Skip to main content
Top expert badge
Recommended expert
Profile header background

Reza N.-Senior IT Security Engineer · Detection & Response · Microsoft Security

Reza N. - Senior IT Security Engineer · Detection & Response · Microsoft Security - profile avatar
Profile header overlay
Available
Dreieich, Germany

Check rate

Experience

Jan 2026 - Present

Senior IT-Security Expert

Teambank AG

Position summary
Senior IT-Security Expert at Teambank AG
Industries
Banking and Finance
Business areas
Information Technology
  • Completed the integration of log sources into Microsoft Sentinel, including GCP workloads – centralized consolidation of all security-relevant events from Azure and GCP environments for complete end-to-end telemetry and comprehensive compliance evidence
  • Developed custom rules and use cases based on the GFG Use-Case Library and the MITRE ATT&CK Matrix to cover company-specific threats and GFG-relevant scenarios with precise, mapped detection rules
  • Tuned detection rules to minimize false positives, optimized detection thresholds, and modeled exceptions – enabling the SOC to work with relevant, prioritized alerts while reducing Mean Time to Detect/Respond
  • Built SOAR capabilities in Sentinel by developing playbooks to automate recurring response processes such as containment, user and host isolation, and ticketing – shorter response times and 24/7 scalability
  • Designed and built a log transformation solution to normalize and enrich incoming raw logs (GeoIP, CMDB, threat intelligence) and convert them into a consistent schema for high-performance KQL queries, use case logic, and correlations
  • Managed Azure security through Azure Policies to enforce security and compliance standards, prevent drift, and continuously remediate deviations
  • Operated the Defender XDR portal to link endpoint, identity, email, and SaaS signals with Sentinel findings, enable holistic incident triage, and orchestrate measures directly from XDR

Technologies: Microsoft Sentinel, Microsoft Defender XDR, Azure Policy, KQL, GCP, MITRE ATT&CK

Jan 2026 - Jun 2026

Principal IT-Security Engineer

nicos GmbH

Position summary
Principal IT-Security Engineer at nicos GmbH
Industries
Information Technology
Telecommunication
Business areas
Information Technology
Project Management
  • Holistically assessed and coordinated security events and managed incident response processes
  • Created and optimized use cases for threat detection in Microsoft Sentinel and SentinelOne
  • Administered and functionally expanded the central security infrastructure with a focus on Microsoft Defender; secured identities and access permissions in Microsoft Entra ID
  • Automated incident response workflows and runbooks using Palo Alto XSOAR and implemented a “Detection & Response as Code” approach to scale security measures
  • Designed and implemented XDR, EDR, and SOAR solutions while considering regulatory requirements under DORA, MaRisk, and BAIT
  • Led the project and technically implemented the company-wide SentinelOne rollout across all endpoints
  • Continuously planned, implemented, and optimized the IT security architecture to adapt to the current threat landscape

Technologies: Microsoft Sentinel, Microsoft Defender, Microsoft Entra ID, SentinelOne, Palo Alto XSOAR

Oct 2025 - Present

Senior IT-Security Engineer

Oldenburgische Landesbank AG

Position summary
Senior IT-Security Engineer at Oldenburgische Landesbank AG
Industries
Banking and Finance
Business areas
Information Technology
  • Analyzed and assessed security alerts and reports in the IBM QRadar SIEM system, identified false positives, and detected and assessed security-relevant incidents
  • Further developed and documented the alerting chain and ensured traceable escalation of critical security events according to project-specific requirements
  • Independently created use case reports and alerts based on existing log data; checked the correct integration and interpretation of log files to reduce false positives
  • Developed and deployed detection logic based on Sigma Rules for proactive threat detection
  • Rolled out the EDR solution across the company and implemented cross-platform security policies
  • Provided conceptual and technical consulting for the migration from IBM QRadar to Palo Alto Cortex XDR
  • Targeted optimization of SIEM processes to improve detection quality and efficiency in security monitoring

Technologies: IBM QRadar, Palo Alto Cortex XDR, Sigma

Aug 2025 - Oct 2025

IT-Security Expert

Taschen GmbH

Position summary
IT-Security Expert at Taschen GmbH
Industries
Media and Entertainment
Business areas
Information Technology
Project Management
  • Identified the company’s specific requirements and goals for SIEM and developed a detailed implementation plan
  • Implemented security policies and rules for detecting and responding to threats
  • Created comprehensive documentation for implementing and using the system and conducted training sessions and workshops

