Interim & fractional IT leadership · Cyprus & remote (EU/DACH)

Johannes Werner · Interim IT Leadership

Interim IT leadership for regulated companies - when stability, compliance or delivery cannot fail.

I step into banking, insurance and healthcare environments to stabilise critical platforms, lead cloud and release programmes, reduce operational risk, and translate technical complexity - including AI and automation decisions - into board-ready execution. Based in Cyprus (EU) - on-island and remote-first.

Cyprus (EU) · on-island & remote Early AI technology background DORA / BaFin ICT-risk-aware
Portrait of Johannes Werner, Interim IT Leadership
Larnaca · Cyprus
15+ years enterprise ITBanking · Insurance · HealthcareEarly AI technology backgroundCloud, reliability & governanceDORA / BaFin ICT-risk-aware delivery
When to bring me in

When IT risk has become business risk

If one of these is happening now, a short conversation is worth it.

  • A critical platform is unstable or hard to operate.
  • A cloud migration or rollout cannot afford downtime.
  • Audit, DORA, BaFin ICT-risk or ISO 27001 pressure is rising.
  • IT leadership capacity is missing or overloaded.
  • Vendors, internal teams and delivery streams need control.
  • The board needs a clear technical decision path.
  • Incidents, releases or restore times are no longer acceptable.
  • AI or automation decisions need a grounded reality check.
How I can help

Three ways to bring me in

Senior IT leadership packaged for regulated, business-critical environments. Every engagement can include a grounded, hype-free view on AI and automation.

Interim IT Leadership

Interim Head of IT / IT Director

Immediate senior IT leadership: operational control, vendor coordination, delivery governance and board-ready reporting - plus grounded guidance on AI, automation and emerging-technology decisions.

  • Leadership coverage without long ramp-up
  • Clear technical priorities
  • Vendor & stakeholder alignment
  • Board-level reporting

Critical Platform Stabilisation

Reliability, incidents & release control

Stabilisation of business-critical platforms: incident patterns, monitoring, backup and recovery, and release control - including where automation can safely reduce manual effort and incident load.

  • Higher availability
  • Faster incident recovery
  • Stronger monitoring & restore
  • Reduced operational risk

Regulated IT Delivery & Audit Readiness

DORA · BaFin ICT-risk · ISO 27001

Governance and delivery for banking, insurance and healthcare: audit readiness, technical governance, secure rollout and M&A IT risk - including governance of AI-enabled systems, data handling and auditability.

  • Stronger audit readiness
  • Fewer findings
  • Better delivery governance
  • Clear risk documentation
Selected outcomes

Proof from regulated, business-critical environments

Selected engagements, shown the way I brief a board: situation, risk, action, result.

rakitin@career:~ · status --:--:-- CY
Uptime posture
Green
Built for high availability
Focus
Regulated
Banking · insurance · healthcare
Experience
15+yrs
Enterprise IT & architecture
Engagement
Interim
Fractional & mandate-based
ALL SYSTEMS OPERATIONAL high-availability delivery
Case studies
01 / MIGRATION

Large-scale cloud migration for a regulated insurer

Situation
A mission-critical insurance platform (Guidewire) serving a large regulated user base had to move to the cloud without disrupting the business.
Risk
Downtime, failed adoption, operational instability and supervisory exposure across several business units.
Action
Led release engineering, system-wide load testing and delivery governance aligned to ICT-risk and operational-resilience expectations.
Result
Migration delivered with minimal disruption and measurable platform performance improvement.
Why it mattered
The insurer modernised a core platform without interrupting business-critical operations.
GuidewireInsuranceCloudGovernance
02 / REGULATED

Securitisation platform in a BaFin-regulated bank

Situation
A German bank needed a securitisation platform delivered from DEV to PRD under ICT-risk and operational-resilience requirements.
Risk
Regulatory findings, insecure rollout and uncontrolled vendor and provisioning activity.
Action
Coordinated a high volume of provisioning and deployment requests and directed vendors across AD, CyberArk, Citrix and MS SQL, with end-to-end testing enforced.
Result
Secure rollout delivered, with fewer audit findings and fewer deployment issues at go-live.
Why it mattered
The bank shipped a regulated platform with controlled risk and a defensible audit trail.
BaFinBankingServiceNowGovernance
03 / RELIABILITY

Reliability & data protection for healthcare platforms

Situation
Acting as Head of IT for a healthcare group, the business depended on sensitive, high-availability platforms.
Risk
Data loss, slow recovery and unacceptable incident and restore times.
Action
Owned a data-protection and reliability roadmap - backup and recovery, infrastructure-as-code automation and monitoring.
Result
Sustained strong production stability, with materially faster recovery and restore and substantially less manual effort.
Why it mattered
Clinical and operational services stayed available and recoverable.
HA / DRHealthcareIaCMonitoring
04 / ADVISORY

M&A technology due diligence & target architecture

Situation
An acquisition needed a clear technology view before and after the deal.
Risk
Hidden technical debt, integration risk and post-merger surprises.
Action
Ran technology due diligence and defined target architecture and an integration roadmap across regulated industries.
Result
Leadership had a board-ready view of risk, cost and integration sequence.
Why it mattered
The deal team could act on a grounded technical assessment, not assumptions.
M&ADue diligenceStrategy
Flagship engagements

Where I've made the difference

Selected mandates across regulated and high-availability environments. Step through, or open the full history below.

