At Gesellschaft für Internationale Zusammenarbeit, I led the end-to-end design and implementation of an ISO/IEC 27001:2022-aligned ISMS, achieving certification on schedule and improving audit readiness by 100%.
I established organization-wide risk assessment and treatment processes, operationalized incident management to reduce response time by 40%, and used KIM, ChatGPT, and Claude to strengthen policy development, cyber-risk scenarios, awareness materials, and incident analysis. I also presented ISMS implementation practices at the Global ISO Conference in Germany and contributed to an international KPI working group.
Previously at Zemen Bank, I led IT and cyber risk management across business units, reducing high-risk exposures by 35% and building more than 20 KRI dashboards for executive risk visibility.
My earlier work includes PCI DSS recertification and security monitoring at EthSwitch, plus private-cloud deployment using OpenStack at the Information Network Security Agency.
