Security consulting and architecture for mid-market enterprises
carmasec is a German security consultancy focused on ISMS, cloud architecture, and compliance across Azure/AWS deployments. The team is exclusively senior-level (16 roles, all senior) and skewed toward security staff over engineers (12:4 split), indicating a services-delivery model rather than product-led growth. Active projects cluster heavily around NIS2/DORA regulatory implementations and cloud infrastructure optimization—signals that their customer base is navigating post-2024 EU regulatory tightening.
carmasec advises mid-market and enterprise customers on comprehensive IT security strategy, spanning information security management systems (ISMS), security architecture, cloud security, and offensive security engagements. The firm operates across Azure and AWS environments, using Infrastructure-as-Code tooling (Terraform, OpenTofu, Kubernetes, Nomad) alongside traditional security platforms (Palo Alto Networks, Fortinet, Trellix, Okta). Based in Essen, Germany, the company was founded in 2018 as a partnership and now employs 11–50 people. Service areas include NIS2/DORA compliance projects, IT risk management, cloud resource automation, and technical security strategy development.
carmasec deploys Azure and AWS with Infrastructure-as-Code via Terraform and OpenTofu, container orchestration through Kubernetes and Nomad, and security appliances from Palo Alto Networks, Fortinet, Trellix, and Okta for identity and threat detection.
carmasec focuses on information security management (ISMS), security architecture, cloud security, offensive security, IT risk management, and regulatory compliance projects (NIS2, DORA). They also provide consulting on Zero Trust frameworks and CRA compliance.
Other companies in the same industry, closest in size