DORA Experts
in minutes from over 15,000 CVs with the power of AI.Hire experts who assess DORA metrics, improve delivery flow, and set up reliable measurement for lead time, deployment frequency, change failure rate, and MTTR, with fast, precise matching from vetted, available freelancers.
Meet FRATCH Experts who have recently used DORA
Matthias Kühnlein
Last position:
Business Owner at AKM
Management of multiple MFA methods for central authentication within a corporate group. Interface between various stakeholders such as support, finance, developers, and security departments. Budget controlling and monitoring of KPIs and SLAs. Review of operational documentation
Onur Kayir
Last position:
Project Manager & Outsourcing Manager at SENEC GmbH (EnBW Group)
- Setup of a scalable nearshore IT developer hub (Croatia, Czech Republic, Poland) as an independent company through a BOT model (Build – Operate – Transfer)
- Identification, selection, and management of full-service agencies; introduction of control and governance mechanisms including KPIs, SLAs, and regular service reviews
- Creation and review of data processing agreements and framework contracts in alignment with Legal & Compliance; integration of regulatory requirements (incl. KRITIS) into process design
- Consulting on cloud vs. on-premise strategies, data storage, and authorization concepts; support for procurement in vendor selection and provider assessments
- Change management and process harmonization between internal teams and nearshore partners; reporting to management, CFO, and CIO
Result: Scalable IT developer hub with an audit-proof governance model, reduced operating costs, and faster product development.
Jens Henneberg
Last position:
Interim CTO (occasional assignments) at Fujitsu / FSAS
Stabilizing an Azure/.NET landscape in live operation.
- Architecture, DevOps, and operational readiness; technical decisions under time pressure
- Azure DevOps, monitoring, ETL/ELT, cloud security, FinOps, and data-mesh-related topics
Technologies: Azure DevOps, .NET, CI/CD, monitoring, FinOps
Henry Hanau
Last position:
Interim Manager IT-Compliance at Int. Fertigungsunternehmen
- Industry: mechanical engineering, vehicle manufacturing
- Regulations: Data Act
- Project focus: data governance, legally compliant use of machine data, data platforms
- Assigned by: CFO, platform product owner
Successes/Results (early phase):
- Compliance support for the setup of an internal standardized data usage platform based on Databricks.
- Created the basis for the legally compliant and effective use of machine data, including:
- Technical: gap analysis and closing of gaps in the segmentation and maintenance of collected machine data.
- Technical: consideration of data flows from the platform to users and third parties.
- Organizational: drafting and finalizing the required data usage agreements.
Jens Brennscheidt
Last position:
Senior Cyber Security Consultant at Brennscheidt IT Consulting
KEY PROJECTS
Since 05/2023 | Bank | Senior Cyber Security Consultant (external)
- Advising and guiding the system owners in creating and further developing IT security concepts
- Coordinating and tracking the remediation of findings from reviews and audits
- Advising on the implementation of regulatory requirements for information security
10/2023 – 02/2024 | Fintech | Project Manager (external)
- Project management to close various audit gaps in the field of information security
- Conceptual design and implementation of an information security management system based on ISO/IEC 27001
- Creation and further development of ISMS documents and processes
Firas Jradi
Last position:
Interim Management Group Head of IT Governance & IAM at French-German Private Bank
- Head of the group-wide, international, and cross-functional IT Governance & IAM department within the central IT division of a large French-German private banking group. Disciplinary management of around 30 employees at five different locations within the group (Frankfurt, Paris, Tunis, Saarbrücken, Düsseldorf). Head of IT committees and key role in direct communication with management, the supervisory board, external stakeholders, and regulators.
- Definition and establishment of a state-of-the-art IT strategy process and related IT governance structures for the group's IT department with more than 600 employees (testified by the German Federal Financial Supervisory Authority and the ACPR) and successful process run.
- Establishment of a new future-oriented process framework for IT and necessary governance structures (process squads) for the continuous improvement of IT processes with regard to new regulatory requirements (including DORA, EU AI Act, etc.).
