Stefan Lohr
I am a professional with an entrepreneurial spirit. My excellent expertise and broad professional experience enable me to make well-considered and realistic decisions, even in complex and difficult situations.
Work Experience
Cybersecurity Cloud Topic Owner / Senior Key Expert Cloud Services
I work on strategic topics for Siemens AG in close collaboration with all the business units and internal audit. Identifying trends and prioritize them for Cybersecurity in alignment with IT Governance. I act as single point of contact for cloud security for our management, cybersecurity community as well as business management.
- Lead Architect: Security Northstar
- Stakeholder management, Customer relations
- zero trust, CASB
- aws, azure, gcp
Cloud Security Architect
In 2014 Siemens started their cloud journey with the CloudFirst@Siemens program, in which I was part of the security project. Part of my achievements was the design of a general network architecture and role model as well as strengthen the DevSecOps teams. After the project ended I still was in very high demand when it came to consulting for big as well as small - but critical - projects in their cloud journey. I organized and held multiple trainings for the cybersecurity community and devops teams.
- aws
- git, gitlab ci, inner source
- terraform, cloud formation, ansible
- trainings: AWS architecture; application design for cloud environments; automate security; proper authentication;
Software Architect / Lead Developer
Also as a Software Architect I joined the Cybersecurity department and was responsible for the cybersecurity dashboard Caremore. Caremore is a service that collects, processes and combines security-relevant information about the important assests of Siemens and makes it availble to the Cybersecurity community in a transparent way. Moreover I was able to convince my management and the datacenter management that we should use a fully automated ci/cd pipeline.
- C#, HTML, JS
- MS SQL Server, TSQL
- git, ci/cd, gitlab ci
- docker, openshift
- oauth2, oidc
- micro services
- Scrum
Software Architect
In the role of an Software Architect and Application Manager I was responsible for a Siemens internal audit application called Multi-Audit-Control Board. In addition to this role I was also nominated as the Security Lead for my department.
- Java, Groovy
- Oracle, PL/SQL, Apex
- OWASP, penetration testing for web applications
- Kanban
Software Architect / Senior Software Developer
The Dräxlmaier Group was in need for a central transport and custom management software and I was given the chance to design and develop a new solution from scrath. this solution was integrated with the order management and the shopfloor management system.
- Java, C#, Delphi, SVN, HTML, JS
- Oracle, PL/SQL
- Technical team lead, Topic Lead for Databases, Delphi
Software Developer
As a developer I was responsible for the internal order management system.
- Delphi
- Oracle, PL/SQL
Projects
Cloud Security Monitoring
The goal of this solution was to combine the cloud provider native security services in one place and integrate this in already existing solutions like reporting, asset management, exception handling as well as vulnerability management.
Cloud Security Project
The goal was to close all identified gaps in the Siemens infrastructure when it comes to cloud computing and establish services that can and will maintain the deliverables.
CloudFirst@Siemens
As part of the security workstream it was our job to make sure that the transition to the cloud was secure, but still viable for the DevOps teams. My main contributions: implement DevSecOps mindset, network architectures, IAM role model.
Long-term Backup
Long-term Backup in central datacenter in near real time with fast read performance to the data.
Miscellaneous
AWS Enterprise User Group
The AWS enterprise user group consists of various german based companies from whom I am the elected leader. Together in this group we address and change a lot of common issues from german companies with the support of AWS. One example would be the IAM Boundaries pushed by this group.
CSSA - Siemens Representative
I represent Siemens in the Cyber Security Sharing & Analytics Group in all workstreams regarding Cloud.
Papers
- 2018 · Co-Author · Siemens Cloud Whitepaper
- 2016 · Core Team Member · Siemens Cloud Security Standard