Frédéric Klein-IT Consultant, Architect, Full Stack, DevOps

Check rate
Experience
Project Manager (Enterprise Cloud Governance)
CompuGroup Medical SE & Co. KGaA
Short description: Lead a group-wide project to establish standardized cloud governance for Microsoft Azure, including policies, security and compliance controls, automation, and cost and operations control while preserving the autonomy of decentralized business units within regulatory boundaries.
Tasks and activities:
Overall responsibility for the design, setup, and implementation of an enterprise-wide cloud governance structure (Azure), incl. target picture, roadmap, and operating model.
Management of internal and external stakeholders (C-level, IT, Security, Compliance, Cloud Architecture, DevOps) incl. decision-making and escalation management.
Planning and facilitation of workshops on cloud strategy, governance principles, and the design of areas such as Identity, Connectivity, and Platform Management.
Definition, implementation, and rollout of cloud policies (Azure Policy / custom policies), security standards, and compliance requirements (including GDPR, ISO 27001, BSI C5).
Building a cloud governance framework aligned with the Azure Cloud Adoption Framework (CAF), incl. landing zone and guardrail concepts.
Introduction of automation solutions for governance, security, and cost control (policy/control automation, IaC, CI/CD-based control mechanisms).
Implementation of cloud security and compliance monitoring mechanisms as well as continuous improvement processes.
Establishment and operationalization of FinOps in an enterprise environment (central and decentralized FinOps teams), incl. cost management strategies, reporting, and guardrails.
Integration of governance policies into DevOps processes (e.g. CI/CD principles for security and compliance checks, GitLab Runner concept in spokes, GitLab CI/CD for CAF landing zones).
Implementation of access concepts incl. RBAC design and "break glass" mechanisms (emergency access) as well as certificate automation (ACME / step-ca).
Achievements:
Created a unified, auditable governance and control set for Azure (policies, standards, compliance mapping) and thus laid the foundation for scalable cloud usage in a regulated environment.
Established repeatable automation for governance, security, and cost control (IaC + CI/CD), reducing manual effort and implementation risks.
Improved operational and decision-making capabilities across central and decentralized units (clearer roles, responsibilities, escalation paths, balance between autonomy and group requirements).
Significantly increased workload compliance for lift-and-shift migrations.
Technologies used:
Microsoft Azure Policy, custom policies.
Terraform, OpenTofu, Terragrunt.
step-ca (ACME).
Entra ID.
Azure Firewall.
Azure networking, hub-and-spoke architecture.
Azure vWAN (evaluation).
Azure Front Door, Azure Application Gateway.
Azure ExpressRoute.
Azure Key Vault.
NetBox.
GitLab (on-premises).
Infrastructure, concepts used:
Cloud shared responsibility model.
Hub-and-spoke connectivity / central shared services (from a hub-spoke context).
Central governance with decentralized delivery (business unit autonomy with guardrails).
Methods used:
Scrum.
Stakeholder management (C-level to engineering).
Cloud governance, Azure Cloud Adoption Framework (CAF).
DevOps, CI/CD.
Cost and FinOps approaches: tagging/chargeback models, budget/alert concepts, reserved instances/savings plans vs. on-demand scenarios, sensitivity analyses.
RBAC, "break glass" concepts.
ACME / certificate automation.
GitLab Runner concept in spokes, GitLab CI/CD pipelines for CAF landing zones.
Project Manager / Subproject Manager (IAM & SSO), Architect
Bank-Verlag GmbH
Short description: Subproject lead for modernizing the identity and access management of an online banking application. The focus was on migrating one tenant from an existing SAML-based integration (Shibboleth) to an SSO approach based on the existing Keycloak IAM architecture, while preserving the existing tenant extensions (central user management, TAN flow generators) and focusing on limiting additional complexity in the core domain.
Tasks and activities:
Analysis of the existing SAML integration of the Spring Boot application via Shibboleth, including authentication and session flows as well as interfaces to the online banking solution.
Review of the existing Keycloak IAM architecture, incl. customer-specific extensions (central user management, cross-tenant TAN flow generators, session management).
Redesign of a Keycloak extension in the form of a custom authenticator (proxy pattern) that forwards authentication requests in a controlled way to the existing online banking solution with the goal of reducing coupling, limiting additional complexity, and not fragmenting the encapsulation of the business core domain.
Technical and business steering of the development team (prioritization, architecture decisions, quality assurance, dependencies/impediments).
Regular reporting to the steering committee incl. status, risks, decision needs, and migration progress.
Achievements:
Defined a migration-ready target architecture for SSO that protects the existing online banking core domain (proxy authenticator instead of deep changes to the application logic).
