Kerberos Experts in Germany
in minutes from over 15,000 CVs with the power of AIHire experts who secure Kerberos realms, set up ticket-based single sign-on, and integrate MIT Kerberos with Linux, Windows, and directory services. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Kerberos
Markus Halbedel
Last position:
Senior M365 Consultant at BITMARCK GmbH
Creation of concepts for M365 implementation, especially Tenants, EntraID, EntraConnect and ExchangeOnline, taking BAS standards into account (mandatory baseline security requirements) in the project "Concept M365" with the aim of transferring the concepts to the M365 environments of Bitmarck and then handing them over to the customer.
- Creation of a current-state analysis of the existing M365 environments as well as the on-premises environments and the BAS standards.
- Creation of concepts for the topics Tenants, EntraID, EntraConnect and ExchangeOnline taking the BAS standards into account
- Design and implementation of an automated solution for creating standardized M365 tenants based on Microsoft M365 DSC (Desired State Configuration)
- Transfer of the concepts into the M365 environments
- Creation of detailed technical documentation
Kevin Fischer
Last position:
DevOps and Platform Engineer at DB Systel GmbH
- Error analysis and fixes including performance optimization of the in-house developed platform API
- Change and incident management in day-to-day operations
- Responsible for compliance with security and compliance requirements
- Vendor management for software development and maintenance
- Planning and execution of migration of legacy services to a cloud native platform
Role in the project: project staff, implementation team
Used skills: requirements analysis, IT service and application management, IT operations, error analysis and performance optimization, software maintenance and lifecycle management
Project environment: Cloud Native Platform (Kubernetes, Crossplane, AWS, ArgoCD, Grafana)
Thomas Übermeier
Last position:
Head of Engineering - Midnight at IOG / Midnight
IOG (IOHK), is one of the world's pre-eminent blockchain infrastructure research and engineering companies.
- Converted a lingering R&D project into a cohesive, production-ready testnet; built and scaled the 35-member engineering team (Core, QA, SRE) to achieve this goal.
- Defined strategic direction and aligned technology development with business objectives as a key member of the leadership.
- Optimized software development processes and implemented agile methodologies, enhancing operational efficiency and code security.
- Delivered projects in a fast-paced startup environment through effective project management and resource allocation.
Frank Bergmann
Last position:
System Engineer at Frequentis Comsoft
- Migrate company software to RHEL10
- Development in Bash, Python, C, Ansible
Markus Ickenroth
Last position:
Senior System Engineer Microsoft at Technidata IT-Service GmbH
As part of the project, I was responsible for operating a Citrix farm for 600 users, including optimizing the user experience and ensuring high availability.
I managed and optimized the entire application landscape of a major customer, evaluated and implemented application updates, and ensured the compatibility and security of the software in use.
I managed user accounts, implemented security policies, and monitored system performance.
I administered Azure Entra ID to control identities and access rights, implemented security policies, and synchronized on-premises directories with the cloud.
I implemented and managed Microsoft Intune for central management of client devices, including the configuration and management of BitLocker for disk encryption.
I managed file servers and NTFS permissions to ensure secure and efficient data access management.
I handled change requests and last-level support tickets efficiently to solve complex system issues and improve user satisfaction.
I supported and advised the customer team on various topics and projects, identified areas for improvement, and implemented best practices.
Technologies used:
- Citrix XenApp and XenDesktop
- Microsoft Windows Server 2012R2 and 2022
- Exchange 2016 and Exchange Online
- Entra ID (Azure AD)
- Entra ID Connect
- BitLocker
- PowerShell scripting
- Microsoft Intune
- LDAP (Lightweight Directory Access Protocol)
- DNS services (Domain Name System)
- Active Directory Certificate Services (AD CS)
Qaiser Abbasi
Last position:
Freelance Lead DevOps Engineer at Schwarz Gruppe Produktion
Bootstrapping a CloudOps team and building a multi-cloud provider backend for a low-code Internal Developer Platform (IDP) with env zero
Introducing user story mapping, ADRs, milestones, and backlog management
Designing and developing core APIs, setting up CI/CD pipelines, OpenTofu/Terraform scripts
Representing and communicating the team with third-party stakeholders (e.g. env zero)
(Cross-)team coaching on DevOps, software design, Terraform, Golang, and agile practices
Hichem Blagui
Last position:
IT Security Consultant & Data Engineer / Freelancer at datadefend GmbH
- Analysis and further development of the security architecture.
