
Astaro Experts in Germany
matched quickly to your projectHire experts who configure Astaro Security Gateway environments, manage Sophos UTM migrations and strengthen firewall, VPN and web security operations. FRATCH matches you precisely with vetted, available freelancers in minutes.
Meet FRATCH Experts in Germany, who have recently used Astaro
Andreas Z.
Last position:
Transformation Architect / Business Analyst at IT Consulting
- Development of a comprehensive transformation model for IT departments and ITSM organizations, from operational stabilization through structuring and optimization to strategic advancement
- Design of a transformation matrix that connects development phases with the implementation activities Position, Focus, Model, Enable, Anchor and Develop
- Development of assessment, maturity and decision-making logic to determine the operational starting point, the appropriate entry point and the prioritized areas of action
- Structuring of an end-to-end approach from current-state assessment and target vision through operating model, roadmap and service modules to implementation and integration into steady-state operations
- Derivation of combinable consulting and implementation modules, including methods, deliverables, role models, governance structures and transformation paths
- Collection, structuring and prioritization of business requirements from the perspectives of IT management, service management and operational roles
- Translation of requirements into target visions, process and role models, decision criteria and traceable deliverables
Environment / Tools: ITIL 4, IT4IT, Operating Model Canvas, SIAM, maturity models Kanban
Christian E.
Last position:
IT Consulting / IT Rebuild at IT-Neuaufbau (PF)
- Analysis of requirements and the current situation
- Migration of an old domain structure and Tobit to Exchange 2019 with integration to MS365
- Evaluation of implementation paths and planning for securing sensitive data
- Planning regarding BSI basic protection, the German Federal Data Protection Act (BDSG), and GDPR
- IT governance and IT security backtests
- Support with ERP setup and securing mail transfer
- Hyper-V 2016/2022, Microsoft Terminal Services Cluster, Microsoft Exchange 2019
- Office 365, Microsoft 365, Azure AD, Teams, Salesforce
- Cisco, Zyxel, and HP switches, Sophos firewalls/UTMs, SecurePoint
- Microsoft IIS 2022, IPv4/IPv6, Veeam, Wortmann online backup, NextCloud
- Services: DNS, DHCP, TCP/IP, subnetting, firewalling, routing, VoIP, Group Policy (GPO), SIEM, remote work, home office, high availability, failover, VLAN, PRTG
Florian K.
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Andreas F.
Last position:
Project Manager & Portfolio Owner for Infrastructure (Automotive) at MHP Management- und IT-Beratung GmbH
- Overall coordination of service providers for all infrastructure topics at a production site being set up in Baden-Württemberg
- Design and finding solutions for internet connectivity, building office communication networks, setting up WLAN in production and administration buildings, IP address management, password policies, time tracking, access control systems, backup strategies, emergency power planning, operating concepts, cost planning, event management, workplace setup including laptop/mobile phones/telephony, remote support, print servers
- Selecting suitable external service providers and planning to meet needs for spare parts, repairs, on-site service, network and workplace support including on-site system replacement by providers
- Choosing suitable external service providers for facility management and building technology (fiber optic connections, data center infrastructure, cable ducts etc.)
- Coordination with clients and service providers
- Escalation management, schedule control
- On-site presence for service meetings and managing service providers
David B.
Last position:
Acting Partner at Bliestal Consulting UG
- Redesigning cablewise infrastructure with CAT 8.1 keystones, measuring the speed and quality of the new installation with Pockethernet, documentation at a local saddlery
- CAT 8.1 installation and building a data center, site linking, VPN and VLAN configuration for a local car dealership, implementation of IT-Security standards like virus protection (G Data) and firewalling (OPNSense)
- Relocation of a tax office with redesign of the IT infrastructure, virus protection (G Data) and backup solutions (QNAP)
- Planning, conception and implementation of an inhouse data center, BSI-compliant for commercial laundry (including Proxmox-based virtualization of existing infrastructures, QNAP, G Data, OPNSense, APC)
- Implementation and conception of security solutions in the SME sector
- Collaboration on the IT-security concept for the Bremen network of authorities (in the dLAN network)
- Creation of IT-security concept VOIS (modules MESO, KFZ/iKFZ) including audit preparation for KBA
- Expansion of the IT-security concept for the online service for electronic residence registration (eWA) to include use as an eFA (one-for-all) service (nationwide)
- Expansion of the IT-security concept to include modules wos & wvp
- Concept development for the implementation of DIN SPEC 27076 at MSEs and SMEs
- Creation and evaluation of emergency concepts
- Creation and evaluation of response actions and BCM plans
- Assessment of existing business continuity management (ISO 22301)
- Development of BCM strategy options
- Conducting awareness training
Christian D.
