Microsoft Defender Experts in Germany
in minutes from over 15,000 CVs with the power of AIHire experts who secure Microsoft 365, Defender for Endpoint, and Defender for Cloud, tune alerts, and harden day-to-day operations. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Microsoft Defender
George Ojog-Schulze
Last position:
IT Senior Consultant at Data Group
- IT Senior Consultant (bank infrastructure, Active Directory, Azure, security, PKI)
- Planning, design, and implementation of cloud solutions based on Microsoft Azure / M365
- Teams, M365, and cloud services
- Vulnerabilities, threats, attacks
- Security analysis, security policy, security architecture
- Conducting meetings and presentations at various management levels
- Organizing and leading team meetings to improve internal communication
- Tools: PowerShell, Active Directory, GPO, DNS, DHCP, scripting
Raj Udani
Last position:
Courier / Operations Support at Closer Go Germany GmbH
- Work within time-critical operating procedures; coordinate issues with customers, partners and central support.
- Maintain reliable handovers and concise incident communication when service, equipment or routing issues occur.
Dominik Piecuch
Last position:
Head of IT at Aarsleff Spezialtiefbau GmbH
- Disciplinary and professional leadership of the IT and service team
- Definition and documentation of the Current Mode of Operation (CMO) in Confluence: application landscape, infrastructure, networks, backup & storage
- Development of the Future Mode of Operation (FMO) including process analysis & stakeholder interviews with all departments using BPMN and flowcharts
- Optimization of license management: reduction of ongoing software costs by approx. 17% p.a.
- Introduction and establishment of Jira as the central tool for project and service management
- Introduction and rollout of the HR software MindKey to digitize HR processes
- Introduction of a VoIP solution with Microsoft Teams incl. PSTN connection to replace classic telephony
- Introduction of the production and planning software OptiControl to digitize operational processes
- Rollout of Intune as a Mobile Device Management solution for Windows, iOS and Android
- Build-up of Power BI dashboards for machine park monitoring and financial reporting
- Planning and execution of the IT consolidation of two locations for 170 users
- Introduction of automated penetration testing with Pentera
- Coaching and mentoring the team in agile methods & project management
- Operational support in day-to-day business: administration, incident & change management
- Management of external service providers and assurance of the quality of outsourced IT services
- Responsibility for the IT budget incl. planning and controlling
- Direct reporting line to management with regular management reports on IT KPIs, budget and project status
Enrique Gallardo
Last position:
Security Architect at Capgemini
I implemented a Zero-Trust architecture for robust, military-grade maritime container mini data centers based on VMware & Tanzu to support containerized GIS workloads for ground forces. The main focus was on securing communications, workload protection, and data access in contested electronic battle environments affected by jamming, interception, signal manipulation, and constantly changing operational conditions. I designed and architected use cases so that every element of workload, identity, and system could continue to operate independently and securely even in degraded or disrupted scenarios. In parallel, I defined the enterprise and solution security architecture with LeanIX, Bizzdesign, and HOPEX as enterprise architecture, repository, and governance platforms to maintain architecture inventory, relationships, traceability, target pictures, and security governance in complex environments. For the architectural designs, I used Sparx Enterprise Architect to describe formal architecture views, interfaces, trust boundaries, and system architecture in both IT and OT environments. IriusRisk was used for threat modeling of the solution to identify architecture-driven risks, derive security requirements, and detect countermeasures and design gaps directly from the solution models. Risk and compliance management was supported with Archer. Architecture decisions, control gaps, and operational risks were translated into controlled governance and auditable compliance measures. For documentation, collaboration, and visual design, I used Confluence to maintain Architecture Decision Records, Security Blueprints, and workflows. I used Lucidchart and draw.io to create design artifacts tailored to stakeholders. I also defined OT security concepts with support from electrical and mechanical engineers in the areas of oil, vehicle onboard systems, rail, power plants, pharma, gas turbines, and nuclear technology. I created the end-to-end OT security strategy, starting with global policy, developed into standards and procedures, and finally aligned with Bell-LaPadula, Purdue Model, SABSA, TOGAF ADM, CENELEC 50701, IEC 62443, and NIST standards. In addition, I worked with engineering team leads to identify critical KBP assets and place them under protective measures that segmented SCADA, PLC, and HMI assets. I drove collaboration between Security, IT, and OT teams to create standardized workflows and use cases for the OT security solution catalog, while integrating Defense-in-Depth and Zero-Trust principles into operational environments. A key part of my work was integrating multidisciplinary engineering, security, and operations stakeholders into a unified security blueprinting strategy and ensuring that architecture, threat modeling, governance, and documentation were technically strong and operationally practical.