Supported consolidation and reusability in the IAM landscape by taking existing Keycloak extensions and tenant mechanisms into account and evolving them in a compatible way.
Improved transparent program control and decision-making through structured stakeholder and steering committee reporting.
Technologies used:
Java.
Spring Boot.
Spring Security.
React.
Keycloak (incl. extensions, session management).
Shibboleth.
SAML (existing integration / migration).
Infrastructure, concepts used:
Tomcat.
Nginx.
Methods used:
Scrum.
Identity & Access Management (IAM).
DevOps.
Standards & patterns: OAuth 2.0 / OpenID Connect (typical for SSO with Keycloak), token and session hardening, back-channel logout.
Security engineering: threat modeling, security by design, audit logging/tracing for auth flows, OWASP ASVS-relevant controls.
Subject Matter Expert (SME), Consultant
CompuGroup Medical SE & Co. KGaA
Short description: Consulting on the further development of a cloud provider strategy that was previously centered on private cloud, moving it toward a public cloud approach. The focus was on organizational and technical readiness, RFP support for business-critical workloads, provider evaluation (scoring), and cost estimates plus compliance/policy mapping for hyperscalers.
Tasks and activities:
Building and aligning an organizational and technical cloud readiness assessment catalog for CTOs of the business segments (including criteria for architecture, operations, security, compliance, and organization).
Consulting procurement, management, and tech leads in an RFP for hosting business-critical applications in the public cloud (requirements, evaluation logic, decision documents).
Performing a comprehensive scoring of the providers participating in the RFP, incl. a consistent evaluation method and result preparation for stakeholder decisions.
Cost estimation and TCO-like projections based on workload bills for 12 products using hyperscaler price calculators (comparability of assumptions, derivation of cost drivers).
Assessment of the existing IT governance with regard to public-cloud readiness (control framework, role/responsibility model, decision and approval processes).
Analysis of existing corporate guidelines and compliance requirements and mapping them to available policy and control mechanisms of the hyperscalers (e.g. Azure Policy rulesets, derivation of gaps and measures).
Achievements:
Created a decision-ready basis for provider selection (RFP consulting, transparent scoring, comparable evaluation logic).
Systematized cloud readiness and harmonized it across segments (assessment catalog for CTOs as a reusable tool).
Increased cost and governance transparency for the public cloud transition (workload-based cost estimates, mapping of guidelines/compliance to hyperscaler controls).
Technologies used:
Azure Price Calculator.
AWS Price Calculator.
Infrastructure, concepts used:
Cloud shared responsibility model.
Amazon Web Services (AWS).
Microsoft Azure.
Google Cloud Platform (GCP).
Azure Policy (policy rulesets / controls).
Azure Cloud Adoption Framework (CAF).
Methods used:
Cloud readiness assessment (workload-oriented).
Software architecture analysis.
RFP sourcing: weighted scorecards, must-/should-criteria, risk and compliance matrix.
Architecture blueprints: reference architectures (landing zone, network/identity baselines), migration wave planning, well-architected checks (provider-specific).
Consultant (Cloud Architecture / Private Cloud)
CompuGroup Medical SE & Co. KGaA
Short description: Architecture and performance consulting for internal Group IT customers in the context of provided private cloud services based on OpenStack. The focus was on building an IaaS service product for running end-customer software in the cloud, diagnosing and fixing storage/disk I/O performance issues in virtualized OpenStack environments, and making proprietary legacy appliances operational in OpenStack through targeted hypervisor/image configuration.
Tasks and activities:
Consulting a business unit on building an IaaS service product based on OpenStack to enable end customers to run the Medistar software in the cloud (service/architecture design, operations and platform requirements, technical guardrails).
Identification of disk I/O jitter in virtualized guest operating systems of an OpenStack cluster; creation of structured analysis and benchmark reports based on fio, diskspd, and Phoronix.
Close collaboration with the infrastructure/platform team on root cause analysis and remediation (hypothesis building, measurement concept, retests, result validation).
Investigation of the impact of I/O jitter on database workloads (including Oracle, PostgreSQL), incl. analysis of Oracle-specific I/O mechanisms and calibration procedures.
Support for bringing proprietary legacy firewalls based on Linux into operation in OpenStack by adjusting the VM boot environment and the libvirt/SCSI layer via image properties/metadata (KVM/libvirt configuration parameters).
Use of IaC approaches for repeatable provisioning/parameterization (Terraform) in the context of private cloud services.
Achievements:
Created performance transparency and a basis for decisions by reproducibly proving, quantifying, and documenting I/O jitter in usable benchmark reports.
