
Identity and Access Management Experts in Berlin
for secure access, matched in minutes with AIHire experts who design identity flows, configure SSO and MFA, and connect directories with cloud applications. FRATCH matches you quickly and precisely with vetted, available freelance professionals suited to your project.
Meet FRATCH Experts in Berlin, who have recently used Identity and Access Management
Paul K.
Last position:
Program Manager – Multi-Project Operational Stabilization (Operational Excellence) at ITDZ - IT Service Center Berlin
- Overall leadership of several strategic operations projects focusing on Workplace Services, SLA Framework, access management, certificate management, e-learning, backup & recovery, test management, and capacity management, as well as the introduction of system monitoring and feasibility studies for 24x7 operations, in some cases including implementation in ServiceNow
- Creation of various ServiceNow operating concepts covering training, access rights, and emergency management as part of a new cloud hosting initiative for the ServiceNow platform
- Executive board reports and leadership of steering committees as part of company-wide strategic objectives, as well as the establishment of new balanced scorecards for measuring KPIs related to optimization-driven project results
Julius H.
Last position:
Freelancer at Freelancer — Pharma Industry
- Led migration to GCP using Terraform, GKE, and GitOps, improving deployment consistency and scalability
- Implemented Datadog observability stack via Terraform and datadog-operator
- Established automated end-to-end tests and on-call processes, improving incident response and service reliability
- Migrated from NGINX Ingress Controller to Kubernetes Gateway API (NGINX Gateway Fabric)
- Migrated stateful services (PostgreSQL and Redis) to GCP, improving scalability and operational reliability
Jorge P.
Last position:
Software Engineer – AWS and Kubernetes Specialist at Citti
- Creation, maintenance and hardening of Kubernetes clusters employing Ansible and ArgoCD
- Keywords: Ansible, AWX, Kubernetes, NetApp, Prometheus, CI/CD ArgoCD, SSO, Fluent-bit, HAProxy, Calico, Keycloak, oauth2-proxy, SealedSecrets, kubeseal, Aqua kube-bench, CIS-Benchmarks, Aqua Trivy operator
Deepak M.
Last position:
Lead ML Platform Engineer at Billie GmbH
- Mentor team of 6 ML platform engineers through weekly 1:1s, technical design reviews, and best practices, improving team velocity by 35% through structured sprint planning and skill development programs
- Define 2025–2026 ML platform roadmap in collaboration with Data Science, Cloud Engineering, and Product teams, prioritizing automated model governance, cost attribution systems, and multi-environment deployment strategies
- Partner with Data Science, SRE, and Product stakeholders to align ML platform capabilities with business objectives, reducing data scientist deployment friction by 60% through self-service platforms
- Architect and deliver production-grade MLOps platform supporting 50+ models in production with automated promotion pipelines, versioning, and rollback capabilities, achieving 99.5% platform uptime SLA
- Design distributed ML pipeline architecture using Metaflow and Argo Workflows (Vertex Pipelines-compatible), reducing model training time by 30% and deployment cycles from 2 weeks to 3 days through full CI/CD automation
- Build containerized ML services on Kubernetes with auto-scaling policies, resource quotas, and multi-tenancy isolation, optimizing infrastructure costs by $180K annually (25% reduction)
- Implement monitoring, alerting, and performance tracking using Prometheus, Grafana, and custom instrumentation, reducing model debugging time by 50% and establishing model performance SLOs
- Lead development of RAG-based document intelligence platform using LangChain, LangGraph, and vector databases, implementing agentic AI workflows for automated financial document processing
- Implement Infrastructure-as-Code using Terraform for reproducible environment provisioning and GitOps workflows, reducing infrastructure drift incidents by 80%
- Design role-based access control for ML platform, implement model lineage tracking, and establish audit trails for regulatory compliance aligned with enterprise IAM best practices
Gor O.
Last position:
Senior IT Transformation Consultant and Business Analyst at Self-employed Consultant
Senior IT Transformation Consultant and Business Analyst with a focus on banking and large-scale transformation projects.
Many years of experience in analyzing, structuring, and implementing business requirements, as well as designing target states in complex IT landscapes.
Strong interface skills between business and IT, with a focus on translating business requirements into workable IT concepts and architectures.
Solid experience in designing and improving end-to-end processes, as well as creating business concepts and decision papers.
Proven project success in the areas of Identity & Access Management (IAM), post-merger integrations, IT infrastructure, and regulatory requirements.
Confident in working with agile methods and artifacts.
Giovanni L.
Last position:
Solution Architect at Nordea Bank
Consumer Cards Solution Architect
