Mend (WhiteSource) Experts in Germany
in minutes with vetted specialists and fast AI matching.Hire experts who keep open-source risk under control, tune dependency policies, and support secure release workflows with Mend, WhiteSource, and Mend.io. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Mend (WhiteSource)
Tan Pham
Last position:
DevOps Engineer in the DevOps Team at Rise-World
- Implementation of specified DevOps solutions to automate infrastructure (Terraform, Bicep, CloudFormation, Ansible) on-premises datacenter (Ovirt, Proxmox, Ceph Cluster, MinIO) and private cloud.
- Administration, configuration and implementation of CI/CD DevOps pipelines (GitLab, GitFlow) to support development process (Artifactory, Prometheus, Istio, service mesh, Helm Chart, OpenShift (Red Hat Enterprise) / Kubernetes cluster), Red Hat Satellite.
- Administration, setup, monitoring and patching of Linux infrastructure based on Red Hat Enterprise for Dev, Test and QA.
- Use of Scrum and Kanban methods.
- Administration, configuration and implementation of security standards for deploying on Dev, Test, QA and Prod stages of the new ePA applications.
- Development of new plugins and add-ons needed on current infrastructure.
- Database support.
- Data analytics support (Python, Spark, Pandas, Power BI, Splunk Enterprise).
- Implementation of best practices for DevSecOps and BizDevOps using GitOps (ArgoCD), Streamlit framework, Semaphore Ansible UI.
- Configuration and testing of iperf, uperf, sysbench using benchmark-operator for external source data and IoT/MDM devices, creating reports via ELK / OpenSearch.
- Building a new Databricks platform to collect and analyze big data from different sources and IoT devices into Hadoop framework (Python, Pandas, PySpark, Power BI, Apache Airflow).
- Building backend data aggregation and processing to automate configuration deployment between different OpenShift clusters and big data framework (Python, Pandas, PySpark, Apache Spark, PostgreSQL, Django 2, Ansible Automation, Jira JSM).
- Building a new ML pipeline platform using Kubeflow, TensorFlow, KServe.
- Data extraction, transformation and loading from different data sources including structured and unstructured data to analytic DWH / big data cluster using Python, Pandas, Polars, Power BI, Django backend and PostgreSQL.
- Setup of new DevOps Test and QA HashiCorp Vault cluster for PKI and IAM.
- Configuration and testing of automated patching based on CVSS score, SIEM-integrated CVEs.
- Use of Nexpose and InsightVM to scan vulnerability events in network, host, container and application.
- Design and implementation of secure and scalable AWS architectures including VPC, EC2, S3, RDS and Route53 and similar setups on Azure and GCP.
- Automated system provisioning and deployment using CloudFormation templates.
- Configuration of IAM roles, policies and permissions to ensure secure access control.
- Patch management, backup automation and disaster recovery setup on AWS infrastructure.
- Monitoring and optimization of system performance using AWS CloudWatch and AWS Trusted Advisor.
- Support of VMware services (vSphere, Aria, Horizon) and the virtual desktop environment.
- Development and maintenance of CI/CD pipelines using Jenkins, GitLab CI/CD and AWS CodePipeline with interface to Nutanix.
- Configuration of AWS CloudWatch to monitor application performance and system events.
- Planning and execution of migration of on-premises applications to AWS cloud platforms.
- Deployment of containerized applications using Docker and Kubernetes in AWS environments.
- Deployment of internal software packages between availability zones using AWS CodeDeploy.
- Building and deploying ML models using Scikit-learn, XGBoost and Spark MLlib including hyperparameter tuning, model evaluation and production deployment.