Alex Volnov
Last position:
CTO, Co-Founder, Cryptography(incl. Post-Quantum Cryptography) and AI Security Expertise at AISLEIPNIR
- Integration of Post-Quantum Cryptography (PQC) algorithms into high level protocols.
- Security of implementations of Post-Quantum Cryptography algorithms.
- Transition to Post-Quantum public key infrastructures.
- Security evaluations of Post-Quantum Cryptography (PQC) primitives.
- Drone Cybersecurity
- Satellite Cybersecurity
- AI Security
Kennedy Aikohi
Last position:
Cybersecurity Trainee at CYBERDEFENDERS
- Completed 25+ hands-on labs focusing on digital forensics, incident response, and advanced threat hunting techniques.
- Earned top-tier badges in malware analysis, enterprise log analysis, and threat intelligence gathering.
- Developed specialised skills in forensic report writing and evidence collection methodologies to support incident investigations.
Cedric Bergermann-Bißlich
Last position:
Enterprise & Cloud Security Architect at ---
Enterprise & Cloud Security Architect supporting the modernization of the SDK application landscape as part of the KVNeo transformation program. Responsible for enterprise architecture, cloud governance, security architecture, and the definition of technical standards for strategic business applications.
Key responsibilities include architecture governance, target architecture development, cloud and integration architecture, security-by-design, and the translation of regulatory requirements into sustainable technical solutions across multiple business domains.
Responsibilities and achievements
- Designed and reviewed target architectures for strategic insurance applications and enterprise services.
- Developed architecture documentation based on Arc42 and Architecture Decision Records (ADRs).
- Defined governance models, architecture principles, and technical guidelines for cross-domain initiatives.
- Supported the modernization of archive, document management, and output management platforms.
- Designed integration architectures using REST APIs and event-driven communication patterns.
- Led architecture discussions with enterprise architects, development teams, product owners, and business stakeholders.
- Translated regulatory requirements such as DORA and ISO/IEC 27001 into practical architecture decisions.
- Designed security concepts covering Identity & Access Management, authorization, authentication, auditability, and logging.
- Supported SIEM integration, security monitoring, and enterprise logging concepts.
- Evaluated technical risks, technical debt, and architecture improvements while providing decision papers for architecture boards.
- Established architecture governance processes and contributed to enterprise-wide transformation initiatives.
- Supported cloud governance activities and the definition of secure cloud architecture standards.
- Facilitated architecture workshops and coordinated cross-functional stakeholders across business and IT.
Technologies & Methods Microsoft Azure • Arc42 • Architecture Decision Records (ADR) • REST APIs • Event-Driven Architecture • Microsoft Entra ID • Active Directory • IAM • SIEM • Cloud Governance • Enterprise Architecture • Security Architecture • Azure API Management • Jira • Confluence • Draw.io • DORA • ISO/IEC 27001 • Agile • Scrum
Markus Ickenroth
Last position:
Senior System Engineer Microsoft at Technidata IT-Service GmbH
As part of the project, I was responsible for operating a Citrix farm for 600 users, including optimizing the user experience and ensuring high availability.
I managed and optimized the entire application landscape of a major customer, evaluated and implemented application updates, and ensured the compatibility and security of the software in use.
I managed user accounts, implemented security policies, and monitored system performance.
I administered Azure Entra ID to control identities and access rights, implemented security policies, and synchronized on-premises directories with the cloud.
I implemented and managed Microsoft Intune for central management of client devices, including the configuration and management of BitLocker for disk encryption.
I managed file servers and NTFS permissions to ensure secure and efficient data access management.
I handled change requests and last-level support tickets efficiently to solve complex system issues and improve user satisfaction.
I supported and advised the customer team on various topics and projects, identified areas for improvement, and implemented best practices.
Technologies used:
- Citrix XenApp and XenDesktop
- Microsoft Windows Server 2012R2 and 2022
- Exchange 2016 and Exchange Online
- Entra ID (Azure AD)
- Entra ID Connect
- BitLocker
- PowerShell scripting
- Microsoft Intune
- LDAP (Lightweight Directory Access Protocol)
- DNS services (Domain Name System)
- Active Directory Certificate Services (AD CS)
André Beran
Last position:
External Attack Surface Assessment & Cybersecurity Readiness Checks at Graydaxe Cybersecurity GmbH
- Conducting cybersecurity readiness checks based on an in-house assessment methodology
- Analyzing the external attack surface using the Graydaxe EASM platform
- Assessing maturity levels and deriving prioritized recommendations for action
Hichem Blagui
Last position:
IT Security Consultant & Data Engineer / Freelancer at datadefend GmbH
- Analysis and further development of the security architecture.
- Design and development of Splunk apps and technical add-ons (TAs).
- Development and implementation of security use cases in the Splunk SIEM.
- Creation and maintenance of incident response playbooks in Cortex XSOAR.