Last position:
Managing Director and Senior Consultant at business-security (b-sec®) GmbH
- Conceptual consulting for securing business processes
- Consulting on planning and implementation of IT and IT security projects
- Security and policy checks, process optimizations, emergency planning
- Project management and interim management in IT infrastructure and information security
Overview of relevant projects:
- 2025: Consulting on a DLP concept for Digid GmbH.
- 2025: Consulting a client after a cybersecurity attack that compromised the IT infrastructure and where the attacker obtained M365 tenant admin rights. Investigated the IT infrastructure and restored it. Developed recommendations to improve IT security.
- 2025: Continued the projects listed below for Thyssenkrupp Marine Systems and Norddeutsche Landesbank.
- 2024: Created a DNS concept including advice on DNS strategy and technology, DNS design, DNS security, load balancing, reverse lookup zones, and automation. Created a DHCP concept including advice on DHCP design, a central DHCP management system and automation. Advised on operating the mentioned products, the operational processes, and updated IT documentation and IT service descriptions for Thyssenkrupp Marine Systems.
- 2024: As-is analysis and assessment of the network and security infrastructure established by providers in terms of overall architecture including design and components. Designed solution proposals to improve current operations for performance and security maximization as well as complexity reduction. Presented the results to C-level, their causes and possible solutions including required decision templates. Developed a SASE concept based on a zero-trust architecture for Norddeutsche Landesbank.
- 2024: Continued the projects listed below for Atlas GmbH and Deutsche Vermögensberatung AG.
- 2023: Consulting on resolving findings from an IT security assessment of the IT infrastructure, conducting proofs of concept for DDoS protection and digital experience monitoring (DEM) with Zscaler (ZIA, ZPA & ZDX), creating a new security architecture based on zero trust, redesigning a Cisco ISE implementation, and designing a DNS security solution to protect guests and financial advisors for Atlas GmbH / Deutsche Vermögensberatung AG.
- 2023: Continued the projects listed below for Digid GmbH, Vaillant Group GmbH (until 09/2023), Federal Institute for Geosciences and Natural Resources (until 05/2023), and Union Investment IT-Services GmbH (until 07/2023).
- 2022: Created and reviewed whitepapers for infrastructure and security architectures, and planned new network infrastructures for the German Aerospace Center.
- 2022: Developed a concept for the technical and procedural modernization of a disaster recovery plan for United Nations Volunteers.
- 2022: Developed a concept for migrating measurement data to a cloud environment, introduced network access control, and conducted an awareness training for Digid GmbH.
- 2022: Developed a network segmentation concept for DZ Hyp AG.
- 2022: Developed a network segmentation concept for the Federal Employment Agency.
- 2021: Developed a new load balancer architecture concept for Bundeswehr Fuhrparkservices GmbH.
- 2021: Conducted a vulnerability scan and penetration test of a web frontend including analysis and recommendations for remediation considering risk and likelihood for the client ifi GmbH.
- 2021: Consulting, design, and subproject management for implementing a network access control solution (certificate authentication and MAC address bypass) and macro segmentation (area and zone concept based on dynamic device assignment) in office and production IT for Vaillant Group GmbH.
- 2021: Upgraded and optimized LAN and WLAN infrastructure for United Nations Volunteers.
- 2021: Developed a target concept for modernizing the IT security infrastructure including the DMZ (Cisco switches, firewalls, WSA, ESA, SMA), internet connections, admin and management networks, and the wireless LAN, including overseeing implementation for the Federal Institute for Geosciences and Natural Resources.
- 2021: Created a micro-segmentation concept based on Cisco DNA, SGT, and zero trust for Union Investment IT-Services GmbH.