Jochen Hinrichsen
Last position:
DevSecOps Expert at DB InfraGO
- Central build and delivery for 20+ applications, 100+ pipelines/day, 700+ GitLab projects
- Build pipelines for Go, Java and JavaScript
- Provisioning of 100+ components
- Quality assurance via GitLab Code Quality and SonarQube
- Checks for dependencies, licensing and vulnerabilities
- Release creation via Jira and ServiceNow
- SBOM, Supply Chain Security, distroless images
- PoC GitLab Runner: Nomad vs. Kubernetes
- Technologies: Artifactory, buildah, GitLab Premium, Go, Gradle, Jenkins, Mend, Podman
Michael Yaco
Last position:
Senior Consultant, Senior DevOps Engineer at DB Regio AG
- Supported implementation and operation of a portal used online and offline in customer-facing vehicles
- Automated processes by introducing CI/CD pipelines
- Provided enablement and methodological guidance for adopting software engineering best practices
- System environment: NestJS, Node.js, npm, AWS, Docker, Docker Swarm, GitLab CI, WhiteSource, PostgreSQL, Prometheus, Grafana, OpenSearch, REST API
Ulrich Cech
Last position:
Java Architect/Developer – Freelancer at DHL/DP – Rentenservice
Implementation of a Java service (daemon) as part of the automated processing of death notifications
Technologies used: Java17, SpringBoot, Hexagonal Architecture, REST API, Oracle, Maven, SonarQube, FindBugs, Checkstyle
Nils Klawitter
Last position:
Vulnerability Management and Secure SDLC at DB InfraGO AG
- Successfully implemented vulnerability management with DefectDojo
- Advised on and implemented technical and procedural aspects of vulnerability management with DefectDojo
- Provided guidance on implementing a secure software development lifecycle
- Skills: GitLab, DefectDojo, Vulnerability Management, SCA, SAST, DAST, Python, Kubernetes, Argo CD, Docker, AWS, Azure, WhiteSource/Mend, Greenbone
Anton Klonov
Last position:
Head of Technical Overall Integration NSC / Hadoop Cloud Development at IABG
Head of technical overall integration NSC (National Secure Cloud project with about 60 employees).
Technical integration of all subprojects into one product, definition of interfaces, basic components of a cloud including hardware, technical architecture of the IABG base.
Development of a Cloud Management Platform (CMP) that can create a private/mixed cloud of any complexity based on a textual description with one click or interactively.
CMP also includes the complete hardware management cycle.
As a foundation, it uses Kubernetes, OpenStack, and Hadoop.
The management layer includes Harbor, Gitea, Longhorn, Keycloak, Rancher and Jenkins, which are automatically configured.
The private cloud can run any customer workloads, including a full Hadoop stack with HDFS, Spark, MapReduce, Mesos, HBase and around 20 other ML/DL technologies.
Hadoop worker clusters can also be automatically installed on bare metal or commodity hardware without Kubernetes.
OpenStack with Nova, Neutron, Ironic, Swift, Cinder, Ceph.
Development of a Java application Rudi: SOAP, REST, containers, database.
Technologies: Kubernetes (K3s, RKE2, Minikube, Harbor, Gitea, Jenkins, Longhorn, Keycloak, Rancher), OpenStack (Nova, Neutron, Keystone, Swift, Ceph, Cinder, Sahara, Magnum, Kayobe, Kolla, Bigrost, Ironic), Hadoop (HDFS, Ambari, Solr, Livy, Ranger, YARN, Tez, HBase, Kafka, Hive, Zookeeper, MapReduce, Spark, Oozie, Flink), virtualization (Kubernetes (K3s), VMware, Oracle), scripting (Ansible, Puppet, Juju, Shell, Groovy, Gradle, Maven).
Jamal Baydoun
Last position:
Freelance Software Architect & Developer at IBM Deutschland GmbH / BWI GmbH
- Architecture, design and further development of a hybrid solution consisting of a Java backend with REST API and C# / WPF frontend
- Development of secure, distributed functions for classified message processing, categorization and encryption
- Integration of backend services with document management systems (DMS) for structured file storage
- Planning, setup and continuous optimization of Azure DevOps pipelines for automated deployment and quality assurance of distributed applications in a security-critical environment
- Technical coordination with Bundeswehr project managers and third-party providers of relevant software and interfaces, and documentation of the developed solutions
Discover over 15,000 top freelancers
Statistics of experts using Mend (WhiteSource)
Aggregated from the professional profiles of matched freelancers.
Experience
25 years
Position duration
2.1 years
Positions per freelancer
24
Top business areas
Information Technology, Product Development, Quality Assurance
Top industries
Information Technology, Banking and Finance, Transportation
Certification focus areas
Information Technology, Product Development, Business Intelligence
Bachelor's degree or higher
100%
Master's degree or higher
71%
Certifications per freelancer
4
Most common languages
German, English, Arabic
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Mend (WhiteSource)
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What it does
Mend, formerly WhiteSource, helps teams track open-source components and spot license or security issues before they reach production. It is used in software supply chain work where dependency control matters. Strong specialists know how to turn scan results into clear actions for product and security teams.
