Firewall Experts in Munich
in minutes from 15,000 CVs with AI matchingHire experts who design, harden, and troubleshoot firewall rules, NAT, VPN access, and next-generation firewall policies for cloud and on-prem networks. Work with vetted, available professionals matched fast and precisely to your environment.
Meet FRATCH Experts in Munich, who have recently used Firewall
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Tezcan Dilshener
Last position:
Solution Architect / Project Manager at German Football Association
- Overall responsibility for the project lifecycle from scope definition to completion
- Close collaboration with platform teams, IT leaders, and external service providers
- Application of SAFe principles and structured sprint work
- Creation of a migration roadmap with clear milestones
- Monitoring of the lifecycle: onboarding, repository migration, replication of permissions, and system tests
- Visualization of the architecture with PlantUML and Gliffy as well as documentation in Confluence
- Regular status reports and running knowledge transfer sessions
Florian Krebs
Last position:
LAN Planner at Global Network AG
- As-is assessment of the current network infrastructure and its documentation, including on-site inspections
- Independent planning of new distribution and main distribution rooms in the individual district offices (components used, rack layout, connectivity), considering the BSI IT-Grundschutz and InfoSic requirements
- Planning of new copper and fiber optic cabling, including patch panels
- Coordination with building services engineering (TGA) to ensure compliance with relevant on-site requirements
- Development of detailed execution plans and high-level concepts for the rollout of the new infrastructure
- Additional support after the components go live (hypercare phase)
- Regular communication with project management and client stakeholders
Mohamad Dib-Skhni
Last position:
DevOps Engineer & IT-Security-Architect at BMW Group
- Set up Azure Kubernetes clusters (AKS) with network policies, security groups, and RBAC
- Developed Terraform-based infrastructure as code for secure, reproducible deployments in the BMW Azure cloud
- Hardened CI/CD pipelines using Jenkins, SonarQube, Fortify SSC, and Contrast AST
- Integrated SAP BTP/Kyma and ServiceNow GRC
Serge Kalinin
Last position:
MLOps (machine learning operations) at REWE Digital GmbH
- It is like a startup within REWE, where we have to build a new forecasting system on Google Cloud Platform from the scratch. Although, officially my role is called MLOps, my actual tasks also include development of data processing pipelines (data engineering) and data scientists tasks such as feature engineering and model trainings.
- GCP: Terraform (tofu), Vertex AI (Kubeflow), Cloud Run, IAM, Google Cloud Storage, BigQuery, Artifact Registry
- Data engineering: Snowflake as the main data warehouse, Terraform, DBT for data model implementations
- CI/CD: GitLab. We have built a CI/CD pipeline that automates deployments of new releases up to production environment
Siegfried-Thor Bolz
Last position:
AI Solutions Architect & Developer at E-Commerce
- Integrated LangChain middleware between AEM and SAP PIM system
- Developed a FastAPI interface for system communication
- Implemented vector embeddings for semantic product search
- Evaluated LLM models (Vertex AI/Gemini, LM Studio, Hugging Face, OpenAI) for product analysis
- Developed an AEM component to display product recommendations and integrated the recommendation API into the AEM authoring process
- Designed and implemented Pinecone vector database for product embeddings
- Optimized response times and caching strategies
- Evaluated Vertex AI Studio for LLM testing and prompt workflows
- Implemented secure API routing and access control for AI components via FastAPI and gateway validation
Weronika Skarbek-Kozietulska
Last position:
Business & Integration Architecture Specialist at Accenture Technology Solution GmbH
Understanding of bank’s fundamentals throughout analysis and writing specifications
Deep analysis of security measurements to be transferred into new environment
Process design and optimization
Collecting requirements from different areas and processing them into agreement documentation, concepts and process description for internal and external partners
Analysis of data delivery sources and transformation of relevant functions into new environment
Analysis and prioritisation of value and benefits resulting from introducing smart data tools
Mapping and migrating data within Power BI upgrade
Change management support and evaluation
Marketing automation and technology enablement
Executing test and release support
Creating training documentation for the client’s employees to understand value and benefits by using new technologies when acquiring new or creating benefits to their existing customers
Creating a complete database of existing firewalls supporting the security of the client’s infrastructure
Migration and re-architecture of reporting systems from multiple data sources into the cloud environment
Konstantinos Metaxas
Last position:
IT-Fly Specialist – Global Rollout at Lufthansa Group
