Curriculum Vitae

Thomas Baetens

Cyber Security Architect, IT Project Manager and Data Protection Officer, former CISO

Profile

IT and security professional with close to twenty years of experience, most of it in regulated pharma, clinical research, life sciences and manufacturing. I combine practical infrastructure knowledge with security governance and structured project delivery.

As CISO and DPO I led ISO 27001 and GDPR programmes for international laboratory groups. Today I design security architecture, act as Data Protection Officer and run IT projects across sites in Belgium, the Netherlands, the United Kingdom and the United States, from SOC and MDR rollouts to IT/OT integration and AI governance. I work well with senior management, auditors and vendors, and I translate regulation into measures that operations can live with.

Looking for: CISO, Security Architect, IT Infrastructure and Operations Manager or IT Project Manager roles. Permanent or interim, remote across Europe and the US, or hybrid in the Benelux.

Experience

Cyber Security Architect, IT Project Manager and Data Protection Officer

Sharp Services · full time consultancy assignment
Jul 2021 to present

Pharmaceutical packaging and clinical supply services, with sites in Belgium, the Netherlands, the United Kingdom and the United States.

  • Design the security architecture and lead security and infrastructure projects across the European and US sites.
  • Act as Data Protection Officer for GDPR compliance.
  • Contribute to the ISO 27001 programme: ISMS documentation, review of the Cyber Incident Response Plan and a data sensitivity classification framework.
  • Led the SOC and MDR implementation and IT/OT integration projects in a manufacturing environment.
  • Run availability monitoring and management reporting across eight remote sites.
  • Built the AI governance baseline: EU AI Act compliance mapping, AI and privacy law baselines for EU, UK and US sites, and an AI cost framework.
  • Handle vendor security reviews and contracts, IT asset management and an application lifecycle framework.

Founder and IT Consultant

De IT Consultant
Jul 2021 to present

My own consultancy, through which I take on security, privacy, infrastructure and project management assignments for regulated organisations. Current full time assignment: Sharp Services.

Chief Information Security Officer and Data Protection Officer

Cerba Research · self employed
Jan 2020 to Jun 2021

Global central laboratory and clinical research organisation.

  • Led the ISO 27001 implementation: scope, ISMS, CMDB, risk assessments and Statement of Applicability.
  • Ran the privacy programme across jurisdictions: GDPR, South Africa POPIA and Japan APPI, Standard Contractual Clauses, breach handling and data subject requests.
  • Supported computer system validation according to GAMP 5.

CISO and System Engineer

BARC Global Central Laboratory
Nov 2015 to Jan 2020
Chief Information Security OfficerJan 2019 to Jan 2020
System EngineerNov 2015 to Jan 2020
  • First CISO of the laboratory: security policies, risk assessments, vulnerability management and awareness training.
  • Engineered and ran the Windows, Linux, VMware and network infrastructure of a regulated clinical laboratory.

Senior Network and System Administrator

Edan Business Solutions · Machelen
Sep 2009 to Nov 2015
  • Installed and maintained customer networks and servers, and the internal SPHINX IT and Edan infrastructure.
  • Sold and implemented Office 365 and designed SharePoint 2010 environments.

Network Engineer

Corilus
Mar 2008 to Aug 2009

Installation and maintenance of IT for customers in the medical sector.

Department Manager

MediaMarkt Oostakker
Sep 2004 to Feb 2008
Department Manager Photo and Telecom, including purchasingDec 2006 to Feb 2008
Department Manager Service, internal IT responsibleSep 2004 to Dec 2006

Expertise

Security governance
ISO 27001 ISMS, NIS2, NIST CSF, risk assessment, internal audit, security policies, third party risk and SOC 2 reviews
Security operations
SOC and MDR, incident response, vulnerability management (Nessus, OpenVAS, Qualys), penetration testing, phishing simulation and awareness training
Privacy and AI
GDPR and DPO practice, DPIA, international data transfers, EU AI Act, AI governance, GAMP 5 validation in GMP environments
Infrastructure and cloud
Windows Server and Active Directory, Microsoft 365, Linux (Debian, Ubuntu, RHEL), VMware vSphere, Proxmox, Docker, Azure, AWS, Cisco, SonicWall and UniFi networking, Veeam, Checkmk and Zabbix
Service management
ITIL practices, change management, CMDB, IT asset management, application lifecycle, availability reporting
Project delivery
Agile and structured project management, IT/OT integration, vendor selection and contracts, budgets, steering committee reporting

Certifications

  • Project Management · Vlerick Business School2025
  • ISO/IEC 27001 Implementer · Advisera2023
  • Data Protection Officer · Data Protection Institute2020
  • ISO 27001 Foundation · Advisera2019
  • Internal Auditor · Amelior2019
  • MCSA Windows Server 20162018
  • Cisco CCNA2016
  • MCSA Windows Server 20122013
  • MCSA Windows Server 20082012

Education

  • Applied Computer Science · HOGENT, Ghent
  • Training: CISSP Bootcamp (Firebrand), Ethical Hacking (MME), CCNA Advanced (Global Knowledge), SonicWall Advanced Networking
  • Languages: Dutch (native), English (full professional), French (elementary)

Languages

  • DutchNative
  • EnglishFull professional
  • FrenchElementary