Lead Software Architect at Mercedes-Benz Group AG - IT Communication & Legal
Our Center of Competence (CoC) IT eDiscovery,
Corporate Data Protection &
ISO, together with other teams, looks after the Integrity and Legal
(IL) board department with a focus on electronic discovery,
data privacy, and information security.
The implementation of my tasks and those of our team also takes
place in close coordination with other IT support teams for IL. In
addition, our team also has responsibility for the Information
Security Officer (ISO) functions at headquarters, as well as the
Information Security Architect (ISA) function at ITP.
As technical leader within ITG/CL, I act
as an intermediary between
internal and external stakeholders and use my expertise to
support our departments in requirements analysis, the development of
solution concepts and the implementation of information security requirements
and, as technical lead, coordinate planning, software development and
operation of new and ongoing IT projects. My tasks are
performed in coordination with the digital strategy of the
respective department or the overarching corporate IT strategy. At
the same time, I provide active input to my team for the
digitization of departmental processes and point out improvements
and opportunities in the digital working world of
Mercedes-Benz.
I also ...
- Lead development teams and manage external suppliers for the digitization of the group-wide Records of Processing Activities (RoPA)1 as well as the global Privacy Management Application (PrIMA)2. My duties include 1) ownership of all technical topics during the software lifecycle, including adherence with information security and data protection requirements, budget management, and procurement of infrastructure, 2) architecture design of interactions and implementation between applications, 3) elaboration of requirements into our existing IT landscape, and 4) outline technical requirements, API design and procurement of infrastructure.
- Support various investigation processes within the scope of the corporate Forensics Center in cooperation with the corporate security team and the investigating units (including CA, Legal, HR). In this context, as IT Case Manager, I act as the central coordination function within the global IT and ensure that necessary data is secured and made available worldwide in a legally required manner.
- Ensure the operation of the Custodian Administration Tool (CAT)3 in the eDiscovery IT landscape. In particular, the implementation of the necessary flagging of the custodians in the directory as well as the automated communication with the custodians to ensure compliance with legal requirements on my own responsibility.
- Provide technical specifications (patching of the IT landscape, as well as access protection). If required, I also support other project managers in their project for a successor solution of the current legal and corporate data privacy software.
- Establish further development of the internal eDiscovery and data protection and compliance IT landscape including forensic hardware and software with my colleagues.
- Prepare presentations for top management and create (technical) software documentations for cooperating business units.
- Take on the role of Security Champion and support information security related audits and penetration testing.
Achievements
- As technical owner, I supported the 2021 company-wide Automated Data Deletion4 including more than 330 entities worldwide. I successfully pushed and managed the implementation of the central Exception Management Tool (AVT)5 for our Corporate Data Protection (CDP) team.
- Thanks to the can-do attitude and goal-driven work with colleagues from Corporate Security, I was able to roll-out our Forensic Management System (eForensics)6 in only 2.5 months from start to production. I am glad that together with the business unit we mastered the project in such a short time with all the hurdles and were able to go live as planned in November 2021.
- In order to validate my proficiency in eDiscovery, adding more value to our organization, and distinguish myself in the industry, I successfully attended trainings in case administration, processing, active learning and analytics with Relativity7.
- I successfully pitched my projects to our CIO and the works council.
- Being a PhD candidate, I've published several scientific papers in leading journals on automotive cybersecurity, artificial intelligence, and intrusion detection.
- More to come. :)
2 Privacy Incident Management Application (PrIMA): Group-wide solution to raise, track, and manage potential data protection incidents.
3 Custodian Administration Tool (CAT): End-to-end management tool of custodian related activities.
4 Experience shows that data in companies is often stored for indefinite periods and is never deleted if there is no regulation limiting the storage period. Often, much of this data is no longer needed or rapidly becomes obsolete. This leads to a continuous increase in the total volume of data stored on the servers as well as an increase in costs – not only due to the storage capacity required but also to data management. The huge amount of data also interferes with performance of the IT systems and efficient workflows. Furthermore, in the case of personal data, data protection regulations – such as the EU’s GDPR – require that such data may only be stored as long as is necessary for the respective purpose.
5 Ausnahmeverwaltungstool (AVT): Successor of the group-wide data retention to manage the retention process (identification of fileshares and SiteCollections (SharePoint) and requesting exceptions). AVT is a .NET tool, partly hosted as Application Consolidation (ApCos) Microsoft Service.
6 Forensic Management System (eForensics): Python-based (Django framework) application hosted as Software-as-a-Service (SaaS). eForensics is used for managing and documenting of IT forensic investigations, as well as collections and imaging of evidence items.
7 Relativity is a complete eDiscovery platform that helps legal teams solve complex data problems during litigation, investigation, and compliance projects. It comes with a set of tools executing on each step of the process on-premise and in the cloud.