Plan & Prepare (Site Design & Readiness): Inventory & Design: Dell PowerEdge R-Series, Aruba switches (L2/L3), notebooks/peripherals; serials/asset tags, IPv4/IPv6 addressing, VLAN-/DHCP-/DNS plan
Runbooks/MOPs: site rollout runbook, backout strategy (<15–30 min), risk register, communication matrix; approvals via CAB/change
Images/Packages: Golden Image (Win10/11), driver packs, BIOS/UEFI baseline; O365/Teams/OneDrive KFM; BitLocker policies; MECM/SCCM, Intune/Autopilot, MDT/WinPE
Logistics: shipping/customs clearance, RMA/DOA, on-site spares; tools (barcode scanner, label printer), "Go-Bag" (cables, SFPs, console cables)
Deliver (on-site implementation): End devices: swap & migration (USMT/OneDrive KFM), peripherals (ATB/BT printers, scanners, boarding gate hardware); domain join, compliance checks, O365 activation, printers/queues, network drives
Acceptance: functional tests for DCS/CUTE/CUPPS/CUSS stations, ticketing/check-in workflows, boarding gates
Server (R-Series): rack & stack, cabling (PDU redundancy, fiber/copper), labeling/naming; firmware/RAID (PERC), Lifecycle Controller, iDRAC network; Windows Server 2022/2025 + CIS/BSI hardening; agents (backup/AV/EDR/monitoring), time service/NTP auth, Syslog/SNMPv3
Network (Aruba): VLANs, LACP trunks, MSTP root; PortFast + BPDU Guard at the edge; QoS (EF/AF); dual stack (v4/v6), DHCP relay. NAC/802.1X with ClearPass/Radius/TACACS+, roles + MAB fallback; guest isolation, ACLs (Guest→Mgmt deny). Telemetry: sFlow, SNMPv3, Syslog→SIEM; LLDP→inventory/CMDB
Airport specifics: CUTE/CUPPS/CUSS terminals; DCS/Amadeus/SITA connectivity; FIDS (read-only); bag tag/boarding pass printing; changes in off-peak/night windows
Stabilize (hypercare): first-day support, KPI tracking (login times, ticket volume, error classes), QoS fine-tuning
Troubleshooting: Wireshark/iperf, event logs, switch counters, sFlow flows; fast incident handling as SPOC
Knowledge transfer: short training sessions for station teams, mini-runbooks (fault/recovery)
Close (documentation & handover): docs & CMDB: final configs (switch/server), topology/patch plans, IP tables, serial/asset lists, before/after photos
Acceptance & sign-off: UAT protocols, functional evidence (use cases), return/reuse of old hardware
Lessons learned: risks, standard packages, driver freeze, "known issues"
Interfaces/communication: station IT, airport IT, SOC/NOC, ground ops/ramp/check-in, provider (SITA/Amadeus). ITSM: ServiceNow (Inc/Req/Change/KB), handover to BAU
Andreas Zimmermann
Last position:
ITSM Consultant at Industrial company / Global IT division
- Designed and implemented a new user support tower organization as part of the global IT transformation initiative.
- Created an operating and control model for the central service desk, including downstream support units (field service, VIP support, service points).
- Performed a comprehensive as-is analysis of existing service desk and field service structures and developed a target architecture based on ITIL 4 and SIAM.
- Defined roles, responsibilities, and governance mechanisms for internal IT and external providers.
- Prepared the blueprint document Service Management & Governance Handbook (User Support) to standardize global service processes (incident, request, problem, change, knowledge, ITSCM, CSI).
- Developed a KPI and SLA framework to measure service quality and performance in global user support.
- Defined the reporting and review structure (operations meeting, service review meeting, management steering board).
- Prepared RFP documents for the external tendering of L1/L2 support services, including definition of scope, governance model, process requirements, tool integration (ServiceNow), and KPI/SLA sets.
- Supported procurement and legal departments in evaluating and negotiating vendor proposals and assisted in vendor selection and contract finalization.
- Oversaw the handover to operational support, including knowledge transfer, training of provider teams, and establishment of a continuous improvement process (CSI).
- Methods / framework / tools: ITIL 4 / ITSM, SIAM, IT4IT, ServiceNow, Jira, BPMN, operating model canvas, KPI & SLA design, governance & performance management
Teemu Suvanto
Last position:
SRE at E.On SE
- Maintained a SaaS billing platform on AWS as part of the Site Reliability Engineering (SRE) team.
- Played a key role in an AWS cloud migration project, implementing Terraform (IaC), creating CI/CD processes and pipelines, hardening images, upgrading tool versions, and developing scripts.
- Wrote documentation.
AWS Cloud migration:
- Design and implement CI/CD for deploying AWS resources using GitLab CI, Terraform, and GitOps.
- Create and configure DevOps toolchain including Jenkins, Harbor, and Vault.
- Deploy billing application, microservices, and supporting infrastructure services to Nomad clusters.
- Re-designed TLS/mTLS certificate management using Vault and Lambda.
Security (Infrastructure Hardening & Patch Management & Vulnerability Scanning):
- Managed multiple AWS accounts for Consul/Nomad/Traefik clusters (10–20 EC2 instances/account, ASG) and DevOps toolchain accounts (Harbor, Jenkins, Vault).
