Find the right CompTIA Security+ professional in Berlin in minutes from 15,000 CVs with the power of AI
Security basics, threat detection, incident response, and secure network operations. A fast way to match with vetted freelancers who hold CompTIA Security+ and can support teams in Berlin.
About the certification
Security baseline
CompTIA Security+ is an entry-to-mid level certification for practical cybersecurity work. It shows that a professional can support core security tasks, speak the language of risk, and help protect systems without needing close guidance on every step. Companies often look for it when they need a freelancer who can step into day-to-day security work quickly.
What it covers
- Threats, attacks, and common attack paths
- Network and application security basics
- Identity and access control concepts
- Incident response and logging
- Risk, governance, and security procedures
- Encryption and secure communication
Typical holder profile
People with Security+ often work as security analysts, system administrators, support engineers, junior consultants, or IT generalists who need a stronger security focus. The certification is also common for freelancers who help teams close security gaps, document controls, or build a more secure setup in mixed cloud and on-prem environments. In Berlin, it can be a good fit for companies that want English-speaking support for international teams and may also need coordination with German stakeholders.
What it signals in a freelancer
A freelancer with CompTIA Security+ should understand how to spot suspicious activity, follow security policies, and respond to common incidents in a structured way. For a company, that means less time explaining basic security terms and more time on the actual task. It is a useful signal when you need help with hardening endpoints, reviewing access settings, improving monitoring, or supporting a security-conscious IT rollout.
Where it fits best
Security+ is most relevant in projects where practical security matters more than deep specialization. That includes internal security support, security operations, awareness work, access reviews, vulnerability follow-up, and general infrastructure protection. It is also useful when a team needs someone who can bridge IT operations and security without starting from zero.
Names and next steps
Searchers may use Security+, CompTIA Security+, or the full name CompTIA Security Plus. Whatever the form, they are usually looking for the same core profile: someone who understands modern security practice and can apply it in real work. If you hire in Berlin, this certification is a strong starting point when you need reliable security support with a practical focus.
Meet FRATCH CompTIA Security+
Andreas Rühl
Principal Consultant Information Security
Last position:
Freelance Information Security Consultant at A-R-C Andreas Rühl Consulting
Development and implementation of tailored information security strategies
Introduction and further development of ISMS according to ISO 27001, BSI Baseline Protection, and other standards
Risk management and creation of security concepts
Consulting for KRITIS, PCI DSS, TISAX, and VdS 3473/10000
Building and improving security organizations
Creation and implementation of guidelines, policies, work instructions, and process descriptions
Audit support and certification preparation
Conducting training sessions, workshops, and awareness campaigns
Selection and consulting for the introduction of IT security solutions such as SIEM, DLP, IDS/IPS, firewalls, and encryption technologies
Conducting penetration tests and vulnerability analyses
Consulting on the selection, integration, and management of security architectures in complex IT environments
Consulting on ITSM and managed security services and SOC
Leading and managing complex projects to improve information security
Process analysis, optimization, and management according to ITIL, ISO 27001, and cybernetics
Introduction and quality assurance of management, documentation, and knowledge management systems
Support in meeting regulatory information security requirements (e.g. GDPR, HIPAA, SOX, GMP, KRITIS)
Development and implementation of risk analysis procedures
Organization of initial response, forensic investigations, and organizational measures in security incidents
Design and delivery of focused workshops on topics such as ISMS, IT risks, and current threat scenarios
Awareness campaigns to promote a security culture in companies
Special training on ISO 27001, BSI Baseline Protection, KRITIS, and other relevant standards
Simulations and exercises to prepare for information security incidents
Interim management for leading information security projects or IT security organizations
Taking on the role of an external CISO (Chief Information Security Officer)
Support in developing and implementing IT security and business strategies
Coaching and mentoring of managers in information security
Building and leading security departments as well as recruiting and qualifying employees
Temporary assumption of management responsibility in critical situations
Kerstin Glawinski
IT Security Officer with TÜV Rheinland certified qualification
Last position:
Information Security Consulting at CAS AG
Can Kocyigit
DevOps Specialist
Last position:
DevOps Specialist at Eviden Germany GmbH
Manage the development release and update process for a digitized nationwide trade register project "AuRegis".
