Navigation überspringen

Christian Fox Cyber Security Consultant

ist bald verfügbar. 🕒

In einer Ausbildung, Training as a OffSec PEN-200, OSCP
Bochum, Deutschland

Fähigkeiten und Kenntnisse

- more than 10 years of practical experiences succ
- more than 7 years of experience in a global IT s
- 5 years of experience in "mergers & acquisitions
- more than 5 years of knowledge in ISMS systems (
- very good analytical and communicative skills -
- Ability to effectively engage and communicate as
- Several years of experience in implementing comp
- Qualifications in information security (CISA CIS
- 6 years of experience in carrying out threat ana
- 5 years of relevant work experience across produ
- Very good experience in IT security architecture
- 6 years experience in the creation and testing o
- Very good knowledge in the development of SIEM p
- Independent Implementation of IT security worksh
- Knowledge of the penetration tools Kali Linux M
Cloud Security
Schwachstellen-Management
Penetrationstest (Informatik)
KI
IT Security Consulting

Werdegang

Berufserfahrung von Christian Fox Cyber Security Consultant

  • Bis heute 3 Monate, seit Apr. 2025

    Developing AI Security Concept & Implementation

    Clandestine

    Developed a comprehensive AI Security Concept to proactively identify, assess, and mitigate risks associated with AI systems. This project focused on creating a robust framework for secure AI development, deployment, and operation, ensuring data integrity, model robustness, and ethical AI use.

  • Bis heute 4 Monate, seit März 2025

    Training as a OffSec PEN-200

    OSCP

  • Bis heute 1 Jahr, seit Juli 2024

    Training as a Generate AI - Degree course

    Universität Helsinki

  • Bis heute 1 Jahr und 3 Monate, seit Apr. 2024

    DORA - Ensuring compliance for IT security

    Helaba
  • Bis heute 3 Jahre und 1 Monat, seit Juni 2022

    DevSecOps - Secure Software development based on BSI, NIST and OWASP

    Deutsche Telekom AG

    - Consulting, auditing and implementation services with regard to BSI basic protection, KRITIS, § 8a BSIG and B3S - Implementation of agile software development project management based on Confluence and Jira - Conducting workshops and training courses on secure software development - Creation of software development guidelines - Carrying out BSI basic protection checks - Creation of security concepts based on BSI standards 200-1, 200-2, 200-3 - Implementation of penetration tests

  • Bis heute 3 Jahre und 1 Monat, seit Juni 2022

    SAP Security - Hardening the SAP systems

    Deutsche Telekom AG

    - Supporting SAP IT projects in identifying, assessing and mitigating cybersecurity risks - Development, implementation and improvement of role and authorizations concepts - Participation in the definition of guidelines and standards with regards to SAP cybersecurity - Defining SAP Security definition for diff. SAP Modules/Systems - Identifying the improvement areas in authorization topic i.e. in both process and technical areas - Support technical SAP cybersecurity audits, tests and self-assessments

  • 2 Jahre und 6 Monate, Juli 2022 - Dez. 2024

    Penetration Testing - Detection and defense of cyber attacks

    Helaba

    - Central contact and coordinator between application managers and IT security management - Implementation of measures tracking and ensuring the elimination of the security gap - Creation reports on progress and status of vulnerability remediation and overview of open findings Applications: PCI DSS, OSST MM, NIST SP800-115, BSI, BAIT, MaRisk, KWG, BCBS239, OWASP, BSI-Penetrationstest Leitfaden, Office, Nessus, Rapid7, Metasploit, Nmap, Wireshark, Splunk, OpenVas, Burp

  • 5 Monate, Mai 2024 - Sep. 2024

    Global rollout vulnerability agent

    Helaba
  • 9 Monate, Nov. 2023 - Juli 2024

    Support Red Team Assessment

    Clandestine

  • 5 Monate, Aug. 2023 - Dez. 2023

    Cloud migration - Outsourcing of security services

    Helaba
  • 7 Monate, Apr. 2023 - Okt. 2023

    Compliance Check - gap analyzes based on the banking standard

    Hamburg Commercial Bank

    - Creation of a process model for carrying out gap analyzes based on the banking standard - Support in the implementation of the model in ServiceNow - Support in conducting gap analyses

