Identity and Access Management Experts in Berlin
in minutes from over 15,000 CVs with the power of AIHire experts who design secure login flows, single sign-on, multi-factor authentication, role models, and lifecycle processes for modern systems. Work with specialists who can join greenfield builds, audits, migrations, and incident fixes, matched fast from vetted, available freelancers.
Meet FRATCH Experts in Berlin, who have recently used Identity and Access Management
Deepak Mishra
Last position:
Lead ML Platform Engineer at Billie GmbH
- Mentor team of 6 ML platform engineers through weekly 1:1s, technical design reviews, and best practices, improving team velocity by 35% through structured sprint planning and skill development programs
- Define 2025ā2026 ML platform roadmap in collaboration with Data Science, Cloud Engineering, and Product teams, prioritizing automated model governance, cost attribution systems, and multi-environment deployment strategies
- Partner with Data Science, SRE, and Product stakeholders to align ML platform capabilities with business objectives, reducing data scientist deployment friction by 60% through self-service platforms
- Architect and deliver production-grade MLOps platform supporting 50+ models in production with automated promotion pipelines, versioning, and rollback capabilities, achieving 99.5% platform uptime SLA
- Design distributed ML pipeline architecture using Metaflow and Argo Workflows (Vertex Pipelines-compatible), reducing model training time by 30% and deployment cycles from 2 weeks to 3 days through full CI/CD automation
- Build containerized ML services on Kubernetes with auto-scaling policies, resource quotas, and multi-tenancy isolation, optimizing infrastructure costs by $180K annually (25% reduction)
- Implement monitoring, alerting, and performance tracking using Prometheus, Grafana, and custom instrumentation, reducing model debugging time by 50% and establishing model performance SLOs
- Lead development of RAG-based document intelligence platform using LangChain, LangGraph, and vector databases, implementing agentic AI workflows for automated financial document processing
- Implement Infrastructure-as-Code using Terraform for reproducible environment provisioning and GitOps workflows, reducing infrastructure drift incidents by 80%
- Design role-based access control for ML platform, implement model lineage tracking, and establish audit trails for regulatory compliance aligned with enterprise IAM best practices
Julius Herrera Glomm
Last position:
Freelancer at Freelancer ā Pharma Industry
- Led migration to GCP using Terraform, GKE, and GitOps, improving deployment consistency and scalability
- Implemented Datadog observability stack via Terraform and datadog-operator
- Established automated end-to-end tests and on-call processes, improving incident response and service reliability
- Migrated from NGINX Ingress Controller to Kubernetes Gateway API (NGINX Gateway Fabric)
- Migrated stateful services (PostgreSQL and Redis) to GCP, improving scalability and operational reliability
Gor Ohanyan
Last position:
Senior IT Transformation Consultant and Business Analyst at Self-employed Consultant
Senior IT Transformation Consultant and Business Analyst with a focus on banking and large-scale transformation projects.
Many years of experience in analyzing, structuring, and implementing business requirements, as well as designing target states in complex IT landscapes.
Strong interface skills between business and IT, with a focus on translating business requirements into workable IT concepts and architectures.
Solid experience in designing and improving end-to-end processes, as well as creating business concepts and decision papers.
Proven project success in the areas of Identity & Access Management (IAM), post-merger integrations, IT infrastructure, and regulatory requirements.
Confident in working with agile methods and artifacts.
Abhiroop Basu
Last position:
Software Engineer III at Foundry Digital
- Developed and deployed microservices in Kotlin and Spring Boot, integrated AWS Secrets Manager to secure credentials and decreased network calls using Spring cache.
- Refactored Kafka consumer using Spring Kafka with semaphore-based backpressure to cap records and keep heap memory stable under spikes; switched to batch upserts to cut down on database invocations; added Testcontainers integration tests for Kafka and database to pave the way for future changes.
- Automated the financial reconciliation workflow in Spring Boot (Kotlin) using Spring Scheduler, transactional boundaries, JPA/Hibernate on MySQL, and Flyway migrations, saving the accounts team 16+ hours per week.
- Designed and dockerized payments end-to-end test framework in Robot (Python) with reusable keyword libraries and profiles; integrated with GitLab CI (JaCoCo XML and HTML reports) to accelerate releases and lift code coverage to 80%.
- Implemented end-to-end observability on Datadog by instrumenting services with Datadog APM, correlating metrics and logs, provisioning dashboards, and creating monitors with burn-rate alerts and anomalies to harden reliability and give stakeholders clear visibility.