- Establishment of stringent processes to close a historical backlog of findings (> 100 IT findings, 40 overdue findings in 2022) from internal and external auditors (WP, ACPR, BaFin). Successful reduction of stock of overdue findings to 0 at the end of 2025.
- Supporting more than 20 IT audits per year and establishment of regulatory monitoring processes. Introduction of ServiceNow to revolutionize regulatory change and IT compliance processes with advanced AI functionalities.
- Realignment of IT control processes in conjunction with the newly established ICT risk function under DORA and the three lines of defense concept using the TopEase GRC solution.
- Reduction of the application landscape, by systematically analysing the purpose with application and business owners, identifying duplicates while implementing a One-Tool Strategy throughout the group. Successful reduction of one third of the application landscape within the CMDB.
- Onboarding of all group applications into One Identity's group-wide IAM solution, as well as operation and further development of the solution in connection with segregation of duties (SoD), role-based access management (RBAC), etc.
Karl-Heinz Reis
Last position:
Support in the further development of a European IT store service organization (15 countries) at European retail company (discount store)
- Capturing the current processes Incident Management, IT Service Request Management, Problem Management, Change Management, Service Configuration Management (including CMDB)
- Carrying out maturity assessments for these processes based on the ITIL® 4 Maturity Model
- Analyzing the different service value streams based on the ITIL® 4 value stream model
- Agreeing maturity levels for the processes being reviewed
- Developing and approving a roadmap to achieve and measure the respective maturity levels
- Presenting the approach, including milestones, to management for approval
- Managing external service providers in 1st level support
Dustin Dehez
Last position:
External consultant at Deutsche Leasing
2nd LoD/Change the Bank (CtB)
- CtB: External consultant and workstream lead for rectifying findings by BaFin following a special IT audit in the 2nd LoD, management of the work package for revising the ICT Risk Management & ICT Asset Classification in accordance with DORA Chapter 2, the processes for structural analysis, protection requirements, and control assessments (4 FTEs).
Robert Francia
Last position:
Interim Project Manager at IT services company of a regional energy supplier
- Delivery of various end-customer projects in server and network infrastructure on time, in quality, and within budget.
- Project 1: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall at an automotive supplier.
- Project 2: Migration of file services from dedicated servers at 5 branch locations into a central managed file service, including DHCP, directory, and print services, as well as decommissioning of the old domain controllers.
- Project 3: Renewal of the network infrastructure at the headquarters and branch locations of a logistics company and transition of the LAN, WLAN, and firewall environments into a managed network service.
- Project 4: Network renewal, replacement of the core and access switches at the headquarters of a medical technology company and transition into a managed network service.
- Project 5: Firewall renewal, replacement of an ASA firewall with a Fortinet firewall for a city.
- Environment: ASA and Fortinet firewalls, Cisco network components, ITSM Heat/Ivanti, Confluence.
Halil Oeztoprak
Last position:
Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD) at KfW Bankengruppe
Regulated environment within a German banking group (approx. 8,500 employees, hybrid cloud strategy).
Responsible for operating, provisioning, and continuously securing business-critical platforms – including a GenAI chat application, a big data/AI platform, and data science workspaces based on Azure Virtual Desktops and VMs. Ownership of Azure DevOps projects for ShaiHulud and React2Shell, as well as BSI alerts – Security Operations improvements across the SDLC.
Deployment responsibility for the GenAI chat application, big data/AI platform (BDAI), and data science workspaces (AVD/VM-based) in the respective landing zones.
Deployment & release management: end-to-end responsibility for deploying portal and service applications across multiple Azure landing zones, including technical approvals, compliance with development team deployment guidelines, and ensuring ITIL-based change and release processes via ServiceNow.
Azure landing zones & network architecture: design, provisioning, and operation of Azure landing zones for 3-tier web applications with enhanced network segmentation, VNet peering, hub-and-spoke architectures, private endpoints, and firewall integration across separate subscriptions and tenants.
