Frédéric Klein-IT Consultant, Architect, Full Stack, DevOps
Check rate
Experience
Project Manager (Enterprise Cloud Governance)
CompuGroup Medical SE & Co. KGaA
Short description: Lead of a group-wide project to establish standardized cloud governance for Microsoft Azure, including policies, security and compliance controls, automation, and cost and operations management, while maintaining the autonomy of decentralized business units within regulatory frameworks.
Tasks and activities:
Overall responsibility for the design, setup, and implementation of a company-wide cloud governance structure (Azure), including target picture, roadmap, and operating model.
Management of internal and external stakeholders (C-level, IT, Security, Compliance, Cloud Architecture, DevOps), including decision and escalation management.
Planning and facilitation of workshops on cloud strategy, governance principles, and the design of areas such as Identity, Connectivity, and Platform Management.
Definition, implementation, and rollout of cloud policies (Azure Policy / custom policies), security standards, and compliance requirements (including GDPR, ISO 27001, BSI C5).
Building a cloud governance framework based on the Azure Cloud Adoption Framework (CAF), including landing zone and guardrail concepts.
Introduction of automation solutions for governance, security, and cost control (policy/control automation, IaC, CI/CD-based control mechanisms).
Implementation of cloud security and compliance monitoring mechanisms as well as continuous improvement processes.
Establishment and operationalization of FinOps in an enterprise environment (central and decentralized FinOps teams), including cost management strategies, reporting, and guardrails.
Integration of governance policies into DevOps processes (e.g. CI/CD principles for security and compliance checks, GitLab Runner concept in spokes, GitLab CI/CD for CAF landing zones).
Implementation of access concepts including RBAC design and "breaking glass" mechanisms (emergency access) as well as certificate automation (ACME / step-ca).
Achievements:
Created a consistent, auditable governance and control set for Azure (policies, standards, compliance mapping), laying the foundation for scalable cloud usage in a regulated environment.
Established repeatable automation for governance, security, and cost control (IaC + CI/CD), reducing manual effort and implementation risks.
Improved operating and decision-making capabilities across central and decentralized units (clearer roles, responsibilities, escalation paths, balance between autonomy and corporate rules).
Significantly increased workload compliance during lift-and-shift migrations.
Technologies used:
Microsoft Azure Policy, custom policies.
Terraform, OpenTofu, Terragrunt.
step-ca (ACME).
Entra ID.
Azure Firewall.
Azure networking, hub-and-spoke architecture.
Azure vWAN (evaluation).
Azure Front Door, Azure Application Gateway.
Azure ExpressRoute.
Azure Key Vault.
NetBox.
GitLab (on-premises).
Infrastructure, concepts used:
Cloud Shared Responsibility Model.
Hub-and-spoke connectivity / central shared services (from hub-spoke context).
Central governance with decentralized delivery (business unit autonomy with guardrails).
Methods used:
Scrum.
Stakeholder management (C-level to engineering).
Cloud governance, Azure Cloud Adoption Framework (CAF).
DevOps, CI/CD.
Cost and FinOps approaches: tagging/chargeback models, budget/alert concepts, reserved instances/savings plans vs. on-demand scenarios, sensitivity analyses.
RBAC, "breaking glass" concepts.
ACME / certificate automation.
GitLab Runner concept in spokes, GitLab CI/CD pipelines for CAF landing zones.
Project Manager / Sub-Project Manager (IAM & SSO), Architect
Bank-Verlag GmbH
Short description: Sub-project leadership for the modernization of identity and access management of an online banking application. The focus was the migration of one tenant from an existing SAML-based integration (Shibboleth) to an SSO approach based on the existing Keycloak IAM architecture, while keeping the existing tenant extensions (central user management, TAN flow generators) and focusing on limiting additional complexity in the core domain.
Tasks and activities:
Analysis of the existing SAML integration of the Spring Boot application via Shibboleth, including authentication and session flows as well as interfaces to the online banking solution.
Review of the existing Keycloak IAM architecture, including customer-specific extensions (central user management, tenant-wide TAN flow generators, session management).
New design of a Keycloak extension in the form of a custom authenticator (proxy pattern) that forwards authentication requests in a controlled way to the existing online banking solution, with the goal of reducing coupling, limiting additional complexity, and not fragmenting the encapsulation of the business core domain.
Technical and functional leadership of the development team (prioritization, architecture decisions, quality assurance, dependencies/impediments).