- Support of technical proof-of-concepts to assess new detection technologies.
- Lifecycle management and operational support for Splunk and Cribl systems.
- Deployment and scaling of Splunk indexers in hybrid data center environments.
- Maintenance, update planning, and optimization of Cribl Stream & Edge for log ingestion and data routing.
- Creation of dashboards and reports to visualize security posture and system availability.
- Technical analysis to assess network topologies and data flows.
- Integration of new data sources via Cribl Stream/Edge and heavy forwarders in cloud and on-prem environments.
- Integration of external security components such as Cortex XSOAR (SOAR) and user behavior analytics (UBA).
- Implementation of complex correlation rules in Splunk Enterprise Security (ES).
- Connection of external ticketing systems via mail gateways and REST APIs.
- Automated deployment of use cases, dashboards, and detection rules via Git and Ansible.
Andreas Eckert
Last position:
IT-Compliance & Security at Bellaseno GmbH
Conducting a gap analysis to assess existing security measures → identifying critical vulnerabilities
Developing a catalog of measures considering risk and cost-effectiveness
Implementing an IT maturity model according to BSI guidelines
Advising management on compliance, governance, and security strategy
Establishing internal processes for a sustainable security organization
Daniel Ubani
Last position:
Senior Application Packaging & Deployment Engineer at Allevio AG (Client: Allianz Technology)
- Enterprise application packaging and deployment for Allianz's global Windows migration programs across Europe, North America, and APAC
- Migrated hundreds of enterprise applications from Windows 10 VDI to Microsoft Azure Windows 365 (Windows 11)
- Created software packages in MSI/MST, FlexApp, PSADT 3/4, and App-V according to enterprise packaging standards
- Developed an ASP.NET packaging automation platform with MongoDB, SQL Server, SharePoint, and Outlook integration
- Built PowerShell modules for automated quality checks of MSI and FlexApp packages
- Developed a release conflict detection module in PowerShell to identify potential deployment issues before production
- Created WDAC monitoring scripts for automated policy oversight and incident response
- Implemented MSGraph API calls in PowerShell for Azure AD and Intune operations
- Created Citrix oData scripts for historical usage analysis (BYOD, VDI, fat clients)
- Developed an Intune Win32 app 'Do Not Disturb' deployment routine for an optimal user experience
- First point of contact for troubleshooting production incidents with packaged applications
- Coordinated application owner, UAT, and release testing for hundreds of deployments
- Administered Microsoft Intune, Citrix environments, and SQL Server security
- Created and tested WDAC policies in Intune; managed configuration policies and Win32 app deployments
- Primary packaging resource for Allianz France since 2019
Florian Frings
Last position:
Consulting & User Adoption at Lila Pflege GmbH
- Consulting on the migration of email systems to Microsoft 365 Exchange Online
- Conducting end-user training & change management
- Goal: easier communication & collaboration in care operations
Mike Barthel
Last position:
System and Endpoint Hardening at CLAAS
- Evaluating and assessing the current state
- Preparing and conducting security audits
- Vulnerability characterization and risk analysis
- Assessing, coordinating and transforming identified vulnerabilities into target states
- Coordinating stakeholder interests
- Developing and implementing IT security strategy for OT and IoT (continuous risk assessment and risk management, awareness, multi-layered security solutions, regular security audits, access restrictions)
- Organizational and technical documentation, presentations and workshops
- Skills: Qualys, Splunk, Nessus, QRadar, National Vulnerability Database (NVD / NIST), Open Worldwide Application Security Project (OWASP), OT, CERT/CC, BSI IT-Grundschutz catalogs, ISO 27001, MITRE ATT&CK, Center for Internet Security (CIS), GitHub, Active Directory, PowerShell, Symantec Endpoint Protection, Microsoft Azure and Office365 App Security, ITSM
Loic Ngansop Njoya
Last position:
Development of an app for managing Power Platform components at Hays GmbH
- Requirements analysis
- Provisioning of SharePoint sites and permissions
- Provisioning of SharePoint libraries and lists as data storage
- Development of the UI with Power Apps
- Development of automations with Power Automate to transfer data from Power Apps using Dataverse connectors
- Creation, customization, and management of Power Platform security roles
- Creation and management of Power Platform pipelines
- Development of UX design with Power Apps
Discover over 15,000 top freelancers
Statistics of experts using Microsoft Defender
Aggregated from the professional profiles of matched freelancers.
Experience
16 years
Position duration
1.9 years
Positions per freelancer
12
Top business areas
Information Technology, Operations, Project Management
Top industries
Information Technology, Banking and Finance, Manufacturing
Certification focus areas
Information Technology, Project Management, Business Intelligence
Bachelor's degree or higher
67%
Master's degree or higher
33%
Doctorate
17%
Certifications per freelancer
6
Most common languages
German, English, French
Speak two or more languages
92%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Microsoft Defender
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Security coverage
Microsoft Defender is used to protect endpoints, identities, email, and cloud workloads across a Microsoft stack. Companies bring it in to reduce attack paths, spot suspicious behavior, and respond faster when something looks wrong.
