Marko Hartwig — portrait Application · Identity & Access Lead

Identity is the control plane.
AI is about to redefine it.
I want to own and shape both.

Twenty-five years in identity and security — building authorization systems, then carrying regulatory accountability for them. Agentic AI is the hardest thing to happen to this discipline in a decade: an opportunity in how identity gets engineered, and a genuine risk in what it grants access to. I want to own that, in both directions, for the enterprise.

Foundation

Fourteen years building IAM

Authorization concepts for more than 3,000 users, SOX-audited and PwC-attested. In 2001 I wrote an authorization management tool myself — its users nominated it for the Innovation Award.

Operating model

Both estates, already run

One owned outright, one governed through engineering teams and delivery partners without line authority over any of them. Both since 2016.

What comes next

AI as multiplier and as risk

I ship AI-assisted systems myself, and argue publicly where agentic automation belongs — and where it quietly manufactures audit findings.

Why me

Twenty-five years in identity: first building it, then answering for it.

From 1998 to 2012 I worked inside identity and access. Authorization concepts for more than 3,000 users at Philip Morris International and Zurich, SOX-audited and PwC-attested, covering segregation of duties, attestation, recertification and the interface to audit. In 2001 I designed and programmed an authorization management tool end to end — the customers who used it nominated it for the Innovation Award, which it won.

Since 2014, as CISO DACH and then EMEA Regional CISO at Zurich Insurance Group, I have been accountable for identity governance in front of FINMA, BaFin and the CBI. Zero Trust and Conditional Access are pillars of a group security strategy I co-developed. Across cloud and move-to-cloud programmes I set the security standards and held internal engineering teams and external delivery partners to them — without line authority over a single one of their engineers.

14
Years hands-on in IAM and authorization design, 1998–2012
3,000+
Users under SOX-audited, PwC-attested authorization concepts
25+
Years in IT and security, 10 of them accountable to a regulator
2
Corporate awards, one of them for an IAM tool

The two estates

Two estates, two genuinely different jobs.

Owning a platform you control is a delivery problem. Owning a standard that other people's engineers have to meet — with a partner contract in between and an auditor at the end of it — is a different discipline, and it fails in different ways. Both have been part of my mandate since 2016.

Estate one · Direct ownership

Workforce identity

Owned outright, delivered as code, governed to FINMA standards. This is the estate where my IAM foundation and my governance record meet.

  • Joiner-Mover-Leaver, privileged access and Conditional Access as programmes with a defined target state — not as tickets.
  • Access reviews, segregation of duties, entitlement attestation and recertification: the exact controls I built and had audited under SOX.
  • Conditional Access and PIM as strategy pillars I co-developed and was accountable for, not features I read about.
  • Evidence and audit-readiness designed in from the start, because I have had to produce it under examination.
Estate two · Ownership without line authority

Client identity

Built by engineering teams and delivery partners. I own the strategy, the standards and the relationships — and carry the risk when it goes wrong.

  • Cloud security governance for move-to-cloud programmes: I set the standard, then held internal teams and external partners to it.
  • Vendor, contract, licensing and third-party risk ownership, including being the escalation point when a partner misses the bar.
  • Ten years of leading BISO teams across EMEA with influence rather than hierarchy — the same operating model, one layer up.
  • The authority problem solved the only way it can be: standards written so they are testable, and evidence demanded as a deliverable.

Where my experience maps directly

What I bring to the mandate.

🧭

Identity governance, built not inherited

Access reviews, segregation of duties, attestation, recertification and least privilege are not a control list I would be learning. I designed them for more than 3,000 users, had them audited under SOX and attested by PwC, and owned the audit interface myself.

🔐

Entra ID, PIM & Conditional Access

Hands-on with Microsoft Entra ID and Privileged Identity Management. Conditional Access and Zero Trust are pillars of a security strategy I co-developed and was accountable for — and as CISO DACH I held governance over identity management and Active Directory directly.

🧪

Still in the technical detail, by choice

Most recently I worked directly with our security engineers on a post-quantum cryptography whitepaper, assessing PQC readiness and what the migration means for our cryptographic estate. Not commissioned from a distance and presented back to me — written with the engineers doing the work. That is the working style this role asks for, and it is the one I already have.

🏛️

Identity risk & audit-readiness

I am already the person Risk, Audit and the regulator turn to. I front FINMA, BaFin and CBI engagements and translate their expectations into defensible processes, evidence, policy documentation, KPIs and KRIs. Audit-readiness as routine, not as a project.