Technologies: Wazuh, Linux Administration, Windows Server

Oct 2024 - Nov 2025

IT-Security Engineer / Security Officer

chargecloud GmbH

Position summary
IT-Security Engineer / Security Officer at chargecloud GmbH
Industries
Information Technology
Business areas
Information Technology
  • Designed secure infrastructure, network, and application architectures and created reference architectures and security best practices for internal teams
  • Integrated and implemented SIEM and EDR in hybrid cloud environments (AWS, Hetzner), planned and carried out EDR/XDR rollouts, and configured log source integration
  • Developed and implemented SIEM use cases to improve threat detection and adapt it to specific business requirements
  • Built vulnerability management: designed and integrated vulnerability scanners (Tenable Nessus), assessed and remediated security vulnerabilities, and defined corresponding policies
  • Designed and wrote ISMS policies according to ISO 27001, NIS2, and CIS v8
  • Implemented and managed firewall security solutions (pfSense) and network security monitoring with IDS/IPS (Suricata, Snort)
  • Secured web applications based on the OWASP Top 10, integrated security controls into system design and development, and planned and reviewed network segmentation

Technologies: Elastic, Wazuh, Security Onion, Suricata, Snort, pfSense, Tenable Nessus, Sumo Logic, Ansible, Terraform, GitLab, Docker, AWS Cloud, Hetzner Cloud, ISO 27001, CIS v8

Apr 2024 - Oct 2025

Security Officer

Lufthansa AirPlus International

Position summary
Security Officer at Lufthansa AirPlus International
Industries
Banking and Finance
Business areas
Audit
Information Technology
  • Primary escalation point for complex security incidents and root cause analyses in multi-stage attack scenarios (lateral movement, data exfiltration) – Tier 2/L2 analysis
  • Assessment of the current system landscape, configuration, and integration of log sources with the SIEM, as well as infrastructure monitoring for the early detection of security incidents
  • Definition and maintenance of detection use cases and automated SOAR workflows for regulatory and security-related requirements
  • Implementation of solutions in compliance with DORA, MaRisk, and BAIT requirements, as well as the introduction of processes and technologies to meet PCI DSS requirements
  • Planning, execution, and setup of an ISMS based on ISO 27001, including ISO 27001-oriented audits and regular internal security reviews
  • Implementation of a case management system with TheHive, as well as automation of analysis, response, and threat intelligence with Cortex and MISP
  • Development of data loss prevention strategies and customized KPIs and metrics for monitoring and assessing vulnerabilities and security incidents
  • Evaluation of interfaces between the EDR system and ZTNA solution (Zscaler) for dynamic access control; design and further development of the architecture in the Azure Cloud

Technologies: Azure Cloud, Logpoint, Elastic, TheHive, Cortex, MISP, Rapid7 InsightVM, NeuVector, Zscaler, Jira, Confluence, Bitbucket, Linux (RHEL), Ansible, PostgreSQL, ISO 27001, PCI DSS

Mar 2024 - Jul 2024

Network Security Engineer

Telefónica Tech GmbH

Position summary
Network Security Engineer at Telefónica Tech GmbH
Industries
Information Technology
Telecommunication
Business areas
Information Technology
  • Implementation and management of Fortinet security solutions and network security monitoring
  • Implementation and consulting on SD-WAN, including technical consulting for the setup of underlay and overlay networks
  • Network design for customer environments, as well as planning and review of current network segmentation
  • Connecting network devices to a central management console for advanced control
  • Definition and development of security policies based on business requirements

Technologies: Fortinet (FortiManager, FortiExtender, FortiGate), Wireshark, Nmap

Oct 2023 - Apr 2024

DevSecOps Engineer

BMW Group AG

Position summary
DevSecOps Engineer at BMW Group AG
Industries
Automotive
Business areas
Audit
Information Technology
  • Integration of automated security tests into the development process for the early detection of vulnerabilities, as well as source code reviews (Snyk, CodeQL, Contrast Assess, OpenText Fortify)
  • Design and implementation of cloud security best practices in Azure and AWS (GuardDuty, IAM, Security Hub), as well as information queries through Azure Resource Graph
  • Operation, implementation, and maintenance of Kubernetes clusters (EKS, AKS), as well as application rollouts through ArgoCD workflows
  • Selection and integration of tools such as Terraform for infrastructure automation and Kubernetes for container orchestration in the CI/CD pipeline
  • Selection and implementation of Sentinel use cases, as well as leading and coordinating security incident response activities, including triage processes for prioritization
  • Planning and execution of ISO 27001-oriented audits, as well as development of a strategy to optimize patch management
  • Development and delivery of security awareness programs, as well as introduction of ITIL best practices to optimize IT service management processes

Technologies: Azure Cloud, AWS Cloud, Microsoft Sentinel, Kubernetes (EKS, AKS), Terraform, ArgoCD, Docker, Snyk, CodeQL, Contrast Assess, OpenText Fortify, Wiz, Elastic, Apache Kafka, GitHub, Bitbucket, ISO 27001, CIS v8