Azure DevOps governance & operations: ownership of the Azure DevOps organization, including projects, repositories, and CI/CD pipelines; implementation of governance requirements such as branch policies, approval gates, permission models, and audit-ready operating structures.
Infrastructure as Code (Terraform): design, implementation, and operation of a modular Terraform architecture for standardized cloud infrastructure deployment, including state management, provider versioning, reusability, and policy-as-code approaches.
CI/CD pipeline engineering: design, operation, and optimization of complex YAML-based CI/CD pipelines with multi-stage deployments, template standardization, self-hosted agents, integrated secret management, and automated quality and security checks.
Git migration & platform consolidation: planning and execution of repository and pipeline migration from Azure DevOps to GitLab CI/CD, including automated scripts, full Git history transfer, pipeline porting, and platform consolidation.
Container & platform operations (AKS): operation and security assessment of containerized workloads on Azure Kubernetes Service, centralization of on-premises container registries for ACR.
OpenShift (OCP) security reviews: security assessment of code baselines, build pipelines, and deployment processes for on-premises OpenShift clusters with critical applications, and derivation of specific hardening recommendations.
Shift-left security & DevSecOps transformation: introduction of a company-wide shift-left approach for early security integration in development and deployment processes, enabling developers to perform self-led security checks and sustainably reduce vulnerabilities before production (IDE integrations, pre-commit hooks, local scanners).
Software supply chain security: analysis and mitigation of supply chain risks in NPM- and Yarn-based applications through dependency audits, CI/CD pipeline hardening, token rotation, and restriction of risky build and lifecycle mechanisms.
Frontend & framework security (React / Next.js): security assessment and coordination of critical vulnerability remediation across platform applications and web frameworks, including coordination and complementary technical mitigations with all teams following BSI alerts.
Software composition analysis (SCA): introduction and operation of automated vulnerability scans for container images, pipelines/artifacts, and third-party dependencies, including SBOM exports within CI/CD pipelines.
SAST/DAST integration: design and piloting of static and dynamic application security tests in close collaboration with security architecture and development teams, for continuous improvement of code and runtime security, and establishing operational acceptance tests.
Artifact & registry consolidation: analysis and consolidation of all package and container repositories for service applications and AKS workloads, aiming for a centralized, secured registry strategy with centralized vulnerability scanning and governance.
Dependency-Track & SBOM strategy: advising the compliance board on introducing a central SBOM and vulnerability management platform to increase enterprise-wide dependency transparency and accelerate CVE response capability.
CI/CD pipeline hardening: security analysis and cleanup of the existing pipeline landscape by removing unused pipelines, improving secrets hygiene, implementing least-privilege principles, and isolating build agent environments.
Azure Web Application Firewall (WAF) optimization: analysis and tuning of existing Azure WAF rules (OWASP Top 10 Core Rule Set, DSR/SDC, custom rules) to defend against known vulnerabilities and exploit patterns, including reducing false positives and improving threat detection.
Documentation & stakeholder communication: creating and maintaining technical documentation, runbooks, and architecture overviews in Jira and Confluence, as well as active knowledge transfer between operations, development, security, and compliance stakeholders.
Justina Kmiecik
Last position:
Freelance Consultant for Change & Data Transformation at Freelance Fast Data Consulting
Project, Strategic Consulting – building the Data Strategy and Data Governance Policy for the German branch, client (private bank Julius Bär, headquarters Zurich), March 2026 – present
- Design and negotiation of the data strategy with key stakeholders, including obtaining board sign-off (strategic consulting) – in this context, regulatory advice on data regulations in the EU and specifically for Germany. The data strategy includes: Data Lifecycle Management: data capture, data storage, data usage, data retention policy, data quality incident management
- Definition of milestones and technical feasibility for implementing TOM for the data strategy, data quality checks, metrics, and a metadata inventory to ensure the bank’s compliance with DORA, BCBS239, and MaRisk requirements.
