Christian Fox Cyber Security Consultant

ist bald verfügbar. 🕒

In einer Ausbildung, Training as a OffSec PEN-200, OSCP
Bochum, Germany

Fähigkeiten und Kenntnisse

- more than 10 years of practical experiences succ
- more than 7 years of experience in a global IT s
- 5 years of experience in "mergers & acquisitions
- more than 5 years of knowledge in ISMS systems (
- very good analytical and communicative skills -
- Ability to effectively engage and communicate as
- Several years of experience in implementing comp
- Qualifications in information security (CISA CIS
- 6 years of experience in carrying out threat ana
- 5 years of relevant work experience across produ
- Very good experience in IT security architecture
- 6 years experience in the creation and testing o
- Very good knowledge in the development of SIEM p
- Independent Implementation of IT security worksh
- Knowledge of the penetration tools Kali Linux M
Cloud Security
Schwachstellen-Management
Penetrationstest (Informatik)
KI
IT Security Consulting

Werdegang

Berufserfahrung von Christian Fox Cyber Security Consultant

  • Current 1 year and 2 months, since Apr 2025

    Developing AI Security Concept & Implementation

    Clandestine

    Developed a comprehensive AI Security Concept to proactively identify, assess, and mitigate risks associated with AI systems. This project focused on creating a robust framework for secure AI development, deployment, and operation, ensuring data integrity, model robustness, and ethical AI use.

  • Current 1 year and 3 months, since Mar 2025

    Training as a OffSec PEN-200

    OSCP

  • Current 1 year and 11 months, since Jul 2024

    Training as a Generate AI - Degree course

    Universität Helsinki

  • Current 2 years and 2 months, since Apr 2024

    DORA - Ensuring compliance for IT security

    Helaba
  • Current 4 years, since Jun 2022

    DevSecOps - Secure Software development based on BSI, NIST and OWASP

    Deutsche Telekom AG

    - Consulting, auditing and implementation services with regard to BSI basic protection, KRITIS, § 8a BSIG and B3S - Implementation of agile software development project management based on Confluence and Jira - Conducting workshops and training courses on secure software development - Creation of software development guidelines - Carrying out BSI basic protection checks - Creation of security concepts based on BSI standards 200-1, 200-2, 200-3 - Implementation of penetration tests

  • Current 4 years, since Jun 2022

    SAP Security - Hardening the SAP systems

    Deutsche Telekom AG

    - Supporting SAP IT projects in identifying, assessing and mitigating cybersecurity risks - Development, implementation and improvement of role and authorizations concepts - Participation in the definition of guidelines and standards with regards to SAP cybersecurity - Defining SAP Security definition for diff. SAP Modules/Systems - Identifying the improvement areas in authorization topic i.e. in both process and technical areas - Support technical SAP cybersecurity audits, tests and self-assessments

  • 2 years and 6 months, Jul 2022 - Dec 2024

    Penetration Testing - Detection and defense of cyber attacks

    Helaba

    - Central contact and coordinator between application managers and IT security management - Implementation of measures tracking and ensuring the elimination of the security gap - Creation reports on progress and status of vulnerability remediation and overview of open findings Applications: PCI DSS, OSST MM, NIST SP800-115, BSI, BAIT, MaRisk, KWG, BCBS239, OWASP, BSI-Penetrationstest Leitfaden, Office, Nessus, Rapid7, Metasploit, Nmap, Wireshark, Splunk, OpenVas, Burp

  • 5 months, May 2024 - Sep 2024

    Global rollout vulnerability agent

    Helaba
  • 9 months, Nov 2023 - Jul 2024

    Support Red Team Assessment

    Clandestine

  • 5 months, Aug 2023 - Dec 2023

    Cloud migration - Outsourcing of security services

    Helaba
  • 7 months, Apr 2023 - Oct 2023

    Compliance Check - gap analyzes based on the banking standard

    Hamburg Commercial Bank

    - Creation of a process model for carrying out gap analyzes based on the banking standard - Support in the implementation of the model in ServiceNow - Support in conducting gap analyses