Regular reporting to the steering committee, including status, risks, decision needs, and migration progress.
Achievements:
Defined a migration-ready target architecture for SSO that protects the existing online banking core domain (proxy authenticator instead of deep changes to the application logic).
Supported consolidation and reusability in the IAM landscape by taking existing Keycloak extensions and tenant mechanisms into account and developing them in a compatible way.
Improved transparent control and decision-making for the program through structured stakeholder and steering committee reporting.
Technologies used:
Java.
Spring Boot.
Spring Security.
React.
Keycloak (including extensions, session management).
Shibboleth.
SAML (existing integration / migration).
Infrastructure, concepts used:
Tomcat.
Nginx.
Methods used:
Scrum.
Identity & Access Management (IAM).
DevOps.
Standards & patterns: OAuth 2.0 / OpenID Connect (typical for SSO with Keycloak), token and session hardening, back-channel logout.
Security engineering: threat modeling, security by design, audit logging/tracing for auth flows, OWASP ASVS-relevant controls.
Subject Matter Expert (SME), Consultant
CompuGroup Medical SE & Co. KGaA
Short description: Consulting on the further development of a cloud provider strategy that was previously centered on private cloud, toward a public cloud approach. Focus on organizational and technical readiness, RFP support for business-critical workloads, provider evaluation (scoring), as well as cost estimates and compliance/policy mapping for hyperscalers.
Tasks and activities:
Building and aligning an organizational and technical cloud readiness assessment catalog for CTOs of the business segments (including criteria for architecture, operations, security, compliance, organization).
Consulting purchasing, management, and tech leads as part of an RFP for hosting business-critical applications in the public cloud (requirements, evaluation logic, decision documents).
Conducting a comprehensive scoring of the providers participating in the RFP, including a consistent assessment method and preparation of results for stakeholder decisions.
Cost estimation and TCO-like projections based on workload bills for 12 products using hyperscaler price calculators (comparability of assumptions, derivation of cost drivers).
Assessment of existing IT governance with regard to public cloud readiness (control framework, role/responsibility model, decision and approval processes).
Analysis of existing corporate guidelines and compliance requirements, and mapping them to available policy and control mechanisms of the hyperscalers (e.g. Azure Policy rulesets, derivation of gaps and measures).
Achievements:
Created a decision-ready basis for provider selection (RFP consulting, transparent scoring, comparable evaluation logic).
Systematized cloud readiness and harmonized it across segments (assessment catalog for CTOs as a reusable tool).
Increased cost and governance transparency for the public cloud transition (workload-based cost estimates, comparison of guidelines/compliance with hyperscaler controls).
Technologies used:
Azure Price Calculator.
AWS Price Calculator.
Infrastructure, concepts used:
Cloud Shared Responsibility Model.
Amazon Web Services (AWS).
Microsoft Azure.
Google Cloud Platform (GCP).
Azure Policy (policy rulesets / controls).
Azure Cloud Adoption Framework (CAF).
Methods used:
Cloud readiness assessment (workload-oriented).
Software architecture analysis.
RFP sourcing: weighted scorecards, must/should criteria, risk and compliance matrix.
Architecture blueprints: reference architectures (landing zone, network/identity baselines), migration wave planning, well-architected checks (provider-specific).
Consultant (Cloud Architecture / Private Cloud)
CompuGroup Medical SE & Co. KGaA
Short description: Architecture and performance consulting for internal customers of Group IT in the context of provided private cloud services based on OpenStack. The focus was on building an IaaS service product for the cloud operation of end-customer software, diagnosing and fixing storage/disk I/O performance issues in virtualized OpenStack environments, and making proprietary legacy appliances operational in OpenStack through targeted hypervisor/image configuration.
Tasks and activities:
Consulting a business unit in building an IaaS service product based on OpenStack to enable customers to run the Medistar software in the cloud (service/architecture design, operations and platform requirements, technical guardrails).
Identification of disk I/O jitter in virtual guest operating systems of an OpenStack cluster; creation of structured analysis and benchmark reports based on fio, diskspd, and Phoronix.
Close collaboration with the infrastructure/platform team on root cause analysis and remediation (hypothesis building, measurement concept, retesting, result validation).
Investigation of the impact of I/O jitter on database workloads (including Oracle, PostgreSQL), including analysis of Oracle-specific I/O mechanisms and calibration procedures.