- Provided architectural leadership in Consumer Cards Domain establishing best practices and improving architectural transparency and maintainability by designing a structured documentation framework to enable reverse engineering of legacy card systems.
- Standardized architectural artefacts including BIAN Business Capabilities, UML diagrams in draw.io format (Use Case, Component, Sequence), naming conventions, document repository, design templates and blueprints, microservices.
- Produced high-level and low-level designs aligned with enterprise architecture governance processes and artefact standards.
- Provided architectural support to the Strategic Card Simplification Programme, focusing on card product migrations and application decommissioning across all countries. Agile environments (Scrum/SAFe).
- Analysed and designed AI use cases in the architecture domain.
Project: Payment Card Industry Data Security Standards (PCI DSS) Strategic Programme
- Analysed and documented existing data flows across card products and geographic regions to assess PCI DSS compliance.
- Identified areas involving sensitive data at rest and data in motion requiring encryption or masking, ensuring adherence to PCI DSS requirements.
- Collaborated with security, infrastructure, and application teams to align encryption strategies with regulatory and organizational policies.
- Provided strategic advisory services on data strategy, data governance, data management, data quality, data architecture, data mesh, MEGA HOPEX, DAMA-DMBOK, event-driven architecture, end-to-end data flows and card product harmonization models.
- Ensured solution design alignment with regulatory compliance (BCBS 239, DORA, GDPR) and internal policies.
Project: Denmark ATM Outsourcing Project
Objective: Outsource ATM operations and maintenance to a third-party provider while expanding the Denmark ATM fleet, with Nordea retaining ownership of ATMs and cash for the existing and extended infrastructure.
- Led a cross-functional delivery team (project management, business analysis, and architecture) and documented the as-is ATM ecosystem architecture, including end-to-end data flows, integrations, and internal/external application interfaces.
- Designed end-to-end processes for authorization, reconciliation, and settlement, aligning operating model, controls, and compliance requirements across Nordea and the outsourced service provider.
- Produced high-level and low-level solution designs using standardized UML artefacts (Use Case, Component, and Sequence diagrams) to support vendor onboarding, integration planning, and implementation.
- Ensured architectural alignment and decision-making across enterprise stakeholders and third-party providers, managing dependencies and interfaces in the context of the outsourcing initiative.
Marina K.
Last position:
Independent Software Developer at LILARAUM
- Independently designed, developed, published, and maintained mobile games for iOS and Android.
- Implemented application architecture, gameplay systems, UI, monetization, analytics, and platform integrations.
- Managed the complete release lifecycle, including testing, store publication, production monitoring, and iterative improvements based on analytics.
Abhiroop B.
Last position:
Software Engineer III at Foundry Digital
- Developed and deployed microservices in Kotlin and Spring Boot, integrated AWS Secrets Manager to secure credentials and decreased network calls using Spring cache.
- Refactored Kafka consumer using Spring Kafka with semaphore-based backpressure to cap records and keep heap memory stable under spikes; switched to batch upserts to cut down on database invocations; added Testcontainers integration tests for Kafka and database to pave the way for future changes.
- Automated the financial reconciliation workflow in Spring Boot (Kotlin) using Spring Scheduler, transactional boundaries, JPA/Hibernate on MySQL, and Flyway migrations, saving the accounts team 16+ hours per week.
- Designed and dockerized payments end-to-end test framework in Robot (Python) with reusable keyword libraries and profiles; integrated with GitLab CI (JaCoCo XML and HTML reports) to accelerate releases and lift code coverage to 80%.
- Implemented end-to-end observability on Datadog by instrumenting services with Datadog APM, correlating metrics and logs, provisioning dashboards, and creating monitors with burn-rate alerts and anomalies to harden reliability and give stakeholders clear visibility.
Bert W.
Last position:
IT Consultant, Program / Project Manager, IT Architect at Self-Employed
- Consulting and project management in IT projects
- Data and process analytics, evaluation, reporting, optimization, dashboards
- Program leadership, project leadership
- Strategic consulting
- Rollout, cutover (design, automation, planning)
- IT infrastructure, IT system architecture, ITIL
- Process and application management
- ITSM, IT security, data protection, IAM
- BPNM
- MDM
André S.
Last position:
IT Consultant SAP® Administration at Lechwerke AG (LEW)
- IT services for the administration of the SAP® systems NETZ/Sales, BW, Core, Portal
- Administration of SAP® authorizations and users via central user administration (ZBV) in SAP® Solution Manager
- Setup and further development of SAP® authorization roles
- Role assignment according to requests
- Creation, change, and deletion of users