Support software in Kubernetes/OpenShift environments, configure management with Kustomize, and implement CI/CD pipelines using Jenkins/GitLab, SonarQube, ArgoCD, and Azure.
Oversee system release of microservice architecture.
Craft the CI/CD stack from scratch with GitLab CI, integrating integration tests, dependency checks, and security measures.
Automate deployment onto OpenShift using Kustomize.
Establish infrastructure components for development, code review, and code quality analysis including SonarQube.
Integrate GitOps tools such as Kustomize and ArgoCD, leveraging both Azure and private cloud for sensitive data handling.
Develop Python scripts in Jenkins for cryptostore configuration and system packaging of products and microservices into deployable units.
Automate delivery to customers and deployment on test systems.
Craft Kustomize manifests for microservices and develop accompanying automation, treating documentation as code for clarity and reproducibility.
Serve as technical advisor for the project's first go-live and oversee further deployments as technical rollout manager.
Paul Karnowka
Program Manager – Multi-Project Operational Stabilization (Operational Excellence)
Last position:
Program Manager – Multi-Project Operational Stabilization (Operational Excellence) at ITDZ - IT Dienstleistungszentrum Berlin
- Overall leadership of multiple strategic operations projects focused on workplace services, SLA framework, access management, certificate management, e-learning, backup & recovery, test management, and capacity management, as well as implementing system monitoring and feasibility studies for a 24x7 operation, partly including ServiceNow implementation
- Development of various ServiceNow operating concepts related to training, permissions, and emergency management as part of a new cloud-hosting initiative for the ServiceNow platform
- Board reporting and leading steering committees within the framework of corporate strategic objectives, as well as establishing new balanced scorecards to measure KPIs for optimization-driven project results
André Beran
External Attack Surface Assessment & Cybersecurity Readiness Checks
Last position:
External Attack Surface Assessment & Cybersecurity Readiness Checks at Graydaxe Cybersecurity GmbH
- Conducting cybersecurity readiness checks based on an in-house assessment methodology
- Analyzing the external attack surface using the Graydaxe EASM platform
- Assessing maturity levels and deriving prioritized recommendations for action
Flamur Abdyli
Fractional Chief Information Security Officer
Last position:
Fractional Chief Information Security Officer at VR Smart Guide GmbH
- Enhance and develop the Information Security Management System (ISMS) in compliance with ISO 27001 and TISAX standards by continuously updating and refining the ISMS to align with evolving global standards.
- Ensure that security practices and policies are integrated into all business processes to achieve and maintain certifications.
- Lead the effort to identify, evaluate and mitigate risks across the organization, setting benchmarks for security measures.
- Oversee and refine security processes, with an emphasis on incident management and rapid response by developing and enforcing policies for rapid detection, investigation and remediation of security incidents.
- Train and lead the incident response team to handle breaches effectively, minimizing impact and ensuring swift recovery.
- Implement continuous monitoring solutions to detect and respond to threats in real time.
- Conduct comprehensive security assessments for internal and external IT projects, ensuring adherence to GDPR, DORA and other relevant standards.
- Oversee security evaluations for all IT projects to ensure they comply with legal and regulatory requirements.
- Integrate security measures from the planning phase through deployment to ensure all projects uphold the organization’s security standards.
- Collaborate with project teams to address findings and ensure that security risks are managed effectively.
- Serve as the principal security advisor to the IT department and senior management, offering insights on potential security challenges.
- Facilitate a culture of security awareness throughout the organization through training and regular communication.
- Lead security initiatives that align with the organization’s long-term strategic goals.
- Establish and oversee a robust third-party risk management framework to mitigate external security threats by regularly assessing third-party security practices and compliance and developing contingency plans and mitigation strategies.
- Provide regular updates and security briefings to the executive leadership and relevant committees, highlighting recent security incidents, responses, lessons learned and recommending strategic improvements.