Improved the operational readiness of business-critical workloads in the private cloud (database workloads and legacy appliances) by analyzing technical root causes and implementing targeted configuration measures.
Enabled a business unit to build a market-ready IaaS service product based on OpenStack through practical architecture and platform consulting.
Technologies used:
Terraform.
Ansible.
fio, diskspd, Phoronix, iostat, vmstat, sar (benchmarking/performance analysis).
PowerShell.
Infrastructure, concepts used:
OpenStack: Nova, Cinder, Neutron, Glance, Heat.
KVM hypervisor.
libvirt (SCSI/storage stack).
Cloudbase-Init (Windows cloud-init).
Operating systems: Linux, Windows.
Databases: Oracle, PostgreSQL.
Storage: Pure Storage.
Methods used:
Cloud shared responsibility model.
Performance/benchmark-driven troubleshooting (measurement concept, reproducibility, validation).
Storage/VM tuning: Virtio-SCSI, IO threading, queue depth tuning, NUMA/CPU pinning.
Interim Head of Software Development (Consulting)
Zeppelin GmbH
Short description: Interim leadership and consulting as Head of Software Development for the Digital Factory of the Zeppelin Group. Focus on multi-team steering (cloud infrastructure, telematics, data management, CMS), development of a cloud strategy incl. framework proposal (governance and architecture guidelines, provider selection, disaster recovery concept by criticality levels), as well as building a task force for health checks and rightsizing of an existing telematics platform.
Tasks and activities:
Functional leadership of four teams in the domains of cloud infrastructure, telematics, data management, and content management systems (prioritization, dependencies, target picture, delivery steering).
Consulting on cloud strategy and migration incl. support for an internal task force (decision and approach models, stakeholder alignment).
Development of a proposal for a cloud framework as a steering and architecture guideline.
Definition of governance and architecture guidelines (e.g. standardization, guardrails, operating models).
Definition of selection criteria for cloud providers (business/technical/compliance-based).
Development of disaster recovery and resilience strategies along a criticality classification model for applications.
Building and steering a task force for health checks and rightsizing of an existing telematics platform; consulting and support in defining and prioritizing requirements (e.g. performance, stability, cost, scaling).
Achievements:
Established a unified leadership and steering structure across multiple teams and thereby strengthened the decision-making and delivery capability of the Digital Factory.
Delivered an implementation-ready proposal for a cloud framework (governance, architecture, provider selection, DR based on a criticality model) as a basis for standardized migration and operations.
Reduced cost and operational risks of a telematics platform by structuring health checks/rightsizing and operationalizing them through a dedicated task force.
Technologies used:
RabbitMQ.
Kafka.
Python.
Scala.
Terraform.
Infrastructure, concepts used:
Kubernetes.
Ansible.
Observability: Prometheus, Grafana.
Identity/IAM: Keycloak.
FinOps (cost control).
AWS Well-Architected Framework (as evaluation/guideline).
BSI-oriented emergency management for cloud applications (DR/BCM reference framework).
Methods used:
Scrum.
Operating model & governance: RACI, Cloud Center of Excellence (CCoE), architecture review board/guardrail processes.
Resilience: RTO/RPO definition, failover strategies (multi-AZ/region), runbooks and regular DR tests.
FinOps practices: tagging standards, budgets/alerts, unit economics/showback/chargeback.
Lead Developer (Full-Stack) / Software Architect
Körber Pharma Inspection GmbH
Short description: Lead full-stack development and software architecture for EjectX, an AI-powered inspection system for detecting safety-relevant product deviations in a pharmaceutical environment. Focus on modernizing and stabilizing the tech stack, interfaces to data science pipelines, introducing an API gateway, and standardizing security/IAM as well as automating AWS deployments and building observability in Kubernetes.
Tasks and activities:
Technical and professional leadership of a development team (4 FTE), including architecture decisions, prioritization, and quality assurance.
Analysis of existing inspection systems taking current interfaces and integration constraints into account (system/interface assessment).
Reduction of technical debt and migration of outdated framework versions to improve maintainability, security, and delivery capability.
Development and stabilization of interfaces to data science pipelines (integration of ML/AI components into the product platform).
Backend and frontend development along defined user stories using definition-of-ready/definition-of-done criteria.
Introduction and enforcement of coding guidelines with a focus on clean code (consistency, testability, review standards).
Introduction of an API gateway based on OpenResty/OpenNginx, including connection to Keycloak via OpenID Connect for centralized authentication/authorization.
Replacing manual infrastructure provisioning in AWS with automated application deployment using GitHub Actions as well as Terraform and Ansible (infrastructure/deployment automation).