Core project data change, client: (ING Bank, Frankfurt am Main), March – December 2025
- Concept development and solution design for new end-to-end processes including technical interfaces
- Definition of synchronization logic and data flows between legacy and target systems (decommissioning of legacy systems)
- Analysis and validation of data models
- Stakeholder communication with product owners, feature engineers, UX designers, and operational teams for decision-making
- Analytics and impact assessments, e.g. to assess downstream effects and regulatory requirements
- Documentation and comments on technical and business requirements to support implementation in agile squads
Project digitalization of a user group, client: (ING Bank, Frankfurt am Main), as Interim Product Owner, Jan 2025 – present
- Co-shaping key decisions on data architecture and process logic in the context of historized data and user login functionality
- Development of business solution concepts for migration to the target system, including system integration and data flows
- Support with analytics and impact analyses, especially regarding the ability to provide information to law enforcement authorities
- Active coordination with stakeholders from different squads to support decision-making and ensure regulatory requirements are met
- Creation of test scenarios for operational teams and backend systems in the area of API management using Postman and Bruno.
Dirk Peter
Last position:
Freelance Cyber Defense Lead & KRITIS/NIS2 Consultant | AI Security Architect at Self-Employed
Situation: Increasing demand for privacy-compliant AI solutions for clients in the KRITIS and mid-market sector that need to analyze sensitive media content (audio, video, documents) without sending data to public cloud LLMs.
Task: Design, deployment, and secure operation of a fully self-hosted AI infrastructure including a custom-built digital management platform for automated media analysis.
Action: Architected and implemented a multi-tier platform on hardened Proxmox infrastructure with frontend (Nuxt 3, Vue 3, TypeScript, Tailwind 4), backend (Laravel 13, PHP 8.4, Sanctum), data storage (PostgreSQL 16, MongoDB 7), caching/queuing (Redis 7, Laravel Queue), AI workers (Python 3.11, Whisper, DeepFace, Librosa), scheduling (Laravel Scheduler/Cron), and local LLMs (Gemma, DeepSeek, Qwen, Mistral, LLaMA, Phi) via OpenWebUI with segmented network access, API hardening, and audit logging following BSI recommendations.
Result: Fully GDPR-compliant, on-premises AI platform with zero data leakage to third parties.
Task: Overall responsibility as an external Head of Cyber Security / CISO-as-a-Service for the design, implementation, and continuous improvement of ISMS according to ISO 27001, BSI IT-Grundschutz, and NIS2.
Action: Built and managed Cyber Defense Centers (CDC) with SOC operations, integrated SIEM solutions (Splunk, Graylog), established risk-based vulnerability management (Qualys, Nessus, OpenVAS), and conducted regular infrastructure, application, and physical penetration tests.
Result: Audit-ready ISMS for multiple clients and a 60% reduction in critical vulnerabilities within 90 days.
Task: Design and execution of NIS2 assessments and operational roll-out plans for KRITIS operators.
Action: Developed an online assessment tool for automated identification of individual weakness profiles, implemented ISMS optimizations, penetration testing, awareness programs, GRC suite deployment, and delivered C-level presentations.
Result: Accelerated the consulting process by 50% and successfully prepared multiple clients for NIS2 compliance.
Task: Incident commander for crisis response, forensics, and business recovery in ransomware attacks and APT campaigns.
Action: Coordinated with state and federal police (LKA, BKA), performed forensic analysis (OSForensics, Wireshark, Kali Linux), executed disaster recovery and BCM strategies, and developed BTC extortion response strategies.
Result: 100% recovery rate within defined RTO windows and sustainable post-incident security architectures.
Action: Planned, built, and operated a hardened multi-VM infrastructure (Proxmox, 15+ VMs) with web and mail servers, Graylog, OPNsense firewalls, CRM/ERP and LLM instances, network segmentation, DDoS mitigation, automated patch management, and backup strategies.
Result: >99.5% uptime over 20+ years and zero compromises.
Action: Designed coordinated phishing campaigns with five levels of difficulty, developed e-trainings and webinars in a PDCA cycle, and led red and blue teams.
