Cisco ISE Experts in Germany
in minutes from over 15,000 CVs with vetted, available specialistsHire experts who design and run Cisco Identity Services Engine policies, 802.1X access control, guest and BYOD access, and network segmentation. Work with specialists who can align Cisco ISE with switches, wireless, Active Directory, and PKI, with fast, precise matching from vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Cisco ISE
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Enrique Gallardo
Last position:
Security Architect at Capgemini
I implemented a Zero-Trust architecture for robust, military-grade maritime container mini data centers based on VMware & Tanzu to support containerized GIS workloads for ground forces. The main focus was on securing communications, workload protection, and data access in contested electronic battle environments affected by jamming, interception, signal manipulation, and constantly changing operational conditions. I designed and architected use cases so that every element of workload, identity, and system could continue to operate independently and securely even in degraded or disrupted scenarios. In parallel, I defined the enterprise and solution security architecture with LeanIX, Bizzdesign, and HOPEX as enterprise architecture, repository, and governance platforms to maintain architecture inventory, relationships, traceability, target pictures, and security governance in complex environments. For the architectural designs, I used Sparx Enterprise Architect to describe formal architecture views, interfaces, trust boundaries, and system architecture in both IT and OT environments. IriusRisk was used for threat modeling of the solution to identify architecture-driven risks, derive security requirements, and detect countermeasures and design gaps directly from the solution models. Risk and compliance management was supported with Archer. Architecture decisions, control gaps, and operational risks were translated into controlled governance and auditable compliance measures. For documentation, collaboration, and visual design, I used Confluence to maintain Architecture Decision Records, Security Blueprints, and workflows. I used Lucidchart and draw.io to create design artifacts tailored to stakeholders. I also defined OT security concepts with support from electrical and mechanical engineers in the areas of oil, vehicle onboard systems, rail, power plants, pharma, gas turbines, and nuclear technology. I created the end-to-end OT security strategy, starting with global policy, developed into standards and procedures, and finally aligned with Bell-LaPadula, Purdue Model, SABSA, TOGAF ADM, CENELEC 50701, IEC 62443, and NIST standards. In addition, I worked with engineering team leads to identify critical KBP assets and place them under protective measures that segmented SCADA, PLC, and HMI assets. I drove collaboration between Security, IT, and OT teams to create standardized workflows and use cases for the OT security solution catalog, while integrating Defense-in-Depth and Zero-Trust principles into operational environments. A key part of my work was integrating multidisciplinary engineering, security, and operations stakeholders into a unified security blueprinting strategy and ensuring that architecture, threat modeling, governance, and documentation were technically strong and operationally practical.
Eddy Abanum
Last position:
Network Administrator at Knauf Bayern
- Support of firewalls (Securepoint)
- Operation and maintenance of the client-server infrastructure (Windows)
- Operation and patching of IoT devices in the hazard management system (cameras, Web IOS, IP serial converters)
- Support with the integration of security technology into existing IT infrastructures
- Planning and execution of network segmentation and separation
- Transfer and implementation of solutions to other plants
- Tools used: Wireshark, Network Service Manager, PRTG, Cisco Catalyst, Nexus, HP Service Manager, FNT/Command Manager Console, ServiceNow, Confluence, Active Directory, Wingard, Securepoint FW
Tony Rosolek
Last position:
Network Expert at Self-employed
- Consulting and execution of migration from Cisco AireOS to Cisco IOS-XE controller
- Solution design
- Configuration and staff training
- Products: Catalyst Center, Cisco controllers and IOS and COS access points, 9800-40, 5520, 8510, 9120, 9136, 9166, Catalyst switches, Aruba Clearpass
- Keywords: Tags, profiles, SSIDs, 802.1X authentication, captive portal, Identity PSK (iPSK), VLANs, troubleshooting, automation, RESTCONF, NETCONF, YANG
Reinhard Gefing
Last position:
IT Infrastructure / User Management at UMF – University Medical Center Frankfurt
- User account management and creation in Active Directory
- Group management and modification in Active Directory
- Permission management on file servers
- Exchange/Outlook support
- VPN setup
- System and product support: Windows 10, Windows 11, Office 2019, Office 365, Active Directory, TeamViewer, RSA VPN, Microsoft Teams, RSA Security Console, Deep Discovery Mail Inspector, ServiceNow, Macmon
Udo Schnell
Last position:
GRC Project Manager at 1 & 1 Mobilfunk
Developed a GRC guideline for project management in the rollout area.