Jeet Pattanaik
Global SAP Program Manager
Last position:
Global SAP Program Manager at Aldi Sued
- Pioneered first enterprise AI-SAP integration at ALDI SÜD, deploying AI-driven automation within one of retail's largest SAP S/4HANA programs, eliminating 50% of manual pre-cycle validation time and establishing replicable automation framework across 11 countries
- Led end-to-end SAP project lifecycle management for implementations across SAP S/4HANA and Manhattan Systems, supporting 7,300+ ALDI SÜD locations globally across Europe and Australia
- Served as primary executive liaison to C-level stakeholders across 11 countries for strategic SAP transformation programs
- Orchestrated automation, performance, and volume testing for critical releases, maintaining 99.9% system SLA compliance during peak retail periods
- Managed cross-functional international teams of 15+ specialists, delivering projects 20% faster than industry benchmarks
- Standardized SAP processes across 11 countries as part of one of retail's largest SAP implementations
- Directly managed €2M budget with 98% allocation accuracy across 12 concurrent projects
- Reduced SAP S/4HANA migration costs by 18% through strategic vendor contract renegotiations and optimization
Sascha Schuster
Freelance Project Manager / Interim Chief of Staff
Last position:
Company Operations Officer at GebJgBtl 233
- Responsible for command post operations and leadership support
Bertrand Rothen
Interim IAM Product Owner (Identity Management)
Last position:
Interim IAM Product Owner (Identity Management) at REWE digital GmbH
- Establishing Identity & Directory Management as a new (split-off) team & product within the IAM cluster.
- Leading the “Identity & Directory Management” product (8 people) as Product Owner.
- Concept for ‘Digital Identities’, i.e. IDs with n users/accounts and strategy for a modernized product offering.
- Upgrading APIs, migrating to a containerized infrastructure, rolling out international markets & standardized solutions across the REWE enterprise group.
- Tech: OpenText™ (NetIQ) eDirectory & Identity Manager, LDAP, SAP HR/HCM, Docker/Kubernetes/Podman, REST APIs, Microsoft Active Directory & Entra ID, postgresDB, Keycloak, Ansible, Cyberark (PAM), Apache Kafka, Jira, Confluence, Miro.
André Görst
IT Consulting Project Management / Engineering Subproject Management
Last position:
IT Consulting Project Management / Engineering Subproject Management at T-Systems (on assignment for government agencies)
- Projects for federal networks (NdB).
- CR management, EoL change requests, design and documentation according to ITSCM.
- Data center planning.
- Project management and engineering subproject management.
- Software development for virtual server environments according to BSI.
Jorge Pérez Suárez
Software Engineer – AWS and Kubernetes Specialist
Last position:
Software Engineer – AWS and Kubernetes Specialist at Citti
- Creation, maintenance and hardening of Kubernetes clusters employing Ansible and ArgoCD
- Keywords: Ansible, AWX, Kubernetes, NetApp, Prometheus, CI/CD ArgoCD, SSO, Fluent-bit, HAProxy, Calico, Keycloak, oauth2-proxy, SealedSecrets, kubeseal, Aqua kube-bench, CIS-Benchmarks, Aqua Trivy operator
Seyed Farhad Miri
Senior Product Security Engineer
Last position:
Senior Product Security Engineer at Delivery Hero
- Developed a custom tool using the Mistral 7B LLM to scan, validate and report security vulnerabilities.
- Security tested AI agents, bots, and other LLMs with a focus on prompt injection, model inversion, data poisoning, EDR/AV bypass and evasion techniques, membership inference, model evasion, overfitting to malicious inputs and contextual manipulation.
- Onboarded repositories to SAST solutions for security scanning, implemented secrets scanning, DAST, SCA, and utilized ZAP for DAST in CI/CD pipelines.
- Engaged in security awareness trainings, developed CTF challenges and training materials to enhance developer security knowledge.
- Planned and executed bi-annual red teaming operations based on the MITRE ATT&CK framework and led internal and external pentests based on the OWASP Top 10 framework for 70+ applications worldwide, resulting in detection, reporting, and remediation of hundreds of vulnerabilities.
- Triaged HackerOne reports.