Lasya Marella
Last position:
Data Engineer at Carelon Global Solutions (Elevance Health)
- Designed and implemented scalable ETL/ELT pipelines using Python, SQL, dbt, AWS and Informatica to ingest data from sources such as APIs, relational databases, and flat files into Snowflake, reducing pipeline runtime by ~30%.
- Migrated high-volume datasets from on-premises Teradata to Snowflake using AWS services (S3, Glue, Step Functions, IAM), ensuring data consistency and integrity.
- Applied Kimball methodology to design star and snowflake schemas, improving query performance and reducing Snowflake compute costs.
- Implemented automated data quality checks using SQL-based dbt tests and the Great Expectations framework to detect anomalies and enforce data correctness before production loads.
- Orchestrated ETL workflows in Airflow using Python and managed code deployments via Git with CI/CD best practices to increase deployment reliability and maintain pipeline uptime.
- Built interactive Power BI dashboards and curated datasets to enable data-driven decision-making for stakeholders.
- Maintained technical documentation in Confluence for ETL workflows, and led knowledge-sharing sessions for new joiners.
Paul Karnowka
Last position:
Program Manager ā Multi-Project Operational Stabilization (Operational Excellence) at ITDZ - IT Dienstleistungszentrum Berlin
- Overall leadership of multiple strategic operations projects focused on workplace services, SLA framework, access management, certificate management, e-learning, backup & recovery, test management, and capacity management, as well as implementing system monitoring and feasibility studies for a 24x7 operation, partly including ServiceNow implementation
- Development of various ServiceNow operating concepts related to training, permissions, and emergency management as part of a new cloud-hosting initiative for the ServiceNow platform
- Board reporting and leading steering committees within the framework of corporate strategic objectives, as well as establishing new balanced scorecards to measure KPIs for optimization-driven project results
AndrƩ Beran
Last position:
External Attack Surface Assessment & Cybersecurity Readiness Checks at Graydaxe Cybersecurity GmbH
- Conducting cybersecurity readiness checks based on an in-house assessment methodology
- Analyzing the external attack surface using the Graydaxe EASM platform
- Assessing maturity levels and deriving prioritized recommendations for action
Flamur Abdyli
Last position:
Fractional Chief Information Security Officer at VR Smart Guide GmbH
- Enhance and develop the Information Security Management System (ISMS) in compliance with ISO 27001 and TISAX standards by continuously updating and refining the ISMS to align with evolving global standards.
- Ensure that security practices and policies are integrated into all business processes to achieve and maintain certifications.
- Lead the effort to identify, evaluate and mitigate risks across the organization, setting benchmarks for security measures.
- Oversee and refine security processes, with an emphasis on incident management and rapid response by developing and enforcing policies for rapid detection, investigation and remediation of security incidents.
- Train and lead the incident response team to handle breaches effectively, minimizing impact and ensuring swift recovery.
- Implement continuous monitoring solutions to detect and respond to threats in real time.
- Conduct comprehensive security assessments for internal and external IT projects, ensuring adherence to GDPR, DORA and other relevant standards.
- Oversee security evaluations for all IT projects to ensure they comply with legal and regulatory requirements.
- Integrate security measures from the planning phase through deployment to ensure all projects uphold the organizationās security standards.
- Collaborate with project teams to address findings and ensure that security risks are managed effectively.
- Serve as the principal security advisor to the IT department and senior management, offering insights on potential security challenges.
- Facilitate a culture of security awareness throughout the organization through training and regular communication.
- Lead security initiatives that align with the organizationās long-term strategic goals.
- Establish and oversee a robust third-party risk management framework to mitigate external security threats by regularly assessing third-party security practices and compliance and developing contingency plans and mitigation strategies.
- Provide regular updates and security briefings to the executive leadership and relevant committees, highlighting recent security incidents, responses, lessons learned and recommending strategic improvements.
Ottavio Braun
Last position:
Semantic Test Framework for LLMs
Bertrand Rothen
Last position:
Interim IAM Product Owner (Identity Management) at REWE digital GmbH
- Establishing Identity & Directory Management as a new (split-off) team & product within the IAM cluster.
- Leading the āIdentity & Directory Managementā product (8 people) as Product Owner.
- Concept for āDigital Identitiesā, i.e. IDs with n users/accounts and strategy for a modernized product offering.
- Upgrading APIs, migrating to a containerized infrastructure, rolling out international markets & standardized solutions across the REWE enterprise group.