  • 2 Monate, Feb. 2023 - März 2023

    Audit - critical cloud service provider audit based on DORA

    Santander Spanien

  • 1 Jahr, Jan. 2022 - Dez. 2022

    Support closing of Bafin and ECB findings

    Helaba
  • 1 Jahr und 10 Monate, März 2021 - Dez. 2022

    Web Application Security - Detection and defense of cyber attacks

    Helaba

    Analyze web application security and perform vulnerability and risk assessments using tests and security guides (OWASP, etc.) - Performing automated scans with web scanner tools - Identification of security vulnerabilities ( e.g. XSS, CSRF, SQL, Command and XPath Injections, Directory and Path Traversal and Security Misconfigurations) - Reporting, evaluation and recommendation of countermeasures - Collaborate with application owners and software developers and conduct vulnerability remediation meetings

  • 2 Jahre, Jan. 2021 - Dez. 2022

    Operationalization Vulnerability Management

    Helaba

    - Vulnerabilities- , Exploits- and Threats Detection for the Helaba GROUP (Cert, CVE, CVSS, Metasploit, ...) - Carrying out of vulnerability scanning (Network, Data bases, Applications, virtual-, container- and cloud environments) - risk-oriented analysis on the basis of data mining - Identification of application and system owners, opening of vulnerability ticket and coordination of actions - Monitor the timely application of security patches and ensuring the implementation of remediation measures

  • 2 Jahre und 6 Monate, Juli 2020 - Dez. 2022

    Vulnerability Management - Detection and defense of cyber attacks

    Helaba
  • 3 Jahre und 2 Monate, Nov. 2019 - Dez. 2022

    Analysis of IT and operational risks - Risk manager

    Helaba

    IT risk management in the banking sector - Analysis of IT and operational risks - Coordination and implementation of mitigating measures - Consideration of the banking supervisory requirements for IT (BAIT) and MaRisk

  • 3 Monate, Apr. 2020 - Juni 2020

    Cloud Security - Development of Cloud security concept

    Amazon

    - Development of a cloud strategy that is tailored to your specific requirements - Development of modern "hybrid cloud architectures" from infrastructure to network, security, governance, compliance and integration into operations - Reduction of your IT costs and generation of added value - Experience with AWS Cloud Platforms

  • 11 Monate, Aug. 2019 - Juni 2020

    Establishing First-line-of-defense - Detection and defense of cyber attacks

    Helaba

    - Responsible for establishing the "First Line of Defense" for the detection and defense of cyber attacks - Detection and defense of cyber attacks by using a vulnerability scanner to detect and prevent, identify, evaluate and conclude vulnerabilities - Recording of vulnerabilities information for automatic evaluation and determination of rules and regulations - Preparation of IT risk and management reports - Development of the process, roles, interfaces and integration into the IT service mngmt

  • 9 Monate, Dez. 2018 - Aug. 2019

    ISMS Implementation - Set up of an international ISMS

    AXA Konzern AG

    - Performing an comprehensive 27001:2013 GAP analysis - Carry out internal ISMS audits - Contact for external auditors on questions concerning KRITIS, VAIT - Responsible for the preparation of a project plan for the implementation of an ISMS - Responsible for the implementation of the ISMS based on ISO 27001:2013 - Responsible for implementing measures for an external Maturity Assessment examination

Ausbildung von Christian Fox Cyber Security Consultant

  • Bis heute 9 Jahre und 6 Monate, seit Jan. 2016

    Cyber Security Consultant

    ________

  • Kaufmann

    ________

Sprachen

  • Deutsch

    Muttersprache

  • Englisch

    Gut

  • Französisch

    Gut

XING – Das Jobs-Netzwerk

  • Über eine Million Jobs

    Entdecke mit XING genau den Job, der wirklich zu Dir passt.

  • Persönliche Job-Angebote

    Lass Dich finden von Arbeitgebern und über 20.000 Recruiter·innen.

  • 22 Mio. Mitglieder

    Knüpf neue Kontakte und erhalte Impulse für ein besseres Job-Leben.

  • Kostenlos profitieren

    Schon als Basis-Mitglied kannst Du Deine Job-Suche deutlich optimieren.

21 Mio. XING Mitglieder, von A bis Z