DevSecOps Experts in CH
in minutes from over 15,000 CVs with the power of AIHire experts who harden delivery pipelines, add security checks to CI/CD, and align code, infrastructure, and compliance work from the start. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in CH, who have recently used DevSecOps
Christoph Pardon
Last position:
ICT DevSecOps Engineer & Security Coordinator at Abraxas Informatik AG
- Interface role with the SOC team; improved incident response time by 45% through structured escalation processes and proactive security monitoring.
- Defined technical standards for a multi-tenant enterprise platform (10+ services), resulting in 30% shorter onboarding time for new clients in the public sector.
- Active knowledge transfer and mentoring of a 6-person team; increased team autonomy and established a sustainable engineering culture.
- Reduced time-to-market by 50% through CI/CD pipeline optimization and the introduction of self-service deployments.
- Stack: GitLab CI/CD, Kubernetes, Nexus, Harbor, ArgoCD, HashiCorp Vault, Grafana, Python, PostgreSQL, Java, Spring Boot, Flyway, Quarkus, JBoss, Loki, Go, Kafka, Kustomize, MongoDB
Osman Tartoussi
Last position:
Senior Developer and Consultant at Federal Office for IT and Telecommunications BIT
IT consulting, analysis, architecture design, new and further development, code review, test automation, continuous integration and continuous delivery in the backend and frontend area.
Technology stack:
JAVA 21
Spring Boot 3
Spring Framework 6
Spring Rest
Spring Data
JPA
Postgres
Aurora Database
Typescript
OWASP
Renovatebot
Sonarqube
Prometheus
Grafana
Spring Security
Single SignOn
Keycloak
Angular 19
NgRx Redux
AWS ECS
AWS Cloudwatch
Terraform
Spacelift
GitOps
Docker
Junit
Maven
Jenkins Pipeline
GitHub
BitBucket
Nexus
Kafka
Conduktor
Kafdrop
OpenApi
Swagger
Scrum
SAFe
Jira
Confluence
Michael Speller
Last position:
Freelance compliance & IT regulatory consultant at Various financial institutions and regulated companies
- Consulting financial institutions on implementing DORA and NIS2 requirements
- Gap analyses between existing governance structures and new regulatory requirements
- Creation and revision of policies, process descriptions, contract annexes, and technical-organizational measures
- Design of digital operational resilience testing programs (DORA Art. 24–25)
- Third-party risk management: building third-party registers, LEI matching, value chain analysis
- Training internal staff on DORA/NIS2 requirements
- Negotiation and renegotiation of outsourcing contracts according to DORA/NIS2 guidelines
- Use of technologies/frameworks: DORA, NIS2, EBA guidelines, BaFin requirements, NIST CSF, ISO 27001
- Engagements are subject to strict NDAs
Stefan Hess
Last position:
Fullstack Development, Product Owner & Tech Lead at Trex AG
- Business analysis, architecture, and implementation of a telemedicine platform for pet owners.
- Leading the development team as Product Owner and Tech Lead.
- Introducing agile processes, setting up development guidelines and system documentation.
- Planning and implementing features like video calls, live chat, and marketing automation.
- Implementing AI-based features such as automated tagging of information (missing pet reports, marketplace entries, etc.), preparation of social media content, and processing of conversation transcripts.
- Skills: Angular, NGXS, Tailwind, Java, Spring Boot, Kubernetes, Docker, CI/CD, MySQL, LLMs, RAG, MCP, Redis, OpenSearch.
- Industry: Veterinary medicine.
Yuri Gladkov
Last position:
Senior Security Devops Engineer at Swisscom
- Implementation and maintenance of highly critical IAM solutions for B2B clients (SSO, MFA, SAML/OIDC, Entra ID, PIM/PAM)
- Security administration of Linux systems (CentOS, Red Hat) in Docker and Kubernetes environments
- Migration from Docker Swarm to Kubernetes
- Infrastructure automation with Terraform
- Planning and execution of risk assessments, threat modeling, and compliance reports
- Development and management of B2B applications (Java, REST/SOAP, Angular) and CI/CD pipelines (Python, Ansible, Jenkins, GitLab)
- Leading integration tests and UAT (Cucumber, Selenium, Katalon)
- Implementing monitoring and observability strategies with Grafana, Prometheus, and Splunk
- Integrating SAST tools like Snyk and SonarQube
- Release management and project coordination according to Scrum and SAFe
- Mentoring and technical support of junior team members
Christoph Janik
Last position:
Project management, Software engineering, Software architect, DevOps at Migros Genossenschafts Bund
- Greenfield project M-Zollmanager: Development of an internal platform to support users in booking requirement areas on line items in assessment notices.
- Greenfield project M-Deliveryplan: Development of an internal platform for planning and tracking deliveries in the international transport sector.
- Created functions to predict the estimated arrival time of container ships and goods from the port of loading to the port of destination, considering potential events.