Pascal Farys
Last position:
Senior Network Security Consultant at IT-Systemhaus
- Provided expert level consulting for lifecycle, upgrades and refresh activities
- Used Remedy for effort recording and billing to customers
- Used ServiceNow for service management and workflow
- Used Jira for project management with agile/Scrum methods
- Used Confluence for documentation
- Worked with customer-specific software tools
- Worked with customer-provided and secured hardware suitable for IT security operations infrastructure setup for customers
- Built firewall rule sets and handed over to service owner and delivery teams
- Environment: Cisco ASA, Cisco Firepower, CSM, Cisco AnyConnect, Cisco ISE, Check Point VSX and gateways
Christian Decker
Last position:
Managing Director and Senior Consultant at business-security (b-sec®) GmbH
- Conceptual consulting for securing business processes
- Consulting on planning and implementation of IT and IT security projects
- Security and policy checks, process optimizations, emergency planning
- Project management and interim management in IT infrastructure and information security
Overview of relevant projects:
- 2025: Consulting on a DLP concept for Digid GmbH.
- 2025: Consulting a client after a cybersecurity attack that compromised the IT infrastructure and where the attacker obtained M365 tenant admin rights. Investigated the IT infrastructure and restored it. Developed recommendations to improve IT security.
- 2025: Continued the projects listed below for Thyssenkrupp Marine Systems and Norddeutsche Landesbank.
- 2024: Created a DNS concept including advice on DNS strategy and technology, DNS design, DNS security, load balancing, reverse lookup zones, and automation. Created a DHCP concept including advice on DHCP design, a central DHCP management system and automation. Advised on operating the mentioned products, the operational processes, and updated IT documentation and IT service descriptions for Thyssenkrupp Marine Systems.
- 2024: As-is analysis and assessment of the network and security infrastructure established by providers in terms of overall architecture including design and components. Designed solution proposals to improve current operations for performance and security maximization as well as complexity reduction. Presented the results to C-level, their causes and possible solutions including required decision templates. Developed a SASE concept based on a zero-trust architecture for Norddeutsche Landesbank.
- 2024: Continued the projects listed below for Atlas GmbH and Deutsche Vermögensberatung AG.
- 2023: Consulting on resolving findings from an IT security assessment of the IT infrastructure, conducting proofs of concept for DDoS protection and digital experience monitoring (DEM) with Zscaler (ZIA, ZPA & ZDX), creating a new security architecture based on zero trust, redesigning a Cisco ISE implementation, and designing a DNS security solution to protect guests and financial advisors for Atlas GmbH / Deutsche Vermögensberatung AG.
- 2023: Continued the projects listed below for Digid GmbH, Vaillant Group GmbH (until 09/2023), Federal Institute for Geosciences and Natural Resources (until 05/2023), and Union Investment IT-Services GmbH (until 07/2023).
- 2022: Created and reviewed whitepapers for infrastructure and security architectures, and planned new network infrastructures for the German Aerospace Center.
- 2022: Developed a concept for the technical and procedural modernization of a disaster recovery plan for United Nations Volunteers.
- 2022: Developed a concept for migrating measurement data to a cloud environment, introduced network access control, and conducted an awareness training for Digid GmbH.
- 2022: Developed a network segmentation concept for DZ Hyp AG.
- 2022: Developed a network segmentation concept for the Federal Employment Agency.
- 2021: Developed a new load balancer architecture concept for Bundeswehr Fuhrparkservices GmbH.
- 2021: Conducted a vulnerability scan and penetration test of a web frontend including analysis and recommendations for remediation considering risk and likelihood for the client ifi GmbH.
- 2021: Consulting, design, and subproject management for implementing a network access control solution (certificate authentication and MAC address bypass) and macro segmentation (area and zone concept based on dynamic device assignment) in office and production IT for Vaillant Group GmbH.
