
Identity and Access Management Expert
for secure access with vetted, available freelancers matched by AIHire experts who design identity platforms, integrate single sign-on and OAuth 2.0, and strengthen privileged access controls. FRATCH matches you quickly and precisely with vetted, available freelancers whose experience fits your security and delivery needs.
Meet FRATCH Experts who have recently used Identity and Access Management
Matthias K.
Last position:
Business Owner at AKM
Management of several MFA methods for centralized authentication within a group. Interface between various stakeholders such as Support, Finance, Developers, and Security departments. Assessment of compliance requirements such as KRITIS. Budget controlling and monitoring of KPIs and SLAs. Support with internal and external audits on MFA topics and with connecting new systems. Review of operational documentation. Participation in steering committees and leadership of service review meetings and decision-making committees.
Tools/Frameworks: FIDO, Yubikey, Veridium, BSI Grundschutz, NIST
Markus H.
Last position:
Senior M365 Consultant at BITMARCK GmbH
Creation of concepts for the M365 implementation, especially Tenants, EntraID, EntraConnect, and ExchangeOnline, taking into account the BAS standards (mandatory baseline security requirements) in the “M365 Concept” project, with the goal of transferring the concepts to the M365 environments of Bitmarck and subsequently handing them over to the customer.
- Creation of an as-is analysis of the existing M365 environments as well as the on-premises environments and BAS standards.
- Creation of concepts for the topics Tenants, EntraID, EntraConnect, and ExchangeOnline, taking into account the BAS standards
- Design and implementation of an automated solution for creating standardized M365 tenants based on Microsoft M365 DSC (Desired State Configuration)
- Transfer of the concepts to the M365 environments
- Creation of detailed technical documentation
Paul K.
Last position:
Program Manager – Multi-Project Operational Stabilization (Operational Excellence) at ITDZ - IT Service Center Berlin
- Overall leadership of several strategic operations projects focusing on Workplace Services, SLA Framework, access management, certificate management, e-learning, backup & recovery, test management, and capacity management, as well as the introduction of system monitoring and feasibility studies for 24x7 operations, in some cases including implementation in ServiceNow
- Creation of various ServiceNow operating concepts covering training, access rights, and emergency management as part of a new cloud hosting initiative for the ServiceNow platform
- Executive board reports and leadership of steering committees as part of company-wide strategic objectives, as well as the establishment of new balanced scorecards for measuring KPIs related to optimization-driven project results
Matthias S.
Last position:
Overall Project Coordinator at Bundeswehr Informatik (BWI GmbH)
- PMO Lead Security Clearance 2 (SÜ2) verified
- Reporting to the GMN sub-program management
- System maintenance 25+
- Functional management and coordination of the Jira setup
- Preparation of decision papers (e.g. project planning, governance model, communication plans, controlling models, roles and responsibilities matrices)
- Development of program-wide knowledge management using Confluence, creation of Jira concept
- Development of an access concept for all project tools
- Analysis of existing processes, identification of improvement potential, and design of solutions to increase efficiency and effectiveness
- Development of a concept for introducing automation approaches into existing tools
- Creation of intranet articles for project marketing
- Responsible for project governance through reporting and resource planning in the sub-program
- Agile development of the project methodology
- Gathering customer requirements (Requirements Engineering)
- Preparation and support of contract negotiations (7-year term, 500+ million budget)
Reza N.
Last position:
Senior IT-Security Expert at Teambank AG
- Completed the integration of log sources into Microsoft Sentinel, including GCP workloads – centralized consolidation of all security-relevant events from Azure and GCP environments for complete end-to-end telemetry and comprehensive compliance evidence
- Developed custom rules and use cases based on the GFG Use-Case Library and the MITRE ATT&CK Matrix to cover company-specific threats and GFG-relevant scenarios with precise, mapped detection rules
- Tuned detection rules to minimize false positives, optimized detection thresholds, and modeled exceptions – enabling the SOC to work with relevant, prioritized alerts while reducing Mean Time to Detect/Respond
- Built SOAR capabilities in Sentinel by developing playbooks to automate recurring response processes such as containment, user and host isolation, and ticketing – shorter response times and 24/7 scalability
- Designed and built a log transformation solution to normalize and enrich incoming raw logs (GeoIP, CMDB, threat intelligence) and convert them into a consistent schema for high-performance KQL queries, use case logic, and correlations
- Managed Azure security through Azure Policies to enforce security and compliance standards, prevent drift, and continuously remediate deviations
- Operated the Defender XDR portal to link endpoint, identity, email, and SaaS signals with Sentinel findings, enable holistic incident triage, and orchestrate measures directly from XDR
Technologies: Microsoft Sentinel, Microsoft Defender XDR, Azure Policy, KQL, GCP, MITRE ATT&CK
Ebru A.
