Uwe Schwarz
Project Manager
I connect technology, people, and business goals ā acting as the bridge between teams, stakeholders, and systems. Whether it's IT security, networking, high-availability infrastructure, or email solutions, I take ownership, lead complex projects, and ensure the results are not just technically sound, but strategically aligned and built to last.

š”ļø GDPRš¤ AIš¤ Human APIš” networkingš” strategyš securityAbout Me

With over two decades of hands-on experience in IT and project leadership, I specialize in building secure, scalable, and future-ready systems. From high-stakes data center migrations to evolving security strategies for regulated industries, Iāve led diverse teams and initiatives that drive tangible business outcomes.
I act as the bridge between technical complexity and strategic clarity. Whether Iām aligning teams on a security roadmap, modernizing infrastructure, or translating compliance requirements into real-world action, I bring a clear head, calm hands, and a passion for connecting the dots between tech and people.
Outside the day-to-day, I stay curious. Iām particularly fascinated by AI and its potential to enhance everything from cybersecurity to user experience. I enjoy experimenting with new tools, self-hosted solutions, and smart workflows ā always with an eye on whatās practical, elegant, and secure.
Experience
Key Projects
Major technical and organizational engagements with high responsibility.
A curated selection of multi-month and multi-year work; further details on request.
Subproject Lead Data Center Migration & Backup Modernization
Joh. Berenberg, Gossler & Co. KG
- Subproject lead within the data center migration project, focusing on Solaris, Linux, storage, and backup environments.
- Responsible for the modernization and full implementation of the new enterprise backup platform based on Rubrik Security Cloud.
- Supported the transition of Solaris infrastructure and legacy systems towards modern, cloud-ready architectures.
- Contributed to the redesign and renewal of the legacy network into a modern, segmented structure with improved security focus.
- Achievement: Successfully led the Rubrik Security Cloud modernization project, enhancing data protection, compliance, and recovery performance across all business units.
- Achievement: Contributed to the successful relocation of two data centers with minimized downtime and coordinated dependencies across multiple infrastructure domains.
Information Security Officer
Threedium Ltd.
- Consulting in all questions about and around IT security.
- Support of the DevOps team.
- Integration of services in SSO infrastructure.
- Certificate audit: SOC2 and ISO27001
- Advice on all aspects of GDPR. Introduction of retention policies and data protection guidelines.
- Introduction of security guidelines.
- Achievement: Implemented IT security measures that passed a SOC2 audit with zero non-conformities, securing key client contracts.
- Achievement: Integrated SSO infrastructure across multiple platforms, improving security and user experience.
- Achievement: Led the team in passing ISO27001 certification within a tight six-month deadline, which opened new markets for the company.
IT Security Consultant
Deutsche Vermƶgensberatung AG
- Consulting regarding any security topics, focus on server and networks.
- Support and strategy handling during a (large) security incident.
- Writing (security) policies and technical concepts.
- Automation vulnerability and inicident management.
- Support for building IT architecture and strategy (including network architecture, cloud infrastructure, firewall concepts, etc.).
- Preparation and accompanying of penetration tests (including network, cloud, applications, Active Directory, etc.).
- Led and managed the Security Operations Center (SOC) team, overseeing daily operations, incident response, and continuous improvement of security processes.
- Security audits.
- Specialization in the areas of Linux and networking.
- IT security consulting also on Windows, Cloud (primarily Azure) and application development.
- Advice on data protection and certification issues (e.g. ISO27001, BSI Grundschutz, NIST framework, MITRE).
- Achievement: Managed the response to a major security incident, coordinating efforts that minimized data loss and restored operations.
- Achievement: Developed and automated a vulnerability management system, reducing incident response time and increasing system uptime.
- Achievement: Implemented security policies that were later adopted as best practices company-wide.
Team Coordinator / System Architect
Deutsche Vermƶgensberatung AG
- Coordination and planning of resources of a small team.
- Focus of the team: e-mail, cloud storage, load balancing, proxy and DNS (all linux based).
- Debugging und solving of problems mainly in the area mail (but not solely).
- Consulting and implementation of IPv6, security topics, high-availability systems and more topics.
- Project part time management: data centre relocation, reconstruction of all servers.
- Achievement: Coordinated a successful data center relocation project.
- Achievement: Led the implementation of IPv6 across the organization, future-proofing the network.
- Achievement: Improved team efficiency through the introduction of automated processes and resource management tools.
Product Owner / System Architect
Deutsche Vermƶgensberatung AG
- Product Owner and system architect for the enterprise-wide email archiving platform, including requirements management, technical roadmap, and long-term evolution.
- Led the design and implementation of a legally compliant archive for more than 50,000 users, ensuring immutable retention, auditability, and long-term maintainability.
- Introduced scalable storage, redundancy concepts, monitoring, indexing and full-text search to enable efficient retrieval of historical correspondence.
- Close collaboration with legal, compliance, and auditing teams to meet regulatory requirements and ensure long-term evidentiary integrity.
- Secondary responsibilities in the surrounding mail infrastructure (dovecot, postfix), Linux-based services, DNS, proxy, load balancing and cloud storage.
- Achievement: Delivered a stable, compliant archive used daily across the entire organization.
- Achievement: Established future-proof data retention strategies aligned with strict regulatory expectations.
Additional & Focused Projects
Complementary or specialized projects with flexible scope.
Specialized, flexible, or focused initiatives that complement the broader work.
Member of the Board
DEGIT AG
- Information Security Officer and Data Protection and Privacy Officer.
- Access to experts from multiple fields.
- Competent and focused partner for all consulting needs.
- Building a secure and compliant IT infrastructure with a focus on modern technologies (IPv6, Zero Trust, Zero-Config VPN, etc.) and best practices.
- Responsible for corporate governance in IT security, privacy and compliance topics.
Founding Member & Data Protection Officer
AKTion gegen Krebs gUG
- Founding member responsible for data protection and GDPR compliance.
- Developed and maintain the organization's backend systems.
- Planning and implementing AI-supported workflows for case management.
- Responsible for IT security strategy and risk management.
- Established GDPR-compliant data protection framework from the ground up.
AI Training Platform & AI Tools Evaluation
DEGIT AG
- Design and implementation of an internal AI training platform for corporate use, focusing on compliance with the EU AI Act and practical enablement of teams.
- Evaluation and decision paper comparing leading AI and automation platforms with regard to data protection, reliability, API integration and governance readiness.
- Evaluation of emerging Agentic AI workflows for multi-step task orchestration and their integration into enterprise automation environments.
- Analyzed and benchmarked: OpenAI ChatGPT, OpenAI Open-Weight GPT-OSS, Microsoft Copilot, Perplexity, Anthropic Claude, Apple Foundation, z.AI GLM, n8n, make.com, Zapier.
Code Review & Security Advisory
GEHR Datentechnik GmbH
- Comprehensive code review of the existing PHP application with a structured assessment of critical, medium and low-severity issues.
- Creation of a detailed review document including technical findings, recommended remediation steps, and prioritization for development teams.
- Consulting on application and infrastructure security with a focus on practical improvements, secure coding patterns and operational hardening.
- Support during the implementation phase to fix identified issues and improve overall application resilience.