Support in bringing proprietary legacy firewalls based on Linux into operation on OpenStack by adjusting the VM boot environment and the libvirt/SCSI layer via image properties/metadata (KVM/libvirt configuration parameters).
Use of IaC approaches for repeatable provisioning/parameterization (Terraform) in the context of private cloud services.
Achievements:
Created performance transparency and a basis for decision-making by reproducing, quantifying, and documenting I/O jitter in usable benchmark reports.
Improved the operability of business-critical workloads in the private cloud (database workloads and legacy appliances) by analyzing technical causes and implementing targeted configuration measures.
Enabled a business unit to build a market-oriented IaaS service product based on OpenStack through practical architecture and platform consulting.
Technologies used:
Terraform.
Ansible.
fio, diskspd, Phoronix, iostat, vmstat, sar (benchmarking/performance analysis).
PowerShell.
Infrastructure, concepts used:
OpenStack: Nova, Cinder, Neutron, Glance, Heat.
KVM hypervisor.
libvirt (SCSI/storage stack).
Cloudbase-Init (Windows cloud init).
Operating systems: Linux, Windows.
Databases: Oracle, PostgreSQL.
Storage: Pure Storage.
Methods used:
Cloud Shared Responsibility Model.
Performance/benchmark-driven root cause analysis (measurement concept, reproducibility, validation).
Storage/VM tuning: Virtio-SCSI, IO threading, queue depth tuning, NUMA/CPU pinning.
Interim Head of Software Development (Consulting)
Zeppelin GmbH
Short description: Interim leadership and consulting as Head of Software Development for the Digital Factory of the Zeppelin Group. Focus on multi-team coordination (cloud infrastructure, telematics, data management, CMS), development of a cloud strategy including a framework proposal (governance and architecture guidelines, provider selection, disaster recovery concept by criticality level), as well as building a task force for health checks and rightsizing of an existing telematics platform.
Tasks and activities:
Functional management of four teams in the areas of cloud infrastructure, telematics, data management, and content management systems (prioritization, dependencies, target picture, delivery steering).
Consulting on cloud strategy and migration, including support for an internal task force (decision and approach models, stakeholder alignment).
Development of a proposal for a cloud framework as a control and architecture guideline.
Definition of governance and architecture guidelines (e.g. standardization, guardrails, operating models).
Definition of selection criteria for cloud providers (business/technical/compliance-based).
Development of disaster recovery and resilience strategies along a classification model for application criticality.
Building and steering a task force for health checks and rightsizing of an existing telematics platform; consulting and support in defining and prioritizing requirements (e.g. performance, stability, cost, scaling).
Achievements:
Established a unified leadership and steering structure across multiple teams, strengthening decision-making and delivery capability of the Digital Factory.
Provided an implementation-ready proposal for a cloud framework (governance, architecture, provider selection, DR based on a criticality model) as a basis for standardized migration and operations.
Reduced cost and operational risks of a telematics platform by preparing health check/rightsizing in a structured way and operationalizing it through a dedicated task force.
Technologies used:
RabbitMQ.
Kafka.
Python.
Scala.
Terraform.
Infrastructure, concepts used:
Kubernetes.
Ansible.
Observability: Prometheus, Grafana.
Identity/IAM: Keycloak.
FinOps (cost control).
AWS Well-Architected Framework (as assessment/guideline).
BSI-oriented emergency management for cloud applications (DR/BCM reference framework).
Methods used:
Scrum.
Operating model & governance: RACI, Cloud Center of Excellence (CCoE), architecture review board/guardrail processes.
Resilience: RTO/RPO definition, failover strategies (multi-AZ/region), runbooks and regular DR tests.
FinOps practices: tagging standards, budgets/alerts, unit economics/showback/chargeback.
Lead Developer (Full-Stack) / Software Architect
Körber Pharma Inspection GmbH
Short description: Lead full-stack development and software architecture for EjectX, an AI-based inspection system for detecting safety-relevant product deviations in the pharmaceutical environment. Focus on modernizing and stabilizing the tech stack, interfaces to data science pipelines, introducing an API gateway, and standardizing security/IAM as well as automating AWS deployments and building observability in Kubernetes.
Tasks and responsibilities:
Technical and disciplinary leadership of a development team (4 FTE), including architecture decisions, prioritization, and quality assurance.
Analysis of existing inspection systems with regard to existing interfaces and integration constraints (system/interface assessment).
