Stuttgart Region
CISO & Head of Resilience at MANN+HUMMEL | Enterprise Risk & Cyber Resilience Leader | Military-Trained Manager Leading enterprise resilience for a β¬4.5B global filtration leader across 80+ locations worldwide. As Head of Resilience, I integrate Information Security, Data Protection, Business Continuity, Crisis Management, and Group Risk Management β creating unified defense ecosystems that protect operations while enabling growth. π‘οΈ Resilience at Scale Managing comprehensive operations with my team in Germany and Czech Republic, directing 30+ local ISO specialists and 30+ Data Protection Coordinators and building next-generation BCM capabilities. Our integrated GRC system seamlessly connects all management frameworks while navigating NIS-2, Cyber Resilience Act, and AI Act compliance. ποΈ Military-Forged Leadership Twenty years of leadership experience (teams up to 80+) shapes my approach to building resilient, high-performing teams under pressure. Combined with family values as father of two, this creates leadership that balances operational excellence with human-centered management. π Community Impact Honored to serve Germany's cybersecurity leadership through: - President, SEKOP2026 β Germany's premier CISO executive conference - Guest Lecturer β TUM Executive MBA & DHBW Stuttgart - Security Advisory Board β Foundation for Family Businesses and Politics - Cybersecurity Councils β KPMG Germany & KuppingerCole Analysts - CIO Award Jury Member β Evaluating Germany's top IT executives π± Building Communities Created and moderate Signal groups connecting 200+ DACH security experts for knowledge sharing, regulatory discussions, and peer support β including specialized NIS-2 and DORA implementation communities that have become essential resources for compliance professionals. π‘ Vision Passionate about building resilience that doesn't just protect organizations, but enables them to thrive in uncertainty. True resilience comes from integrated systems, empowered teams, and leaders who make confident decisions when stakes are highest. Always eager to connect with fellow resilience leaders, CISO's and professionals who understand that protecting what matters requires both technical excellence and smart governance. Building tomorrow's resilience, today.
Head of Resilience - Information Security, Data Protection, BCM, Crisis Management & Enterprise Risk Management Leading enterprise-wide resilience strategy and operations for MANN+HUMMEL Group, a β¬4.5B global automotive and industrial filtration leader with 22,000+ employees across 80+ locations worldwide. Stakeholder Engagement: Collaborating with C-suite, business units, and external partners to embed resilience into organizational DNA. π― Strategic Leadership & Scope β¦ Integrated Resilience Portfolio: Orchestrating Information Security & Data Protection, Business Continuity Management, Crisis Management, and Enterprise Risk Management as unified resilience ecosystem β¦ Global Team Leadership: Managing high-performing teams in Germany and Czech Republic (Resilience Infrastructure Service Center) β¦ Community Management: Directing 30+ local Information Security Officers and 30+ Data Protection specialists worldwide, with expanding BCM community π‘οΈ Operational Excellence β¦ One of a kind GRC Integration: Championing integrated Governance, Risk & Compliance system connecting all management frameworks for seamless operations β¦ Regulatory Mastery: Leading enterprise compliance with NIS-2, Cyber Resilience Act, AI Act, and emerging regulations β¦ Crisis-Ready Operations: Building a resilient organization capable of maintaining business continuity under any relevant threat scenario π Innovation & Transformation β¦ Service-Oriented Architecture: Establishing Resilience Infrastructure Team as cross-functional capability provider serving all resilience functions Passionate about building resilience capabilities that protect operations while enabling sustainable growth, innovation, and competitive advantage in an increasingly complex threat landscape.
π GRC Platform Transformation β¦ Led complete transformation from fragmented legacy systems (Verinice single-user, SharePoint DPMS) to integrated Alyne-based management platform connecting ISMS, DPMS, and enterprise risk management. β¦ Built comprehensive solution spanning policy controls, asset management, risk assessments, Monte-Carlo risk aggregation, and individualized risk owner dashboards. π‘οΈ World-Class Security Culture Development β¦ Development of a first-class program to raise awareness of security issues with innovative campaigns: custom-built games (Who Wants to Be a Millionaire, Escape Rooms), QR-code campaigns, guest CISO presentations on ransomware experiences, and more. π Enterprise Encryption & Compliance Excellence β¦ Successfully implemented Microsoft MIP end-to-end document encryption, achieving significant data protection coverage safeguarding against breach exploitation. β¦ Led TISAX coordination globally, achieving 100% audit success rate through pre-audit assessments and systematic finding remediation. π Global Program Scaling β¦ Built and managed worldwide ISO and DPC communities, providing centralized expertise to distributed teams. β¦ Expanded team strategically, including dedicated data protection specialist conducting global legislative risk assessments and gap analyses across all operational jurisdictions. βοΈ NIS-2 Thought Leadership β¦ Recognized NIS-2 subject matter expert in Germany, regularly presenting implementation strategies at industry conferences. β¦ Successfully delivered early NIS-2 compliance through proactive stakeholder engagement, comprehensive gap analysis, and timely remediation ahead of regulatory deadlines. π Measurable Impact β¦ Transformed MANN+HUMMEL's security posture from disparate point solutions to integrated enterprise resilience platform, establishing foundation for current Head of Resilience role while building internationally recognized expertise in regulatory compliance and security culture development.