Aug 2022 - Sep 2023

SOC Analyst

dacoso GmbH

Position summary
SOC Analyst at dacoso GmbH
Industries
Information Technology
Business areas
Information Technology
Operations
  • SIEM administration and service monitoring in compliance with SLAs and KPIs, as well as administration of network and security infrastructure (via SIEM and EDR)
  • Design and consulting for the setup of the security operations platform and integration of critical infrastructure areas
  • Setup, configuration, and integration of log sources with the SIEM, as well as configuration and monitoring of EDR/NDR systems
  • Leading and coordinating security incident response activities for the rapid detection, analysis, and containment of security incidents, including triage and mitigation measures
  • Implementation of detection rules in the EDR (SentinelOne), as well as selection and configuration of Sentinel use cases
  • Design of the security incident handling process and creation of a SOC reporting baseline for compliance and management levels
  • Identification of vulnerabilities in web applications using Burp Suite and OWASP ZAP, as well as definition and tracking of remediation measures
  • Implementation of zero-trust security strategies through continuous verification and authentication, as well as automation of cross-system and cross-application integrations via interfaces/APIs

Technologies: Microsoft Sentinel, Microsoft Defender, IBM QRadar, Darktrace, Elastic, Wazuh, SentinelOne, FortiGate, Burp Suite, OWASP ZAP, Tenable Nessus, Wireshark, Nmap, Linux, ISO 27001

Apr 2022 - Aug 2022

Cyber Security Engineer

dacoso GmbH

Position summary
Cyber Security Engineer at dacoso GmbH
Industries
Information Technology
Business areas
Information Technology
  • Setup and subsequent monitoring of the infrastructure, as well as analysis of network traffic to detect and defend against potential threats
  • Planning, installation, and configuration of SIEM, EDR/XDR, and IDS/IPS systems, including the further development of HIDS/NIDS architecture
  • Creation and validation of runbooks for SOC L1 analysis, as well as support in implementing automation solutions
  • Analysis of customer requirements for EDR based on critical infrastructure and NIS2
  • Setup of firewalls, as well as planning, review, and adjustment of network segmentation
  • Containerization of applications using virtualization solutions, as well as support for version control and configuration management

Technologies: Snort, Palo Alto Cortex XDR, FortiGate, Elastic, Loki, Prometheus, Grafana, InfluxDB, Telegraf, Docker, Terraform, GitHub, Linux

Jan 2018 - Oct 2020

IT Consultant / CAx Team Lead

Telekom AG

Position summary
IT Consultant / CAx Team Lead at Telekom AG
Industries
Automotive
Information Technology
Business areas
Information Technology
Operations
Product Development
  • Interface contact between Mercedes-Benz Group AG and Telekom AG
  • Administration and 2nd-level support, including incident, change, and release management
  • BCM process review and coordination of BCM development and adjustments
  • Identification of vulnerabilities and opportunities for improvement in CAD, CAE, and CAM workflows to increase efficiency
  • Introduction and integration of new software solutions, adaptation of existing systems, and delivery of training
May 2017 - Dec 2017

IT Systems Administrator

Devoteam GmbH

Position summary
IT Systems Administrator at Devoteam GmbH
Industries
Information Technology
Business areas
Information Technology
  • Installation, configuration, and maintenance of servers, workstations, and network components
  • Management and monitoring of networks, including routers, switches, and firewalls
  • Support with the implementation and monitoring of IT security measures
  • Creation and maintenance of documentation on system configurations, processes, and IT policies

Industry experience

See where this freelancer has spent most of their professional time.

Experienced in Information Technology, Automotive, Banking and Finance, and Telecommunication.

Information Technology
Automotive
Banking and Finance
Telecommunication
Profile match chart

Business area experience

See which departments and functions this freelancer has contributed to most.

Experienced in Information Technology, Operations, Product Development, Audit, and Project Management.

Information Technology
Operations
Product Development
Audit
Project Management
Profile match chart

Summary

Over 9 years of experience in IT. I design and operate SOC, SIEM, and SOAR platforms for banks, automotive, telecommunications, and energy companies – from connecting log sources and engineering use cases and detections to incident response. Focus on the Microsoft security stack (Sentinel, Defender XDR, Entra ID) as well as multi-SIEM environments (QRadar, Elastic, Splunk, Wazuh). Implementation of regulatory requirements under DORA, MaRisk, BAIT, ISO 27001, NIS2, BSI IT-Grundschutz, and PCI DSS in complex hybrid infrastructures.