Full history
  • 2022 - Present Independent Interim IT Leadership & Consulting Regulated-industry clients Europe · Remote
    • IT Lead Consultant, healthcare group - high availability, DR & data-protection roadmap
    • Cloud migration & release lead, insurance - Guidewire to cloud with minimal disruption
    • Senior DevOps, regulated banking - BaFin-regulated securitisation platform
    • Senior infrastructure architect - HA/DR & ISO 27001 audit readiness
    • Technology M&A - due-diligence & target architecture across regulated sectors
  • 2020 - 2022 Team Lead, Product Owner & IT Backend Manager FIL Fondsbank (Fidelity Group) Germany
    • Product Owner & Team Lead for core software CFM (6-person team); high straight-through processing
    • Chief Release Manager - versioning, supplier coordination and budget control
    • Directed DIAMOS-D core-banking backend, 24/7 availability, ITIL incident/problem mgmt
  • 2018 - 2019 Data Warehouse & CI/CD Engineer EXXETA (Consultant @ DB Systel) Germany
    • Built & ran an Oracle DWH (UC4, PL/SQL) with high data accuracy
    • CI/CD pipelines (Jenkins, PowerShell, Shell) - materially fewer deployment errors
  • 2014 - 2017 Working Student, IT Goethe University Frankfurt Germany
    • Internal databases & sites (PHP/MySQL) across 5+ departments; IT support & training
  • 2009 - 2013 Early IT roles & internships DB Netz, DekaBank, DVAG Germany
    • Enterprise banking & infrastructure exposure; DB management, troubleshooting, documentation
Capabilities

What I bring to the table

A stack built for regulated, high-availability environments - from strategy and governance down to the pipelines.

01 Leadership & Strategy

Platform OwnershipRelease GovernanceAudit ReadinessIncident MgmtChange MgmtVendor MgmtIT Strategy

02 Cloud & Infrastructure

OpenShiftKubernetesAWS/GCP/AzureContainerisationInfra StrategyMulti-Cloud

03 Reliability & Security

SplunkZabbixActive DirectoryPrometheusGrafanaSecure Data ExchangeKerberosCyberArkHA/DR/BackupScheduling

04 Automation & Delivery

DevSecOpsGitOpsRelease AutomationBashPowerShellCI/CDJenkinsGitLabMavenIaC Mindset
AI & emerging technology

AI Governance Without Theatre

AI earns its place in a regulated business only when the systems around it are reliable, secure, observable and auditable. That intersection is where I work: a senior infrastructure and platform architect who also designs and builds modern AI systems hands-on - so the technology reaches production without becoming the next audit finding.

I treat AI as an engineering and governance problem, not a demo. I assess where models genuinely add value, design the data flows, guardrails and evaluation around them, and give leadership a clear-eyed read on risk, cost and control - the same discipline I bring to any business-critical platform.

  • LLM & RAG systems, built for productionRetrieval-augmented and LLM-backed systems with grounding, evaluation and fallbacks - engineered, not prompt-and-pray.
  • AI governance & model riskControls, policies and documentation that hold up to DORA / BaFin-style ICT-risk and auditability expectations.
  • Data protection by designTraining, retrieval and inference paths kept minimised, compliant and traceable end to end.
  • Vendor-independent by defaultModels chosen and integrated without lock-in, with a routing layer that keeps cost and control in-house.
  • Observability & evaluationMonitoring for quality, drift and cost so an AI feature stays trustworthy long after launch.

I've followed this field since a dedicated Artificial Intelligence course in my computer-science studies (2015/16) - well before the hype - and have watched it mature from the infrastructure, security and governance side, not the vendor stage.

Engagement model

How I typically engage

I work with regulated and business-critical IT environments where leadership, stability and execution need to improve quickly.