- Incident handling and error analysis (e.g. authorization trace, debugging in test systems)
- Cooperation with the SAP® development team on new implementations and process changes
- Special tasks
- Execution of Privileged User Management (PUM) 2023–2025 using Security Bridge
- Decommissioning of the SAP® Core system and migration to S/4HANA
Daniel B.
Last position:
Senior Cloud Consultant and Developer at SDIA/Leitmotiv
- Consulting an NGO in the field of data center sustainability in publicly funded projects (BMUKN with NADIKI and Umweltbundesamt with SIEC)
- Development of Python APIs and web applications, deployment on AWS/ECS with Terraform
- Collecting power consumption metrics for servers, CPUs, GPUs running AI workloads
- Technologies used: AWS, EC2, ECS, Fargate, CloudMap, VPC, Route53, Lambda, EventBridge, CodeBuild/CodePipeline/CodeDeploy, Terraform, Docker, Linux, Bash scripting, Python, Flask, SQLAlchemy, SQL, MariaDB, InfluxDB, Telegraf, Prometheus, Zabbix, Kubernetes, Letsencrypt, certificate management
André B.
Last position:
External Attack Surface Assessment & Cybersecurity Readiness Checks at Graydaxe Cybersecurity GmbH
- Conducting cybersecurity readiness checks based on an in-house assessment methodology
- Analyzing the external attack surface using the Graydaxe EASM platform
- Assessing maturity levels and deriving prioritized recommendations for action
Unnikuttan V.
Last position:
Managing Director (Co-Founder) at AathmaSignals
- Spearheading investor outreach and partnership development as founding MD, building the business case and technical narrative needed to attract initial funding and strategic collaborators in the digital health space
- Designing multi-agent AI systems for autonomous biosignal analysis, orchestrating LLM-based reasoning pipelines with domain-specific medical context to enable intelligent, clinical decision support
Flamur A.
Last position:
Fractional Chief Information Security Officer at VR Smart Guide GmbH
- Enhance and develop the Information Security Management System (ISMS) in compliance with ISO 27001 and TISAX standards by continuously updating and refining the ISMS to align with evolving global standards.
- Ensure that security practices and policies are integrated into all business processes to achieve and maintain certifications.
- Lead the effort to identify, evaluate and mitigate risks across the organization, setting benchmarks for security measures.
- Oversee and refine security processes, with an emphasis on incident management and rapid response by developing and enforcing policies for rapid detection, investigation and remediation of security incidents.
- Train and lead the incident response team to handle breaches effectively, minimizing impact and ensuring swift recovery.
- Implement continuous monitoring solutions to detect and respond to threats in real time.
- Conduct comprehensive security assessments for internal and external IT projects, ensuring adherence to GDPR, DORA and other relevant standards.
- Oversee security evaluations for all IT projects to ensure they comply with legal and regulatory requirements.
- Integrate security measures from the planning phase through deployment to ensure all projects uphold the organization’s security standards.
- Collaborate with project teams to address findings and ensure that security risks are managed effectively.
- Serve as the principal security advisor to the IT department and senior management, offering insights on potential security challenges.
- Facilitate a culture of security awareness throughout the organization through training and regular communication.
- Lead security initiatives that align with the organization’s long-term strategic goals.
- Establish and oversee a robust third-party risk management framework to mitigate external security threats by regularly assessing third-party security practices and compliance and developing contingency plans and mitigation strategies.
- Provide regular updates and security briefings to the executive leadership and relevant committees, highlighting recent security incidents, responses, lessons learned and recommending strategic improvements.
Karthikeyan R.
Last position:
Full-Stack Developer — Own Product at Self-employed
Java 21 · Spring Boot 3 · Keycloak · PostgreSQL · Docker · Nginx · GitHub Actions · DigitalOcean · React 18 · TypeScript · Plasmo
- Architected and shipped a production-ready Job Application Tracker end-to-end: REST API with 5-stage workflow, pagination, sorting, and dynamic filtering — full ownership from design to live cloud deployment on DigitalOcean.
- Implemented production-grade identity management: OAuth 2.0 / OpenID Connect / JWT / RBAC via Keycloak, applying Hexagonal Architecture and DDD principles.
- Built automated CI/CD pipeline (GitHub Actions); containerised with Docker; Nginx reverse proxy with path-based routing and SSL termination.
- Developed a Chrome Extension (Plasmo framework, Manifest V3) that auto-fills job applications directly from LinkedIn into the tracker — demonstrates full product thinking across backend API and browser client.
Discover over 15,000 top freelancers
Statistics of experts using Identity and Access Management
Aggregated from the professional profiles of matched freelancers.
Experience
20 years