- 2021: Reviewed and updated ISMS level 3 policies and created procedure instructions for Software AG.
- 2021: Project lead for the global tech refresh project Meraki WLAN 2.0, coordinated the outsourcing of LAN/WLAN infrastructure to a managed service provider, and created a WLAN concept for automated guided vehicles for Heraeus Infosystems GmbH.
- 2021: Project management and technical support for the 'Transition of SIEM/SOC Services' project migrating a client to a shared environment, and took on the interim role of Head of Security Operations at Datagroup SE.
- 2021: Conducted a workshop for the future implementation of mobile device management for Allgeier Experts Go GmbH.
- 2021: Subproject management for implementing a firewall rule management tool and recertifying NAC endpoints based on 802.1x and MAB for Union Investment IT-Services GmbH.
- 2020: Developed a network segmentation concept for two data centers based on Cisco and VMware for Aareon AG.
- Recorded and analyzed the current network architecture including project initiation.
- Designed a micro-segmentation concept in the data center and access network.
- 2020: Infrastructure and security architecture audit for Stuttgarter Versicherung AG.
- Analyzed the IT infrastructure and security architecture regarding network and security component configurations. Also reviewed contracts, process documents, and manuals for completeness. Developed recommendations to improve the stability and operation of the infrastructure. Created a network segmentation concept and led the project to implement the measures from the audit.
- 2020: Consulting on setting up an ISMS-light for Josera foodforplanet GmbH & Co. KG.
- 2020: Security architecture consulting for Datagroup SE.
- Developed a future IT infrastructure and IT security architecture.
- Documented the current IT architecture of all 23 entities.
- Made recommendations to optimize the IT infrastructure and drafted a comparison of a traditional perimeter security concept versus a zero trust model.
- Created a security zone concept.
- Designed an IT infrastructure architecture in coordination with all entities.
- 2018 - 2019: Stream lead in the cybersecurity program at Deutsche Lufthansa AG.
- Responsible for designing and implementing 9 projects in IT security infrastructure and user access management, as well as managing project managers and experts.
- Project area: Network segmentation and access control.
- Project area: Security architecture.
- Project area: Privileged, identity & access management.
- Project area: Simplify user authentication (MFA).
- Project area: Mobile & endpoint security.
- Project area: OT security.
- Project area: E-enabled aircraft.
- 2018: Security architecture consulting for Deutsche Lufthansa AG.
- Project management for the development, evaluation, and management of the company-wide information security architecture.
- Developed a security strategy and a roadmap to align the security architecture with the zero trust model.
- Evaluated market security solutions, services, and tools.
- Defined requirements for RFPs and assessed proposals.
- Developed, maintained, and monitored security architecture artifacts.
- Conducted security assessments of existing and new IT systems and security services.
- 2018: ISMS consulting for GLS IT Services GmbH.
- Advised on implementing and initially operating an ISMS based on ISO27001.
- Audited the IT environments of GLS country subsidiaries.
- Analyzed and assessed IT security risks and derived necessary measures.
- Developed solution proposals in coordination with relevant stakeholders.
- Managed the project and handed over the ISMS to operations.
- 2016 - 2018: Security pre-sales consultant for Cisco Systems GmbH.
- Provided nationwide strategic and conceptual consulting to major enterprise and financial and insurance clients on Cisco and Meraki security products and services such as Firepower, WSA, ESA, Stealthwatch, and ISE.
- 2017 - 2018: Designed and implemented an ISMS for Verivox GmbH.
- Conducted various BIAs and gap analyses.
- Developed security policies based on ISO 2700x.
- Served as interim information security officer.
- 2017: Developed an emergency concept for VPV Lebensversicherungs-AG.
- Reviewed and updated the IT emergency manual.
- 2016: Consulting and project management for designing cloud & hosting services for Vodafone Group Services GmbH.
- Analyzed and optimized the sell-build-run process.
- Created detailed level designs for cloud products.
Markus K.
Last position:
Administration / Support at Hessische Zentrale für Datenverarbeitung
- Operation and development support (Linux, Tomcat)
- Web release builds with Jenkins and deployment
- Monitoring and operation planning
- Support for Online Access Act (OZG)
- Data queries and corrections in Oracle SQL via CloudBeaver and Rundeck
- Keycloak administration
- Regression testing and documentation in Jira
- Development of complex address database with MS Access/VBA
- Creation of documentation and guides in XWiki
Andreas M.
