You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Dennis KastDK

Dennis Kast

Fractional CISO | IAM | NIS-2 · DORA · ISO 27001

€1,200/day
3 projects
Hamburg, DE
8-15 years

Average response time: 1 hour

About Dennis

As a Fractional CISO, I bring C-level security expertise into your organization — pragmatic, immediately audit-proof, and without slowing down your engineering teams with bureaucracy.

I translate regulatory pressure into actionable cloud architectures, resilient business continuity planning (BCM), and auditable governance structures.

What I do:
NIS-2 compliance for healthcare infrastructures
DORA compliance for fintechs & regulated financial entities
Business Continuity & Incident Readiness (BIA/RIA)
Cloud security & third-party risk management
AI Governance & EU AI Act readiness

TÜV-certified IT Security Manager | Information Security Officer (latest ISO 27001 available)


References
„I had the pleasure of working with Dennis while I was IT Director at Sport Alliance, and I can confidently recommend him as a highly reliable and skilled IT consultant. Dennis consistently demonstrated strong expertise in IAM, security governance, and identity platforms such as Okta. Beyond being an excellent professional, Dennis is also a genuinely trustworthy person, a great team player, and someone who is very easy to collaborate with and interact with across all levels of the organization. I would gladly work with Dennis again and strongly recommend him for IT security and identity-related projects."
— Arnaldo Toledo, IT Director, Sport Alliance
  • German

    Native or bilingual

  • English

    Fluent

Can work on-site
Hamburg (up to 50km)

Experience

  • Universal Investment GmbH
    Fractional Head of IAM & DORA Project Lead
    BANKING AND INSURANCE
    March 2026 - Today (4 months)
    Frankfurt, Germany
    Embedded fractional IAM leadership engagement for a regulated alternative investment manager operating under DORA, BaFin BAIT and GDPR. Took full operational and strategic ownership of the IAM function while simultaneously driving the DORA compliance project stream | Team: 4–8 cross-site (EU). IAM Team Leadership: Led and coordinated a cross-functional IAM team across two sites (Frankfurt/Hamburg) — coaching, prioritization, and performance management of 2–4 direct reports alongside a hands-on operational role. Identity Lifecycle Operations Designed and enforced Joiner Mover-Leaver processes; managed RBAC/SoD models, access reviews and periodic recertifications for 1500+ identities across regulated financial environments. IAM Tooling & Implementation: Hands-on delivery of Okta IGA (250+ SSO/SCIM integrations), EntraID Conditional Access, MFA enforcement, Privileged Access Management, and service account governance. Directory Services & Federation: EntraID / AD administration, SAML/OIDC/OAuth federation architecture, and directory synchronisation across hybrid cloud and on-premise environments. DORA Project Lead: Led IAM-stream of DORA implementation programme — gap analysis, ICT risk framework mapping, third-party provider controls, and board-level reporting on ICT resilience for financial services client.
    Cyber Security Compliance Identity and Access Management (IAM) DORA IT Governance
  • Taxdoo GmbH
    Fractional IT Manager & Project Lead
    E-COMMERCE
    July 2025 - Today (1 year)
    Hamburg, Germany
    Strategic IAM Governance & Risk Reduction (Okta | Google IdP) Identity Consolidation Strategy: Directed a high-impact IAM migration from Okta to Google Cloud Identity, aiming to reduce supply chain complexity and operational costs while maintaining strict compliance standards. Zero-Trust & Access Control: Redesigned the authentication architecture to enforce Least Privilege principles and context-aware access, aligning the new Google IdP setup with ISO 27001 access control controls (A.9). Migration Risk Management: Spearheaded the gap analysis and migration planning, mitigating risks of data loss or service interruption through meticulous rollback strategies and parallel testing phases. Seamless Integration: Configured advanced Directory Sync and SAML/OIDC integrations for third-party apps, ensuring a seamless yet secure user experience (UX) that minimized shadow IT risks.
    Cyber Security Risk Management Digital Transformation IT Architecture IT-Compliance
  • Covierance
    Founder & Fractional CISO
    DIGITAL AND IT
    January 2019 - Today (7 years and 6 months)
    Hamburg, Germany
    Translating compliance into resilience: We help hospitals, eHealth, fintech, and regulated financial services turn regulatory requirements (DORA, NIS-2) into pragmatic IT security architectures — zero red tape, full auditability.
    Compliance Cyber Security IT-Security IT Architecture Consulting

Reviews

5,0

Out of 2 ratings

M

Michael

ARMBRUSTER empiric it

Reviewed on 14/08/2023

Dennis has chosen to hide 1 review

1 written review is private.

Recommendations

Be the first to recommend Dennis

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Duale Ausbildung, Fachinformatiker für Systemintegration
    Deutsche Telekom / T-Systems GmbH
    2012
    Duale Ausbildung, Fachinformatiker für Systemintegration

Certifications

  • TÜV IT-Security Manager
    TÜV Rheinland
    ISMS Informationssicherheitsmanagement Cyber Security Notfallmanagement ISO 27001 Information Security CIO CISO BCM BSI IT-Grundschutz

Skill set

Categories