- Design and development of Splunk apps and technical add-ons (TAs).
- Development and implementation of security use cases in the Splunk SIEM.
- Creation and maintenance of incident response playbooks in Cortex XSOAR.
- Support of technical proof-of-concepts to assess new detection technologies.
- Lifecycle management and operational support for Splunk and Cribl systems.
- Deployment and scaling of Splunk indexers in hybrid data center environments.
- Maintenance, update planning, and optimization of Cribl Stream & Edge for log ingestion and data routing.
- Creation of dashboards and reports to visualize security posture and system availability.
- Technical analysis to assess network topologies and data flows.
- Integration of new data sources via Cribl Stream/Edge and heavy forwarders in cloud and on-prem environments.
- Integration of external security components such as Cortex XSOAR (SOAR) and user behavior analytics (UBA).
- Implementation of complex correlation rules in Splunk Enterprise Security (ES).
- Connection of external ticketing systems via mail gateways and REST APIs.
- Automated deployment of use cases, dashboards, and detection rules via Git and Ansible.
Matthias Schmälzle
Last position:
Subproject Manager / Head of Monitoring at IT service provider (Berlin/Kolbermoor)
- Subproject Manager / Head of Monitoring for facility management and handling operational project parts as well as coordinating operations
- CheckMK consulting: central monitoring infrastructure with CheckMK master and distributed CheckMK satellites
- Implementation of advanced monitoring approaches, integration of new plugins and customization of the CheckMK agent
- Graphic representation of performance metrics with InfluxDB and Grafana, creation of NagVis/Grafana templates and dashboards
- Monitoring of Linux/UNIX/Windows systems and active components using CheckMK agents/MRPE as well as hardware monitoring via SNMP
- Development of monitoring plugins based on Bash scripting
- Inventory and cross-disciplinary analysis for application-specific monitoring
- Concept design, testing and documentation for integrating CheckMK status messages and performance data into a higher-level umbrella system (Data Leak)
- Technical and conceptual point of contact
Nikhil Gyamlani
Last position:
Co-founder / Solution Architect at Lima Care GmbH
- Developed a comprehensive business concept for a medical fall detection device based on a patented process registered in Germany
- Identified and collected use cases for medical device deployment in residential buildings and healthcare provider facilities
- Expanded the product scope to industry standards such as HL7/FHIR and designed a product based on modern communication protocols for IIoT
- Supported offshoring activities, defined SLA and scope-of-work documents for development teams after selecting various vendors
- Identified and selected hardware components (Terrabee, E-Con Systems) for LIDAR/TDOA functions
- Defined integrated AI features and LLM models for patient fall detection as well as AI-based audio triggers
- Oversaw the implementation of algorithms for object detection, fall detection, and false alarm identification
Rupesh Kumar Sendge
Last position:
IT Baseline Compliance Consultant at Consultant
- Baseline compliance verification against MAS audit findings
- Building technical architecture concept for 30 technologies to build hardening standard artifacts
- Identifying and building automation possibilities for given technologies based on CIS
- Building the standard baseline configuration based on internal security standard
- Responsible for building Cloud Native Application Protection Platform (CNAPP) architecture artifacts based on Azure cloud platform
- Responsible for RFQ and RFP for different CNAPP solutions (Qualys Total Cloud, CrowdStrike, Azure Security Center)
- Supporting compliance verification and validation via automated scripts for a sample population of IT devices and instances
- Responsible for complete vulnerability management lifecycle using Nexpose, remediation, reporting and integration of results with Splunk, HPSM and Tableau
- Audit support for MAS
Matthias Weigel
Last position:
Self-employed at maweos GmbH
Mohamad Alosman
Last position:
Systems Engineer for Network Security at Bechtle AG
- SD-WAN solution by Aruba – Swiss energy company (330 sites): design and implementation of an SD-WAN branch solution with Aruba 9004 gateways, encrypted overlay, policy-based routing, WAN load balancing, and centralized management via Aruba Central.