Building a monitoring/observability setup with Prometheus/Grafana, deployed in the Kubernetes cluster, including an operational baseline for operations and error analysis.
Achievements:
Increased delivery and operational readiness of the system through consistent reduction of technical debt and framework migrations (lower maintenance risk, modernized foundation).
Unified security and access concepts by introducing a central API gateway with OIDC integration to Keycloak (consistent authN/authZ layer).
Established reproducible deployments and better scalability through IaC and CI/CD automation (Terraform/Ansible + GitHub Actions) as well as a Kubernetes-based operations platform.
Improved operational transparency by introducing Prometheus/Grafana as the monitoring standard in the cluster.
Technologies used:
JavaScript, TypeScript.
Node.js, AdonisJS.
Vue.js.
Cypress (E2E/frontend tests).
Python, TensorFlow (data science/ML integration).
Nginx, OpenResty (API gateway).
Terraform.
Infrastructure and concepts used:
AWS.
Docker.
Kubernetes.
Ansible.
GitHub Actions (CI/CD).
IAM / identity: Keycloak, OpenID Connect (OpenIDC).
Observability: Prometheus, Grafana.
Methods used:
Scrum.
Clean code (coding guidelines, reviews, quality standards).
Architecture and engineering practices: domain-driven interface design (e.g. bounded contexts), API design (REST/async), ADRs (architecture decision records).
Kubernetes ops: Helm/Kustomize, ingress standards, resource limits/requests, horizontal pod autoscaling.
CEO (Seed Phase, Product & Technology)
IT4Medic GmbH
Short description: Management and building of a startup in the seed phase to develop a platform for real-time patient monitoring on nursing and general wards (non-ICU) using sensor-based body-area networks. Responsibility covered IP/patents, product and prototype development (platform + wearables), network concept (LoRaWAN), as well as preparation of clinical field trials and stakeholder work in the healthcare environment.
Tasks and activities:
Steering the seed phase including overall operational responsibility for product, technology, and stakeholder management.
Initiating and supporting patent filings (IP strategy, documentation, FTO analyses, coordination with patent attorneys/stakeholders).
Rapid prototyping of a monitoring platform (full stack) as well as development of wearable/sensor components (prototype iteration, integration, demonstrator capability).
Product development including collecting requirements from the clinical context, prioritizing features, and defining an MVP approach.
Preparation and design of clinical field trials (study/pilot design, organizational alignment, technical requirements for field operation).
Design of broadcast/transmission networks based on LoRaWAN for reliable, energy-efficient communication in ward environments.
Achievements:
Secured seed funding of EUR 0.5 million and thereby created the basis for prototype development, patenting, and preparation for clinical studies.
Built a prototype end-to-end solution (platform + wearables + network design) that could serve as the basis for demonstrations and pilot use in a clinical environment.
Created the IP foundation through patent filings and thus addressed the protectability of key solution components.
Prepared clinical validation (field trial concept), enabling a structured transition from prototype to real-world proof.
Technologies used:
Java.
Spring Boot.
Vue.js.
C (embedded/wearables).
Infrastructure and concepts used:
InfluxDB (time-series data for measurement/sensor data).
LoRaWAN (radio/network stack for low-power communication).
Methods used:
Scrum.
Stakeholder management.
Seed funding management (preparation/steering of early-stage financing).
Freedom-to-operate analysis.
MedTech engineering: risk management according to ISO 14971, usability engineering (IEC 62366), privacy/security by design (GDPR).
IoT architecture: device provisioning, OTA updates, edge gateways, MQTT/CoAP patterns.
Data & monitoring: alerting logic, event streaming, data quality/validation, audit trails for clinical use.
Study preparation: ethics approval processes, inclusion/exclusion criteria, data management plan (DMP).
Head of Engineering & Consulting / Authorized Signatory / Member of Management Board
birkle IT AG
Short description: Leadership role in an engineering and consulting environment with power of attorney and responsibility for building, scaling, and steering a software delivery organization. The focus was on building seven full-stack teams (around 60 developers and business analysts), delivering several parallel customer initiatives (public sector, healthcare, automotive), and establishing DevOps/IaC, security responsibility, and a tech-business incubation unit with spin-offs.
Tasks and activities:
Building and scaling seven full-stack teams in software delivery (headcount approx. 60), including recruiting, team setup, delivery structures, coaching/mentoring, and architecture and technology governance.
Role as lead software/DevOps architect and developer in critical projects; enabling teams through standards, reviews, best practices, and technical coaching.
Role as security officer (SiBe): building a full-stack team at a federal authority (14 person-years), including conditions from security screening (SÜG §10) and relevant regulations (BVerfSchG §3 para. 2).