🚨

Identity incident response that has been rehearsed

I designed and rolled out Zurich's Data Incident Management process globally — recognised with the Group Compliance Award — and was the single point of ownership across Security, Legal, Compliance and Risk. Making identity signals reach the SOC and stand up under a real incident is work I have already done once.

📋

Budget, vendors & service ownership

Budget, contract, licensing and third-party risk ownership including escalation. As Head of IT Service Operations I ran incident, change and escalation as a discipline with ITIL-certified processes — the run half of run-versus-change, from the inside.

📊

The same story to three audiences in one day

Monthly reporting to COOs, risk narratives and decision papers in executive committees, and technical challenge in the same week. Defending an identity roadmap to a regulator, a CIO and an engineer on the same day is a description of my current job.

👥

Growing the function, not just staffing it

I lead BISO teams across EMEA — different countries, different regulators, no shared office. Set a clear standard, give people the mandate to own their market, stay accountable for the outcome myself. Two of my former direct reports describe a decade of mentoring below.

AI-enabled and non-human identity

Agentic AI is not a future topic. It is an identity topic — today.

I work extensively on agentic AI and am a regular voice at CISO roundtables on agentic AI and non-human identity — including the need for micro- and nano-segmentation of access that follows from it. My position: once AI agents become first-class identities, least privilege has to be enforced at a granularity that classic RBAC models can no longer deliver.

The positions I argue at these roundtables

  • AI agents need a full identity lifecycle — scoping, attestation, rotation, sunset — just like every joiner, mover and leaver.
  • Micro- and nano-segmentation of access is the only viable answer to autonomous, fast-moving non-human actors.
  • Agentic automation of IAM operations — access requests, JML exceptions, evidence collection — belongs in production only with a human in the loop and a complete audit trail.
  • The productivity gain from AI has to be measured honestly. Otherwise it is a risk, not a multiplier.

What this means for the bank

An identity architecture that treats AI agents, workload identities and service accounts as a first-class identity type from day one — with least-privilege scoping, credential management and guardrails that hold up in front of FINMA.

  • AI as a force multiplier in engineering and governance, with auditability built in as a design principle.
  • Access review intelligence, entitlement drift and anomaly detection as measurable automation.
  • A standard for non-human identity that scales before demand forces it.
Not a position paper · What I actually build

I use these tools myself, on my own time, in code.

You asked for demonstrated use of AI tooling to increase engineering output, with a considered view of its risks and limits. Mine is not a slide. Outside my day job I design and ship working systems with AI-assisted engineering:

  • A multi-tenant ISO 27001 / NIS2 / DORA compliance platform — control library, evidence management, audit logging, incident workflow — running in production for my own advisory work.
  • A security-readiness gate that runs SAST, dependency and secret scanning against a repository and returns a pass/fail verdict before release.
  • A deployment pipeline behind both: tests as a gate, immutable releases, pre-deployment backups, health checks and automatic rollback on failure.

That is the same engineering discipline this role wants applied to identity — and it is why I can say honestly that I know both what AI-assisted delivery accelerates and where it quietly produces work that will not survive an audit.

"If you give AI agents access without rethinking identity, you haven't built automation — you've built an audit finding."
Marko Hartwig, CISO roundtable on agentic AI & non-human identity

Against your essential criteria

Where I am strong, and the two places I would be ramping.

You will check this list anyway. I would rather be the one who brings it up — including the parts where the honest answer is "adjacent, not equivalent". A candidate who cannot tell you what he still has to learn is not a candidate you want owning identity risk.