Reduction of technical debt and migration of outdated framework versions to improve maintainability, security, and delivery capability.
Development and stabilization of interfaces to data science pipelines (integration of ML/AI components into the product platform).
Backend and frontend development based on defined user stories using definition-of-ready/definition-of-done criteria.
Introduction and enforcement of coding guidelines with a focus on clean code (consistency, testability, review standards).
Introduction of an API gateway based on OpenResty/OpenNginx including connection to Keycloak via OpenID Connect for centralized authentication/authorization.
Replacing manual infrastructure provisioning in AWS with automated application deployment using GitHub Actions as well as Terraform and Ansible (infrastructure/deployment automation).
Building a monitoring/observability setup with Prometheus/Grafana, deployment in the Kubernetes cluster including an operational baseline for operations and error analysis.
Achievements:
Increased delivery and operational maturity of the system through consistent reduction of technical debt and framework migrations (lower maintenance risk, modernized foundation).
Unified security and access concepts by introducing a central API gateway with OIDC integration to Keycloak (consistent authentication/authorization layer).
Established reproducible deployments and better scalability through IaC and CI/CD automation (Terraform/Ansible + GitHub Actions) as well as a Kubernetes-based operations platform.
Improved operational transparency by introducing Prometheus/Grafana as the cluster monitoring standard.
Technologies used:
JavaScript, TypeScript.
Node.js, AdonisJS.
Vue.js.
Cypress (E2E/frontend tests).
Python, TensorFlow (data science/ML integration).
Nginx, OpenResty (API gateway).
Terraform.
Infrastructure, concepts used:
AWS.
Docker.
Kubernetes.
Ansible.
GitHub Actions (CI/CD).
IAM / Identity: Keycloak, OpenID Connect (OpenIDC).
Observability: Prometheus, Grafana.
Methods used:
Scrum.
Clean code (coding guidelines, reviews, quality standards).
Architecture and engineering practices: domain-driven interface separation (e.g. bounded contexts), API design (REST/Async), ADRs (architecture decision records).
Kubernetes ops: Helm/Kustomize, ingress standards, resource limits/requests, horizontal pod autoscaling.
CEO (Seed Phase, Product & Technology)
IT4Medic GmbH
Short description: Management and setup of a startup in the seed phase to develop a platform for real-time patient monitoring in care and general wards (non-ICU) using sensor-based body area networks. Responsibilities included IP/patents, product and prototype development (platform + wearables), network concept (LoRaWAN), as well as preparation of clinical field trials and stakeholder work in the healthcare environment.
Tasks and responsibilities:
Managing the seed phase, including overall operational responsibility for product, technology, and stakeholder management.
Initiating and supporting patent filings (IP strategy, documentation, FTO analyses, coordination with patent attorneys/stakeholders).
Rapid prototyping of a monitoring platform (full stack) as well as development of wearable/sensor components (prototype iteration, integration, demonstrator readiness).
Product development including requirements gathering from the clinical context, feature prioritization, and definition of an MVP approach.
Preparation and design of clinical field trials (study/pilot design, organizational coordination, technical requirements for field operation).
Design of broadcast/transmission networks based on LoRaWAN for reliable, energy-efficient communication in ward environments.
Achievements:
Secured seed funding of EUR 0.5 million, creating the basis for prototype development, patenting, and preparation for clinical studies.
Built a prototype end-to-end solution (platform + wearables + network design) that could serve as a basis for demonstrations and piloting in the clinical environment.
Created the IP foundation through patent filings and addressed the protectability of key solution components.
Prepared clinical validation (field trial concept), enabling a structured transition from prototype to proof in practice.
Technologies used:
Java.
Spring Boot.
Vue.js.
C (embedded/wearables).
Infrastructure, concepts used:
InfluxDB (time-series data for measurement/sensor data).
LoRaWAN (radio/network stack for low-power communication).
Methods used:
Scrum.
Stakeholder management.
Seed funding management (preparation/management of early-stage financing).
Freedom-to-operate analysis.
MedTech engineering: risk management according to ISO 14971, usability engineering (IEC 62366), privacy/security by design (GDPR).
IoT architecture: device provisioning, OTA updates, edge gateways, MQTT/CoAP patterns.
Data & monitoring: alerting logic, event streaming, data quality/validation, audit trails for clinical use.
Study preparation: ethics approval processes, inclusion/exclusion criteria, data management plan (DMP).