Last position:
Product Analytics & App Tracking Consultant at EnBW mobility+ AG & Co. KG
- Product Analytics, Mobile App Tracking & Tracking Governance (B2C Mobility App) – agile project management (Scrum/Kanban)
- Product Ownership for Product Analytics and Mobile App Tracking of the EnBW mobility+ app; gathering, prioritizing, and translating business requirements into actionable concepts and Azure DevOps user stories with acceptance criteria.
- Derivation of tracking requirements when introducing new app features (including Resilient Map), definition of tracking parameters (screens, events, custom definitions), and ensuring privacy-compliant tracking (Firebase, GA4, Adjust) based on the tracking concept.
- Design and adaptation of dashboards and funnel reporting for campaigns (GA4 validation, onboarding and order flow analyses, conversion funnels, charging start flow) to identify drop-off points and optimization potential.
- Management of the technical raw data export (Adjust to BigQuery) and connection to the data warehouse/data lakehouse, including data mapping; collaboration with international development teams, Data Engineering, Marketing/Sales, and Product Management.
- Establishment of standardized tracking architecture, naming conventions, and governance; analysis and expansion of tracking (new features and “blind spots”), test design, handover to testers, and quality assurance and approval before releases; documentation in Conceptboard.
Wolfgang O.
Last position:
Project Manager at EnBW - Netze Südwest
- New development and further development of the existing MS Dynamics CRM
IT systems: Microsoft Dynamics Customer Service, SharePoint, DevOps, SAP IS-U
- CRM implementation / further development
- Taking over from the previous service provider
- Business process analysis
- Agile project organization
- Business analysis / requirements engineering with AI support
- Use of AI in development
- Analysis of master data processes
- CRM customer data management
- Requirements documentation
- Stakeholder management
- Workshop moderation
Shamaila M.
Last position:
Founder/Kubernetes and Cloud Architect at Kubekanvas
- Developed a browser-based platform for Kubernetes no-code deployment and cluster management
- Developed a CLI in TypeScript to deploy resources in the cluster without leaving the browser UI.
- Implemented DevSecOps pipelines: image scanning, SBOM, policy enforcement, supply-chain security, and used Kyverno. Implemented IAM integration for the command-line utility tool.
- Designed role and permission models for Keycloak, OAuth/OIDC, and social login flows.
- Used LLMs to convert user intent into diagrams.
- Worked on integration with multiple sovereign clouds like StackIT, Hetzner, CIVO, UpCloud, plus public clouds like AWS, GCP, and Azure
- The technology stack includes Java, Spring Boot, Kubernetes, OpenAI, Kubernetes multi-tenancy using vCluster, Karpenter, RBAC for CLI, Helm, React
Jens R.
Last position:
Platform Architect & Senior Developer at Direct client, industrial measurement technology, medium-sized company
- Technical leadership across hardware, firmware, and software teams; scope: hardware/firmware team (4 people) and leadership group (5 people)
- Consolidated and documented a product family that had grown over more than 15 years and aligned it with CRA compliance — from the bare-metal I/O module to the cloud interface.
- Provided the most important customer product with the essential requirements and architecture documentation within two months — for a firmware landscape that had grown over more than 15 years. It now supports the customer’s modernization strategy.
- Established a monthly reporting line to the supervisory board and executive board within three months: nine meetings since 12/2025. The report itself is versioned and built from the CI pipeline; it is based on automatically collected activity and release data instead of assessments.
- Built a container-based CI/CD infrastructure from scratch: cross-compilation, host tests, and documentation builds in one continuous pipeline.
- Introduced declarative QA gates for DevOps and development artifacts — from the start using lefthook instead of pre-commit, executed in a dedicated container image.
