Iulian Datcu/ Security · DevSecOps · AI Governance Start a conversation

Available for freelance-first engagements — Luxembourg & EU

Four disciplines.
One operating picture.

Cybersecurity defines the controls. DevSecOps automates them into repeatable, auditable pipelines. AI sharpens analysis and operations. Process governance connects it all to business outcomes. I deliver the four as one system — for organisations where security has to hold up in front of an auditor, a regulator and a board.

Enquiries receive a reply within 1–2 business days.

Iulian Datcu professional portrait

AVAILABLE / freelance-first / hybrid / remote

EST. 2004Evidence
on file
Luxembourg
20+ yrsprogressive technical leadership
Luxembourgon-site · hybrid · remote
EN · FR · ROC2 · C1 · native
DORA · NIS2 · EU AI Actreadiness to evidence
Delivery record BNP Paribas Securities ServicesING LuxembourgAXA LuxembourgCyber Solutions LuxembourgAmCham Luxembourg
01

The operating model

Most consultancies sell these as four separate practices. In regulated delivery they only work as one.

I. Cybersecurity

Threat detection and vulnerability management, EDR/XDR review, security operations, SOC implementation, incident response, Zero Trust and audit readiness.

Detect · Assess · Respond

II. DevSecOps

Automation, CI/CD security, infrastructure as code, Kubernetes/OpenShift, cloud security, GitOps and continuous compliance — controls as running code.

Build · Secure · Scale

III. AI & Process

AI risk analysis, LLM guardrails, RAG/LLMOps, BPMN/ARIS modeling, RACI, SIPOC, process mining and automation — adoption with oversight built in.

Model · Automate · Govern AI

IV. Governance & Resilience

DORA, NIS2, MiCA, EU AI Act, ICT risk, operational resilience, KPI/KRI and control mapping, DR and crisis exercises — evidence a regulator accepts.

Govern · Evidence · Recover

02

The profile

Iulian Datcu started in technology the hard way: at 18, co-founding an internet service provider that grew into web, VPS and dedicated hosting — where security wasn't a slide, it was whether customers stayed online. Twenty years later, the through-line hasn't changed: build systems that hold, and be able to prove it.

My route then took me through group-CTO responsibility at an international contract-management organisation and more than a decade inside Luxembourg's regulated financial core. I led configuration and release governance, built an automation capability and delivered DevSecOps across a production Linux estate, including Cybereason EDR with custom tooling.

Since 2024 I run an innovation startup focused on taking regulated organisations from DORA, NIS2, MiCA and EU AI Act requirements to working controls and auditable evidence. I also build practical, local AI systems with governance designed in, not bolted on. Alongside client work, I have served as voluntary CTO of AmCham Luxembourg since 2018, where I co-founded the Cybersecurity Committee and serve on the AI Committee.

I work in English (C2), French (C1) and Romanian (native). I am an EU citizen and Luxembourg permanent resident with full work authorisation; no sponsorship is required.

03

The evidence

Outcomes carry more weight than adjectives. A selection, from the record:

42min

Deployment cycle, down from 6–12 hours

Deployment automation expanded to 95% coverage across delivery and testing workflows. The full deployment and validation cycle became repeatable, auditable and materially faster for release teams.

Funds
Industry
4months

First automation squad, 90% automation

Automation Management System delivered in four months; infrastructure moved from local to hybrid to Azure. The model connected automation, infrastructure transition and operational governance while reducing manual delivery handoffs.

Financial
Systems
SOC2

Security governance across a production Linux estate

SOC2 implementation, vulnerability management, CIS benchmark reviews, RHEL Satellite, DORA readiness and implementation, and custom Cybereason EDR tooling in production. The work connected endpoint telemetry, baseline reviews and remediation evidence to production resilience.

Insurance
Market
~97%

Legal research workflow automated, EU AI Act-aligned

Fully local agentic AI system for document review and legislation research — plus cloud-agnostic AKS/containerisation delivery for production clients. The approach combines local processing, controlled data handling and traceable outputs for sensitive research workflows.

Innovation
Startup
24/7

Infrastructure scaled and operated across four locations

From ~40 to 60+ physical servers and ~120 VMware VMs as group CTO, with round-the-clock support operations. The operating model combined infrastructure growth, service continuity and practical management accountability.

Technology
Systems
2018→

Voluntary CTO, Cybersecurity Committee co-founder, AI Committee member

Technology stewardship, vendor management and cyber/AI governance awareness for a 500+ member business community.

AmCham
Luxembourg
04

Ways of working

Advisory

Assessments, architecture reviews, regulatory gap analysis and prioritised roadmaps you can defend in front of an auditor.

Hands-on delivery

Implementation in production — detection, automation, hardening, platform and pipeline work. Not slideware.

Management solutions

KPI/KRI frameworks, control mapping, evidence programmes and process transformation connected to business outcomes.

CISO-as-a-Service

Interim and part-time security leadership support for organisations that need the function before the full-time hire.

Method
  1. Framethe real constraint, risk appetite and available evidence
  2. Prioritisegaps into an accountable, measurable sequence
  3. Deliverhands-on, automating the manual as we go
  4. Provewith KPI/KRI, reporting and a clear audit trail
05

The working stack

Selected for the delivery context, not displayed as a keyword wall.

Security operations
Cybereason EDR (production, incl. custom tooling) · ELK / Elastic Security · Qualys · MITRE ATT&CK · EDR review experience: Cisco Secure Endpoint, Sophos Intercept X/XDR, Trellix EDR/XDR
DevSecOps & cloud
Azure · AWS · GCP · Kubernetes / AKS · OpenShift/OKD · Terraform · Ansible · Helm · GitLab · ArgoCD · GitOps
Governance & resilience
DORA · NIS2 · MiCA · EU AI Act · GDPR · SOC2 · CIS · Zero Trust · ISO-aligned controls · KPI/KRI · ICT risk
Observability & data
Prometheus · Grafana · ELK · Thanos · Keycloak · PostgreSQL · MongoDB · S3 · Python
Also in the toolbox
Docker · Rancher · VMware · OpenStack · KubeVirt · Red Hat · SonarQube · Nexus/Artifactory · Robot Framework · Cucumber · TestLink · Mule
06

Before you write

What kind of engagements do you take?

Freelance-first: advisory, hands-on implementation, management solutions and CISO-as-a-Service support. Long-term missions and interim mandates are both welcome — on-site in Luxembourg, hybrid or remote.

Which regulations do you work with?

DORA, NIS2, MiCA, the EU AI Act, GDPR, SOC2 and CIS-aligned control frameworks — translated into working technical controls and audit evidence, not just documentation.

What should my first email include?

Engagement type, expected duration, location model and one paragraph of context. That's enough for a useful first reply — normally within 1–2 business days. Rates are discussed directly.

Do you work outside Luxembourg?

Yes — hybrid or remote across the EU. EU citizen, Luxembourg permanent resident, full work authorisation: no sponsorship required.

Bring the constraint.
Leave with a clearer path.

One conversation is usually enough to tell whether I can help. If I can't, I'll say so.

Email iulian@datcu.email Connect on LinkedIn ↗ Capability brief (PDF) ↓

Hesperange, Luxembourg · on-site / hybrid / remote
Reply within 1–2 business days