P. ZIMMERMANN
STATUS: SECURING SYSTEMS

Patrick Zimmermann

Information Security Specialist

I'm passionate about information security and bring broad expertise across security management, product security, and data privacy. Over the past years I've built and led security functions within multinational companies, spanning both manufacturing and agile cloud-first environments.

Focus areas

01
ARCHITECTURESecurity Management & Architecture — building ISMS structures, governance, and policy frameworks that scale across large organizations.
PRODUCTProduct Security & Secure Development — embedding security into engineering and CI/CD pipelines, aligned with standards such as IEC 62443.
DEFENSECyber Defense & Security Operations — detection engineering, incident response, and SOC capability building.
CLOUDCloud Security — governance and architecture for cloud-first environments.
RISKVulnerability Management — attack surface monitoring, vulnerability disclosure, and bug bounty programs.
OT/ICSOT / Industrial Security — securing operational technology in manufacturing environments.
COMPLIANCEData Privacy & Compliance — GDPR readiness, ISO 27001 certification, and audit management.
DELIVERYAgile Frameworks — driving security work through Scrum and SAFe in agile organizations.

Experience

02
2018 — NOW

Expert Information Security Specialist

Bühler AG

Built the company's ISMS and led it to ISO 27001 certification. Leads product security, including a global IEC 62443-aligned product security framework and the vulnerability disclosure program, and contributes to SOC detection engineering and phishing defense. As part of the Agile Transformation Team, supported the global IT function adopt agile working principles and acts as Scrum Master for the cybersecurity team.

2017 — 2018

Security Engineer / Head of Information Security a.i.

siroop AG

Built the information security function from the ground up, including policies, GDPR readiness, and CI/CD security integration. Ran security awareness training and phishing simulations, set up incident management, and coordinated external security reviews and penetration tests.

2012 — 2016

IT Security Analyst

Sulzer Management Ltd.

Worked closely with the CISO to establish the information security organization, covering policies, audit concept, and risk management framework. Led security audits, vulnerability scanning, and incident management, and took on interim responsibility for information security before serving as deputy to the CISO.

2011 — 2012

System Administrator / Engineer

Sulzer Management Ltd.

System administration and engineering for an infrastructure of 500 servers and 12,000 users.

2007 — 2011

Client Support & System Administration

Sulzer Chemtech Ltd.

Technical lead for client management and user support across 1,200 employees in EMEA.

Certifications

03
CISSP CCSP CCSK CompTIA Security+ ISO 27001 Lead Auditor COSTE — OT Security Data Protection Officer (Swiss InfoSec) PSM I SPC