Head of Engineering & Consulting / Authorized Signatory / Member of Management Board
birkle IT AG
Short description: Leadership role in an engineering and consulting environment with signing authority and responsibility for building, scaling, and steering a software delivery organization. Focus was on building seven full-stack teams (about 60 developers and business analysts), delivering several parallel customer initiatives (public sector, healthcare, automotive), as well as establishing DevOps/IaC, security responsibility, and building a tech business incubation unit with spin-offs.
Tasks and responsibilities:
Building and scaling seven full-stack teams in software delivery (headcount about 60), including recruiting, team setup, delivery structures, coaching/mentoring, and architecture and technology governance.
Role as lead software/DevOps architect and developer in critical projects; enabling teams through standards, reviews, best practices, and technical coaching.
Role as security officer (SiBe): building a full-stack team at a federal authority (14 person-years) including framework conditions from security clearance (SÜG §10) and relevant regulations (BVerfSchG §3 para. 2).
Building a machine learning team for healthcare customers (10 person-years) with a focus on object detection, pose estimation, and natural language processing; technical and organizational leadership.
Building a tech business incubator unit including concept development, team setup, delivery, and successful spin-off/capitalization of two startups in the healthcare environment (AI-based real-time analysis of surgical procedures, ubiquitous patient monitoring).
Building a DevOps team (10 person-years) and evangelizing/introducing Infrastructure as Code (standardization, automation, delivery acceleration).
Building an infrastructure team (2 person-years) for on-prem/hybrid platform topics (including VMware ESX, Proxmox, Unifi, Active Directory, Keycloak) including operations and integration aspects.
End-to-end introduction of an ERP system Odoo at an automotive customer (10 person-years), including organizational/process consulting, integration, and delivery management.
Migration of an inventory management software for insurance policies (30 person-years), including program management, modernization focus areas, and transition/parallel operation aspects.
Achievements:
Built a scalable delivery organization (7 teams, ~60 FTE) and thus made parallel, multi-domain customer programs deliverable.
Established DevOps and IaC capabilities and embedded them in delivery (higher repeatability, lower operational/deployment risks).
Operationalized innovation/business building: built an incubator unit and supported two spin-offs through to capitalization.
Strengthened public sector capability by building a team under high security requirements including formal security clearances.
Technologies used:
Java, Spring Boot.
Python.
Node.js.
ECMAScript/TypeScript, HTML5, CSS, Sass/Less.
Angular.
TensorFlow, YOLO (ML/CV).
Maven, Gradle.
Terraform, Vagrant.
OpenID (including OIDC context), OpenAPI.
Infrastructure, concepts used:
Jira, Confluence.
GitLab, Bitbucket.
CI/CD & platform: Jenkins, OpenShift, Kubernetes, Docker, Rancher.
Cloud/Compute: AWS EC2.
IAM: Keycloak, Active Directory.
Data/Storage: InfluxDB, MongoDB, PostgreSQL.
Computer vision: OpenCV.
Interfaces: REST.
Methods used:
Scrum.
Engineering leadership: OKR/objective systems, capability/skill matrix, communities of practice, architecture governance through architecture review boards.
Delivery excellence: SDLC standards, definition-of-ready/done, quality gates, testing strategies (E2E/contract/performance).
Security & compliance: secure SDLC, threat modeling, IAM hardening, audit/logging standards (especially public sector).
DevOps practices: GitOps, IaC module standards, platform self-service, observability standards (metrics/logs/traces).
Software Architect & Lead Developer (Lead Architect Product Area "Contract Creation")
Allianz Technology
Short description: Consulting as software architect and lead developer in the ABSi program for the further development of a multi-tenant car insurance platform for OEM customers. Focus was on agile, program-wide architecture work in the product area "Contract Creation", standardizing frontend integration via an API gateway, modernizing legacy components toward microservices, and migrating a proprietary CMS stack to Adobe Experience Manager, including modernization of the authentication layer to OpenID/Keycloak. Additional responsibility for transition and knowledge transfer activities toward offshore/India.
Tasks and responsibilities:
Lead architect of the product area Contract Creation within a program-wide "agile architecture" (architecture guardrails, consistency across teams, decision and review processes).
Introduction of an API gateway for all web frontends based on Netflix Zuul (centralization of routing, cross-cutting concerns, consolidation of frontend/backend interfaces).
Migration of five legacy Java portlets to a microservice architecture with a modernized Angular frontend (decoupling, modernization of delivery and deployment structure).