Result: Phishing click rate reduced from 35% to under 5% within three campaign cycles.
Peter Konrad
Last position:
IT Audit Expert at Sparkasse
Support for Internal Audit:
Conducting an audit of the data protection officer and data protection management:
- Preparing an audit program based on the audit field concept
- Requesting the necessary audit documentation
- Carrying out control testing based on the audit program with the following focus:
- Reviewing the relevant PPS processes
- Reviewing the data protection mission statement, data protection policy, and data protection management concept
- Conducting audit interviews with the data protection officer
- Preparing the audit documentation
- Training a junior auditor in the methodology of Internal Audit
- Coordinating the audit documentation with the head of audit
Alicja Wilczek
Last position:
Integrated security and emergency documentation for a 24/7 logistics company at Medium-sized logistics company
- Creation of complete bilingual (DE/EN) security and emergency documentation: Business Continuity Plan / Disaster Recovery Plan, Incident Response Plan v2.0 with four case-specific playbooks (PICERL), access control policy, vulnerability management policy, business resilience programme, risk governance plan
- Consolidation into an integrated emergency handbook (12 chapters) with immediate checklists for six emergency scenarios, a prioritized action table, and a formal approval structure
- Review of a penetration test report (Greenbone) with complete remediation of all findings and formal risk acceptance of a residual risk with documented compensating control
- Review and documentation of NIS2 and HinSchG applicability, including the legal reasoning for non-applicability
Doaa Abdelghafar
Last position:
Technical Program Manager/Agile Coach at Visa
- Drove two cross-functional engineering teams within the SAFe framework to deliver backend and integration solutions for Visa’s Terminal Management and Cybersource Onboarding platforms
- Served as Program Coach for ten teams within the Platform Services organization, advancing Agile maturity, delivery alignment, and a culture of continuous improvement
- Orchestrated Agile ceremonies including Product Manager syncs, metrics reviews, inspect-and-adapt sessions, system demos, and leadership workshops to strengthen transparency, collaboration, and delivery performance
- Championed the rollout of the Re-imagine Work@Visa scaled delivery framework within the Agile Transformation Team, improving collaboration and delivery predictability
- Increased release frequency 18× per quarter by synchronizing distributed teams and developing a comprehensive release guide
- Partnered with the Release Manager to standardize deployments across Visa Data Center, AWS, and Mobile platforms
- Led teams to close all security findings and embed remediation into BAU, achieving zero open issues by mid-2024
- Directed the Security Findings Program across the portfolio, ensuring visibility, accountability, and progress tracking
- Supported the roll out of the OKR framework and led quarterly reviews to align execution with business goals
- Strengthened communication across distributed teams, removed blockers, and advocated for continuous improvement and automation
- Delivered on demand workshops for teams with raising maturity and adoption of best practices
- Co-founded a Center of Excellence and Agile Community of Practice to promote continuous learning and alignment
- Partnered with SRE and InfoSec teams on multi-region rollout and security initiatives to enhance reliability and compliance
Discover over 15,000 top freelancers
Statistics of experts using DORA
Aggregated from the professional profiles of matched freelancers.
Experience
21 years
Position duration
2.4 years
Positions per freelancer
16
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Banking and Finance, Professional Services
Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
89%
Master's degree or higher
61%
Doctorate
9%
Certifications per freelancer
7
Most common languages
German, English, French
Speak two or more languages
97%
Based on our profile pool as of 6 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts using DORA
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 6 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What DORA means DORA usually refers to the DevOps Research and Assessment framework and its core metrics. Teams use it to measure software delivery performance in a clear, practical way. It is often discussed as DORA metrics, DORA metrics for DevOps, or simply DORA.
What specialists do
- Define how lead time, deployment frequency, change failure rate, and MTTR are measured
- Connect CI/CD, incident, and version control data into one view
- Turn raw delivery data into reports teams can act on
- Support coaching, reviews, and improvement plans for engineering leadership Strong professionals keep the measurement simple, consistent, and useful.
