Information Security Officer

Security & Infrastructure

David
Lahoz.

I build and run the security function for a six-entity group — ISO 27001-aligned governance, awareness programs that actually change behavior, and incident response that holds up under audit. IT must be an enabler, not a bottleneck.

David Lahoz
10+
years in IT & security
06
entities under governance
ISO27001
aligned practice
06
languages spoken
01

About

Originally from Barcelona, based in Munich since 2021. Over a decade of hands-on IT — from Windows Server rooms to multi-entity cloud governance — before moving into the security office. I specialize in making security programs that people can actually live with: stable, scalable, and measured against real standards rather than checkbox theater.

Firm believer that every office
should have a dog. Or a small pack.

02

Experience

Nov 2025 — Present

Information Security Officer

pure11 GmbH (Dastex Group)

  • Stood up information security governance covering all six Dastex Group entities, aligned with ISO 27001 — one standard for the whole group instead of six local practices.
  • Run the group's security awareness program end to end — recurring phishing simulations and training, with results tracked campaign over campaign.
  • Own risk assessment, incident response, and access-control policy across the group's Microsoft 365 and hybrid environments.
  • Advise executive management directly on cybersecurity strategy, policy frameworks, and audit readiness — the group's single accountable owner for information security.
Risk AssessmentIncident ResponseSecurity AwarenessCompliance
Mar 2024 — Nov 2025

IT Manager

pure11 GmbH (Dastex Group)

  • Brought six newly acquired entities onto one IT and security standard — consolidated infrastructure, with MFA and Conditional Access rolled out group-wide — co-owning policy governance with executive leadership.
  • Defined and executed the group's unified post-acquisition IT strategy, from strategic planning to hands-on implementation.
  • Automated recurring IT work across business units, cutting day-to-day operational workload for the team.
Microsoft 365Conditional AccessAutomationGovernance
Feb 2022 — Mar 2024

System Administrator

Stryber

  • Delivered the company-wide MDM migration to Kandji, bringing the entire international Mac fleet in line with CIS benchmarks.
  • Regional IT lead supporting global offices (Dubai, Singapore, Kyiv, Zurich, Valencia, Munich).
macOSKandji (MDM)CIS BenchmarksGoogle Workspace
Mar 2021 — Feb 2022

System Administrator

Grifols

  • Administered Citrix, VMware, and Windows Server environments; retired End-of-Support infrastructure and delivered cross-border deployments through a post-acquisition integration.
CitrixVMwareWindows Server
Jun 2018 — Jun 2020

Solutions Engineer

char desarrollo de sistemas

  • Technical pre-sales for PBX middleware solutions — demos, proof-of-concepts, and deployment alignment for enterprise and hospitality clients.
PBXVoIPPre-Sales
Jul 2010 — May 2018

System Administrator

Abertis

  • Windows Server administration, lifecycle management, and internal audit support across business units.
Windows ServerAuditingLifecycle Management
03

Skills

Operating Systems & Platforms

WindowsmacOSLinux (basic)VMware

Cloud & Identity

Microsoft 365Entra IDExchange Online

Cybersecurity & Governance

Conditional AccessCIS ControlsIT PolicyAccess Standards

Device Management

IntuneKandjiApple Business Manager

ITSM & Automation

Jira SMWorkflow AutomationAsset LifecycleSLA Monitoring
04

Education & Languages

2020 — 2022

Associate Degree in Systems and Network Administration

La Salle Gràcia, Spain

2007 — 2009

Associate Degree in IT Systems Operations

Salesians de Sarrià, Spain

Catalan (Native)Spanish (Native)English (Fluent)French (Intermediate)German (Basic)Italian (Basic)
05

Contact

Let's talk.

The form goes straight to my inbox and is Turnstile-protected — bots need not apply.

Prefer LinkedIn?
0/500