Technologies used: arc42, req42, tpo42, docToolchain, PlantUML, ArchiMate, C4 model, ADR, C, C++ (GTest), CMake, Bare Metal (ARM Cortex-M3/M7), OCI containers, Jenkins, lefthook, Prometheus, Grafana, SBOM, CRA, OPC, SCADA, PLC integration, IPv6 migration, Zero Trust, Sociocracy 3.0, Cynefin
Christian F.
Last position:
Architecture Management at Agency
Expert in the company's architecture management area
Support for standardizing the company's IT landscape
Further development of architecture management
Shaping the company's business architecture
Restructuring, administration and maintenance of all IT assets
Support in creating a unified software asset management and CMDB
Creation of unified document management (e-file)
Transition of documents into a central DMS structure
Link between architecture management and the department's internal business process management
Support in developing strategic and tactical development plans
Organizing communication with key stakeholders
Support in the conception, organization and coordination of the architecture office to be built up
Accompanying and advising the entire architecture management process
Advising the company's business units on architectural topics and their framework conditions
MS Office, Windows 10, VBA
ITIL, TOGAF, PowerBi, Kanban, Scrum
Internal agency tools
Open Touch Conversation, Webex, wire, bdbos
MS Sharepoint, JIRA, Confluence
ARIS, Archimate, BPMN
Jens H.
Last position:
Interim CTO (occasional assignments) at Fujitsu / FSAS
Stabilization of an Azure/.NET landscape in live operation.
- Architecture, DevOps, and operational readiness; technical decisions under time pressure
- Azure DevOps, monitoring, ETL/ELT, cloud security, FinOps, and data-mesh-related topics
Technologies: Azure DevOps, .NET, CI/CD, monitoring, FinOps
Michael S.
Last position:
Establishment of Compliance/TPRM at Haftpflichtkasse
Establishment of Compliance Department & DORA Operationalization
- Establishment of a complete compliance organization in accordance with DORA
- Development and operationalization of the SfO
- Use of AI agents for automation:
- Evaluation of due diligence questionnaires including risk classification
- AI-supported contract analysis (DORA/MaRisk compliance)
- Monitoring of external data sources (cyber incidents, newsfeeds)
- Establishment of a decentralized risk and action register
- Preparation of GAP analyses and derivation of measures
- Establishment and maintenance of the Outsourcing Information Register
- Use of proprietary TPRM frameworks, checklists and process models
Establishment of Compliance Department & DORA Operationalization
- Establishment of a complete compliance organization in accordance with DORA
- Development and operationalization of the SfO
- Use of AI agents for automation:
- Evaluation of due diligence questionnaires including risk classification
- AI-supported contract analysis (DORA/MaRisk compliance)
- Monitoring of external data sources (cyber incidents, newsfeeds)
- Establishment of a decentralized risk and action register
- Preparation of GAP analyses and derivation of measures
- Establishment and maintenance of the Outsourcing Information Register
- Use of proprietary TPRM frameworks, checklists and process models
- Project controlling - presentation and structured measurement of project goals achieved as part of management reporting.
- Overall responsibility for establishing a Compliance, Governance and Risk organization
- Establishment of an integrated GRC model and executive reporting for the Management Board.
Collin K.
Last position:
Software Architect / Fullstack Developer at Equity Bytes
Built an international e-commerce platform for a multi-vendor marketplace for digital assets from scratch. Designed and operated cloud native architectures at enterprise scale.