Migration of 17 legacy BFF/frontend applications from a proprietary CMS to Adobe Experience Manager (AEM), including replacing the auth layer with a modern OpenID-based IAM solution with Keycloak (replacement of historical authentication mechanisms, harmonization of identity integration).
Lead consultant for India transition including planning and running knowledge transfer sessions (knowledge transfer, enablement, handover of responsibility).
Achievements:
Established standardized, scalable frontend integration through the introduction of a central API gateway (uniform technical control points for web frontends).
Accelerated legacy modernization and improved maintainability through successful migration of portlets and CMS-related applications to microservices/Angular and AEM in time, in budget and in quality.
Successful transition support through structured knowledge transfer toward offshore/India.
Technologies used:
Java.
Spring Boot.
ECMAScript/TypeScript.
HTML5, CSS, Sass/Less.
AngularJS / Angular (2/5).
Netflix Zuul (API gateway).
Maven, Gradle.
OpenID, OpenAPI.
Infrastructure, concepts used:
Jira, Confluence.
Bitbucket.
Eclipse, WebStorm.
Adobe Experience Manager (AEM).
DB2.
Docker.
OpenShift, Kubernetes.
Keycloak.
REST.
SAML (legacy/integration context).
CORS (frontend/gateway context).
Methods used:
Scrum.
Communities of practice.
Architecture in scaled agile: SAFe-/LeSS-like practices, architecture runways, enabler epics, architecture reviews/boards.
API management: rate limiting, authZ policies, contract testing, API versioning.
Security: OIDC/OAuth2 hardening, token strategies, zero-trust patterns for BFF/gateway.
Delivery: CI/CD pipelines, blue/green or canary deployments in OpenShift/Kubernetes.
On-call duty: lead engineer for all portals on release weekends, responsible for emergency hotfixes before go-live.
VP Operations (Startup) – Embedded/SDR Product Development & Operations
Modula Team GmbH
Short description: VP Operations in a startup for developing a digital interface for a tactical COFDM modem with a very small ROM footprint (max. 50 KB). Responsibilities included business and financing activities (business plan, investor acquisition, financing rounds) as well as the prototype hardware/signal path concept (ADC cascade, dynamic range/noise optimization), field test tooling (GPS-based measurement) and the full-stack development of a web interface including a bare-metal embedded backend (minimal IP/TCP stack and web server without RTOS on SmartFusion2/ARM Cortex).
Tasks and responsibilities:
Creating the business plan including derivation of product/market assumptions, cost/financial planning, and the investor story.
Acquiring investor capital and coordinating/managing financing rounds (pipeline, documents, stakeholder management).
Prototypical design of the receiver unit and ADC cascade including optimization of dynamic range and noise thresholds (signal quality, robustness in field conditions).
Development of a GPS-based measurement tool to capture transmit/receive values on pilot frequencies; running/supporting field tests with pilot customers and preparing the measurement results.
Full-stack development of a web interface under strict resource constraints (ROM footprint) with frontend (jQuery/HTML/CSS/SASS; partly Vue.js/Angular) and backend as a minimal TCP/IP stack plus web server.
Implementation of core embedded components bare metal without RTOS on SmartFusion2 (ARM Cortex IP core) with the goal of maximum control over resource usage and deterministic runtime behavior.
Technical coordination of measurement and test setups (e.g. spectrum analyzer/network analyzer) to validate RF and reception characteristics.
Achievements:
Implemented a prototype end-to-end solution (embedded backend + web UI + field test tooling) that enabled development, demonstration, and pilot use at the customer.
Enabled operation under extremely tight resource constraints (ROM footprint optimization) through a minimal protocol/web server implementation and a strictly lean UI architecture.
Improved measurement and field test capability through a GPS-based measurement tool and structured data collection on pilot frequencies.
Professionalized financing preparation and investor discussions through the business plan and coordinated financing rounds.
Technologies used:
C (embedded, bare metal).
JavaScript.
HTML5, CSS3, SASS.
jQuery.
Vue.js, AngularJS/Angular (2).
Infrastructure, concepts used:
SmartFusion2 (SoC/FPGA environment), ARM Cortex (IP core).
Jira.
Leaflet (map/GPS visualization in the measurement tool).
RF/measurement equipment: R&S Spectrum Analyzer, Network Analyzer.
Receiver circuit design & noise optimization (hardware/RF design activities).