- LAN/WLAN & security – schools in Germany (9 sites): deployment of Aruba switches & AP-505, FortiGate 80F firewalls; setup of Checkmk monitoring, incident and change management, and secure admin access (BeyondTrust).
- Multi-site security – energy billing company (20 sites): deployment of a complete Fortinet solution (FortiGate HA cluster, FortiSwitch PoE, FortiAP), IPsec remote-access VPN via FortiClient, centralized management via FortiCloud, IntraID authentication, operations and incident management.
- Data center migration – German client: migration of data center switches (Mellanox), firewall cluster, and OfficeConnect switches to a new data center; securing configurations, implementing HA designs, testing, monitoring, and coordinated change and incident processes. Setup of two new 6300 M VSX clustered switches.
- Data center security – university hospital: implementation of a high-availability FortiGate 400F firewall cluster across three data centers; security policy design, operational support, and change/incident management.
- Enterprise campus & network access control – manufacturing company in Germany: introduction of Aruba ClearPass NAC, setup of a VSX-based switching architecture, secure WLAN access with MPSK, and integration into existing networks.
- EU client (Germany & Poland) – Sophos firewalls: operations, incident and change management of Sophos firewalls including IPsec VPN; troubleshooting and ongoing optimization of security configurations.
- Network modernization – pharmacy client in Germany: design and rollout of core and access switching (Mellanox, Aruba Instant On), migration from Sophos to Fortinet firewalls, network segmentation, and security hardening.
Martin Frlička
Last position:
IT Security Consultant at Freelance
Marcus Wiederstein
Last position:
Administrator, DevOps at KZVB
- Planned and implemented new network infrastructure (VLAN, LACP, DMZ, structured cabling)
- Migrated from VMware to KVM using Oracle Linux Virtualization Manager (OLVM), including CPU pinning
- Hardened the entire environment using SELinux (KVM hosts, container hosts, database servers)
- Configured and operated the virtualization platform with OLVM and Ansible-based provisioning
- Containerized and redeployed critical services: WordPress, Jenkins, PostgreSQL, MariaDB, Subversion with Apache + AD integration
- Developed Ansible playbooks for automated deployment and configuration management
- Integrated Foreman for repository and security management in the DMZ
- Produced technical documentation in Markdown; organized in Bookstack
- Coordinated with external vendors (e.g. HPE) for hardware installation and setup
- Delivered all contributions documented and reproducible in Markdown
Rick Grassmann
Last position:
Interim IT Security Analyst at GLS IT Services GmbH
- Risk Management
- Incident Management
- Security Analysis
- Secure Coding
- Information Security Management System (ISMS)
Discover over 15,000 top freelancers
Statistics of experts using Kerberos
Aggregated from the professional profiles of matched freelancers.
Experience
19 years
Position duration
2.7 years
Positions per freelancer
14
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Banking and Finance, Manufacturing
Certification focus areas
Information Technology, Project Management, Product Development
Bachelor's degree or higher
93%
Master's degree or higher
60%
Doctorate
7%
Certifications per freelancer
5
Most common languages
German, English, Arabic
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Kerberos
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Kerberos basics
Kerberos is a network authentication protocol for proving identity without sending passwords across the wire. It uses tickets and a trusted key distribution center, often called a KDC, to let users and services trust each other across a domain or realm.
What it powers
Companies use Kerberos for single sign-on, internal access control, and secure service-to-service authentication. It shows up in Unix and Linux estates, Active Directory environments, and mixed setups where many systems need one login flow.