Last position:
Managing Director at ESIS-ERP GmbH
- Took over management of the company
Marco K.
Last position:
Freelancer at IBM Deutschland GmbH NGNCC
- Design and setup of infrastructure concepts for virtualized servers with VMware vSphere and VMware vCenter
- Migration from vCenter 7 environments to vCenter 8
- Automated deployment of virtual machines using Microsoft PowerShell and VMware PowerCLI as well as Ansible Tower
- Prototype setup and test migration of applications in various container environments
- Administration of firewalls and network components (routing and switching)
- Migration of VPN connection for all employees from Sophos UTM to Fortigate IPSec VPN with FortiToken
- Automation of OS installations on Linux with Ansible and GitLab
- VMware vSphere 8 with VMware vCenter 8
- VMware API
- VMware NSX-T
- VMware vSAN
- VMware Tanzu
- Red Hat OpenShift
- Docker
- SLES 15, Red Hat 9 and Microsoft Windows Server
- Microsoft Windows PowerShell
- GitLab
- Ansible Tower (AWX)
- SUSE Manager 4 and 5
- Fortigate Firewalls
- Fortinet Analyzer and Manager
- Juniper and Cisco switches and routers
Heiko S.
Last position:
Consultant Managed Print Service at ALDI Einkauf SE & Co. oHG
- Incident management of the existing printer fleet (multivendor)
- Technical consulting and support for the transition to a managed print service based on HP hardware and LRS software (VPSX / mfpsecure / VSPA) as the backend for a secure print / Follow Me solution
- Design and implementation of a hybrid operation for direct printing in branches
Szabolcs K.
Last position:
Senior Network Security Consultant at Mann+Hummel
- Network segmentation in a production IT environment
- Firewall migrations
- Integration of remote access sites
- Implementation of POCs (Backup, SCADA)
- Working in a multicultural environment
- Applied technologies: Panorama & Palo Alto Firewalls, Checkpoint, ServiceNOW, MS Azure Cloud
H̊akan K.
Last position:
Consultant at Simulina GmbH
- Project planning of photovoltaic systems for a citizens' initiative
- Design of billing systems
Discover over 15,000 top freelancers
Statistics of experts using Astaro
Aggregated from the professional profiles of matched freelancers.
Experience
26 years

Position duration
2.7 years

Positions per freelancer
16

Top business areas
Information Technology, Operations, Customer Service

Top industries
Information Technology, Banking and Finance, Telecommunication

Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
25%
Master's degree or higher
13%

Certifications per freelancer
6

Most common languages
German, English, French

Speak two or more languages
92%
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Astaro
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Astaro experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (100%)
- Banking and Finance (67%)
- Telecommunication (67%)
- Government and Administration (58%)
- Automotive (50%)
- Manufacturing (50%)
- Aerospace and Defense (42%)
- Professional Services (42%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
Astaro Security Gateway
Astaro is best known for the Astaro Security Gateway, a unified threat management appliance for protecting company networks. It combined firewalling, VPN access, web and email security, intrusion prevention, and traffic controls in one administration interface. After Sophos acquired Astaro, the product line became Sophos UTM, while many teams still use Astaro when referring to the platform and its operating model.
Core capabilities
Astaro environments can control traffic between offices, users, servers, and the public internet. Specialists work with site-to-site and remote-access VPNs, routing, network address translation, authentication, content filtering, malware protection, and high-availability designs. They also review logs and policies so security controls remain effective without disrupting business services.
- Configure firewall zones, rules, and network objects
- Establish IPsec or SSL VPN connectivity
- Set up web, email, and intrusion protection
- Integrate directory services and authentication
Ecosystem and migration
Astaro projects often involve Sophos UTM, Sophos Firewall, and related Sophos Central services. A professional may also need knowledge of Active Directory, LDAP, DNS, DHCP, VLANs, routing, virtualisation, backup, and monitoring. Migration work requires careful mapping of existing rules, certificates, interfaces, VPN peers, and reporting requirements before changes reach production.