Building a machine learning team for healthcare customers (10 person-years) with focus on object detection, pose estimation, and natural language processing; professional and organizational steering.
Building a tech business incubator unit including concept, team setup, delivery, and successful spin-off/capitalization of two startups in the healthcare environment (AI-supported real-time analysis of surgical procedures, ubiquitous patient monitoring).
Building a DevOps team (10 person-years) and evangelizing/introducing infrastructure as code (standardization, automation, faster delivery).
Building an infrastructure team (2 person-years) for on-prem/hybrid platform topics (including VMware ESX, Proxmox, Unifi, Active Directory, Keycloak), including operations and integration aspects.
End-to-end introduction of an ERP system, Odoo, for an automotive customer (10 person-years), including organizational/process consulting, integration, and delivery steering.
Migration of an inventory management system for insurance policies (30 person-years), including program steering, modernization focus, and transition/parallel operation aspects.
Achievements:
Built a scalable delivery organization (7 teams, ~60 FTE) and thus made parallel, multi-domain customer programs deliverable.
Established DevOps and IaC capabilities and embedded them in delivery (higher repeatability, lower operation/deployment risks).
Operationalized innovation/business building: built an incubator unit and supported two spin-offs through capitalization.
Strengthened public sector capability by building a team under high security requirements including formal security clearances.
Technologies used:
Java, Spring Boot.
Python.
Node.js.
ECMAScript/TypeScript, HTML5, CSS, Sass/Less.
Angular.
TensorFlow, YOLO (ML/CV).
Maven, Gradle.
Terraform, Vagrant.
OpenID (including OIDC context), OpenAPI.
Infrastructure and concepts used:
Jira, Confluence.
GitLab, Bitbucket.
CI/CD & platform: Jenkins, OpenShift, Kubernetes, Docker, Rancher.
Cloud/compute: AWS EC2.
IAM: Keycloak, Active Directory.
Data/storage: InfluxDB, MongoDB, PostgreSQL.
Computer vision: OpenCV.
Interfaces: REST.
Methods used:
Scrum.
Engineering leadership: OKRs/objective systems, capability/skill matrix, communities of practice, architecture governance through architecture review boards.
Delivery excellence: SDLC standards, definition of ready/done, quality gates, testing strategies (E2E/contract/performance).
Security & compliance: secure SDLC, threat modeling, IAM hardening, audit/logging standards (especially public sector).
DevOps practices: GitOps, IaC module standards, platform self-service, observability standards (metrics/logs/traces).
Software Architect & Lead Developer (Lead Architect Product Area "Contract Creation")
Allianz Technology
Short description: Consulting as software architect and lead developer in the ABSi program for the further development of a multi-tenant car insurance platform for OEM customers. The focus was on agile, program-wide architecture work in the product area “Contract Creation”, standardizing frontend integration via an API gateway, modernizing legacy components toward microservices, and migrating a proprietary CMS stack to Adobe Experience Manager, including modernizing the authentication layer to OpenID/Keycloak. Additional responsibility for transition and knowledge transfer activities toward offshore/India.
Tasks and activities:
Lead architect of the product area Contract Creation within a program-wide “Agile Architecture” (architecture guidelines, consistency across teams, decision and review processes).
Introduction of an API gateway for all web frontends based on Netflix Zuul (centralization of routing, cross-cutting concerns, consolidation of frontend-backend interfaces).
Migration of five legacy Java portlets to a microservice architecture with a modern Angular frontend (decoupling, modernization of delivery and deployment structure).
Migration of 17 legacy BFF/frontend applications of a proprietary CMS to Adobe Experience Manager (AEM), including replacement of the auth layer with a modern OpenID-based IAM solution using Keycloak (replacing historical auth mechanisms, harmonizing identity integration).
Lead consultant for India transition, including planning and running knowledge transfer sessions (knowledge transfer, enablement, handover of responsibility).
Achievements:
Established a standardized, scalable frontend integration through introduction of a central API gateway (uniform technical control points for web frontends).
Accelerated legacy modernization and improved maintainability through successful migration of portlets and CMS-related applications to microservices/Angular and AEM in time, in budget, and in quality.
Successful transition support through structured knowledge transfer toward offshore/India.
Technologies used:
Java.
Spring Boot.
ECMAScript/TypeScript.
HTML5, CSS, Sass/Less.
AngularJS / Angular (2/5).
Netflix Zuul (API Gateway).
Maven, Gradle.
OpenID, OpenAPI.
Infrastructure and concepts used:
Jira, Confluence.
Bitbucket.
Eclipse, WebStorm.
