Project specification
Project expertise
Description
Objective: Reorganization and migration of the existing Linux infrastructure and IAM platform to a hybrid target environment (on-premises + hyperscaler)
Building Blocks:
Analysis & Target Architecture
Survey of existing Linux systems, workloads, and interfaces
Design of a scalable and highly available target infrastructure (incl. network and storage concepts)
Definition of the target architecture considering scalability, security, and availability
Assessment of the existing IAM solution
Survey of the existing IAM platform, workloads, and interfaces
Definition of the new target infrastructure (on-premises & cloud)
Integration of the existing IAM solution
Adoption and integration of the existing IAM structure into the new target infrastructure (e.g., IDM, LDAP, Azure AD)
Architecture for central authentication & authorization across all target environments
SSO and MFA concepts incl. federation with hyperscalers (e.g., SAML, OIDC, SCIM)
Ensuring auditability and compliance requirements (GDPR, ISO27001)
Migration strategy
Definition of migration paths: lift & shift, replatforming
Definition, planning, and orchestration of moves including downtime, fallback, and test concepts
Automation & Standardization
Further development of IaC (e.g., Terraform, Ansible)
Creation of reusable system and security modules
Hybrid/Multi-Cloud Architecture
Design and implementation of cloud connectivity (e.g., AWS, Azure, GCP)
Securing and identity federation of cloud resources with the existing IAM
Introduction of a consistent identity lifecycle
Handover & Documentation
Creation of operational, architecture, and security documentation
Conducting knowledge transfer workshops for operations and security
Requirements
- Architecture and migration of distributed Linux infrastructures in traditional and cloud data centers
- Integration of existing IAM solutions into hybrid and multi-cloud environments
- Ensuring role and rights management across hybrid and multi-cloud environments
- Cloud integration with e.g., AWS IAM, Azure RBAC, GCP IAM, SSO/SAML/OIDC federation
- Access control at system, application, and API levels
- Zero-trust strategies & segmentation of access rights
- Automation (Ansible, Terraform), containerization (Kubernetes), CI/CD pipelines
- Network & security architecture (VPN, MFA, SSH access controls)
- Monitoring, logging & auditing (e.g., Azure Monitor, Prometheus)
Not applying this time?
Get notified about similar projects matching your experience.
Frequently asked questions
The project is based in Karlsruhe, Germany.
The project preferably starts in November 2025 and is planned to end in February 2026 (3 months).
The project requires a commitment of 95 - 100% capacity (full-time).
The project offers 95 - 100% remote work.
The project offers a daily rate of 648 - 848€ which breaks down to an hourly rate of 81 - 106€/h.
The project requires the following languages: German (Advanced) and English (Advanced).
The project is related to the following industry: Information Technology.
The project covers the following business area: Information Technology.
Yes! Recommend a freelancer for the project and earn 30% of FRATCH's profits every time they get placed — for the duration of that project. Simply share your invite link with a colleague to get started.
To apply for the project, click the Apply button on the project page to submit your profile for review. We will forward your resume to the client and get back to you within a few days.