8+ years in IT, 5+ in IAM, as accountable owner of an identity platform, programme or roadmap Core strength
25+ years in IT and security. Fourteen of them hands-on in IAM and authorization design, then a decade owning identity governance, Active Directory and access control as CISO DACH and EMEA Regional CISO.
Identity strategy or target operating model in a regulated environment Core strength
Co-developed Zero Trust and Conditional Access as pillars of a group security strategy and drove regional implementation across EMEA — a highly regulated, multi-jurisdiction footprint.
Deep command of IAM principles: RBAC/ABAC, least privilege, zero trust, privileged access, identity governance Core strength
This is my professional foundation, not a reading list. SOX-audited role and authorization design, segregation of duties, attestation, recertification — built, defended in audit, and awarded.
Owning identity strategy and standards for a client-facing platform built by others, including the delivery partners Core strength
The operating model I have run since 2016: set the standard, hold internal engineering teams and external partners to it, own the contracts and escalation, carry the risk personally. Applied to cloud security governance rather than CIAM specifically — see the ramp below.
Regulatory grounding (FINMA, ISO 27001, NIST) and experience fronting internal or regulatory audit Core strength
FINMA, BaFin, CBI, DORA, GDPR and Swiss DSG engagements led personally. ISO 27001, NIST CSF and CIS Controls used as working frameworks — my former direct report says so unprompted in his recommendation below.
Vendor relationships, budgets and service management (incident, change, escalation) Core strength
Budget, contract, licensing and third-party risk ownership. Head of IT Service Operations with ITIL-certified incident, change and escalation processes — I have run the service side, not only governed it.
Demonstrated use of AI tooling to increase engineering or operational output, with a view of its risks and limits Core strength
I design and ship AI-assisted systems personally — a multi-tenant compliance platform, a security-readiness gate, and the deployment pipeline behind both. I also speak publicly on where agentic automation belongs and where it manufactures audit findings.
Excellent stakeholder communication in English; German an advantage Core strength
German native speaker, dual German and Swiss citizenship, and a decade of Board, C-suite and regulator communication in English across EMEA.
Hands-on Entra ID depth — enough to review a design, challenge it, and contribute to it directly Strong, deepening
I work with Entra ID and PIM and own Conditional Access as a strategy pillar, so I can review and challenge a design today. What I have not done is spend the last three years in the portal daily. I would expect to earn that credibility with your engineers in the first months rather than assume it — and I have never had a problem being the most senior person in the room asking the most basic question.
Infrastructure-as-code delivery (Terraform, CI/CD) applied to identity Adjacent, ramping
Honest answer: I have governed IaC-delivered environments and I build and run my own deployment pipelines — tests as a gate, immutable releases, health checks, automatic rollback — but I have not personally authored production Terraform for an identity platform. I read it, I can challenge it, and I intend to be reviewing pull requests properly rather than nodding at them. This is the gap I would close first.
CIAM protocol depth (SAML, OAuth2, OpenID Connect) sufficient to challenge a partner's design Adjacent, ramping
My federation and protocol work sits on the workforce side and in architecture governance rather than in registration and recovery journeys for retail clients. The governance model transfers directly; the specific customer-journey depth I would build with your engineering teams and partners, and I would rather say that now than discover it in month three.

Track record

Read it backwards. It starts and ends in identity.

2016 — present

EMEA Regional CISO · Zurich Insurance Group

Identity relevance: co-developed Zero Trust and Conditional Access as strategy pillars; set security standards for cloud and move-to-cloud programmes and held internal engineering teams and external delivery partners to them without line authority; owned vendor contracts, budget and escalation; fronted FINMA, BaFin and CBI on control questions. Alongside that: regional implementation of the global security strategy, leadership of distributed BISO teams and Board reporting.

2014 — 2016

CISO DACH · Zurich Insurance Company

Identity relevance: direct governance over identity management, Active Directory and device access control, plus SOX and internal controls. The role where my hands-on IAM background became an accountable governance mandate.

2012 — 2014

Audit, security & IT operations leadership

Identity relevance: ownership of access and identity management, and SAP GRC 10.0 as Corporate Head of Audit & Security. As Head of IT Service Operations I ran incident, change and escalation with ITIL-certified processes — the service-management half of this mandate.

1998 — 2012

Fourteen years inside IAM · Philip Morris International, Zurich

This is the foundation the rest is built on. Authorization concepts for more than 3,000 users, SOX-compliant and PwC-reviewed, covering segregation of duties, attestation, recertification and the interface to audit. Innovation Award (2001) for an authorization management tool at Philip Morris International that I designed and programmed end to end — nominated by the customers who used it, which is the endorsement I still value most. Later led SAP BI platform teams with ITIL-certified processes.

What the people who worked with me say

You want someone who can lead, coach and grow the function. That is not a claim I can make for myself.

LinkedIn recommendations from people who reported directly to me, from peers, and from a senior colleague outside my reporting line. The themes they return to unprompted: calm judgment under pressure, a team built to be accountable, and mentoring that lasted a decade. One of them also confirms the ISO 27001, NIST CSF and regulator record without being asked to.