ADC dynamic range optimization (signal path optimization).
Methods used:
Scrum.
Embedded engineering practices: linker script/memory layout optimization, static analysis, unit tests on target, deterministic timing analyses.
Networking/protocols: lwIP-like minimal stacks, HTTP/1.1 minimal profiles, secure update mechanisms (bootloader/OTA).
RF/field testing: standardized measurement protocols, automated report generation, heatmaps/geo-fencing for coverage analyses.
COO, Co-Founder, Seed Investor
Deutscher Televisionsklub Betriebs GmbH, Satelio
Short description: Co-founded Satelio and took operational responsibility as COO for a pay-TV platform for German expats in southern Africa via Intelsat. Scope included rights/licensing management, international legal clarification for commercial rebroadcasting, negotiation of transponder capacity worth several million USD, seed financing (EUR 1.5 million), technical planning (link budgets), and building and operating a DVB uplink station. In addition, I implemented the web presence and a shop/order system.
Tasks and activities:
Licensing of copyright for international TV content, including coordination with rights holders and exploitation partners.
Coordination of international legal opinions (including Namibia, Bulgaria, Germany) on copyright and the commercial rebroadcasting of German TV channels (risk and compliance coverage).
Negotiation and conclusion of contracts for satellite transponder capacity worth several million US dollars (commercial terms, terms, performance parameters).
Raising investor capital and carrying out the seed financing (EUR 1.5 million), including investor relations and document coordination.
Planning the link budgets of an Intelsat transponder (signal/coverage planning, technical parameters, operating assumptions).
Planning and installation of digital video broadcasting uplink stations, including decoding, encoding, multiplexing, and transmission (end-to-end broadcast chain).
Development of the website and shop/order system (HTML5/CSS3/JavaScript/jQuery/PHP) for customer acquisition and order processing.
Achievements:
Secured seed financing of EUR 1.5 million and thus created the basis for product development and market entry.
Established the technical and commercial basis for satellite distribution (transponder contracts, link budget planning, uplink station as operational enablement structure).
Built legal readiness in an international context through coordinated legal opinions and licensing processes for content rights.
Operationalized digital sales channels through a web and shop/order system for customer acquisition and order handling.
Technologies used:
HTML5, CSS3.
JavaScript, jQuery.
PHP.
QPSK (modulation/transmission context).
DVB multiplex (broadcast/headend context).
Infrastructure, concepts used:
Elemental Encoder.
Blankom DVB Headend.
Conditional Access Systems (pay-TV access control).
Methods used:
Scrum.
QPSK link budget planning.
Broadcast engineering: DVB-S/DVB-S2 planning logic, EPG/metadata handling, monitoring/signal quality KPIs (MER/BER).
Security/commerce: payment provider integration, fraud prevention, data protection/compliance processes in e-commerce.
Operations: SLA/provider management, incident/problem management for uplink/headend operations.
CEO, Project Manager, Founder, Seed Investor
Panaccess Systems GmbH
Short description: Founded and built Panaccess as a conditional access platform for digital video services. Scope included strategic business development and global partnerships, building sales channels in LATAM/EMEA, seed financing (EUR 2 million), and project management in the development of security-critical hardware and embedded components (FPGA/embedded) for PCMCIA-based Conditional Access Modules (CAM) in the environment of integrated receiver decoders (IRD) and multiplex/modulator infrastructure (QAM/QPSK).
Tasks and activities:
Strategic business development, including building global partnerships with established industry vendors (partner strategy, go-to-market, contract/cooperation initiation).
Building and scaling sales channels in LATAM and EMEA (channel strategy, pipeline development, partner enablement).
Raising investor capital and carrying out the seed financing of EUR 2 million (investor relations, fundraising process, capitalization coordination).
Project management for the development of security hardware based on FPGA and embedded systems for PCMCIA-based conditional access modules (CAM).
Steering development and integration in the context of IRDs (integrated receiver decoders) as well as multiplex/modulator systems for QAM and QPSK (interfaces, system tests, integration in headend environments).
Implementation/coordination of technical components around DVB-specific signal/metadata processing (e.g. multiplexing/remultiplexing) and scrambling/decryption chains.
Achievements:
Secured seed financing of EUR 2 million and thereby enabled the startup's growth and product development.
Supported international market expansion by building sales channels in LATAM and EMEA and through strategic industry partnerships.
