, Compliance, Legal, Procurement, and Data Privacy teams.
IT Security Engineer
Jan 2016 - Dec 2016Discovered security gaps and implemented missing security layers. Led testing and solutions integration. Collaborated with system integrators and major vendors. Identified and labeled sensitive data, and specified encrypted data in transit in preparation for PCI DSS certification.
Senior Network and Telecommunications Engineer Dec 2008 - Dec 2015
Responsible for leading a team of network engineers. Designed a highly available and secure network of more than 1500 endpoints. Collaborated with vendors and system integrators. Introduced secure authentication, authorization, and accounting for administrative access, and rolled out role-based access for network devices and firewall clusters.
Education: BASc in E-Business
Certifications: Open FAIR Foundation, CISSP, SSCP, CCSK, ITIL Foundation