I. Cybersecurity
Threat detection and vulnerability management, EDR/XDR review, security operations, SOC implementation, incident response, Zero Trust and audit readiness.
Detect · Assess · Respond
Available for freelance-first engagements — Luxembourg & EU
Cybersecurity defines the controls. DevSecOps automates them into repeatable, auditable pipelines. AI sharpens analysis and operations. Process governance connects it all to business outcomes. I deliver the four as one system — for organisations where security has to hold up in front of an auditor, a regulator and a board.
Enquiries receive a reply within 1–2 business days.

AVAILABLE / freelance-first / hybrid / remote
Most consultancies sell these as four separate practices. In regulated delivery they only work as one.
Threat detection and vulnerability management, EDR/XDR review, security operations, SOC implementation, incident response, Zero Trust and audit readiness.
Detect · Assess · Respond
Automation, CI/CD security, infrastructure as code, Kubernetes/OpenShift, cloud security, GitOps and continuous compliance — controls as running code.
Build · Secure · Scale
AI risk analysis, LLM guardrails, RAG/LLMOps, BPMN/ARIS modeling, RACI, SIPOC, process mining and automation — adoption with oversight built in.
Model · Automate · Govern AI
DORA, NIS2, MiCA, EU AI Act, ICT risk, operational resilience, KPI/KRI and control mapping, DR and crisis exercises — evidence a regulator accepts.
Govern · Evidence · Recover
Iulian Datcu started in technology the hard way: at 18, co-founding an internet service provider that grew into web, VPS and dedicated hosting — where security wasn't a slide, it was whether customers stayed online. Twenty years later, the through-line hasn't changed: build systems that hold, and be able to prove it.
My route then took me through group-CTO responsibility at an international contract-management organisation and more than a decade inside Luxembourg's regulated financial core. I led configuration and release governance, built an automation capability and delivered DevSecOps across a production Linux estate, including Cybereason EDR with custom tooling.
Since 2024 I run an innovation startup focused on taking regulated organisations from DORA, NIS2, MiCA and EU AI Act requirements to working controls and auditable evidence. I also build practical, local AI systems with governance designed in, not bolted on. Alongside client work, I have served as voluntary CTO of AmCham Luxembourg since 2018, where I co-founded the Cybersecurity Committee and serve on the AI Committee.
I work in English (C2), French (C1) and Romanian (native). I am an EU citizen and Luxembourg permanent resident with full work authorisation; no sponsorship is required.
Outcomes carry more weight than adjectives. A selection, from the record:
Deployment automation expanded to 95% coverage across delivery and testing workflows. The full deployment and validation cycle became repeatable, auditable and materially faster for release teams.
Automation Management System delivered in four months; infrastructure moved from local to hybrid to Azure. The model connected automation, infrastructure transition and operational governance while reducing manual delivery handoffs.
SOC2 implementation, vulnerability management, CIS benchmark reviews, RHEL Satellite, DORA readiness and implementation, and custom Cybereason EDR tooling in production. The work connected endpoint telemetry, baseline reviews and remediation evidence to production resilience.
Fully local agentic AI system for document review and legislation research — plus cloud-agnostic AKS/containerisation delivery for production clients. The approach combines local processing, controlled data handling and traceable outputs for sensitive research workflows.
From ~40 to 60+ physical servers and ~120 VMware VMs as group CTO, with round-the-clock support operations. The operating model combined infrastructure growth, service continuity and practical management accountability.
Technology stewardship, vendor management and cyber/AI governance awareness for a 500+ member business community.
Assessments, architecture reviews, regulatory gap analysis and prioritised roadmaps you can defend in front of an auditor.
Implementation in production — detection, automation, hardening, platform and pipeline work. Not slideware.
KPI/KRI frameworks, control mapping, evidence programmes and process transformation connected to business outcomes.
Interim and part-time security leadership support for organisations that need the function before the full-time hire.
Selected for the delivery context, not displayed as a keyword wall.
Freelance-first: advisory, hands-on implementation, management solutions and CISO-as-a-Service support. Long-term missions and interim mandates are both welcome — on-site in Luxembourg, hybrid or remote.
DORA, NIS2, MiCA, the EU AI Act, GDPR, SOC2 and CIS-aligned control frameworks — translated into working technical controls and audit evidence, not just documentation.
Engagement type, expected duration, location model and one paragraph of context. That's enough for a useful first reply — normally within 1–2 business days. Rates are discussed directly.
Yes — hybrid or remote across the EU. EU citizen, Luxembourg permanent resident, full work authorisation: no sponsorship required.
One conversation is usually enough to tell whether I can help. If I can't, I'll say so.