Skills

  • Security Operations: Siem Setup And Operations, Detection Engineering, Use Case Design, Alert Tuning, Threat Hunting, Incident Response (L2/L3), Soc Reporting, Kpi/Metric Design, Vulnerability Management
  • Detection & Response: Microsoft Sentinel, Defender Xdr, Ibm Qradar, Palo Alto Cortex Xdr/Xsoar, Sentinelone, Elastic, Splunk, Logpoint, Wazuh, Darktrace, Security Onion, Thehive, Misp, Opencti
  • Cloud & Infrastructure: Azure (Policy, Entra Id, Resource Graph), Aws (Guardduty, Iam, Security Hub), Gcp Log Sources, Kubernetes (Eks/Aks), Docker, Terraform, Ansible, Argocd, Linux (Rhel, Ubuntu)
  • Frameworks & Compliance: Iso/Iec 27001, Nist Csf, Bsi It-Grundschutz, Dora, Marisk, Bait, Nis2, Kritis, Pci Dss, Cis V8, Mitre Att&Ck, Owasp Top 10
  • Automation: Soar Playbooks, Detection-As-Code, Sigma Rules, Kql, Python, Bash, Ci/Cd (Github, Gitlab, Azure Devops), Infrastructure As Code

Languages

German
Native
English
Advanced

Education

Oct 2021 - May 2024

Hochschule Darmstadt – University of Applied Sciences

B. Sc. Information Science · Information Science · Darmstadt, Germany

Mar 2019 - Sep 2020

Evening Grammar School for Working Professionals

University of Applied Sciences entrance qualification · Evening Grammar School · Germany · 2.7

Certifications & licenses

API Security Fundamentals

APIsec University

Black Hat Python

EC-Council

Blue Team Junior Analyst

Security Blue Team

CompTIA CASP+

CompTIA CySA+

CompTIA Pentest+ Path

TryHackMe

Endpoint Security

Cisco Networking Academy

Fortinet NSE 1, NSE 2, NSE 3

Category B

Linux Foundation Certified System Administrator (LFCS)

Microsoft Certified: Security Operations Analyst Associate (SC-200)

Network Defense

Cisco Networking Academy

Practical Cyber Threat Intelligence

EC-Council

Practical Ethical Hacking

TCM Security

Practical Web Application Security and Testing

TCM Security

Practical Windows Forensics

TCM Security

SOC Core Skills

Antisyphon Training

Security Operations Center

EC-Council

Windows Penetration Testing Essentials

EC-Council

Statistics

Experience

Total positions 12
Experience in Information Technology 6.5 y
Avg length 10 m
Longest experience 2 y 9 m

Expertise

Recent roles Senior IT-Security Expert, Principal IT-Security Engineer, Senior IT-Security Engineer
Main industries Information Technology, Automotive, Banking and Finance
Main business areas Information Technology, Operations, Product Development

Qualifications

Highest degree Bachelor
Certifications earned 22

Profile

Member since
Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions

Frequently asked questions

Have questions? Find more information here.

Reza is based in Dreieich, Germany and can operate in on-site, hybrid, and remote work models.

Reza speaks the following languages: German (Native), English (Advanced).

Reza has at least 8 years of experience. During this time, Reza has worked in at least 12 different roles and for 11 different companies. The average length of individual experience is 1 year and 8 months. Note that Reza may not have shared all experience and actually has more experience.

Based on recent experience, Reza would be well-suited for roles such as: Senior IT-Security Expert, Principal IT-Security Engineer, Senior IT-Security Engineer.

Reza's most recent position is Senior IT-Security Expert at Teambank AG.

In recent years, Reza has worked for Teambank AG, nicos GmbH, Oldenburgische Landesbank AG, Taschen GmbH, and chargecloud GmbH.

Reza is most experienced in industries like Information Technology, Automotive, and Banking and Finance. Reza also has some experience in Telecommunication and Media and Entertainment.

Reza is most experienced in business areas like Information Technology, Operations, and Product Development. Reza also has some experience in Audit and Project Management.

Reza has recently worked in industries like Information Technology, Banking and Finance, and Telecommunication.

Reza has recently worked in business areas like Information Technology, Audit, and Operations.

Reza holds a Bachelor in Information Science from Hochschule Darmstadt – University of Applied Sciences.

Reza has 22 certificates. Among them, these include: API Security Fundamentals, Black Hat Python, and Blue Team Junior Analyst.

Reza is immediately available part-time for suitable projects.

Daily rate distribution

0 2 4 6 8
<€800 €800-​960 €960-​1120 €1120-​1280 €1280+

The rates shown represent the typical market range for freelancers in this position based on recent contracts on our platform.

Average rates for similar positions

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 924 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 916 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 7 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.