- Tech: OpenText⢠(NetIQ) eDirectory & Identity Manager, LDAP, SAP HR/HCM, Docker/Kubernetes/Podman, REST APIs, Microsoft Active Directory & Entra ID, postgresDB, Keycloak, Ansible, Cyberark (PAM), Apache Kafka, Jira, Confluence, Miro.
Jorge PƩrez SuƔrez
Last position:
Software Engineer ā AWS and Kubernetes Specialist at Citti
- Creation, maintenance and hardening of Kubernetes clusters employing Ansible and ArgoCD
- Keywords: Ansible, AWX, Kubernetes, NetApp, Prometheus, CI/CD ArgoCD, SSO, Fluent-bit, HAProxy, Calico, Keycloak, oauth2-proxy, SealedSecrets, kubeseal, Aqua kube-bench, CIS-Benchmarks, Aqua Trivy operator
AndrƩ Siegmund
Last position:
IT Consultant SAPĀ® Administration at Lechwerke AG (LEW)
- IT services for the administration of the SAPĀ® systems NETZ/Sales, BW, Core, Portal
- Administration of SAPĀ® authorizations and users via central user administration (ZBV) in SAPĀ® Solution Manager
- Setup and further development of SAPĀ® authorization roles
- Role assignment according to requests
- Creation, change, and deletion of users
- Incident handling and error analysis (e.g. authorization trace, debugging in test systems)
- Cooperation with the SAPĀ® development team on new implementations and process changes
- Special tasks
- Execution of Privileged User Management (PUM) 2023ā2025 using Security Bridge
- Decommissioning of the SAPĀ® Core system and migration to S/4HANA
Ali Yazdani
Last position:
Principal Product Security Engineer at Payrails GmbH
- Defined and executed a comprehensive security roadmap: integrated Shift-Left Security, CNAPP, and DevSecOps principles to streamline secure product development and reduce risk exposure.
- Established a robust threat modeling framework: embedded security into design processes, enabling early identification of vulnerabilities and reducing potential risks.
- Developed a scalable Vulnerability Management program: accelerated detection and remediation of new vulnerabilities, significantly shortening the risk response cycle.
- Enhanced cloud and container security: leveraged advanced tools such as Tetragon to achieve deeper visibility and implement a defense-in-depth strategy.
- Automated security controls within CI/CD pipelines: integrated security measures into the development lifecycle to maintain continuous delivery with robust safeguards.
- Championed cross-functional collaboration: partnered with developers and infrastructure teams to prioritize threats and align remediation efforts, fostering a unified security culture.
- Ensured regulatory compliance and audit readiness: collaborated closely with the InfoSec team to adhere to internal policies and successfully support audits for standards like PCI-DSS and SOC2.
Alexander Vitanyi
Last position:
Product Owner at FI-TS
- Rebuilding an existing cloud solution with Kubernetes, Terraform, Ansible, Prometheus, Grafana, GitLab, Argo CD and PostgreSQL
- Coordinating and managing external partners and service providers
- Ensuring service delivery on time and on budget with budget responsibility
- Integrating the cloud solution with external public clouds (AWS)
- Setting up and defining processes and workflows in Jira and Confluence
- Product management of software development for automation and self-service in CI/CD DevOps mode
- Agile software development with Kanban and Scrum in various development teams
- Single point of contact for key customers in respective projects
- Creating and aligning the product backlog with stakeholders from sales, architecture, development teams, marketing, management and customers
- Migrating existing customers to the AWS cloud as product owner
- Creating and aligning a product roadmap with internal and external stakeholders
Tino Truppel
Last position:
Director Technology at Forte Digital Germany
- Leading 20+ staff in development, site reliability engineering, and architecture.
- Leading the group-wide agentic AI initiative (Norway, Poland, Germany).
- Hands-on solution architect and AI consultant for over 50% of my working time on client projects in the publishing sector ā from local publishers to international corporations.
- Strategic consulting and technical implementation of AI workflow platforms (n8n, Workato).
- Developing prototypes for traditional, AI-based, and agentic AI workflows.
Discover over 15,000 top freelancers
Statistics of experts using Identity and Access Management
Aggregated from the professional profiles of matched freelancers.
Experience
18 years (Germany: 19 years)
Position duration
2.5 years (Germany: 2.2 years)
Positions per freelancer
10 (Germany: 13)
Top business areas
Information Technology, Product Development, Project Management
Top industries
Information Technology, Banking and Finance, Automotive
Certification focus areas
Information Technology, Project Management, Audit
Bachelor's degree or higher
86%
Master's degree or higher
43% (Germany: 54%)
Certifications per freelancer
5 (Germany: 4)
Most common languages
English, German, French
Speak two or more languages
97% (Germany: 96%)
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Berlin are distributed, based on recent contracts on our platform. Each bar covers a rate range ā its height shows how many freelancers charge within that range.