- Designed and operated a highly scalable microservice and serverless architecture
- Built the complete cloud infrastructure with Terraform + AWS CDK in AWS
- Provisioned ECS/EKS clusters (Fargate), Application Load Balancers (reverse proxy), and Lambda functions
- Observability & tracing with CloudWatch, DataDog, Prometheus, and Grafana
- End-to-end setup with DataDog (formerly AWS CloudWatch), Prometheus, and custom Grafana dashboards
- Integration of advanced metrics (including ORM mapper) and distributed tracing with Jaeger
- Robust backup and disaster recovery strategies
- RDS Postgres backups and hourly snapshots
- Read-only, asynchronously synchronized replicas with automated master failover in emergencies
- Minute-level rollback capability through versioned Docker images on ECS and Git-based CI/CD pipelines
- Created CI/CD pipelines with GitHub Actions for automated multi-stage deployments (Dev, Testing, Prod)
- Integrated Stripe for international payment processing
- Built a marketplace payment system with multiple parties and payout routines
- Used Algolia for high-performance real-time search of digital assets on the platform
- Federation of services with GraphQL and Hasura
- Later migration to GraphQL Mesh
- Test Driven Development (TDD) - unit, integration, and E2E testing with Jest, Vitest, and Playwright
- Used Next.js / React for modern frontend applications in the nx monorepo
- Enterprise security architecture & access control
- Integration of JWT tokens with Auth0, OAuth, OIDC, IP guards, BOLA protection, and secret vaults
- Authorization concepts with RBAC, ABAC, and native Postgres Row-Level Security (RLS)
- Built internal microfrontends with Retool for fast prototyping and operational business processes
Technologies: ABAC, AWS CDK, AWS CloudWatch, AWS ECS, AWS EKS, AWS Fargate, AWS RDS, AWS S3, Algolia, Auth0, DataDog, Docker, GitHub Actions, Grafana, GraphQL, GraphQL Mesh, Hasura, JWT, Jaeger, Java, JavaScript, Jest, Kotlin, Kubernetes, Monorepo, Next.js, OIDC, Playwright, Postgres, Postgres RLS, Prometheus, RBAC, Redis, Retool, Serverless, Stripe, Terraform, TypeScript, Vitest
Christian H.
Last position:
Senior Business Consultant CTV Monetization - Livestreaming
- Strategic consulting for the implementation of a CTV monetization concept in the livestreaming sector - sports
- Consulting and support in selecting monetization partners
- Strategic consulting and screening of ad technologies, their integration, and the implementation of an integrated business workflow
- Stakeholder management and management support
- Pricing, cost, and benefit analyses
- Sub-project leadership for external and internal stakeholders and teams
Michael N.
Last position:
Senior AI Engineer | Forward Deployed Engineer at Tiefbau
- Development of an AI-powered project organization tool for a civil engineering company that intelligently links project, task, tender, schedule, and document data through a knowledge graph.
- Implementation of AI features for document analysis, information extraction, context-based assistance, and voice-based data capture based on Microsoft Azure AI, reducing administrative effort, making information available faster, and supporting project teams in decision-making.
- Tech stack: Python, React, TypeScript, FastAPI, Claude Code, Codex, Graphify, PostgreSQL, Microsoft Azure AI Foundry, Azure OpenAI, Azure AI Speech, Azure AI Document Intelligence, Microsoft Graph, Microsoft Entra ID, Docker, Git, CI/CD.
Discover over 15,000 top freelancers
Statistics of experts using Identity and Access Management
Aggregated from the professional profiles of matched freelancers.
Experience
20 years

Position duration
2.2 years

Positions per freelancer
14

Top business areas
Information Technology, Project Management, Product Development

Top industries
Information Technology, Banking and Finance, Professional Services

Certification focus areas
Information Technology, Project Management, Product Development
Bachelor's degree or higher
85%
Master's degree or higher
52%
Doctorate
6%

Certifications per freelancer
4

Most common languages
German, English, French

Speak two or more languages
96%
Based on our profile pool as of 1 Oct 2026.
Daily rate distribution
The chart shows how the daily rates of experts in this technology are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows the share of experts charging within that range.
Average rates of experts using Identity and Access Management
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 1 Oct 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Identity and Access Management experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (93%)
- Banking and Finance (60%)
- Professional Services (43%)
- Automotive (39%)
- Manufacturing (39%)
- Retail (35%)
- Telecommunication (33%)
- Government and Administration (33%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
Identity foundations
Identity and Access Management, often called IAM, controls who can access systems, applications and data, under which conditions and with which permissions. It combines identity lifecycle management, authentication, authorization and audit trails. IAM is used across cloud estates, enterprise applications, customer portals, APIs and internal networks.
Core capabilities
Strong IAM specialists connect policy with practical identity services. Their work can include:
- Designing joiner, mover and leaver workflows
- Implementing single sign-on with SAML or OpenID Connect
- Applying multifactor authentication and adaptive access rules
- Managing roles, groups, entitlements and privileged accounts
- Building access reviews, approval flows and audit reporting
Ecosystem and tooling
IAM projects often span Microsoft Entra ID, formerly Azure Active Directory, Okta, Keycloak, Ping Identity and CyberArk. Specialists work with LDAP and Active Directory alongside cloud identity providers, SCIM provisioning, OAuth 2.0, OpenID Connect and SAML. They also connect IAM to Terraform, CI/CD pipelines, SIEM tools and service management workflows.