Typical work
- Design realms, principals, and keytabs
- Connect services to LDAP, Active Directory, or FreeIPA
- Fix ticket lifetimes, clock skew, and encryption settings
- Harden authentication flows for servers, clusters, and remote access
Tools and ecosystem
Strong specialists know MIT Kerberos, Heimdal, krb5 tools, and the surrounding identity stack. They work with DNS, time sync, PAM, GSSAPI, SPNEGO, SSSD, and service accounts because Kerberos rarely lives alone.
When to bring in help
Teams bring in freelance expertise when logins fail across domains, a migration breaks service tickets, or a new platform must join an existing realm. In Germany, this often helps with hybrid infrastructure, enterprise directory projects, and multilingual collaboration between local IT and remote teams.
What strong specialists do
A strong Kerberos specialist reads traces, checks tickets, and follows trust paths end to end. They document principal naming, key rotation, and delegation rules clearly, then leave the setup stable enough for day-two operations and future audits.
Frequently asked questions
Everything clients usually want to know about Kerberos, in one place.
Kerberos is used for secure authentication, especially single sign-on across many internal systems. It lets users prove identity with tickets instead of sending passwords to every service. That makes it a common fit for directory-backed enterprise access and service authentication.
Kerberos handles authentication at the protocol level, while LDAP is usually a directory and SAML or OAuth are federation and authorization patterns. In practice, Kerberos often works underneath the login experience, while SAML and OAuth connect users to external apps. A good specialist knows where each one belongs.
A Kerberos specialist is useful when ticketing stops working, a realm trust needs to be built, or Linux and Windows systems must share one identity flow. They also help during migrations, keytab fixes, and service onboarding. If authentication touches many systems, bring in someone experienced early.
A strong Kerberos freelancer usually also knows Active Directory, LDAP, DNS, time synchronization, and Linux security basics. SSSD, PAM, GSSAPI, and SPNEGO matter too because they shape how authentication behaves on real systems. Without those skills, a setup can look correct but still fail in production.
MIT Kerberos is a widely used implementation of the Kerberos protocol, not a different authentication model. You may also see krb5 in tools, package names, and configuration paths. When hiring, it helps to know whether the project needs protocol design, MIT Kerberos administration, or both.
A simple Kerberos integration may need only focused implementation work, but cross-domain trust, mixed operating systems, or custom service authentication calls for deeper experience. The hard part is often not the first login, but the edge cases around clock skew, delegation, and encryption settings. Look for someone who has solved those before.
Kerberos projects can often be handled remotely if the specialist has secure access to logs, configs, and test environments. On-site time can help when teams need to map an old identity landscape or coordinate with local infrastructure staff in Germany. The key is fast access to the right systems, not physical presence.
A good Kerberos specialist explains the realm design, principal naming, trust relationships, and ticket flow in plain language. They should be able to debug failures from logs and traces, not just edit configuration files. Ask for examples that involve service tickets, keytabs, and real production incidents.
The average hourly rate of freelancers in Germany who have used Kerberos in their recent projects is 106 €, which corresponds to a daily rate of about 844 € based on an 8-hour working day.
Of the freelancers in Germany who have used Kerberos in their recent projects, 93% hold at least a Bachelor's degree, 60% hold at least a Master's degree, and 7% hold a doctorate.
On average, freelancers in Germany who have used Kerberos in their recent projects have 19 years of professional experience, with a single engagement typically lasting around 2.7 years.
The most common languages among freelancers in Germany who have used Kerberos in their recent projects are German (100%), English (100%), and Arabic (8%).
The most common industries among freelancers in Germany who have used Kerberos in their recent projects are Information Technology (96%), Banking and Finance (50%), and Manufacturing (46%).
The most common business areas among freelancers in Germany who have used Kerberos in their recent projects are Information Technology (100%), Operations (77%), and Project Management (62%).
Main locations of FRATCH Experts, who have recently used Kerberos
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