Emmanuel Ezeokala
Privacy Compliance Associate (Volunteer)
Last position:
Privacy Compliance Associate (Volunteer) at Word Alive Ministries (Stone Church)
- Maintain internal GDPR documentation and manage data access controls within digital systems.
- Train users on privacy protocols, recordkeeping, and document management standards.
Mohamed Ghassen Brahim
Founder & CEO
Last position:
Lead / Principal Cloud, AI & Security Architect at Freelancer / CC Conceptualise GmbH
Projects:
Project: RWE – Development of a company-wide Zero Trust cybersecurity architecture (CITADEL) Role: Senior Enterprise Cybersecurity Architect / Zero Trust Architect Company: RWE AG Description: Concept and implementation of the strategic CITADEL cybersecurity target architecture at RWE, based on the Zero Trust architecture principle and aligned with regulatory requirements such as NIS2, ISO 27001 and company-wide security governance policies. The goal was to build a measurable, auditable and scalable security architecture with a strong focus on Identity Governance, compliance transparency and operational manageability. Responsibilities & Achievements:
- Zero Trust architecture design: Developed a company-wide Zero Trust reference architecture (Identity, Device, Network, Application, Data) including trust zones, control points and enforcement mechanisms according to NIS2.
- Identity & Access Governance (IGA): Designed and introduced IGA governance structures including role models, recertification processes, segregation of duties (SoD) and lifecycle management for identities and access.
- Security governance & KPIs: Defined and implemented security KPIs and metrics to manage Zero Trust maturity, identity risks and compliance at the management level.
- Compliance & reporting: Built standardized compliance reports and dashboards to support internal audits, external assessments and regulatory evidence (e.g. NIS2).
- Architecture & stakeholder alignment: Worked closely with Enterprise Architecture, IT operations and business units to integrate the CITADEL architecture into existing IT and security landscapes.
- Strategic security consulting: Advised programs and projects on Zero Trust compliance, identity centricity and regulatory requirements in the energy and critical infrastructure (KRITIS) environment. Technologies & Methods: Zero Trust Architecture, NIS2, Identity Governance & Administration (IGA), IAM, RBAC, SoD, Entra ID, SailPoint, Zscaler, Terraform / IaC, Policy as Code, security KPIs, compliance reporting, NIST 2.0, ISO 27001, Enterprise Security Architecture, governance frameworks, risk & control management
Project: Scalable AI Workbench Platform on Microsoft Azure Role: Cloud Architect & Engineer Company: Siemens Energy Description: Design, development and operation of a secure, modular cloud infrastructure to support Data Science, Machine Learning and AI applications for various engineering teams at Siemens Energy. Responsibilities & Achievements:
- Cloud architecture: Designed and implemented an Infrastructure-as-Code solution (Terraform) for automated provisioning of Azure resources (Resource Groups, Storage Accounts, Cosmos DB, Application Insights, networking, PostgreSQL Flexible Server, Azure Container Apps, Azure Container Registry).
- Developer portal: Used Backstage with custom frontend and backend plugins (Node.js, TypeScript, React.js, PostgreSQL, Container Apps) to enable self-service and empower developers, data scientists and AI/ML engineers.
- Role-based access control: Implemented Azure RBAC to grant targeted access (e.g. Storage Blob Data Contributor, Reader) to engineering groups (e.g. AI Engineers) for relevant resources.
- Data platform engineering: Built and configured a multi-layered storage landscape (Raw, Curated, Vector data), including automated container creation and access control for advanced analytics and AI workloads.
- DevOps integration: Integrated with Azure DevOps for CI/CD pipelines to automate deployment, monitoring and compliance.
- Security & compliance: Implemented Private Endpoints, network policies and Managed Identities to ensure data protection and regulatory compliance.