Adobe Experience Manager (AEM).
DB2.
Docker.
OpenShift, Kubernetes.
Keycloak.
REST.
SAML (legacy/integration context).
CORS (frontend/gateway context).
Methods used:
Scrum.
Communities of practice.
Architecture in scaled agile: SAFe-/LeSS-like practices, architecture runways, enabler epics, architecture reviews/boards.
API management: rate limiting, authZ policies, contract testing, API versioning.
Security: OIDC/OAuth2 hardening, token strategies, zero-trust patterns for BFF/gateway.
Delivery: CI/CD pipelines, blue/green or canary deployments in OpenShift/Kubernetes.
On-call duty: lead engineer for all portals during release weekends, responsible for emergency hotfixes before go-live.
VP Operations (Startup) – Embedded/SDR Product Development & Operations
Modula Team GmbH
Short description: VP Operations in a startup developing a digital interface for a tactical COFDM modem with a very small ROM footprint (max. 50 KB). Responsibilities included business and financing activities (business plan, investor acquisition, financing rounds) as well as prototype hardware/signal-path design (ADC cascade, dynamic range/noise optimization), field-test tooling (GPS-supported measurement), and full-stack development of a web interface including a bare-metal embedded backend (minimal IP/TCP stack and web server without RTOS on SmartFusion2/ARM Cortex).
Tasks and activities:
Creation of the business plan including derivation of product/market assumptions, cost/financial planning, and investor story.
Acquisition of investor capital and coordination and steering of financing rounds (pipeline, documents, stakeholder management).
Prototype design of the receiver unit / ADC cascade including optimization of dynamic ranges and noise thresholds (signal quality, robustness in field conditions).
Development of a GPS-supported measurement tool to capture transmit/receive values in pilot frequencies; conducting/supporting field tests with pilot customers and preparing the measurement results.
Full-stack development of a web interface under strict resource constraints (ROM footprint) with frontend (jQuery/HTML/CSS/SASS; in some areas Vue.js/Angular) and backend as a minimal TCP/IP stack plus web server.
Implementation of central embedded components bare metal without RTOS on SmartFusion2 (ARM Cortex IP core) with the goal of maximum control over resource usage and deterministic runtime behavior.
Technical coordination of measurement and test setups (e.g. spectrum analyzer/network analyzer) for validating RF and reception properties.
Achievements:
Built a prototype end-to-end solution (embedded backend + web UI + field-test tooling) that enabled development, demonstration, and customer pilot use.
Enabled operation under extreme resource constraints (ROM footprint optimization) through a minimalist protocol/web server implementation and a very lean UI architecture.
Improved measurement and field-test capability through a GPS-supported measurement tool and structured data collection in pilot frequencies.
Professionalized financing preparation and investor discussions through the business plan and coordinated financing rounds.
Technologies used:
C (embedded, bare metal).
JavaScript.
HTML5, CSS3, SASS.
jQuery.
Vue.js, AngularJS/Angular (2).
Infrastructure and concepts used:
SmartFusion2 (SoC/FPGA environment), ARM Cortex (IP core).
Jira.
Leaflet (map/GPS visualization in the measurement tool).
RF/measurement equipment: R&S spectrum analyzer, network analyzer.
Receiver circuit design & noise optimization (hardware/RF design activities).
ADC dynamic range optimization (signal path optimization).
Methods used:
Scrum.
Embedded engineering practices: linker script/memory layout optimization, static analysis, unit tests on target, deterministic timing analyses.
Networking/protocols: lwIP-like minimal stacks, HTTP/1.1 minimal profiles, secure update mechanisms (bootloader/OTA).
RF/field testing: standardized measurement protocols, automated report generation, heatmaps/geo-fencing for coverage analyses.
COO, Co-founder, Seed Investor
Deutscher Televisionsklub Betriebs GmbH, Satelio
Short description: Co-founding and operational responsibility (COO) for Satelio, a pay-TV platform for German expats in southern Africa via Intelsat. The scope covered rights/license management, international legal clarifications for commercial retransmission, negotiation of transponder capacity in the multi-million USD range, seed financing (EUR 1.5 million), technical planning (link budgets), and building and operating a DVB uplink station. In addition, I implemented the web presence and a shop/order system.
Tasks and activities:
Licensing of copyrights for international TV content, including coordination with rights holders and distribution partners.
Coordination of international legal opinions (including Namibia, Bulgaria, Germany) on copyright and the commercial retransmission of German TV channels (risk and compliance protection).
Negotiation and conclusion of contracts for satellite transponder capacity worth several million US dollars (commercial terms, terms, performance parameters).