When expertise matters
Companies bring in freelance IAM professionals during cloud migrations, platform consolidation, compliance programmes and security transformations. They are also valuable when access remains manual, permissions have grown without ownership, or a merger requires identities and policies to work across separate environments. Short-term expertise can help define the target model, deliver integrations and transfer operational knowledge.
Delivery in practice
An IAM engagement may cover discovery, architecture, configuration, migration and testing. The specialist maps business roles to technical entitlements, protects privileged paths, validates federation flows and prepares rollback plans. Good delivery includes clear documentation, stakeholder training and monitoring that shows whether access policies work as intended.
What strong specialists bring
Experienced IAM professionals understand security without losing sight of user experience and operational support. They explain policy decisions clearly, challenge excessive access and test failure scenarios such as expired credentials or unavailable identity providers. Look for evidence of secure integrations, controlled migrations, reliable automation and careful handling of personal and authentication data.
Frequently asked questions
Everything clients usually want to know about Identity and Access Management, in one place.
Identity and Access Management controls digital identities and their access to applications, infrastructure and data. Companies use IAM to provide sign-on, enforce authentication policies, manage permissions throughout the identity lifecycle and produce evidence for security reviews.
IAM is the broader discipline covering identities, authentication, authorization, lifecycle processes and governance. Single sign-on focuses on convenient access across applications, while privileged access management focuses on protecting powerful accounts, sessions and credentials.
A strong Identity and Access Management specialist often brings knowledge of cloud security, networking, directory services and scripting. Experience with Microsoft Entra ID, Active Directory, Okta, Keycloak, Terraform, SIEM integration and data protection controls can be valuable depending on the environment.
The right level for an IAM engagement depends on scope and risk, not on a fixed duration. A focused integration may need a specialist familiar with the relevant protocols and provider, while a company-wide redesign calls for someone who can handle governance, migration, architecture and stakeholder alignment.
Identity and Access Management work is often suitable for remote collaboration because discovery, configuration, documentation and testing can be performed securely online. On-site sessions may still help with workshops, regulated environments, hardware-based access controls or complex coordination with internal teams.
Look for a Identity and Access Management specialist who can explain decisions in terms of risk, business roles and user impact. Ask for examples of federation, lifecycle automation, access reviews, privileged access controls and controlled migrations, while protecting confidential client details.
A capable IAM professional should understand when to use SAML, OAuth 2.0, OpenID Connect and SCIM, rather than treating them as interchangeable. They should also know directory synchronization, token handling, claims, session controls and the security implications of each integration pattern.
A typical Identity and Access Management engagement can produce a target architecture, role and entitlement model, integration designs, configured policies, migration plans and test evidence. It should also leave clear runbooks, ownership rules, monitoring guidance and documentation for future access reviews.
The average hourly rate of freelancers who have used Identity and Access Management in their recent projects is 106 €, which corresponds to a daily rate of about 847 € based on an 8-hour working day.
Of the freelancers who have used Identity and Access Management in their recent projects, 85% hold at least a Bachelor's degree, 52% hold at least a Master's degree, and 6% hold a doctorate.
On average, freelancers who have used Identity and Access Management in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 2.2 years.
The most common languages among freelancers who have used Identity and Access Management in their recent projects are German (98%), English (96%), and French (20%).
The most common industries among freelancers who have used Identity and Access Management in their recent projects are Information Technology (93%), Banking and Finance (60%), and Professional Services (43%).
The most common business areas among freelancers who have used Identity and Access Management in their recent projects are Information Technology (99%), Project Management (73%), and Product Development (68%).
Main locations of FRATCH Experts, who have recently used Identity and Access Management
Our freelancers and interim experts are at home all over Germany — available on-site in Berlin, Hamburg, Munich and every major business hub, or fully remote. Choose a city to discover matched specialists, local market insights and up-to-date availability.
Countries:
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Cologne
Frankfurt
Stuttgart
Dusseldorf
Essen
Nuremberg
Vienna
Zurich