Typical mandates

  • Interim Head of IT / IT Director
  • Fractional IT leadership
  • Critical platform stabilisation
  • Regulated cloud & release programme leadership
  • M&A IT due diligence & integration roadmap
  • Audit readiness & technical governance

Typical setup

  • Remote-first from Cyprus (EU)
  • On-site workshops in DACH / EU when needed
  • 3–12 month mandates, extendable
  • Fast onboarding into regulated environments
  • Board, vendor & engineering communication included
Credentials

Certified, multilingual, well-rounded

Certifications & education

  • RE Requirements Engineering (IREB CPRE FL)
    iSQI
  • PO Scrum Product Owner (PSPO I)
    Scrum.org
  • SM Scrum Master (PSM I)
    Scrum.org
Studies in Information Technology
Computer Science & IT Systems
Frankfurt University of Applied Sciences
2012 - 2019 · Frankfurt, Germany

Languages

German Native (C2)
English Full professional (C1)
Greek Elementary (A1)

Beyond work

Outside work I train strategic thinking, resilience and precision - through Go, martial arts and endurance sport.

References

Trusted by the people I've delivered for

In their own words - leaders and clients across regulated banking, insurance and infrastructure.

Delivered for
He is characterised by his strong analytical mindset, problem-solving skills and quick grasp - an excellent team player who is able to motivate and inspire others.
Head of IT Operations & Governance Baloise Insurance
His proactive approach and innovative solutions were invaluable to the team. I fully recommend him for any role that requires a skilled and experienced Senior DevOps Manager.
Client reference ING · securitisation project Banking · Regulated
In his commitment Johannes is exemplary: he goes well beyond what is expected and delivers visible added value for the bank.
Managing Director FIL Fondsbank · Fidelity Group Fund banking
Even for the most difficult problems he found very good solutions after only a short onboarding, and consistently achieved excellent results.
Senior Manager EXXETA · Consultant @ DB Systel Consulting
Clever, creative, solution-oriented, strong-willed, focused […] your perspective is challenging and refreshing in equal measure.
Regional Director DVAG · Deutsche Vermögensberatung Consulting
What stands out is his ability to find optimal solutions. […] His performance always met our high expectations in the best possible way.
Head of Technology Principles DB Netz AG · Deutsche Bahn Infrastructure
His humor and empathy quickly earned him a place in the team - colleagues like to come to him for advice. […] Working with Johannes was always a real pleasure, as I learned a great deal from our conversations myself.
Managing Director Officium21 Healthcare
Even under heavy workload, Mr. Werner proved highly resilient, always working in a considered, calm and focused manner. […] We were extremely satisfied with his performance at all times.
Head of the Center for Psychotherapy Goethe University Frankfurt University
He consistently demonstrated the ability to translate technical complexity into clear business decisions, risk-based priorities and pragmatic execution plans.
Managing Director HR Navix · Cyprus Infrastructure
RAKITIN decoded
RA Rapidly Adapting
KIT Keeping It Tailored
IN Innovating Now
Good questions

What clients ask before we start

Do you work on-site or remotely?

Based in Cyprus (EU) and remote-first, working across EU and DACH time zones. I come on-site in DACH or the EU for workshops, go-lives and board sessions when it genuinely helps - but most delivery runs remotely, with no loss of control.

How quickly can you start?

Fast. Engagements are built for rapid onboarding into regulated environments - usually within days, not the weeks or months a permanent hire needs. That is the point of interim leadership: senior coverage exactly when the capacity is missing.

How long is a typical engagement?

Most mandates run three to twelve months and are extendable, each scoped to a clear outcome - a stabilised platform, a delivered migration, audit readiness. No long lock-in: you keep the leverage and renew only if it is working.

How do you charge?

On a day-rate or fixed-mandate basis depending on scope, agreed up front with no hidden extras. Interim leadership costs a fraction of an unstable platform, a failed audit or a mis-hire - and you carry none of the long-term employment overhead.

How do you handle confidentiality and regulated data?

As the baseline, not an afterthought. I work inside banking, insurance and healthcare under NDA, with DORA, BaFin ICT-risk and ISO 27001 expectations built into how I operate from day one.

How do we know it is the right fit?

Start with a free 30-minute check-up. You will leave with an honest, no-theatre view on whether and how I can help - and if I am not the right fit, I will say so and point you in a better direction.

Take it with you

Downloads

Take the profile or full CV with you - or request the complete dossier and I'll send it straight to your inbox.

Most requested

Full dossier

CV, reference letters and certificates - the complete picture, sent securely to your inbox.

Request the dossier

One-page profile

The 60-second executive overview.

Download PDF
Next step

Discuss your IT leadership or platform risk

If your organisation is facing platform instability, audit or DORA/BaFin pressure, migration risk or an IT-leadership gap, book a free 30-minute check-up. You'll leave with a clear, honest view on whether and how I can help - no sales theatre. Based in Cyprus (EU); remote across the EU and DACH.

Free check-up