- 2021: Upgraded and optimized LAN and WLAN infrastructure for United Nations Volunteers.
- 2021: Developed a target concept for modernizing the IT security infrastructure including the DMZ (Cisco switches, firewalls, WSA, ESA, SMA), internet connections, admin and management networks, and the wireless LAN, including overseeing implementation for the Federal Institute for Geosciences and Natural Resources.
- 2021: Created a micro-segmentation concept based on Cisco DNA, SGT, and zero trust for Union Investment IT-Services GmbH.
- 2021: Reviewed and updated ISMS level 3 policies and created procedure instructions for Software AG.
- 2021: Project lead for the global tech refresh project Meraki WLAN 2.0, coordinated the outsourcing of LAN/WLAN infrastructure to a managed service provider, and created a WLAN concept for automated guided vehicles for Heraeus Infosystems GmbH.
- 2021: Project management and technical support for the 'Transition of SIEM/SOC Services' project migrating a client to a shared environment, and took on the interim role of Head of Security Operations at Datagroup SE.
- 2021: Conducted a workshop for the future implementation of mobile device management for Allgeier Experts Go GmbH.
- 2021: Subproject management for implementing a firewall rule management tool and recertifying NAC endpoints based on 802.1x and MAB for Union Investment IT-Services GmbH.
- 2020: Developed a network segmentation concept for two data centers based on Cisco and VMware for Aareon AG.
- Recorded and analyzed the current network architecture including project initiation.
- Designed a micro-segmentation concept in the data center and access network.
- 2020: Infrastructure and security architecture audit for Stuttgarter Versicherung AG.
- Analyzed the IT infrastructure and security architecture regarding network and security component configurations. Also reviewed contracts, process documents, and manuals for completeness. Developed recommendations to improve the stability and operation of the infrastructure. Created a network segmentation concept and led the project to implement the measures from the audit.
- 2020: Consulting on setting up an ISMS-light for Josera foodforplanet GmbH & Co. KG.
- 2020: Security architecture consulting for Datagroup SE.
- Developed a future IT infrastructure and IT security architecture.
- Documented the current IT architecture of all 23 entities.
- Made recommendations to optimize the IT infrastructure and drafted a comparison of a traditional perimeter security concept versus a zero trust model.
- Created a security zone concept.
- Designed an IT infrastructure architecture in coordination with all entities.
- 2018 - 2019: Stream lead in the cybersecurity program at Deutsche Lufthansa AG.
- Responsible for designing and implementing 9 projects in IT security infrastructure and user access management, as well as managing project managers and experts.
- Project area: Network segmentation and access control.
- Project area: Security architecture.
- Project area: Privileged, identity & access management.
- Project area: Simplify user authentication (MFA).
- Project area: Mobile & endpoint security.
- Project area: OT security.
- Project area: E-enabled aircraft.
- 2018: Security architecture consulting for Deutsche Lufthansa AG.
- Project management for the development, evaluation, and management of the company-wide information security architecture.
- Developed a security strategy and a roadmap to align the security architecture with the zero trust model.
- Evaluated market security solutions, services, and tools.
- Defined requirements for RFPs and assessed proposals.
- Developed, maintained, and monitored security architecture artifacts.
- Conducted security assessments of existing and new IT systems and security services.
- 2018: ISMS consulting for GLS IT Services GmbH.
- Advised on implementing and initially operating an ISMS based on ISO27001.
- Audited the IT environments of GLS country subsidiaries.
- Analyzed and assessed IT security risks and derived necessary measures.
- Developed solution proposals in coordination with relevant stakeholders.
- Managed the project and handed over the ISMS to operations.
- 2016 - 2018: Security pre-sales consultant for Cisco Systems GmbH.
- Provided nationwide strategic and conceptual consulting to major enterprise and financial and insurance clients on Cisco and Meraki security products and services such as Firepower, WSA, ESA, Stealthwatch, and ISE.
- 2017 - 2018: Designed and implemented an ISMS for Verivox GmbH.
- Conducted various BIAs and gap analyses.
- Developed security policies based on ISO 2700x.
- Served as interim information security officer.
- 2017: Developed an emergency concept for VPV Lebensversicherungs-AG.
