Senior Cybersecurity Consultant
Cybersecurity professional with experience across security operations, detection and response, security governance, infrastructure security, and identity and access management.
My work combines hands-on technical implementation with security architecture, process development, and stakeholder management. I have supported organizations in healthcare, financial services, and pharmaceutical environments, working on SOC transformation, threat modeling, security hardening, and audit remediation.
Alongside consulting, I write about cybersecurity and professional development, speak at industry events, and document the lessons behind my technical journey.
Areas of Expertise
#Security Operations
Detection and response, SIEM engineering, SOC processes, alert analysis, log-source onboarding, and operational automation.
Security Engineering
Secure architecture, threat modeling, endpoint security, system hardening, vulnerability management, and identity security.
Governance & Transformation
Audit remediation, operating models, policies, standards, procedures, and technical transformation programs.
Leadership & Communication
Technical project leadership, team leadership, executive stakeholder management, proposals, workshops, writing, and public speaking.
Professional Experience
#Senior Consultant
Mar 2026 — Present
Deloitte · Germany
Working across security operations, managed detection and response, security governance, and technical transformation engagements.
- Lead and support SOC and MDR transformation projects
- Design operating models, processes, architectures, and technical onboarding approaches
- Develop and optimize Microsoft Sentinel environments, integrations, and reporting
- Translate audit findings into actionable governance documents and controls
- Coordinate technical teams, delivery partners, and senior stakeholders
Cybersecurity Consultant & Team Lead
Jan 2025 — Feb 2026
IBM Germany · Munich
- Held professional and personnel responsibility for an eleven-member team
- Delivered engagements covering threat modeling, SOC services, and security architecture
- Supported technical bids, proposals, and customer-facing solution development
- Developed security documentation, operating procedures, and automation concepts
Cybersecurity Engineer — Infrastructure Security
Feb 2024 — Dec 2024
UniCredit · Munich
- Implemented server and workstation hardening based on CIS and STIG guidance
- Improved endpoint patching and vulnerability-management processes
- Collaborated with SOC and incident-response teams to strengthen endpoint security
- Established and documented technical security baselines
Cybersecurity Engineer — Identity & Access Management
Feb 2023 — Feb 2024
UniCredit · Munich
- Managed decentralized and centralized identity and access processes
- Administered role-based access across enterprise applications
- Controlled access requests and approvals through ticket-based workflows
- Supported transparent and compliant authorization management
Selected Engagements
#Selected client engagements across healthcare, banking, and pharmaceutical environments.
SOC Capability Development
Mar 2026 — PresentDAK-Gesundheit
- Administered and configured Microsoft Sentinel and developed operational workbooks.
- Selected and onboarded additional log sources and connectors.
- Analyzed alerts, identified environment-specific false positives, and monitored ingestion costs.
- Derived technical and organizational improvements, operational rules, and security best practices.
Managed Detection & Response Onboarding
Mar — Jul 2026Sana IT Services
- Designed the target architecture and operating model for an MDR service.
- Led the technical onboarding and coordinated operational and executive stakeholders.
- Established project governance, weekly reporting, and supporting proposal material.
- Designed integrations for Zscaler, Proofpoint, Microsoft Entra ID, Sentinel, and relevant log sources.
Security Governance Remediation
Mar 2026 — PresentInvestitions- und Strukturbank Rheinland-Pfalz (ISB)
- Developed governance documentation in response to security audit findings.
- Created organizational policies, standards, operating procedures, and process models.
- Covered vulnerability management, penetration testing, change management, patch management, and security logging.
- Translated audit requirements into practical security controls and responsibilities.
eHealth Security Architecture
Mar — Aug 2025gematik
- Developed a threat-modeling report for a security identity provider.
- Assessed architectural threats, trust boundaries, and security risks.
- Supported the development of an endpoint detection and response rollout process.
- Translated technical findings into recommendations for implementation and architecture.
SOC Process Development
Oct — Dec 2025Bayer
- Developed automation concepts for SOC analyst workflows using Microsoft Logic Apps.
- Updated the core standard operating procedure template.
- Created and structured an inventory of existing SOC procedures.
- Improved the consistency and automation readiness of operational documentation.
Selected Certifications
#- CompTIA Security+
- CompTIA Cloud+
- CompTIA Server+
- CompTIA Data+
- ISC2 Certified in Cybersecurity
- Professional Scrum Master I
- PRINCE2 Foundation
The dedicated Certifications section provides the broader learning context behind these credentials.
Education
#M.Sc. IT Security — Studies paused
Technical University of Darmstadt · 2020–2022
B.Sc. Business Informatics
University of Applied Sciences Landshut · 2015–2020
Focus: Cybersecurity
Languages
#- German: Native
- English: Professional working proficiency · TOEFL iBT 100/120
Beyond the CV
#A conventional CV captures roles and dates, but rarely the thinking behind the work. My writing, conference talks, public projects, and certification reflections document that wider journey.