- Collaboration: Worked closely with cross-functional teams to align the cloud infrastructure with business and technical requirements and drive digital transformation at Siemens Energy. Technologies: Azure, Terraform, Azure DevOps, Cosmos DB, Application Insights, Azure Storage, Private Endpoints, Azure Synapse, Azure Machine Learning, Azure Entra ID, RBAC, Backstage, Node.js, React.js, PostgreSQL, Python (automation), Git
Christopher Mäuer
Mobile & Full-Stack Engineer
Last position:
Mobile & Full-Stack Engineer at Propstack GmbH
- Refactored the mobile app by reimplementing stores, models, API client, screens and components using Typescript
- Added performant on-device storage for stores as preparation for offline mode
- Integrated RNUILib to achieve a minimal and modern UI design quickly
- Implemented native packages to provide additional features such as displaying of caller IDs
- Planned feature development and UX improvements following initial refactoring and redesign
Discover over 15,000 top freelancers
CompTIA Security+ statistics
Aggregated from the professional profiles of matched freelancers.
Experience
21 years
Position duration
2.3 years
Positions per freelancer
18
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Professional Services, Automotive
Certification focus areas
Information Technology, Project Management, Legal
Bachelor's degree or higher
84%
Master's degree or higher
48%
Doctorate
16%
Certifications per freelancer
10
Most common languages
German, English, French
Speak two or more languages
89%
Daily Rate Distribution
The chart shows how the daily rates of freelancers holding this certification are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Average rates for CompTIA Security+ & Seniority distribution
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Frequently Asked Questions
Want to know more? Check out our simple guide about FRATCH
CompTIA Security+ validates practical cybersecurity knowledge for day-to-day work. It covers common threats, secure network basics, access control, incident response, and risk awareness. For a company, it suggests the freelancer can support security tasks with a solid baseline rather than only theory.
Yes. Security+ is the common short form, and many people also search for CompTIA Security Plus or CompTIA Security+. They all point to the same certification and the same core skill set.
CompTIA Security+ sits at a practical foundation level. It is broader than many niche certifications, but it does not go as deep into advanced architecture, governance, or senior-level strategy. Companies often use it to identify freelancers who can handle core security work before moving into more specialized areas.
CompTIA Security+ fits freelance professionals who work in IT support, system administration, security operations, or junior consulting and need to prove a security baseline. It is especially useful when the project involves general protection work, secure configuration, or incident handling. In Berlin, it can be a good match for international teams that want clear, practical security skills.
Preparing for Security+ usually means building a broad understanding of common attack types, secure operations, identity management, and incident response. Candidates typically need both study and hands-on exposure to IT or security tasks to make the material concrete. It is designed for people who can learn concepts and apply them in real environments, not just memorize terms.
There is no strict technical prerequisite built into the certification itself, but it helps to have a basic IT background before attempting CompTIA Security+. Many candidates come from support, networking, or admin roles. That background makes the security topics easier to connect to real systems and workflows.
CompTIA Security+ is maintained through CompTIA's continuing education approach. Holders need to keep their knowledge current with security developments and meet renewal requirements set by CompTIA. For companies, that matters because the certification reflects ongoing professional development, not just a one-time exam result.
Security+ is useful in projects that need practical security support: endpoint hardening, access reviews, security monitoring, incident triage, secure rollout of tools, and general infrastructure protection. It also helps when a team needs someone who can work across IT and security functions. In Berlin, it is often relevant for international companies that need flexible freelance help with clear communication and solid security habits.
The average hourly rate for freelancers with CompTIA Security+ in Berlin is 118 €, which corresponds to a daily rate of about 942 € based on an 8-hour working day.
Of the freelancers with CompTIA Security+ in Berlin, 84% hold at least a Bachelor's degree, 48% hold at least a Master's degree, and 16% hold a doctorate.
On average, freelancers with CompTIA Security+ in Berlin have 21 years of professional experience, with a single engagement typically lasting around 2.3 years.
The most common languages among freelancers with CompTIA Security+ in Berlin are German (96%), English (93%), and French (26%).
The most common industries among freelancers with CompTIA Security+ in Berlin are Information Technology (85%), Professional Services (67%), and Automotive (52%).
The most common business areas among freelancers with CompTIA Security+ in Berlin are Information Technology (96%), Project Management (81%), and Operations (67%).
FRATCH CompTIA Security+ main locations
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a Free Demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