- Reviewed and updated the IT emergency manual.
- 2016: Consulting and project management for designing cloud & hosting services for Vodafone Group Services GmbH.
- Analyzed and optimized the sell-build-run process.
- Created detailed level designs for cloud products.
Abdelhak Mahou
Last position:
Network Architect at Bechtle Managed Services GmbH
- Created as-is network documentation for a Bechtle customer
- Analyzed existing configurations and adjusted them
- Advised on Fortinet and Check Point products
- Troubleshot complex routing, switching and application issues
- Tools: MS Azure, FortiManager, Cisco Nexus & Catalyst, Cisco WLAN Controller, Citrix Netscaler SD-WAN, MS Visio, Checkpoint VSX, Wireshark
Hisham Elsharawy
Last position:
System Engineer Network & Security at Isringhausen GmbH
- Operation, maintenance and administration of the global network & security system landscape
- Troubleshooting and support in 2nd & 3rd levels and provide technical advice to other dept.
- Configuration of complex LAN/WAN/SD-WAN and WLAN network infrastructures (N5K, N9K, ASR 8000, Wireless Controller WLC9800, AP C91xx and VMware Velo Cloud)
- Control of external service providers as part of service and escalation management
- Implementation and monitoring of system updates (software upgrades, minor/major changes)
Christian Wolpert
Last position:
Cisco Catalyst Center - SDA Wireless Consultant at IT Service Provider
- Implementation of Cisco Catalyst Center wireless network for a federal ministry in Berlin with focus on wireless topics
- Troubleshooting of day 0, day 1 and ongoing templates for zero-touch provisioning of switches and access points
- Client authentication and authorization troubleshooting using Cisco ISE
- Wireless guest access via Cisco ISE captive portals
- Ekahau site surveys and WLAN survey reports
- Cisco DNA Center, Cisco WLC and Cisco ISE
- LAN and WLAN network design and planning based on existing HLD and LLD documents
- C9300L and C9500 series switches, CW9166i access points
Krisztián Korcz
Last position:
IT-Soc/Vulnerability at ITZBund
- Vulnerability management (Greenbone, Tenable SC, Rapid7)
- Automation of vulnerability scans
- OpenTofu (Terraform)/Ansible/Vault/Podman/Docker
- Compliance audit
- SOC (ElasticSearch, Graylog)
- Python/Rust/Bash/Shell/PowerShell
- Git collaboration
- Report standardization and automation
- POC for several vulnerability scanning systems
- Setup of vulnerability scanning system
Majid Asadpoor
Last position:
Lead Consultant at Infosys
- Network automation
- CI/CD and Docker environment
- Python Nornir for network automation
- pyATS for monitoring and test case automation
- Network Access Control (RADIUS) and device admin access control (TACACS) with AAA and Cisco ISE on Cisco/HP/Aruba devices
- Cisco ISE cluster configuration (2/4/8 nodes)
- Cisco ISE authentication and authorization configuration
- Cisco/HP/Aruba switch/WLC TACACS/dot1x/RADIUS configuration
- Cisco ISE automation with RESTCONF and Python
Mohammed Abadel
Last position:
Business Start-up and Continuing Education at Self-Employment
- Evaluation of further training options in the field of artificial intelligence
- Development of a business plan for self-employment in the AI sector
- Development of an offline chatbot for Excelsior GmbH
- Preparation for the "AWS Certified Solutions Architect – Associate" certification to expand cloud skills
Discover over 15,000 top freelancers
Statistics of experts using Cisco ISE
Aggregated from the professional profiles of matched freelancers.
Experience
21 years
Position duration
2.2 years
Positions per freelancer
13
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Banking and Finance, Manufacturing
Certification focus areas
Information Technology, Audit, Legal
Bachelor's degree or higher
64%
Master's degree or higher
36%
Certifications per freelancer
9
Most common languages
German, English, Arabic
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Cisco ISE
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What ISE does
Cisco ISE, short for Identity Services Engine, controls who and what can connect to your network. It is used for wired, wireless, and VPN access policies, plus guest access and device profiling. Strong specialists turn policy goals into clear access rules.
