Stefan Lohr

Cloud Security Expert

image

I am a professional with an entrepreneurial spirit. My excellent expertise and broad professional experience enable me to make well-considered and realistic decisions, even in complex and difficult situations.


Work Experience

Cybersecurity Cloud Topic Owner / Senior Key Expert Cloud Services

Siemens | 2019 - present

I work on strategic topics for Siemens AG in close collaboration with all the business units and internal audit. Identifying trends and prioritize them for Cybersecurity in alignment with IT Governance. I act as single point of contact for cloud security for our management, cybersecurity community as well as business management.

  • Lead Architect: Security Northstar
  • Stakeholder management, Customer relations
  • zero trust, CASB
  • aws, azure, gcp

Cloud Security Architect

Siemens | 2016 - 2019

In 2014 Siemens started their cloud journey with the CloudFirst@Siemens program, in which I was part of the security project. Part of my achievements was the design of a general network architecture and role model as well as strengthen the DevSecOps teams. After the project ended I still was in very high demand when it came to consulting for big as well as small - but critical - projects in their cloud journey. I organized and held multiple trainings for the cybersecurity community and devops teams.

  • aws
  • git, gitlab ci, inner source
  • terraform, cloud formation, ansible
  • trainings: AWS architecture; application design for cloud environments; automate security; proper authentication;

Software Architect / Lead Developer

Siemens | 2015 - 2019

Also as a Software Architect I joined the Cybersecurity department and was responsible for the cybersecurity dashboard Caremore. Caremore is a service that collects, processes and combines security-relevant information about the important assests of Siemens and makes it availble to the Cybersecurity community in a transparent way. Moreover I was able to convince my management and the datacenter management that we should use a fully automated ci/cd pipeline.

  • C#, HTML, JS
  • MS SQL Server, TSQL
  • git, ci/cd, gitlab ci
  • docker, openshift
  • oauth2, oidc
  • micro services
  • Scrum

Software Architect

Siemens | 2012 - 2015

In the role of an Software Architect and Application Manager I was responsible for a Siemens internal audit application called Multi-Audit-Control Board. In addition to this role I was also nominated as the Security Lead for my department.

  • Java, Groovy
  • Oracle, PL/SQL, Apex
  • OWASP, penetration testing for web applications
  • Kanban

Software Architect / Senior Software Developer

Dräxlmaier Group | 2005 - 2012

The Dräxlmaier Group was in need for a central transport and custom management software and I was given the chance to design and develop a new solution from scrath. this solution was integrated with the order management and the shopfloor management system.

  • Java, C#, Delphi, SVN, HTML, JS
  • Oracle, PL/SQL
  • Technical team lead, Topic Lead for Databases, Delphi

Software Developer

Dräxlmaier Group | 2001 - 2005

As a developer I was responsible for the internal order management system.

  • Delphi
  • Oracle, PL/SQL

Projects

Cloud Security Monitoring

Product Owner / 2020-2021

The goal of this solution was to combine the cloud provider native security services in one place and integrate this in already existing solutions like reporting, asset management, exception handling as well as vulnerability management.

Cloud Security Project

Technical Director / 2018 - present

The goal was to close all identified gaps in the Siemens infrastructure when it comes to cloud computing and establish services that can and will maintain the deliverables.

CloudFirst@Siemens

Core Member / 2015 - 2018

As part of the security workstream it was our job to make sure that the transition to the cloud was secure, but still viable for the DevOps teams. My main contributions: implement DevSecOps mindset, network architectures, IAM role model.

Long-term Backup

Project Manager / 2010-2011

Long-term Backup in central datacenter in near real time with fast read performance to the data.

Miscellaneous

AWS Enterprise User Group

The AWS enterprise user group consists of various german based companies from whom I am the elected leader. Together in this group we address and change a lot of common issues from german companies with the support of AWS. One example would be the IAM Boundaries pushed by this group.

    CSSA - Siemens Representative

    I represent Siemens in the Cyber Security Sharing & Analytics Group in all workstreams regarding Cloud.

      Papers

      • 2018 · Co-Author · Siemens Cloud Whitepaper
      • 2016 · Core Team Member · Siemens Cloud Security Standard