I combine an industrial engineering background with hands-on cybersecurity training and practical security projects, with a focus on Governance, Risk & Compliance (GRC), information security, security operations, risk management, and regulatory frameworks.
My portfolio focuses on applying security and compliance principles to realistic enterprise scenarios, with particular interest in European cybersecurity and regulatory requirements.
- CompTIA Security+ (SY0-701)
- ISO/IEC 27001 Lead Implementer (Provisional) — PECB
- Master in Cybersecurity & Ethical Hacking (Professional Program) — EPICODE Institute of Technology
- Diploma in Mechanical Engineering
- Governance, Risk & Compliance (GRC)
- ISO/IEC 27001 & Information Security Management Systems (ISMS)
- NIS2 & Cybersecurity Regulatory Compliance
- DORA & ICT Operational Resilience
- GDPR & Privacy Risk Management
- ISO/IEC 42001 & AI Governance
- Enterprise Risk Assessment
- Security Controls & Control Mapping
- Identity & Access Management (IAM)
- Third-Party & ICT Risk
- Security Operations & Incident Response
- Industrial & OT Cybersecurity
A structured portfolio of synthetic enterprise case studies demonstrating practical application of Governance, Risk & Compliance principles across information security, privacy, operational resilience, identity governance, AI governance, and European regulatory frameworks.
-
ISO/IEC 27001 — ISMS Risk Assessment
Information security risk assessment covering ISMS governance, risk treatment, Annex A controls, Statement of Applicability, and continual improvement. -
NIS2 — Cybersecurity Risk Assessment
Enterprise cybersecurity assessment covering governance, incident reporting, supply-chain security, risk management, and regulatory requirements. -
DORA — ICT Risk & Operational Resilience Assessment
Digital operational resilience assessment covering ICT risk, third-party risk, resilience testing, incident management, and recovery. -
GDPR — Privacy Risk Assessment
Privacy and data governance assessment covering DPIA, data subject rights, processing activities, processor risk, retention, and breach management. -
ISO/IEC 42001 — AI Governance & Risk Assessment
AI governance assessment covering AI lifecycle governance, AI risk management, human oversight, monitoring, accountability, and AI governance controls. -
IAM — Identity & Access Risk Assessment
Identity and access governance assessment covering RBAC, PAM, privileged access, joiner-mover-leaver controls, segregation of duties, and non-human identities. -
Enterprise GRC — Control Mapping
Cross-framework enterprise GRC case study integrating GDPR, ISO/IEC 27001, ISO/IEC 42001, DORA, and NIS2 through common-control ownership, evidence governance, regulatory change management, and integrated assurance.
Selected practical cybersecurity projects covering security monitoring, vulnerability assessment, network security, threat intelligence, and security operations.
Areas include:
- SIEM & security monitoring
- Wazuh
- Splunk
- Nmap
- Nessus
- Wireshark
- Burp Suite
- Metasploit
- Vulnerability assessment
- Network security
- Threat intelligence
- MITRE ATT&CK
- Incident response
- Security testing
Security & Monitoring
Splunk Wazuh Nmap Nessus Wireshark
Security Testing
Burp Suite Metasploit Kali Linux DVWA OWASP
Security & Risk
SIEM EDR NDR Threat Intelligence Vulnerability Management
Governance & Compliance
ISO/IEC 27001 NIS2 DORA GDPR ISO/IEC 42001 GRC Risk Assessment Control Mapping ISMS IAM
I am particularly interested in roles involving:
- Cybersecurity Governance
- GRC & Compliance
- Information Security
- Risk Management
- Security Operations
- ISMS
- Regulatory Compliance
- ICT Risk & Operational Resilience
- IAM & Access Governance
- AI Governance
- Industrial & OT Cybersecurity
The projects in this portfolio are designed as structured professional case studies rather than claims of client engagements.
They demonstrate how security and compliance requirements can be translated into:
Requirements → Risks → Controls → Evidence → Testing → Findings → Remediation → Management Reporting
The objective is to demonstrate practical analytical thinking, risk-based decision making, control governance, and the ability to connect multiple regulatory and security requirements within an enterprise operating model.
The portfolio assessments are synthetic case studies created for professional demonstration and learning purposes.
They do not represent real client engagements, confidential information, audit opinions, legal or regulatory advice, certification evidence, or production implementations.
📍 Based in Upper Austria, Austria