Established technical product capability in the security-critical broadcast environment through the development and integration of FPGA/embedded security hardware for CAM/IRD/headend ecosystems.
Technologies used:
C / C++ (embedded/systems).
Perl (scripting/tooling).
HTML5, CSS3.
JavaScript, jQuery.
PHP5.
DVB multiplex, NIT remultiplex.
Common Scrambling Algorithm (CSA2, CSA3).
FPGA.
Infrastructure, concepts used:
Jenkins (build/automation).
PostgreSQL.
Methods used:
Scrum.
Secure engineering: key management/KMS concepts, secure boot/hardware root of trust, penetration testing in an embedded context.
Broadcast/headend: DVB-C/S/S2 environments, CAS/DRM processes, monitoring entitlement/ECM/EMM flows.
Product & go-to-market: channel partner programs, pricing/packaging for B2B platforms, partner certification/enablement.
Industry Experience
See where this freelancer has spent most of their professional time.
Experienced in Telecommunication, Media and Entertainment, Information Technology, Healthcare, Aerospace and Defense, and Insurance.
Business Area Experience
See which departments and functions this freelancer has contributed to most.
Experienced in Product Development, Project Management, Information Technology, Strategy, Operations, and Finance.
Summary
Frederic has 25 years of experience as an incubator and IT consultant, and has led complex transformation and modernization projects in regulated environments (HealthTech, Banking, Industry) from cloud strategy to identity & access management. His focus areas were enterprise cloud governance for Microsoft Azure (CAF, policies, security/compliance, FinOps) as well as consulting on public cloud provider transitions, including RFPs, readiness, and TCO analyses. In addition, he implemented IAM/SSO migrations (SAML/Shibboleth to Keycloak) both architecturally and as sub-project lead. In product projects, he was responsible as lead developer/architect for the modernization of platforms (AWS/Kubernetes, CI/CD, observability) and the integration of ML/AI components – always with a strong focus on stakeholders and delivery.
Skills
- Cloud & Governance: Aws (Architecture/Platform) – 4.7 Years
- Cloud & Governance: Finops / Cloud Cost Control – 1.5 Years
- Cloud & Governance: Azure Caf / Landing Zones – 1.3 Years
- Cloud & Governance: Azure Policy / Enterprise Guardrails – 1.3 Years
- Cloud & Governance: Microsoft Azure (Architecture & Operations) – 1.3 Years
- Cloud & Governance: Openstack (Private Cloud Iaas) – 0.6 Years
- Cloud & Governance: Cloud Provider Strategy / Rfp / Scoring – 0.3 Years
- Leadership & Methods: Scrum / Agile Delivery – 16.5 Years
- Leadership & Methods: Project Management / Program Control – 10.5 Years
- Leadership & Methods: Stakeholder Management (C-Level To Engineering) – 10.5 Years
- Platform & Devops: Terraform / Opentofu / Terragrunt (Iac) – 7.6 Years
- Platform & Devops: Ci/Cd (Gitlab Ci, Github Actions, Jenkins) – 7.5 Years
- Platform & Devops: Kubernetes / Openshift – 6.6 Years
- Platform & Devops: Observability (Prometheus/Grafana) – 4.0 Years
- Security & Iam: Keycloak (Including Extensions) – 7.2 Years
- Security & Iam: Oauth2 / Openid Connect – 7.2 Years
- Security & Iam: Saml / Shibboleth – 2.8 Years
- Security & Iam: Security Engineering (Threat Modeling, Secure Sdlc, Owasp) – 11.0 Years
- Security & Iam: Compliance (Gdpr, Iso 27001, Bsi C5) – 4.1 Years
- Software Engineering: Java / Spring Boot – 7.2 Years
- Software Engineering: Javascript/Typescript (Node.Js, Web) – 15.3 Years
- Software Engineering: Frontend (Vue.Js / React / Angular) – 10.5 Years
- Software Engineering: Python (Including Ml/Automation) – 4.5 Years
- Software Engineering: Machine Learning / Computer Vision – 2.9 Years
- Software Engineering: Databases (Postgresql, Oracle, Influxdb, Mongodb, Db2) – 11.0 Years
Languages
Education
University of Augsburg
Pre-Diploma · Economics · Augsburg, Germany
Lion Feuchtwanger Gymnasium
Abitur · Munich, Germany
Statistics
Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Project Manager (Enterprise Cloud Governance)
Nearby freelancers
Professionals working in or nearby Walpertskirchen, Germany
