251119-Profile Dirk Meissner with project overview.pdf
About me
Senior Projektleiter und Security/GRC-Experte mit Schwerpunkt ISMS (ISO 27001/BSI), BCMS und Risikomanagement. Langjährige Erfahrung in Healthcare, Versicherungen und Automotive. Stark in Audit, Governance, Prozessen und Team-Coaching.
Amazon Web ServicesAuditingAutomotive IndustryMicrosoft AzureCloud Computing SecurityControl Objectives for Information and Related Technology (COBIT)ComplianceConsultingGovernanceGovernance Risk Management and ComplianceInformation Technology Infrastructure Libraries (ITIL)Information Technology AuditInsurance Management and AftercareISO/IEC 27001Risk AnalysisSecurity Information and Event ManagementStakeholder ManagementSustainabilityTisaxInformation Security Management SystemData ProtectionRisk ManagementDevSecOps
Senior Projektleiter und Security/GRC-Experte mit langjähriger Erfahrung in regulierten Branchen wie Healthcare, Versicherungen und Automotive. Spezialisiert auf ISMS (ISO 27001/BSI), BCMS, Risikomanagement und Compliance. Leite komplexe Transformations- und Sicherheitsprojekte, unterstütze bei Audits und Nachweisen und entwickle klare Prozesse, Policies und Governance-Strukturen für nachhaltige Sicherheit.
Umfassende Kenntnisse in ISO 27001/2, BSI 200-x/100-x, NIS2, DORA, TISAX, NIST 800-x, CIS Controls, ITIL und COBIT. Erfahrung in SOC/MDR, SIEM, Cloud Security (Azure/AWS), GRC-Frameworks, BCM/TCM, Data Privacy (GDPR/CDPSE), Audit & Compliance, Risikoanalyse, DevSecOps, Architekturberatung sowie Multi-Projekt- und Stakeholder-Management auf C-Level.
Languages
GermanNative speakerEnglishFluentFrenchFluent
Project history
Leitung Fachgruppe Informationssicherheit
ISACA Chapter Germany e.V.
Auditing, Taxes & Law
1000-5000 team member
Als Leiter der ISACA-Fachgruppe Informationssicherheit verantworte ich die fachliche Ausrichtung, Organisation und Weiterentwicklung der Arbeitsgruppe. Dazu gehört die Planung und Moderation regelmäßiger Expertensessions, die Koordination von Fachbeiträgen und Publikationen sowie die Vernetzung von Security-Professionals aus Unternehmen, öffentlicher Verwaltung und Wissenschaft. Ich identifiziere relevante Trends und regulatorische Entwicklungen (BSI, ISO, NIS2, DORA, KI-Regulierung) und überführe sie in praxisorientierte Leitfäden, Best Practices und Wissensformate. Zudem unterstütze ich ISACA Germany beim Community-Aufbau, der Mitgliederentwicklung sowie beim Austausch mit nationalen und internationalen Gremien. Schwerpunkt der Arbeit ist die Förderung eines hohen professionellen Standards im Bereich Informationssicherheit sowie der Wissenstransfer zwischen Experten und Organisationen.
Information Security / Cloud Vendor Auditor
DCSO GmbH
Internet & IT
50-250 team member
Cloud Vendor Assessments (CVA) based on DCSO defined security domains (NIST/ISO)
Security Matter Expert BMW Cloud Security
BMW AG
Automotive & Vehicle Manufacturing
>10.000 team member
- Define security concept for all relevant applications running on the platform.
- Connect applications to BMW central SOC / Splunk.
- Regular Pen tests, IAST / SAST / DAST scans.
- Assure compliance with BMW regulations.
Implementation of ISMS according to ISO2700x and NIST CSF
Ottobock SE
Pharmaceuticals & Medical Technology
5000-10.000 team member
- Define and implemnent an Information Security Management System according ot ISO27xxx and NIST CSF
- Setup Security Incident Response / MDR Team with 24/7 operations
- Conduct Business Impact Analysis
Interim IT-Security Manager EMEA
Evident Scientific Europe GmbH
Pharmaceuticals & Medical Technology
1000-5000 team member
Interim CISO with full line function responsibility
- Conduct ISO 27001 Assessment
- Implement 3rd party risk management
- define IT-Security policies
- Support DPO
Datenschutzbeauftragter / Data Protection Officer
Linkando GmbH
Internet & IT
10-50 team member
Data Protection Officer of Linkando GmbH:
- Audit of Linkando Cloud solution based on GDPR requirements
- Contact person for all GDPR related topics
Information Security Assessment Cloud Data Center
Bechtle AG
Internet & IT
>10.000 team member
- Conduct ISO 27001:2021 control assessment.
- Conduct BSI C5 control assessment.
- Define risk-based technical and organizational measurements to improve overall Cyber Security maturity level and resilience.
Senior Consultant Information Security BMW AWS Cloud
Ottobock SE
Pharmaceuticals & Medical Technology
5000-10.000 team member
Implenentation of an ISMS according to ISO2700x with complimentary NIST CSF Controls
Setup of a Security Incident Response Teams with 24/7 operations
Condut a Business Impact Analyse
Allianz Partners AIT Coordinator APAC Region
Allianz SE
Insurance
>10.000 team member
Background:
Allianz Information Transition (AIT) projects are mandatory for all Allianz Entities worldwide.
Responsible for the alignment of the different project pillars
Responsible for the overall project budged controlling
Responsible for the alignment between projects and local CIO´s for whole APAC region
Responsible for the steering of the project execution
Achievements:
Successful rollout of AGN, AGN security services and GM in 2018
Rollouts for AVC and DCC in 2019
Allianz Virtual Client (AVC) Program Manager
Allianz SE
Insurance
>10.000 team member
Background:
Allianz Virtual Client (AVC) is the mandatory Workplace solution for all Allianz OEs worldwide with 140K users.
Annual program budget approximate 20M Euro
Program started in 2013
Tasks:
Profit and Lost responsibility for AVC program
Align with Organization Entities (OEs) the rollout plan for AVC
Escalation counterpart for management of OE
Steer rollout preparation and rollout execution
Responsible for the AVC architecture team, package factory, Engineering department, Rollout team, PMO, Finance team with over 70 staff members (internals and externals)
Reporting to top management of Allianz SE
Achievements:
Customization of AVC solution to fit 24/7 operation model of Allianz Partners
Rollout of AVC to over 70K users in Europe and APAC till end of 2018
CISO / IT Sicherheitsbeauftragter BSI
ZfP Südwürttemberg
Government and Public Services
5000-10.000 team member
Background:
Zentrum für Psychatrie is a public healthcare organization with several thousand employees.
Need information security officer to define and implement information security concept.
Security concept based on BSI 100-x and ISO 27xxx
Setup and maintain ISMS
Tasks:
Create internal security organization for over 20 locations/business units in Germany
Define information security policy according to BSI and ISO standards and consult the management in all topics related to information security
Execute audits and follow-up audit findings
Achievements:
BSI 100-1/2 and ISO27xxx information security concept
IT-Emergency concept based on BSI 100-4
Handover of ISMS end of 2018 to successor
Senior Security Consultant
BMW AG
Automotive & Vehicle Manufacturing
>10.000 team member
Background:
BMW Group need new IT-Security blueprint for all SAP systems worldwide
Tasks:
Collect and align all IT-Security relevant requirements within BMW Group
Create a new SAP IT-Security concept as blueprint
Test new SAP IT-Security concept in production and define worldwide rollout plan
Achievements:
New SAP IT-Security concept created
Proof of concept with one productive SAP system in Munich
Create worldwide rollout plan and align with all relevant parties