- Developed the TrackAndTrace add-on for M-Deliveryplan to track and plan goods and containers.
- Built a generic AI chatbot for Migros app infrastructure, including ChatGPT integration and creating AI workflows with N8N.
- Developed AI assistants to automate repetitive tasks, such as creating release notes or processing Jira tasks based on N8N workflows.
- Further development and maintenance of the M-LFS, M-Vehicleaccess and M-Worklog apps.
- Used C#, Angular 18, DevOps practices, N8N, Kubernetes, Docker, Jira, Confluence and Azure.
- Ongoing project with continuous development of platforms and workflows.
Discover over 15,000 top freelancers
Statistics of experts using DevSecOps
Aggregated from the professional profiles of matched freelancers.
Experience
19 years
Position duration
1.5 years
Positions per freelancer
18
Top business areas
Information Technology, Product Development, Operations
Top industries
Information Technology, Energy, Healthcare
Certification focus areas
Information Technology, Business Intelligence
Certifications per freelancer
2
Most common languages
German, English, French
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in CH are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in CH using DevSecOps
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
DevSecOps in practice
DevSecOps brings security into software delivery instead of adding it at the end. It is used to shape secure build, test, release, and runtime workflows for cloud apps, internal tools, APIs, and infrastructure as code.
Typical work
- Secure CI/CD design
- Policy checks in pipelines
- Container and image scanning
- Secrets handling and access control
- Cloud and infrastructure reviews
Tooling and stack
Strong specialists know how to wire security tools into GitHub Actions, GitLab CI, Jenkins, Azure DevOps, and similar pipelines. They also work with SAST, DAST, dependency scanning, SBOMs, Terraform, Kubernetes, and secret management.
When companies bring help
Teams often need outside expertise when delivery is moving faster than security review, when a new cloud setup needs guardrails, or when audit findings need clear fixes. In CH, this often matters for regulated sectors, product companies, and teams that split work between local staff and remote experts.
What good experts deliver
A strong DevSecOps professional does more than run tools. They define sensible controls, remove noise from alerts, explain risks in plain language, and make secure delivery repeatable for the whole team.
Signs you need a specialist
- Security checks slow every release
- Findings keep repeating
- Cloud permissions feel unclear
- Pipelines are hard to trust
- Teams need secure defaults
A good fit is someone who understands developers' pace, security requirements, and operational reality. That balance is what turns DevSecOps from a slogan into a working delivery model.
Frequently asked questions
What clients ask us most about DevSecOps — answered in short.
DevSecOps covers the security practices that are built into software delivery, from source control to deployment and runtime checks. It usually includes pipeline controls, code scanning, dependency review, container security, secrets handling, and policy enforcement.
DevSecOps adds security ownership to the DevOps flow instead of treating security as a final review step. DevOps focuses on speed and reliability across build and release; DevSecOps keeps that flow while adding controls, checks, and feedback that help teams ship safely.
A strong DevSecOps specialist usually knows CI/CD systems, cloud platforms, Terraform, Kubernetes, IAM, and common security scanners. They should also be able to read risk, tune alerts, and work with code, infrastructure, and compliance teams without slowing delivery.
DevSecOps is valuable when a team is building new pipelines, moving to cloud infrastructure, containerizing services, or facing security audit pressure. It also helps when teams need better secrets management, dependency control, or a clear path from findings to fixes.
Many DevSecOps tasks can be done remotely because they live in code, pipelines, and cloud settings. On-site work can help when workshops, access reviews, or stakeholder alignment are sensitive, which is why teams in CH often use a mix of both.
Ask which pipelines, cloud services, and security tools the DevSecOps specialist has worked with, and how they handled rollout and adoption. Also ask how they reduce false positives, document controls, and make security checks usable for the team.
A good DevSecOps expert can explain trade-offs clearly and show how security checks fit into daily delivery. Look for practical examples: cleaner pipelines, fewer repeat findings, better access control, and fixes that stay in place after the engagement ends.
DevSecOps sits between cloud security and application security by embedding both into delivery workflows. Cloud security focuses on the platform and permissions, application security focuses on the software itself, and DevSecOps connects those controls to the way teams build and release.
The average hourly rate of freelancers in Switzerland who have used DevSecOps in their recent projects is 105 €, which corresponds to a daily rate of about 841 € based on an 8-hour working day.
On average, freelancers in Switzerland who have used DevSecOps in their recent projects have 19 years of professional experience, with a single engagement typically lasting around 1.5 years.
The most common languages among freelancers in Switzerland who have used DevSecOps in their recent projects are German (100%), English (100%), and French (50%).
The most common industries among freelancers in Switzerland who have used DevSecOps in their recent projects are Information Technology (83%), Energy (67%), and Healthcare (67%).
The most common business areas among freelancers in Switzerland who have used DevSecOps in their recent projects are Information Technology (100%), Product Development (83%), and Operations (67%).
Main locations of FRATCH Experts, who have recently used DevSecOps
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