Where it helps DORA is useful when a company wants to see how software delivery really performs, not just how busy teams look. It helps identify slow handoffs, unstable releases, and weak recovery after incidents. That makes it relevant for product teams, platform teams, and delivery leaders.
Tooling and data A good DORA setup depends on clean data from tools already in use. Experts often work with Jira, GitHub, GitLab, Bitbucket, Jenkins, Azure DevOps, or incident systems. The best results come when the metrics match the real workflow, not an idealized process.
When to bring in help Companies often bring in freelance DORA expertise when metrics are inconsistent, hard to trust, or spread across too many tools. It also helps when leaders want a baseline before a transformation, or when teams need a simple dashboard for delivery health. In Germany, remote work is common for this kind of analysis, but on-site workshops can help align teams faster.
What good experts look like Good DORA specialists know both delivery systems and the habits that distort measurement. They can spot missing timestamps, poor incident tagging, and false signals from automation. They explain trade-offs clearly and focus on improvement, not vanity reporting.
Frequently asked questions
The facts hiring teams ask for most often when it comes to DORA.
DORA is used to measure software delivery performance in a practical way. It helps teams understand how quickly they release, how often releases happen, how many changes fail, and how fast they recover after incidents. Companies use it to spot bottlenecks and make delivery more stable.
In most searches, yes. DORA usually points to the DevOps Research and Assessment framework and its four core metrics, so people often say DORA metrics when they mean the same thing. If you are hiring, look for specialists who can explain both the metric definitions and the data behind them.
DORA is narrower and more operational than many broad maturity models. It focuses on delivery flow and incident recovery, while other approaches may look at culture, architecture, or process compliance. That makes it strong when you want measurable delivery signals instead of general assessments.
A strong DORA specialist usually knows CI/CD pipelines, incident management, version control, and delivery analytics. Experience with Jira, GitHub, GitLab, Azure DevOps, or similar tools is often useful because the metrics depend on reliable event data. Clear reporting skills matter too, since the numbers must be easy to trust and explain.
A DORA project does not always need a long setup, but it does need someone who understands how your delivery data is generated. Small teams may only need a focused assessment and a clean dashboard, while larger organizations may need data mapping across several systems. The key is practical experience with real workflows, not just the metric names.
DORA works very well with remote collaboration because most of the work is data review, process analysis, and reporting. On-site time can still help when teams need workshops, shared definitions, or quick alignment across product, engineering, and operations. Many experts combine both, depending on how spread out the teams are.
Look for someone who can explain how each metric is calculated and what can make it misleading. A good DORA expert will question data quality, show where timestamps or labels are missing, and avoid turning the numbers into a vanity dashboard. They should also connect the metrics to concrete actions, not just report them.
Freelancers working with DORA usually want to know which systems hold the delivery data, who owns the metrics, and how the results will be used. They also need to know whether the goal is a one-time assessment, an ongoing dashboard, or a wider improvement program. Clear scope matters because DORA work can range from simple measurement to deeper process change.
The average hourly rate of freelancers who have used DORA in their recent projects is 123 €, which corresponds to a daily rate of about 984 € based on an 8-hour working day.
Of the freelancers who have used DORA in their recent projects, 89% hold at least a Bachelor's degree, 61% hold at least a Master's degree, and 9% hold a doctorate.
On average, freelancers who have used DORA in their recent projects have 21 years of professional experience, with a single engagement typically lasting around 2.4 years.
The most common languages among freelancers who have used DORA in their recent projects are German (98%), English (97%), and French (23%).
The most common industries among freelancers who have used DORA in their recent projects are Information Technology (84%), Banking and Finance (74%), and Professional Services (62%).
The most common business areas among freelancers who have used DORA in their recent projects are Information Technology (95%), Project Management (92%), and Operations (73%).
Main locations of FRATCH Experts, who have recently used DORA
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Cologne
Frankfurt
Dusseldorf
Essen