Common work
- Defender for Endpoint setup and policy tuning
- Microsoft 365 Defender alert handling and incident review
- Defender for Cloud posture checks and recommendations
- Identity and email protection aligned with Entra and Exchange
- Hardening, exclusions, and false-positive cleanup
Ecosystem fit
Strong specialists know how Microsoft Defender connects with Microsoft 365, Entra ID, Intune, Sentinel, and Azure. They understand where each product adds signal, where policies overlap, and how to keep controls consistent across devices, users, and cloud services.
When to bring help
Freelance expertise helps when an environment is noisy, a rollout is stalled, or the team needs a clean security baseline after growth or migration. In Germany, companies often want specialists who can work with local IT teams, document clearly in English or German, and join remote or on-site workshops when needed.
What good specialists do
Good Microsoft Defender professionals look beyond dashboards. They read alert context, verify detections, adjust security settings without breaking business work, and explain tradeoffs in plain words. They also coordinate with infrastructure, cloud, and security stakeholders so changes stick.
Deliverables
A focused engagement usually ends with practical outputs, not vague advice.
- Tuning notes and secure configuration changes
- Detection and response workflow improvements
- Rollout guidance for endpoints, email, and cloud security
- Clear handover for internal teams and future support
Frequently asked questions
Not sure where to start with Microsoft Defender? These answers cover the essentials.
Microsoft Defender is used to protect endpoints, email, identities, and cloud workloads in a Microsoft environment. Teams rely on it to detect threats, investigate suspicious activity, and apply security controls across daily operations. It is often part of a broader Microsoft security stack rather than a standalone tool.
Microsoft Defender is the current umbrella name for Microsoft’s security products, while Windows Defender was the older name many people still use. The exact product may be Defender for Endpoint, Defender for Office 365, or Defender for Cloud. A strong specialist knows the name differences and how they map to real security tasks.
A good Microsoft Defender freelancer should be able to explain what they have configured, what they have tuned, and how they handle false positives. Ask how they work with policies, incident handling, and reporting. If your environment is in Germany, also confirm whether they can collaborate in the language your internal team uses.
A strong Microsoft Defender specialist usually understands Microsoft 365, Entra ID, Intune, Azure, and sometimes Microsoft Sentinel. They should also be comfortable with security baselines, alert triage, and endpoint hardening. Scripting and log analysis are often useful, but the key skill is making the security setup practical.
Microsoft Defender fits best when a company already uses Microsoft services and wants security controls that work together. Compared with separate point tools, it can be easier to centralize policy and response across users, devices, email, and cloud apps. The tradeoff is that it needs someone who understands the Microsoft ecosystem well.
Microsoft Defender work ranges from basic rollout support to deep incident and policy tuning. A small cleanup may only need a specialist who knows the product family well, while a complex enterprise setup needs someone who has handled detection engineering, integrations, and secure operating models. The right depth depends on how much is already deployed.
Most Microsoft Defender tasks can be done remotely because policy review, alert work, and configuration changes are handled in cloud tools. On-site time helps when a company wants workshops, stakeholder alignment, or access to sensitive internal processes. In Germany, many teams prefer a mix of remote delivery and occasional on-site sessions.
Look for someone who can explain why they changed a setting, not just say they changed it. A strong Microsoft Defender specialist shows how alerts were reduced, how detections were improved, and how the team will keep things stable after handover. Clear documentation and a calm, methodical approach matter as much as technical depth.
The average hourly rate of freelancers in Germany who have used Microsoft Defender in their recent projects is 91 €, which corresponds to a daily rate of about 724 € based on an 8-hour working day.
Of the freelancers in Germany who have used Microsoft Defender in their recent projects, 67% hold at least a Bachelor's degree, 33% hold at least a Master's degree, and 17% hold a doctorate.
On average, freelancers in Germany who have used Microsoft Defender in their recent projects have 16 years of professional experience, with a single engagement typically lasting around 1.9 years.
The most common languages among freelancers in Germany who have used Microsoft Defender in their recent projects are German (100%), English (88%), and French (16%).
The most common industries among freelancers in Germany who have used Microsoft Defender in their recent projects are Information Technology (96%), Banking and Finance (56%), and Manufacturing (52%).
The most common business areas among freelancers in Germany who have used Microsoft Defender in their recent projects are Information Technology (100%), Operations (72%), and Project Management (72%).
Main locations of FRATCH Experts, who have recently used Microsoft Defender
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