  • 2 months, Feb 2023 - Mar 2023

    Audit - critical cloud service provider audit based on DORA

    Santander Spanien

  • 1 year, Jan 2022 - Dec 2022

    Support closing of Bafin and ECB findings

    Helaba
  • 1 year and 10 months, Mar 2021 - Dec 2022

    Web Application Security - Detection and defense of cyber attacks

    Helaba

    Analyze web application security and perform vulnerability and risk assessments using tests and security guides (OWASP, etc.) - Performing automated scans with web scanner tools - Identification of security vulnerabilities ( e.g. XSS, CSRF, SQL, Command and XPath Injections, Directory and Path Traversal and Security Misconfigurations) - Reporting, evaluation and recommendation of countermeasures - Collaborate with application owners and software developers and conduct vulnerability remediation meetings

  • 2 years, Jan 2021 - Dec 2022

    Operationalization Vulnerability Management

    Helaba

    - Vulnerabilities- , Exploits- and Threats Detection for the Helaba GROUP (Cert, CVE, CVSS, Metasploit, ...) - Carrying out of vulnerability scanning (Network, Data bases, Applications, virtual-, container- and cloud environments) - risk-oriented analysis on the basis of data mining - Identification of application and system owners, opening of vulnerability ticket and coordination of actions - Monitor the timely application of security patches and ensuring the implementation of remediation measures

  • 2 years and 6 months, Jul 2020 - Dec 2022

    Vulnerability Management - Detection and defense of cyber attacks

    Helaba
  • 3 years and 2 months, Nov 2019 - Dec 2022

    Analysis of IT and operational risks - Risk manager

    Helaba

    IT risk management in the banking sector - Analysis of IT and operational risks - Coordination and implementation of mitigating measures - Consideration of the banking supervisory requirements for IT (BAIT) and MaRisk

  • 3 months, Apr 2020 - Jun 2020

    Cloud Security - Development of Cloud security concept

    Amazon

    - Development of a cloud strategy that is tailored to your specific requirements - Development of modern "hybrid cloud architectures" from infrastructure to network, security, governance, compliance and integration into operations - Reduction of your IT costs and generation of added value - Experience with AWS Cloud Platforms

  • 11 months, Aug 2019 - Jun 2020

    Establishing First-line-of-defense - Detection and defense of cyber attacks

    Helaba

    - Responsible for establishing the "First Line of Defense" for the detection and defense of cyber attacks - Detection and defense of cyber attacks by using a vulnerability scanner to detect and prevent, identify, evaluate and conclude vulnerabilities - Recording of vulnerabilities information for automatic evaluation and determination of rules and regulations - Preparation of IT risk and management reports - Development of the process, roles, interfaces and integration into the IT service mngmt

  • 9 months, Dec 2018 - Aug 2019

    ISMS Implementation - Set up of an international ISMS

    AXA Konzern AG

    - Performing an comprehensive 27001:2013 GAP analysis - Carry out internal ISMS audits - Contact for external auditors on questions concerning KRITIS, VAIT - Responsible for the preparation of a project plan for the implementation of an ISMS - Responsible for the implementation of the ISMS based on ISO 27001:2013 - Responsible for implementing measures for an external Maturity Assessment examination

Ausbildung von Christian Fox Cyber Security Consultant

  • Current 10 years and 5 months, since Jan 2016

    Cyber Security Consultant

    ________

  • Kaufmann

    ________

Sprachen

  • German

    C2 (Verhandlungssicher / Muttersprachlich)

  • English

    B1-B2 (Gute Kenntnisse)

  • French

    B1-B2 (Gute Kenntnisse)

XING – Das Jobs-Netzwerk

  • Über eine Million Jobs

    Entdecke mit XING genau den Job, der wirklich zu Dir passt.

  • Persönliche Job-Angebote

    Lass Dich finden von Arbeitgebern und über 20.000 Recruiter·innen.

  • 21 Mio. Mitglieder

    Knüpf neue Kontakte und erhalte Impulse für ein besseres Job-Leben.

  • Kostenlos profitieren

    Schon als Basis-Mitglied kannst Du Deine Job-Suche deutlich optimieren.

21 Mio. XING Mitglieder, von A bis Z