Start a conversation

Available for engagements - Luxembourg & EU

Four disciplines.
One operating picture.

Cybersecurity defines the controls. DevSecOps automates them into repeatable, auditable pipelines. AI sharpens analysis and operations. Process governance connects it all to business outcomes. I bring the four together as one system for organisations that need security to stand up to auditors, regulators and boards today, while remaining scalable and vendor-agnostic over time.

Enquiries receive a reply within 1-2 business days. Advisory and hands-on mandates are delivered through my Luxembourg entity, Cyber Solutions Luxembourg.

Iulian Datcu professional portrait

AVAILABLE / freelance-first / hybrid / remote

EST. 2004Evidence
on file
Luxembourg
20+ yrsprogressive technical leadership
Luxembourgon-site · hybrid · remote
EN · FR · ROC2 · C1 · native
DORA · NIS2 · EU AI Actreadiness to evidence
Delivery record Banking deliveryInsurance securityFunds operationsInnovation startupBusiness association
01

The operating model

Most consultancies sell these as four separate practices. In regulated delivery they only work as one.

I. Cybersecurity

Threat detection and vulnerability management, EDR/XDR review, security operations, SOC implementation, incident response, Zero Trust and audit readiness.

Detect · Assess · Respond

II. DevSecOps

Digitalisation, automation, CI/CD security, infrastructure as code, Kubernetes/OpenShift, cloud security, GitOps and continuous compliance - secure, repeatable delivery with controls as running code.

Build · Secure · Scale

III. AI & Process

AI risk and hazard analysis, LLM guardrails, RAG/LLMOps, BPMN/ARIS modelling, RACI, SIPOC, process mining, and people-and-LLM training - adoption with oversight built in.

Model · Automate · Govern AI

IV. Governance & Resilience

DORA, NIS2, MiCA, EU AI Act, ICT risk, operational resilience, KPI/KRI and control mapping, DR and crisis exercises - evidence a regulator can inspect and accept.

Govern · Evidence · Recover

02

The profile

Iulian Datcu - I started in technology early, driven by a need to understand how things work. At 16, after becoming a victim of identity theft, I went deeper into coding and systems. That experience became the starting point of my cybersecurity journey, taking me through different sides of the field, from early black- and grey-hat exploration to white-hat practice and the discipline of red-team work.

At 18, I co-founded an internet service provider that grew into web, VPS and dedicated hosting - where security was not a slide; it was whether customers stayed online. Around 2008, when the DevOps mindset was emerging, I recognised something familiar: technology should give people time back. I moved into DevOps because automation, repeatability and operational discipline matched the way I already thought about systems.

As technologies matured, I came to see technology, automation and security as one connected cycle. Today, regulation reinforces the same principle: DORA, NIS2, MiCA and the EU AI Act require resilience to be designed, operated and evidenced, not simply documented. The through-line has not changed: build systems that hold, and be able to prove it.

My route then took me through group-CTO responsibility at an international contract-management organisation and more than a decade inside Luxembourg's regulated financial core. I led configuration and release governance, built automation capability and delivered DevSecOps across production estates, including Zero Trust architecture, secure platforms and EDRs with custom tooling.

Since 2024, I run an innovation startup focused on taking regulated organisations from DORA, NIS2, MiCA and EU AI Act requirements to working controls and auditable evidence. I also build practical, local AI systems with governance designed in, not bolted on. Alongside client work, I have served as voluntary CTO of AmCham Luxembourg since 2018.

I work in English (C2), French (C1) and Romanian (native). I am an EU citizen and Luxembourg permanent resident with full work authorisation; no sponsorship is required.

03

The evidence

Outcomes carry more weight than adjectives. A selection, from the record:

42min

Deployment cycle, down from 6-12 hours

Deployment automation expanded to 95% coverage across delivery and testing workflows. The full deployment and validation cycle became repeatable, auditable and materially faster for release teams.

Funds
Industry
4months

First automation squad, 90% automation

Automation Management System delivered in four months; infrastructure moved from local to hybrid to Azure. The model connected automation, infrastructure transition and operational governance while reducing manual delivery handoffs.

Financial
Systems
SOC2

Security governance across a production Linux estate

SOC2 implementation, vulnerability management, CIS benchmark reviews, RHEL Satellite, DORA readiness and implementation, and EDR operations with custom tooling in production. The work connected endpoint telemetry, baseline reviews and remediation evidence to production resilience.