"Marko is a highly experienced security leader who defines and leads Information Security strategy across complex, regulated environments, with teams spanning all of Europe and the Middle East. He built a strong and accountable team and fostered a culture of continuous improvement and development. His skill in leadership was especially notable during the pandemic lockdowns, when the team always felt together despite being geographically dispersed. […] He operates with authority at Board and C-suite level and has extensive experience working with regulators and audit functions, including FINMA, BaFin and the CBI, consistently delivering strong outcomes. […] I would strongly recommend him to any organisation seeking a CISO with proven leadership, deep technical expertise and the ability to deliver in highly regulated environments."

Peter O Murchu
Information Security & Transformation Leader · CISO · Board & Executive Advisor
Reported directly to me

"Marko is a one-of-a-kind executive leader who understands putting people where their strengths are and creates great team spirit, while being approachable, empathetic and empowering at the same time. With his wealth of skills and knowledge, security is not only a profession for him but also a passion. He sparks curiosity to learn and a willingness to go the extra mile for what is right instead of what is convenient. I am deeply thankful for having had the opportunity to get to know him and to learn from one of the best. He was a fantastic mentor to me over the course of 10 years."

Jan Schuwirth
Business Information Security Officer · Zurich Insurance Company Ltd
Reported directly to me

"I really enjoyed working with Marko and have huge respect for the way he leads. He brings calm, clarity and strong judgment to complex information security and cyber topics, making discussions both productive and reassuring. Marko is also a generous mentor: he consistently takes the time to explain context, challenge thinking constructively, and support others in building confidence when navigating senior or complex discussions. It has been a pleasure working with him, and I would gladly recommend him as a thoughtful and impactful cyber security leader."

Matilda McVann
Global Head of Cyber Service Delivery · Zurich Insurance
Senior colleague, outside my reporting line

"It has been a privilege working with Marko over the past decade. He is a thoughtful leader who focuses on leveraging team strengths to achieve security goals while maintaining a supportive and accessible management style. I have particularly appreciated his dedication to ethical, thorough work and his consistent commitment to mentoring, which has had a meaningful impact on my professional development."

Christian Sturm
Business Information Security Officer · Zurich Insurance Company Ltd
Reported directly to me

"Marko and I worked closely together to deliver a consistent security service to the Group Functions, Corporate Center and the Swiss Business Unit within the Zurich Insurance Group. His collaborative focus, leadership and approach to people made this journey enjoyable, and he was able to support a broad range of business challenges. I can highly recommend him."

Benjamin Colen
IT Security · Cyber Security · IT Risk Management · Cloud Security
Peer, same team

"I had the pleasure of working with Marko at both PMI and Triumph, and I highly value and appreciate his open spirit, his willingness to drive change, and his leadership."

Thomas Tralmer
SAP GRC · Audit · GDPR · Training and Phishing
Reported directly to me

Why this role, why now

Identity is about to be rebuilt around AI. I want to be the one who shapes it.

Agentic AI is the most consequential thing to happen to this discipline in a decade, and it arrives as both halves at once: a genuine multiplier in how identity is engineered and governed, and a genuine risk once agents become identities that hold access in their own right. Most organisations will meet that as a problem after the fact. I want to own it before it arrives, and shape it deliberately — for the enterprise, not just for the control. This mandate puts the control plane, the engineering resource and the accountability in one pair of hands, which is the only configuration in which that is actually possible.

What actually motivates me

  • Identity as the object of the mandate, with the authority to make decisions about it stick.
  • An architecture still being shaped, in a market where the regulator has not finished writing the rules — rather than remediating something built without security in the room.
  • Working out what agentic automation genuinely delivers in identity operations, and where it quietly manufactures audit findings. Both answers matter and only one of them is comfortable.
  • Setting a standard for non-human and AI agent identity before the demand forces one, instead of retrofitting it afterwards.

What you get

Someone who has already been the person the regulator turns to when a control is questioned, who has built the identity governance you need before it was called that, and who will not need to be taught what audit-readiness costs.

  • Identity risk and audit-readiness owned personally, with evidence generated as a by-product of the design rather than assembled before an examination.
  • Standards for client identity that are written to be testable, so partners can be held to them without a hierarchy that does not exist.
  • A function built to be accountable, and a standard that holds up when I am not in the room.
  • An honest measurement of what AI adoption delivers — including when the answer is less than the slide promised.

I want this mandate, and I will carry the accountability that comes with it.