Position duration
2.6 years (Germany: 2.2 years)

Positions per freelancer
10 (Germany: 14)

Top business areas
Information Technology, Product Development, Project Management

Top industries
Information Technology, Banking and Finance, Professional Services

Certification focus areas
Information Technology, Project Management, Product Development
Bachelor's degree or higher
86% (Germany: 85%)
Master's degree or higher
47% (Germany: 52%)

Certifications per freelancer
4

Most common languages
English, German, French

Speak two or more languages
98% (Germany: 96%)
Based on our profile pool as of 19 Sep 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Berlin are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Berlin using Identity and Access Management
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 19 Sep 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
Identity and Access Management experts industry focus
See which industries our matched freelancers work in most often — every figure is calculated live from the freelancers on FRATCH.
- Information Technology (93%)
- Banking and Finance (53%)
- Professional Services (37%)
- Automotive (35%)
- Retail (28%)
- Manufacturing (26%)
- Media and Entertainment (26%)
- Telecommunication (26%)
Please note that freelancers can work across multiple industries, so percentages overlap.
About the technology
Identity foundations
Identity and Access Management, commonly called IAM, controls who can access which systems, applications and data. It covers authentication, authorization, account lifecycle management and access reviews. Companies use it to create consistent sign-in experiences while reducing excessive permissions and unmanaged accounts.
Access use cases
IAM supports workforce, customer and machine identities across hybrid environments. Typical project goals include:
- Single sign-on for cloud and internal applications
- Multi-factor authentication and passwordless access
- Automated joiner, mover and leaver workflows
- Role-based and attribute-based access control
- Privileged access and service account governance
Ecosystem and tooling
Professionals work with directories such as Microsoft Entra ID and Active Directory, and with platforms including Okta, Ping Identity, Keycloak and Auth0. They connect applications through SAML, OAuth 2.0, OpenID Connect and SCIM. Strong knowledge of APIs, scripting, cloud identity, logging and policy design helps turn separate tools into a manageable access model.
When expertise matters
Companies often bring in freelance IAM expertise during cloud migrations, mergers, audits, application launches or directory modernisation. Warning signs include manual account creation, shared accounts, inconsistent permissions, repeated access requests and unclear ownership of identities. In Berlin, specialists may support distributed teams remotely or work on site with security, infrastructure and application groups.
What strong experts deliver
A capable specialist begins with the business roles, data flows and risk boundaries rather than configuring a product in isolation. They document the target architecture, map permissions, define approval paths and plan migration without disrupting users. They also test recovery, monitor sign-in events and leave clear runbooks for internal teams.
Secure, usable access
Effective IAM balances protection with daily usability. Good professionals make policies enforceable, explain trade-offs clearly and measure whether access remains appropriate as teams and systems change. They consider language and collaboration needs when working with Berlin-based stakeholders, and they can coordinate securely with remote teams across time zones.
Frequently asked questions
Quick answers to the questions that come up most around Identity and Access Management.
Identity and Access Management controls digital identities and their access to applications, infrastructure and data. An IAM specialist can implement single sign-on, MFA, lifecycle automation, access reviews and privileged access controls for workforce, customer or machine identities.
IAM includes directory services but goes further by governing authentication, authorization, federation, lifecycle processes and access policies across many systems. A directory may store accounts, while IAM connects those accounts to business roles, applications and security controls.
Identity and Access Management work benefits from skills in cloud platforms, network security, API integration, scripting, compliance controls and incident response. Familiarity with Microsoft Entra ID, Active Directory, Okta, Keycloak, SAML, OAuth 2.0, OpenID Connect and SCIM is often valuable.
The right IAM experience depends on scope and risk. A focused SSO integration may need a specialist familiar with the target applications, while a directory migration or enterprise access model requires proven planning, testing, stakeholder coordination and rollback practices.
Identity and Access Management projects often work well remotely because configuration, documentation and workshops can be handled securely online. On-site sessions may help with sensitive discovery or stakeholder alignment, while Berlin teams should clarify working hours, German or English language needs and access procedures upfront.
A company should consider an IAM freelancer when access is managed manually, cloud systems are expanding, a merger changes identity sources or an audit exposes weak controls. External expertise can provide focused delivery without requiring a permanent internal role for a time-bound transformation.
Ask an Identity and Access Management expert to explain a comparable access model, including identity sources, role design, exceptions, testing and recovery. Look for clear documentation, least-privilege thinking, secure change management and the ability to explain technical risks to business stakeholders.
An IAM freelancer should confirm the systems in scope, identity populations, current directory structure, authentication methods, ownership of roles and required integrations. They should also clarify success criteria, production access rules, data handling, change windows and how internal teams will operate the solution afterward.
The average hourly rate of freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects is 108 €, which corresponds to a daily rate of about 864 € based on an 8-hour working day.
Of the freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects, 86% hold at least a Bachelor's degree and 47% hold at least a Master's degree.
On average, freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 2.6 years.
The most common languages among freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects are English (100%), German (93%), and French (16%).
The most common industries among freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects are Information Technology (93%), Banking and Finance (53%), and Professional Services (37%).
The most common business areas among freelancers in Berlin, Germany who have used Identity and Access Management in their recent projects are Information Technology (100%), Product Development (77%), and Project Management (65%).
Main locations of FRATCH Experts, who have recently used Identity and Access Management
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Hamburg
Munich
Cologne
Frankfurt
Stuttgart
Dusseldorf
Essen
Nuremberg