Raising investor capital and carrying out the seed financing (EUR 1.5 million), including investor relations and document coordination.
Planning the link budgets of an Intelsat transponder (signal/coverage planning, technical parameters, operating assumptions).
Planning and installation of digital video broadcasting uplink stations, including decoding, encoding, multiplexing, and transmission (end-to-end broadcast chain).
Development of the website and shop/order system (HTML5/CSS3/JavaScript/jQuery/PHP) for customer acquisition and order processing.
Achievements:
Secured seed financing of EUR 1.5 million and thereby created the foundation for product development and market entry.
Established the technical and commercial basis for satellite distribution (transponder contracts, link budget planning, uplink station as an operational enablement structure).
Built legal operating capability in an international context through coordinated legal opinions and licensing processes for content rights.
Operationalized digital sales channels through a web and shop/order system for customer acquisition and order processing.
Technologies used:
HTML5, CSS3.
JavaScript, jQuery.
PHP.
QPSK (modulation/transmission context).
DVB Multiplex (broadcast/headend context).
Infrastructure, concepts used:
Elemental Encoder.
Blankom DVB Headend.
Conditional access systems (pay-TV access control).
Methods used:
Scrum.
QPSK link budget planning.
Broadcast engineering: DVB-S/DVB-S2 planning logic, EPG/metadata handling, monitoring/signal quality KPIs (MER/BER).
Security/commerce: payment provider integration, fraud prevention, data protection/compliance processes in e-commerce.
Operations: SLA/provider management, incident/problem management for uplink/headend operations.
CEO, Project Manager, Founder, Seed Investor
Panaccess Systems GmbH
Short description: Founded and built Panaccess as a conditional-access platform for digital video services. The scope included strategic business development and global partnerships, building sales channels in LATAM/EMEA, seed financing (EUR 2 million), and project management in the development of security-critical hardware and embedded components (FPGA/Embedded) for PCMCIA-based Conditional Access Modules (CAM) in the environment of integrated receiver decoders (IRD) and multiplex/modulator infrastructure (QAM/QPSK).
Tasks and activities:
Strategic business development with the setup of global partnerships with established industry providers (partner strategy, go-to-market, contract/cooperation initiation).
Building and scaling sales channels in LATAM and EMEA (channel strategy, pipeline development, partner enablement).
Raising investor capital and carrying out seed financing in the amount of EUR 2 million (investor relations, fundraising process, capitalization coordination).
Project management for the development of security hardware based on FPGA and embedded systems for PCMCIA-based Conditional Access Modules (CAM).
Steering development and integration in the use context of IRDs (Integrated Receiver Decoders) as well as multiplex/modulator systems for QAM and QPSK (interfaces, system tests, integration into headend environments).
Implementation/coordination of technical components around DVB-specific signal/metadata processing (e.g. multiplexing/remultiplexing) and scrambling/decryption chains.
Achievements:
Secured seed financing of EUR 2 million and thereby enabled the startup's growth and product development.
Supported international market expansion through the building of sales channels in LATAM and EMEA as well as strategic industry partnerships.
Established technical product capability in a security-critical broadcast environment through the development and integration of FPGA/embedded security hardware for CAM/IRD/headend ecosystems.
Technologies used:
C / C++ (embedded/systems).
Perl (scripting/tooling).
HTML5, CSS3.
JavaScript, jQuery.
PHP5.
DVB Multiplex, NIT Remultiplex.
Common Scrambling Algorithm (CSA2, CSA3).
FPGA.
Infrastructure, concepts used:
Jenkins (build/automation).
PostgreSQL.
Methods used:
Scrum.
Secure engineering: key management/KMS concepts, secure boot/hardware root of trust, penetration testing in an embedded context.
Broadcast/headend: DVB-C/S/S2 environments, CAS/DRM processes, monitoring of entitlement/ECM/EMM flows.
Product & go-to-market: channel partner programs, pricing/packaging for B2B platforms, partner certification/enablement.
Industry experience
See where this freelancer has spent most of their professional time.
Experienced in Telecommunication, Media and Entertainment, Information Technology, Healthcare, Aerospace and Defense, and Insurance.
Business area experience
See which departments and functions this freelancer has contributed to most.
Experienced in Product Development, Information Technology, Project Management, Strategy, Operations, and Finance.
Summary
Frederic has 25 years of experience as an incubator and IT consultant, and in regulated environments (HealthTech, Banking, Industry) he has been responsible for complex transformation and modernization projects from cloud strategy to identity & access management. His focus areas were enterprise cloud governance for Microsoft Azure (CAF, policies, security/compliance, FinOps) as well as consulting on public-cloud provider transitions incl. RFP, readiness, and TCO analyses. In addition, he implemented IAM/SSO migrations (SAML/Shibboleth to Keycloak) from an architectural perspective and as part-project lead. In product projects, he was responsible as lead developer/architect for modernizing platforms (AWS/Kubernetes, CI/CD, observability) and integrating ML/AI components - always with a strong focus on stakeholders and delivery.