Average rates of experts in Berlin using Identity and Access Management
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates ā half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancersā daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
IAM Scope
Identity and Access Management defines who can sign in, what they can reach, and how access changes over time. It covers login, SSO, MFA, roles, consent, provisioning, and deprovisioning. Strong IAM keeps user access simple for the right people and locked down for everyone else.
Common Stack
- SSO with SAML, OAuth 2.0, and OpenID Connect
- MFA, passwordless login, and adaptive access rules
- Directory sync with Active Directory and Entra ID
- Platforms such as Okta, Keycloak, Ping, and Auth0
- API and app integration for web, mobile, and internal tools
Delivery Work
Companies bring in freelance IAM experts for new identity platforms, legacy migration, and access cleanup after growth or restructuring. They also help when login breaks across apps, when roles are too broad, or when audit evidence is missing. In Berlin, this often touches SaaS, media, fintech, and larger enterprise teams with mixed on-site and remote work.
What Good Looks Like
A strong specialist thinks in flows, not only in products. They can map identities across systems, design least-privilege access, and make sign-in clear for users without weakening controls. They also document decisions so security, product, and operations teams can support the setup later.
Typical Tasks
- Design identity architecture and account lifecycle rules
- Set up federation, claims, and application trust
- Tune MFA, recovery, and step-up access paths
- Clean up roles, groups, and permissions
- Support audits, incident reviews, and tenant migrations
When To Hire
Bring in freelance IAM expertise when access is blocking delivery, when an acquisition adds another identity stack, or when compliance work needs clean evidence. It also helps during platform change, because identity mistakes spread fast across every connected system. Good professionals reduce risk without slowing the business down.
Frequently asked questions
Quick answers to the questions that come up most around Identity and Access Management.
Identity and Access Management controls how people and systems sign in, what they can use, and when access should end. It is used for SSO, MFA, role-based access, user provisioning, and secure access to apps, APIs, and cloud services.
IAM is the broader setup; SSO and MFA are only parts of it. SSO simplifies login, and MFA strengthens verification, but IAM also covers identity records, roles, approvals, lifecycle rules, and access governance.
A strong Identity and Access Management freelancer often works with Okta, Microsoft Entra ID, Keycloak, Ping, or Auth0. They also need SAML, OAuth 2.0, OpenID Connect, LDAP, and Active Directory knowledge to connect modern apps and older systems.
You do not need a finished blueprint, but you should know the main systems, user groups, and security goals. IAM work goes better when access problems, app owners, and compliance needs are clear, even if the final design is still open.
Most Identity and Access Management work can be done remotely because it is mostly design, configuration, testing, and review. On-site time in Berlin can help at the start if workshops, stakeholder alignment, or sensitive rollout planning need closer coordination.
A good IAM specialist usually understands cloud platforms, application security, directory services, and basic network or certificate concepts. They should also be comfortable with documentation, access reviews, and working across security, operations, and product teams.
Look for clear examples of identity design, migration work, and troubleshooting across multiple systems. A strong Identity and Access Management professional can explain trade-offs in plain language, show how they handle least privilege, and describe how they test rollback and recovery.
If users cannot log in cleanly, permissions are scattered, or offboarding is unreliable, the IAM setup needs attention. Other warning signs are duplicated identities, manual account handling, broken federation, and audit gaps around who can access sensitive systems.
The average hourly rate of freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects is 110 ā¬, which corresponds to a daily rate of about 883 ⬠based on an 8-hour working day.
Of the freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects, 86% hold at least a Bachelor's degree and 43% hold at least a Master's degree.
On average, freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects have 18 years of professional experience, with a single engagement typically lasting around 2.5 years.
The most common languages among freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects are English (100%), German (94%), and French (18%).
The most common industries among freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects are Information Technology (94%), Banking and Finance (52%), and Automotive (39%).
The most common business areas among freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects are Information Technology (100%), Product Development (76%), and Project Management (64%).
Main locations of FRATCH Experts, who have recently used Identity and Access Management
Our freelancers and interim experts are at home across the DACH region ā available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Hamburg
Munich
Cologne
Frankfurt
Stuttgart
Dusseldorf
Essen
Nuremberg