Core functions
- 802.1X authentication and authorization
- Guest portal and BYOD onboarding
- Profiling of endpoints and devices
- Role-based network access and segmentation
- Integration with Active Directory and certificates
Typical projects
Companies bring in freelance experts for new rollouts, policy redesigns, and upgrades from ACS or legacy NAC setups. They also need help after mergers, when access rules must be unified across sites. In Germany, this often matters in regulated, multi-site environments with mixed wired and wireless networks.
Ecosystem fit
Cisco ISE rarely works alone. It usually connects to Cisco switches, wireless controllers, VPN gateways, Active Directory, PKI, MDM tools, and logging systems. Skilled professionals understand how authentication flows, certificates, RADIUS, and endpoint posture checks interact.
Signs you need help
- Access requests are handled manually
- Guest or BYOD flows are inconsistent
- Certificate issues block device enrollment
- Policy changes are hard to test safely
- Network teams and security teams disagree on rules
What strong specialists deliver
Good Cisco ISE professionals document the current design, clean up policy sets, and keep authentication predictable. They check fallback behavior, device profiles, TACACS+ or RADIUS use where relevant, and operational handover. The best ones leave a setup your team can support without guesswork.
Frequently asked questions
Everything clients usually want to know about Cisco ISE, in one place.
Cisco ISE is used to control network access for users, devices, and guest connections. It helps enforce 802.1X, posture checks, profiling, and policy-based access across wired, wireless, and VPN environments. Companies use it when they need consistent identity-driven access decisions instead of open network ports.
Cisco ISE is often chosen when the network already has a strong Cisco base and needs deep policy control. Compared with simpler NAC tools, it usually offers broader integration with switches, wireless, certificates, and identity stores. The trade-off is that it needs careful design and experienced configuration.
A strong Cisco ISE specialist usually knows RADIUS, 802.1X, certificates, Active Directory, and basic PKI design. Experience with Cisco switching, wireless access, guest portals, and endpoint profiling also matters. Security logging and troubleshooting across the access path are important too.
A Cisco ISE rollout or redesign benefits from someone who has handled real authentication and policy issues before. Simple tasks may need only targeted help, while migrations, certificate changes, or segmentation work call for deeper expertise. The risk is usually not syntax, but unexpected access behavior.
Bring in Cisco ISE help when you are planning a rollout, fixing unstable access policies, or moving away from ACS or another legacy NAC setup. Freelance specialists are also useful during audits, mergers, or when guest and BYOD access needs to be cleaned up quickly. They can step in without long onboarding.
Yes, Cisco ISE work is often handled remotely if the specialist has secure access to the management environment and good documentation. Remote collaboration works well for policy design, testing plans, and troubleshooting logs. On-site time is more useful for switch, wireless, or certificate issues that need hands-on validation.
A good Cisco ISE expert explains policy flow clearly and can show how authentication, authorization, and profiling fit together. Look for clean documentation, sensible fallback design, and practical troubleshooting steps rather than vague confidence. Real quality shows up in stable access behavior after the handover.
Cisco ISE is common in larger and more complex environments, but it is not limited to them. Any company that needs controlled access for many users, devices, guests, or sites can benefit from it. The key factor is network complexity, not company size alone.
The average hourly rate of freelancers in Germany who have used Cisco ISE in their recent projects is 102 €, which corresponds to a daily rate of about 812 € based on an 8-hour working day.
Of the freelancers in Germany who have used Cisco ISE in their recent projects, 64% hold at least a Bachelor's degree and 36% hold at least a Master's degree.
On average, freelancers in Germany who have used Cisco ISE in their recent projects have 21 years of professional experience, with a single engagement typically lasting around 2.2 years.
The most common languages among freelancers in Germany who have used Cisco ISE in their recent projects are German (100%), English (100%), and Arabic (21%).
The most common industries among freelancers in Germany who have used Cisco ISE in their recent projects are Information Technology (93%), Banking and Finance (71%), and Manufacturing (57%).
The most common business areas among freelancers in Germany who have used Cisco ISE in their recent projects are Information Technology (100%), Operations (79%), and Project Management (79%).
Main locations of FRATCH Experts, who have recently used Cisco ISE
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