- Created hardened AMIs via Packer based on CIS benchmarks for Nomad, Jenkins, Harbor, and Vault; deployed using Terraform.
- Integrated Trivy via Harbor plugin for container image scanning.
- Implemented strict AWS VPC security group rules.
- Developed and maintained patching process across environments using Qualys and Wiz.
- Deployed Qualys Cloud Agent to all EC2 instances, tracked CVEs and tested patches in lower environments before rollout.
- Automated patch deployment across all AWS accounts using Terraform and GitLab CI and verified patch compliance via Qualys/Wiz dashboards.
Gilbert Lintner
Last position:
Cyber Security Expert at TüV Süd AG (via Sthree GmbH)
- Security analysis of alerts
- Further development of the security operations center
- Development of processes and workflows in the security environment
- Implementation of SOC solutions
- Forensic expertise
- Conducting hunts
- Vulnerability scans and proof of concepts
- Risk assessments and risk analyses
- Maintenance and further development of the Tenable.sc ScanCenter environment
Rupesh Kumar Sendge
Last position:
IT Baseline Compliance Consultant at Consultant
- Baseline compliance verification against MAS audit findings
- Building technical architecture concept for 30 technologies to build hardening standard artifacts
- Identifying and building automation possibilities for given technologies based on CIS
- Building the standard baseline configuration based on internal security standard
- Responsible for building Cloud Native Application Protection Platform (CNAPP) architecture artifacts based on Azure cloud platform
- Responsible for RFQ and RFP for different CNAPP solutions (Qualys Total Cloud, CrowdStrike, Azure Security Center)
- Supporting compliance verification and validation via automated scripts for a sample population of IT devices and instances
- Responsible for complete vulnerability management lifecycle using Nexpose, remediation, reporting and integration of results with Splunk, HPSM and Tableau
- Audit support for MAS
Rallis Tsetinis
Last position:
Senior Project Manager Datacenter, Cloud, Network and Collocation at Noris Network AG
- Successfully led IT infrastructure projects with budgets up to €10M, including data center migrations and cloud transformations, improving operational efficiency by 30%.
- Managed project specifications, resources, and stakeholder alignment, delivering 95% of projects on time and within budget, ensuring seamless execution.
- Reduced project risks by 40% through proactive risk, cost, and claim management while maintaining 99.9% system uptime and effective C-level communication.
- Optimized team performance by 25% using agile methodologies like Scrum, enhancing service readiness and ensuring a 20% faster go-live for IT solutions.
Alexandru Gunescu
Last position:
Head of Cloud Infrastructure at BP
- Migrated the Electric Vehicle Charging SaaS App of the EV Division from on-premises and Azure to AWS Cloud, resulting in a hybrid multi-cloud multi-tenant solution
- Developed a streaming data pipeline using AWS MSK for Apache Kafka and implemented an event-driven architecture to ingest and process near real-time data from OCPI-protocol IoT devices
- Implemented multi-tenant strategies including database schema isolation, bridge model for resource sharing, and tenant-based RBAC controls
- Provisioned Kubernetes clusters on AWS EKS with namespaces and RBAC for tenant isolation
- Led migration from on-premises and Azure to AWS using AWS DataSync, Snowball, and Database Migration Service
- Orchestrated collaboration across 5+ systems, vendors, service providers, and on-site teams
- Supported development and maintenance of IT strategy aligned with business requirements
- Managed €40 million infrastructure budget with AWS & Azure cost optimization, achieving 15% savings
- Led 50+ developers to implement advanced database procedures, increasing productivity by 20%
- Spearheaded multi-cloud, multi-tenant infrastructure migration for 30% faster processing times
- Negotiated vendor pricing to reduce payroll/benefits administration costs by 20%
- Developed a two-year infrastructure technology roadmap yielding 25% cost savings
- Tech stack: Kubernetes on AWS EKS, Docker, Kafka/AWS MSK, Terraform, AWS CDK, TypeScript, React, NextJS, Node.js, NestJS, Python, Aurora Serverless, RDS (MySQL, SQL Server), GitHub Actions, Azure DevOps, ArgoCD, AWS Lambda, API Gateway, AWS Security Hub, AWS Database Migration Service, AWS DataSync, AWS Organizations, AWS Control Tower, Odoo, Microsoft Navision, MS Dynamics
Stephan Krausenegger
Last position:
Migration Coordination at ITZBund
- Analysis and assessment of government business processes with regard to migration capability
- Definition and preparation of the technical framework conditions in the new master data center
- Development and optimization of migration procedures and processes
- Transformation of existing solutions to new technical standards (technology refresh)
- Coordination of architecture and technical cross-cutting topics
Discover over 15,000 top freelancers
Statistics of experts using Firewall
Aggregated from the professional profiles of matched freelancers.