Insurance
Market
~97%

Legal research workflow automated, EU AI Act-aligned

Fully local agentic AI system for document review and legislation research - plus cloud-agnostic AKS/containerisation delivery for production clients. The approach combines local processing, controlled data handling and traceable outputs for sensitive research workflows.

Innovation
Startup
24/7

Infrastructure scaled and operated across 3 data centres

From ~40 local servers to 60+ physical servers and 9 VMware hosts with ~120 VMs across 3 data centres in 3 separate countries as Group CTO, with round-the-clock support operations. The operating model combined infrastructure growth, service continuity and practical management accountability.

Technology
Systems
2018→

Voluntary CTO, Cybersecurity Committee co-founder, AI Committee member

Technology stewardship, vendor management and cyber/AI governance awareness for a 500+ member business community. View the AmCham announcement

Business
association
04

Ways of working

Advisory

Assessments, architecture reviews, regulatory gap analysis and prioritised roadmaps you can defend in front of an auditor.

Hands-on delivery

Implementation in production - detection, automation, hardening, platform and pipeline work. Not slideware.

Management solutions

KPI/KRI frameworks, control mapping, evidence programmes and process transformation connected to business outcomes.

CISO-as-a-Service

Interim and part-time security leadership support for organisations that need the function before the full-time hire.

Method
  1. Framethe real constraint, risk appetite and available evidence
  2. Prioritisegaps into an accountable, measurable sequence
  3. Deliverhands-on, automating the manual as we go
  4. Provewith KPI/KRI, reporting and a clear audit trail
05

The working stack

Selected for the delivery context, not displayed as a keyword wall.

Security operations
Cybereason EDR (production, incl. custom tooling) · ELK / Elastic Security · Qualys · MITRE ATT&CK · EDR review experience: Cisco Secure Endpoint, Sophos Intercept X/XDR, Trellix EDR/XDR
DevSecOps & cloud
Azure · AWS · GCP · Kubernetes / AKS · OpenShift/OKD · Terraform · Ansible · Helm · GitLab · ArgoCD · GitOps
Governance & resilience
DORA · NIS2 · MiCA · EU AI Act · GDPR · SOC2 · CIS · Zero Trust · ISO-aligned controls · KPI/KRI · ICT risk
Observability & data
Prometheus · Grafana · ELK · Thanos · Keycloak · PostgreSQL · MongoDB · S3 · Python
Also in the toolbox
Docker · Rancher · VMware · OpenStack · KubeVirt · Red Hat · SonarQube · Nexus/Artifactory · Robot Framework · Cucumber · TestLink · Mule
06

Before you write

What kind of engagements do you take?

Freelance-first: advisory, hands-on implementation, management and delivery solutions, and CISO-as-a-Service support. Long-term missions and interim mandates are both welcome - on-site in Luxembourg, hybrid or remote.

To whom is your work directed?

My work ranges from practical guidance for individuals who need help with online security, to small companies planning their first digitalisation steps or opening their first office, through to larger organisations with regulatory, SOC and CI/CD requirements. The common thread is a practical, proportionate solution that can be operated and improved.

What solutions do you provide?

Even if you are a small company, you do not need a large consulting structure to make a digital initiative work. I can act as a senior hands-on partner for a digitalisation, process optimisation, AI, SEO or digital-footprint project: define the right scope, select practical tools, automate where it creates value and deliver a cost-effective solution sized to your reality. We can discuss the outcome you need and build the smallest solution that is secure, maintainable and able to grow with you.

Which regulations do you work with?

DORA, NIS2, MiCA, the EU AI Act, GDPR, SOC2 and CIS-aligned control frameworks - translated into working technical controls and audit evidence, not just documentation.

What should my first email include?

Engagement type, expected duration, location model and one paragraph of context. That's enough for a useful first reply - normally within 1-2 business days. Rates are discussed directly.

Do you work outside Luxembourg?

Yes - hybrid or remote across the EU. EU citizen, Luxembourg permanent resident, full work authorisation: no sponsorship required.

Bring the constraint.
Leave with a clearer path.

One conversation is usually enough to understand whether I can help. If I cannot, I will say so.

Contact Iulian Datcu Connect on LinkedIn ↗ Capability brief (PDF) ↓

Luxembourg · on-site / hybrid / remote
Reply within 1-2 business days