Skills
- Cloud & Governance: Aws (Architecture/Platform) – 4.7 Years
- Cloud & Governance: Finops / Cloud Cost Control – 1.5 Years
- Cloud & Governance: Azure Caf / Landing Zones – 1.3 Years
- Cloud & Governance: Azure Policy / Enterprise Guardrails – 1.3 Years
- Cloud & Governance: Microsoft Azure (Architecture & Operations) – 1.3 Years
- Cloud & Governance: Openstack (Private Cloud Iaas) – 0.6 Years
- Cloud & Governance: Cloud Provider Strategy / Rfp / Scoring – 0.3 Years
- Leadership & Methods: Scrum / Agile Delivery – 16.5 Years
- Leadership & Methods: Project Management / Program Control – 10.5 Years
- Leadership & Methods: Stakeholder Management (C-Level To Engineering) – 10.5 Years
- Platform & Devops: Terraform / Opentofu / Terragrunt (Iac) – 7.6 Years
- Platform & Devops: Ci/Cd (Gitlab Ci, Github Actions, Jenkins) – 7.5 Years
- Platform & Devops: Kubernetes / Openshift – 6.6 Years
- Platform & Devops: Observability (Prometheus/Grafana) – 4.0 Years
- Security & Iam: Keycloak (Incl. Extensions) – 7.2 Years
- Security & Iam: Oauth2 / Openid Connect – 7.2 Years
- Security & Iam: Saml / Shibboleth – 2.8 Years
- Security & Iam: Security Engineering (Threat Modeling, Secure Sdlc, Owasp) – 11.0 Years
- Security & Iam: Compliance (Gdpr, Iso 27001, Bsi C5) – 4.1 Years
- Software Engineering: Java / Spring Boot – 7.2 Years
- Software Engineering: Javascript/Typescript (Node.Js, Web) – 15.3 Years
- Software Engineering: Frontend (Vue.Js / React / Angular) – 10.5 Years
- Software Engineering: Python (Incl. Ml/Automation) – 4.5 Years
- Software Engineering: Machine Learning / Computer Vision – 2.9 Years
- Software Engineering: Databases (Postgresql, Oracle, Influxdb, Mongodb, Db2) – 11.0 Years
Languages
Education
University of Augsburg
Pre-diploma · Economics · Augsburg, Germany
Lion Feuchtwanger Gymnasium
Abitur · Munich, Germany
Statistics
Experience
Expertise
Qualifications
Profile
Frequently asked questions
Have questions? Find more information here.
Frédéric is based in Walpertskirchen, Germany and can operate in on-site, hybrid, and remote work models.
Frédéric speaks the following languages: German (Native), English (Advanced), French (Elementary).
Frédéric has at least 17 years of experience. During this time, Frédéric has worked in at least 12 different roles and for 10 different companies. The average length of individual experience is 1 year and 5 months. Note that Frédéric may not have shared all experience and actually has more experience.
Based on recent experience, Frédéric would be well-suited for roles such as: Project Manager (Enterprise Cloud Governance), Project Manager / Subproject Manager (IAM & SSO), Architect, Subject Matter Expert (SME), Consultant.
Frédéric's most recent position is Project Manager (Enterprise Cloud Governance) at CompuGroup Medical SE & Co. KGaA.
In recent years, Frédéric has worked for CompuGroup Medical SE & Co. KGaA, Bank-Verlag GmbH, Zeppelin GmbH, Körber Pharma Inspection GmbH, and IT4Medic GmbH.
Frédéric is most experienced in industries like Telecommunication, Media and Entertainment, and Information Technology. Frédéric also has some experience in Healthcare, Aerospace and Defense, and Insurance.
Frédéric is most experienced in business areas like Product Development, Project Management, and Information Technology. Frédéric also has some experience in Strategy, Operations, and Finance.
Frédéric has recently worked in industries like Information Technology, Healthcare, and Pharmaceutical.
Frédéric has recently worked in business areas like Information Technology, Project Management, and Product Development.
Frédéric attended University of Augsburg for Economics.
Frédéric is immediately available full-time for suitable projects.
Daily rate distribution
The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 7 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Similar freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a Project Manager (Enterprise Cloud Governance)
Nearby freelancers
Professionals working in or nearby Walpertskirchen, Germany