When companies need support
Companies bring in freelance Astaro specialists when an appliance needs a secure redesign, a VPN must be stabilised, or an ageing installation is approaching a platform change. External support is also useful during office moves, data-centre changes, acquisitions, incident reviews, and audits. In Germany, projects may combine remote administration with on-site work at offices or server locations, depending on access and security policies.
- Replace unclear or conflicting firewall rules
- Prepare an Astaro-to-Sophos migration
- Improve remote access for distributed teams
- Investigate unusual traffic or security alerts
What strong specialists deliver
Strong professionals begin with a clear network and dependency map rather than changing rules immediately. They document every decision, test failover and VPN behaviour, protect configuration backups, and explain operational effects to internal teams. They can separate a genuine security issue from a routing, certificate, DNS, or authentication problem and leave behind procedures that others can maintain.
Choosing the right expertise
The right specialist depends on the system’s age, topology, security requirements, and planned future. Ask for evidence of comparable Astaro Security Gateway or Sophos UTM work, especially around migrations, multi-site VPNs, high availability, and incident troubleshooting. German companies should also clarify remote-access procedures, documentation language, availability for maintenance windows, and whether on-site collaboration is required.
Frequently asked questions
Key details about Astaro, drawn from the questions we get asked most.
Astaro was used to protect networks through a unified security appliance. The Astaro Security Gateway combined firewall, VPN, web and email filtering, intrusion prevention, authentication, and reporting in one system. It is now commonly encountered as Sophos UTM in existing environments.
Astaro Security Gateway became Sophos UTM after Sophos acquired Astaro. The administration concepts and many operational tasks remain familiar to teams supporting older installations, but product versions, licensing, support paths, and migration options need to be checked for each environment.
Astaro is often valued for its integrated security services and clear central administration. Sophos Firewall is the more current Sophos path, while alternatives such as pfSense, Fortinet, or Palo Alto Networks may differ in hardware, policy models, subscriptions, automation, and advanced network controls. The best choice depends on existing skills, topology, and migration constraints.
A strong Astaro specialist should understand IP routing, VLANs, DNS, DHCP, certificates, Active Directory or LDAP, and IPsec and SSL VPNs. Experience with virtualisation, monitoring, backup, Sophos products, and incident response is useful when the appliance supports several business-critical services.
The complexity of the environment matters more than a fixed amount of experience. Astaro Security Gateway work involving a small rule review may need focused firewall knowledge, while a multi-site migration or high-availability redesign calls for a professional who has handled dependencies, rollback planning, testing, and production changes.
Much Astaro administration can be performed remotely through secure access, provided the company has suitable procedures and an approved maintenance window. On-site work may still be useful for cabling, hardware replacement, console access, or changes at locations where remote access is restricted. German and English documentation expectations should be agreed in advance.
Ask how the professional approaches discovery, rule cleanup, configuration backups, VPN testing, logging, and rollback. For Astaro migrations, request a clear treatment of interfaces, certificates, authentication, reporting, and dependencies rather than relying on a simple configuration copy.
Quality Astaro work is documented, tested, and easy for another specialist to operate. Look for least-privilege rules, meaningful object names, controlled administrative access, verified alerts, tested failover, and evidence that business traffic was validated after each change. A strong professional also explains risks and open decisions in plain language.
The average hourly rate of freelancers in Germany who have used Astaro in their recent projects is 109 €, which corresponds to a daily rate of about 872 € based on an 8-hour working day.
Of the freelancers in Germany who have used Astaro in their recent projects, 25% hold at least a Bachelor's degree and 13% hold at least a Master's degree.
On average, freelancers in Germany who have used Astaro in their recent projects have 26 years of professional experience, with a single engagement typically lasting around 2.7 years.
The most common languages among freelancers in Germany who have used Astaro in their recent projects are German (100%), English (92%), and French (50%).
The most common industries among freelancers in Germany who have used Astaro in their recent projects are Information Technology (100%), Banking and Finance (67%), and Telecommunication (67%).
The most common business areas among freelancers in Germany who have used Astaro in their recent projects are Information Technology (100%), Operations (92%), and Customer Service (83%).
Main locations of FRATCH Experts, who have recently used Astaro
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