Experience
20 years (Germany: 22 years)
Position duration
1.7 years (Germany: 2.3 years)
Positions per freelancer
15 (Germany: 14)
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Banking and Finance, Automotive
Certification focus areas
Information Technology, Project Management, Business Intelligence
Bachelor's degree or higher
85% (Germany: 74%)
Master's degree or higher
60% (Germany: 40%)
Doctorate
10% (Germany: 6%)
Certifications per freelancer
5
Most common languages
English, German, French
Speak two or more languages
100% (Germany: 98%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Munich are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Munich using Firewall
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Firewall basics
A firewall controls which traffic can enter, leave, or move inside a network. It is used to protect offices, data centers, cloud workloads, and remote access paths from unwanted connections and risky protocols.
Common setups
Typical work covers:
- perimeter filtering for office and data center networks
- cloud security groups and firewall policies
- VPN access rules for remote teams
- application and port-based access control
- segmentation between internal systems
Tools and platforms
Firewall specialists work with hardware appliances, virtual firewalls, and cloud-native controls. Common environments include Cisco ASA, Palo Alto Networks, Fortinet FortiGate, Check Point, pfSense, and Windows Firewall, plus AWS, Azure, and Google Cloud network controls.
When companies need help
Teams bring in freelance experts when a rule base has grown messy, traffic is blocked without clear cause, or a new site, cloud account, or merger needs a clean policy design. In Munich, this often means work that must fit local office networks, hybrid setups, and cross-team coordination.
What strong experts do
Good professionals read packet flows, spot conflicting rules, and separate business access from broad network openings. They document changes clearly, test in staging where possible, and keep security tight without breaking critical services.
Deliverables and handover
A solid engagement usually ends with a clean rule set, a change log, and clear guidance for future maintenance. Strong experts also leave behind VPN settings, segmentation notes, and rollback steps so internal teams can operate the firewall with confidence.
Frequently asked questions
Questions about Firewall? Start with the answers below.
A strong Firewall freelancer designs and maintains rules that control network traffic, user access, and service exposure. They often handle NAT, VPN access, segmentation, logging, and cleanup of old rules that no longer serve a purpose.
Not exactly. A firewall is the broad control point for traffic filtering, while a next-generation firewall adds features such as application awareness, intrusion prevention, and deeper traffic inspection. Many companies now look for both the policy basics and NGFW experience.
A good Firewall specialist should be comfortable with the products your environment already uses, such as Palo Alto Networks, Fortinet FortiGate, Check Point, Cisco ASA, or pfSense. Cloud firewall controls in AWS, Azure, and Google Cloud are also common.
A Firewall expert usually needs solid networking knowledge: IP addressing, routing, DNS, VPNs, and TLS basics. Scripting, log analysis, and cloud networking are valuable too, especially when the policy set spans multiple sites or environments.
A Firewall project can be small or complex, depending on whether it is a simple rule review or a full redesign. For rule cleanup or troubleshooting, a focused specialist may be enough; for segmentation or cloud migration, you want someone who has handled similar network changes before.
Most Firewall tasks can be done remotely if the specialist has secure access to logs, dashboards, and a change process. On-site work in Munich helps when physical appliances, local network teams, or sensitive cutovers require close coordination.
A strong Firewall specialist explains why each rule exists, removes unnecessary access, and avoids broad allow rules that create risk. Look for clear documentation, careful change handling, and the ability to troubleshoot blocked traffic without guesswork.
If a Firewall rule base is full of duplicates, nobody trusts the logs, or changes keep breaking business traffic, it is time to bring in help. The same is true when you are opening a new site, moving to cloud services, or tightening access after an audit.
The average hourly rate of freelancers in Munich, Germany who have used Firewall in their recent projects is 103 €, which corresponds to a daily rate of about 821 € based on an 8-hour working day.
Of the freelancers in Munich, Germany who have used Firewall in their recent projects, 85% hold at least a Bachelor's degree, 60% hold at least a Master's degree, and 10% hold a doctorate.
On average, freelancers in Munich, Germany who have used Firewall in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 1.7 years.
The most common languages among freelancers in Munich, Germany who have used Firewall in their recent projects are English (100%), German (96%), and French (31%).
The most common industries among freelancers in Munich, Germany who have used Firewall in their recent projects are Information Technology (92%), Banking and Finance (69%), and Automotive (54%).
The most common business areas among freelancers in Munich, Germany who have used Firewall in their recent projects are Information Technology (100%), Operations (77%), and Project Management (69%).
Main locations of FRATCH Experts, who have recently used Firewall
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Cologne
Frankfurt
Stuttgart
Dusseldorf
Dortmund
Nuremberg