Typical work
- Set up repository and build tool scanning
- Tune policy rules for allowed and blocked packages
- Review license findings and security alerts
- Support release checks in CI pipelines
- Clean up noisy findings and false positives
Skills around it
Good Mend specialists understand open-source governance, dependency management, and secure delivery pipelines. They often work with GitHub, GitLab, Bitbucket, Jenkins, Maven, Gradle, npm, and similar build tools. They also know how to explain risk in plain language so engineering and compliance teams can act on it.
When to bring help
Companies bring in freelance experts when scans are live but policies are not, when reports are hard to trust, or when releases keep getting blocked. This is common during tool rollout, migration from WhiteSource to Mend, or a wider AppSec programme. In Germany, remote work is common, but on-site sessions can help with security, procurement, and engineering alignment.
What strong experts do
Strong professionals do more than install the tool. They map repositories, refine ignore rules, connect identity and build systems, and build repeatable processes for triage and remediation. They also keep the setup usable as teams, packages, and compliance needs change.
Deliverables
A solid engagement usually ends with working scans, usable dashboards, policy guidance, and clear handover notes. Good experts leave behind a setup that development teams can maintain without guesswork. That matters whether the stack is Java, JavaScript, .NET, Python, or mixed polyglot services.
Frequently asked questions
The facts hiring teams ask for most often when it comes to Mend (WhiteSource).
Mend (WhiteSource) is used to manage open-source risk in software delivery. It scans dependencies, flags license and security issues, and helps teams decide what can move through the pipeline. Companies use it to keep control over third-party components without slowing releases.
Yes. WhiteSource is the former name, and Mend is the current product name. Searchers often use both names when they look for someone who can set up scans, policies, and reporting in the same environment.
A strong Mend (WhiteSource) setup is often compared with tools such as Snyk, Black Duck, or Dependabot-related workflows. Mend is typically chosen when teams want policy control, license tracking, and centralized governance around open-source usage. The right fit depends on how much reporting, process control, and build integration the company needs.
A good Mend specialist should understand build systems, source control, and CI/CD pipelines. Experience with Maven, Gradle, npm, GitHub, GitLab, Jenkins, and release processes is very useful. Knowledge of open-source licensing and security triage is just as important as the product configuration.
Most WhiteSource projects need someone who has already worked through setup, policy tuning, and alert cleanup in a real environment. Basic installation is not enough when repositories are large or teams need different rules for security and licensing. The best results usually come from specialists who have handled both rollout and ongoing maintenance.
Yes, Mend work is often delivered remotely, including for teams in Germany. Many tasks only need access to repositories, build pipelines, and policy discussions, which fits remote collaboration well. On-site workshops can still help when security, engineering, and compliance teams need to align quickly.
Look for someone who can explain why a finding matters, not just how to turn on scans in Mend (WhiteSource). Quality shows up in clean policy design, sensible false-positive handling, and clear handover notes. A strong specialist also makes the setup workable for the teams who must use it every day.
A WhiteSource project succeeds when policy, build integration, and ownership are clear from the start. It fails when the tool is installed but no one agrees on what to do with the results. The best specialists connect the technical setup to a practical review process and keep that process simple.
The average hourly rate of freelancers in Germany who have used Mend (WhiteSource) in their recent projects is 98 €, which corresponds to a daily rate of about 784 € based on an 8-hour working day.
Of the freelancers in Germany who have used Mend (WhiteSource) in their recent projects, 100% hold at least a Bachelor's degree and 71% hold at least a Master's degree.
On average, freelancers in Germany who have used Mend (WhiteSource) in their recent projects have 25 years of professional experience, with a single engagement typically lasting around 2.1 years.
The most common languages among freelancers in Germany who have used Mend (WhiteSource) in their recent projects are German (100%), English (100%), and Arabic (29%).
The most common industries among freelancers in Germany who have used Mend (WhiteSource) in their recent projects are Information Technology (100%), Banking and Finance (86%), and Transportation (86%).
The most common business areas among freelancers in Germany who have used Mend (WhiteSource) in their recent projects are Information Technology (100%), Product Development (100%), and Quality Assurance (86%).
Main locations of FRATCH Experts, who have recently used Mend (WhiteSource)
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