π Virtual Leadership Excellence During Crisis β¦ Successfully led remote team transformation during COVID-19 lockdowns, converting a disparate team into a cohesive, high-performing team of 14 specialists β¦ Achieved remarkable team bonding across virtual environment - over 50% of team members met physically for the first time at departure celebration, yet maintained exceptional collaboration and personal connections beyond the term β¦ Scaled team operations 100% from 7 to 14 professionals while maintaining quality and team cohesion under challenging remote work conditions π‘οΈ Information Security Governance Leadership β¦ Strategic accountability for enterprise-wide Information Security Governance (distinct from advisory consulting), encompassing InfoSec strategy development, policy framework, and comprehensive risk management architecture β¦ Shaped the design and implementation of the new Information Security Risk Management program, including systematic risk assessments, aggregated risk reporting to enterprise risk management, and strategic risk treatment planning β¦ Established governance frameworks ensuring regulatory compliance and strategic alignment with business objectives across Mercedes-Benz Bank operations βοΈ BaFin Regulatory Program Excellence β¦ Served as primary Information Security subject matter expert across multiple high-stakes projects, providing strategic guidance and technical oversight for critical business transformations β¦ Shaped future organizational capabilities through active involvement in process design, methodology development, and strategic planning initiatives π‘ Strategic Innovation & Process Development β¦ Co-architected next-generation security processes and methodologies that became organizational standard, demonstrating forward-thinking approach to information security governance Immersive learning environment enabling deep expertise development while actively contributing to Mercedes-Benz Bank's security transformation
π Comprehensive IT Governance Leadership Led complete IT Governance team encompassing all IT activities except operations and development: IT Project Management, IT Controlling, strategic vendor management, and regulatory compliance oversight Dotted line management of Information Security Officer (ISB), establishing integrated security governance across organization Successfully managed Individual Development Processes (IDV) ensuring regulatory compliance and operational efficiency βοΈ Banking Regulatory Excellence β¦ Deep immersion in German banking regulation including MaRisk (Minimum Requirements for Risk Management) and BAIT (Banking Supervisory Requirements for IT), becoming subject matter expert in financial services compliance β¦ Primary interface with external auditors, internal audit, and LBBW Group InfoSec team for all IT-related examinations and regulatory assessments β¦ Findings management leadership - systematically addressed audit findings, implemented remediation strategies, and established sustainable compliance frameworks π‘ Strategic Technology Innovation β¦ Co-developed and implemented IT procurement tool with development teams, creating efficiency gains that attracted adoption requests from multiple business units across organization π€ Rapid Network Building & Stakeholder Management β¦ Built comprehensive professional network at Pariser Platz 7 within record time β¦ Horizontal IT integration - established strong relationships across all IT functions and leadership levels β¦ Vertical business alignment - created strategic partnerships spanning all business units and management tiers β¦ Became trusted advisor to senior leadership on IT governance, regulatory compliance, and strategic technology initiatives This role provided intensive exposure to financial services regulation while building comprehensive IT governance capabilities and establishing proven track record in stakeholder management across complex organizational hierarchies.
ποΈ Security Architecture Leadership & Governance Served as P-ISA (Principal Information Security Architect) for Communications, HR, Corporate Security, and External Affairs IT units, establishing comprehensive security architecture governance across critical business functions Strategic advisory role to IT colleagues on Information Security Architect procurement, engagement management, deliverable governance, and results implementation, ensuring consistent security standards across diverse technology environments Enterprise Architecture Board member representing cybersecurity perspective in group-wide technology decision-making, influencing strategic IT investments and architectural standards π Global Cybersecurity Network Integration β¦ Active participant in group-wide P-ISA community, collaborating with Principal Information Security Architects across all Daimler IT units through regular Global Cyber Security meetings π‘ Enterprise-Wide Technology Innovation β¦ Cross-collaborative project leadership as key member of 10-person global MFA implementation team, successfully deploying PingID multi-factor authentication solution across entire Daimler enterprise π― Post-Military Career Foundation β¦ First civilian role after military service, successfully transitioning from military leadership to corporate security architecture while maintaining high performance standards β¦ Recognized personal preference for leadership responsibilities, identifying individual contributor limitations and setting foundation for future management roles This role provided comprehensive exposure to enterprise-scale security architecture while building strategic relationships across global technology organization and establishing expertise in enterprise governance frameworks.
π― Leadership & Program Management β¦ Directed comprehensive military communications training programs as "HΓΆrsaalleiter" (Training Cource Director), managing 36 Non-Commissioned Officers (Feldwebel to Oberstabsfeldwebel) annually across multiple cohorts (2x 3-month and 1x 6-month programs) β¦ Led and coordinated a team of five instructors (Hauptfeldwebel, Oberleutnant, and Hauptmann level), overseeing curriculum development, training delivery, and program quality assurance β¦ Served as Hauptmann (Captain) with full responsibility for advanced training curricula and mobile military communication systems supporting critical field operations π‘οΈ Technical Training & Expertise β¦ Delivered expert-level instruction on mobile communication infrastructure connecting satellite communications, radio relay, tactical radio, and cable transmission systems to local networks β¦ Achieved Cisco CCNP Voice and CCNP Service Provider certifications, translating advanced networking concepts into practical military applications β¦ Trained Non-Commissioned Officers (Feldwebel) in deployment and operation of mission-critical communication systems for field operations π₯ Military Leadership Excellence β¦ Managed 12-student cohorts through intensive technical training programs with >90% completion rates β¦ Balanced dual responsibilities as technical expert and program administrator, ensuring both educational excellence and operational efficiency β¦ Developed junior leaders' technical capabilities while maintaining military standards and discipline This role combined advanced technical expertise in military communications with proven leadership capabilities, preparing skilled communications specialists for critical military operations while managing comprehensive training programs.