One Identity Manager Experts in Germany
in minutes from over 15,000 CVs with the power of AIHire experts who deliver One Identity Manager access governance, role modeling, connector setup, and user lifecycle workflows. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used One Identity Manager
Firas Jradi
Last position:
Interim Management Group Head of IT Governance & IAM at French-German Private Bank
- Head of the group-wide, international, and cross-functional IT Governance & IAM department within the central IT division of a large French-German private banking group. Disciplinary management of around 30 employees at five different locations within the group (Frankfurt, Paris, Tunis, Saarbrücken, Düsseldorf). Head of IT committees and key role in direct communication with management, the supervisory board, external stakeholders, and regulators.
- Definition and establishment of a state-of-the-art IT strategy process and related IT governance structures for the group's IT department with more than 600 employees (testified by the German Federal Financial Supervisory Authority and the ACPR) and successful process run.
- Establishment of a new future-oriented process framework for IT and necessary governance structures (process squads) for the continuous improvement of IT processes with regard to new regulatory requirements (including DORA, EU AI Act, etc.).
- Establishment of stringent processes to close a historical backlog of findings (> 100 IT findings, 40 overdue findings in 2022) from internal and external auditors (WP, ACPR, BaFin). Successful reduction of stock of overdue findings to 0 at the end of 2025.
- Supporting more than 20 IT audits per year and establishment of regulatory monitoring processes. Introduction of ServiceNow to revolutionize regulatory change and IT compliance processes with advanced AI functionalities.
- Realignment of IT control processes in conjunction with the newly established ICT risk function under DORA and the three lines of defense concept using the TopEase GRC solution.
- Reduction of the application landscape, by systematically analysing the purpose with application and business owners, identifying duplicates while implementing a One-Tool Strategy throughout the group. Successful reduction of one third of the application landscape within the CMDB.
- Onboarding of all group applications into One Identity's group-wide IAM solution, as well as operation and further development of the solution in connection with segregation of duties (SoD), role-based access management (RBAC), etc.
Vicenco Kenk
Last position:
ITSM Project Manager (self-employed)
Unified ITSM framework
- Definition of a company-wide ITSM target picture
- Introduction of a uniform service structure across all business units
SLA and OLA management
- Building a standardized SLA framework
- Definition of service classes (Business Critical, Standard, Low Priority)
- Introduction of OLAs between internal teams
- Building meaningful SLA reporting
- Definition of KPI and service dashboards for business units
Service portfolio management
- Definition of service descriptions
- If needed, preparing possible cost and service billing
Ticketing & processes
- Incident management
- Uniform ticket categories
- Standardized prioritization
- Escalation matrix
- Automations
- Self-service optimization
Request fulfillment
- Service catalog across all business units
- Approval workflows
Problem management
- Introduction of root cause analysis
- Known error database
- Problem review process
Complete asset management concept
- Hardware lifecycle management
- Software lifecycle management
- Leasing lifecycle
- Mobile device lifecycle
- Monitor lifecycle
- Phone lifecycle
Processes
- Procurement
- Goods receipt
- Inventory
- Assignment
- Return
- Disposal
- Leasing return Goal: single source of truth for all assets
CMDB design
- Definition of all configuration items:
- Workplace
- Notebooks
- Monitors
- Mobile phones
- Printers
Infrastructure
- Servers
- Firewalls
- Switches
- WLAN
- Storage
- Backup systems
Cloud
- Azure resources
- Microsoft 365
- SaaS services
Relationships
- User ↔ Asset
- Asset ↔ Service
- Service ↔ Infrastructure
- Location ↔ Asset
- Goal: make all service dependencies visible
Software asset & license management
- License management concept
- License balancing
- Compliance reporting
- Microsoft license management
- Adobe license management
- SaaS management
- Contract management
- Renewal management
Interfaces & automation Existing systems
- Workday
- Joiner
- Mover
- Leaver
TESMA
- Leasing data
- Contract data
Matrix42
- Asset synchronization
- User synchronization
Active Directory / Entra ID
- User management
Microsoft 365
- License assignment
- Group management
Dormakaba
Access processes
Lifecycle services
Monitoring platforms
- PRTG
- Palo Alto
- Cisco
Reporting & KPI framework
- Definition of a management dashboard
- KPIs
- Ticket volume
- SLA fulfillment
- MTTR
- First resolution rate
- Asset accuracy
- License compliance
- Change success rate
- Service availability
- Degree of automation
Network redesign support
- Governance
- Support of the network redesign from an ITSM point of view
- Definition of affected services
- Change management structure
- Communication concept
CMDB integration
- Recording of all network components
- Service mapping
- Dependency analysis
Validation of documentation and knowledge base articles
- Network documentation
- Operations documentation
- Standard changes
Monitoring & event management
- Target picture
- Central monitoring concept
- Event management process
- Alerting strategy
- Escalation model
Systems
Cisco
Palo Alto
Fortinet
Rubrik
Veeam
Matrix42
Azure
Microsoft 365 Automation
Ticket creation from monitoring
Escalations
Standard actions
Audit, compliance & information security
- ISO 27001 consulting
- TISAX consulting
- NIS2 preparation - consulting
- Audit-ready processes
- Documentation structure
- Evidence tracking in Matrix42
Roadmap
- 12-month roadmap
- Prioritization of all measures
- Quick wins
- Medium-term projects
- Long-term target picture
- Documentation
Michael Schwendemann
Last position:
Compliance/TPRM setup at Haftpflichtkasse
Compliance department setup & DORA operationalization
- Setup of a complete compliance organization according to DORA
- Development and operationalization of SfO
- Use of AI agents for automation:
- Evaluation of due diligence questionnaires including risk classification
- AI-supported contract analysis (DORA/MaRisk compliance)
- Monitoring of external data sources (cyber incidents, news feeds)
- Setup of a decentralized risk and action register
- Creation of gap analyses and derivation of actions
- Setup and maintenance of the outsourcing information register
- Use of own TPRM frameworks, checklists and process models
Compliance department setup & DORA operationalization
- Setup of a complete compliance organization according to DORA
- Development and operationalization of SfO
- Use of AI agents for automation:
- Evaluation of due diligence questionnaires including risk classification
- AI-supported contract analysis (DORA/MaRisk compliance)
- Monitoring of external data sources (cyber incidents, news feeds)
- Setup of a decentralized risk and action register
- Creation of gap analyses and derivation of actions
- Setup and maintenance of the outsourcing information register
- Use of own TPRM frameworks, checklists and process models
- Project controlling - presentation and structured measurement of achieved project goals within management reporting.
Matthias Batz
Last position:
Windows Administrator at Telair GmbH
Windows Administrator, software deployment, user support, Azure / Entra administrator, hardware support, software packaging, defining and introducing processes
Tasks performed:
- Handling incidents, service requests & changes in the Matrix42 ticket system
- Handling / resolving incidents
- User creation / permissions
- Installation and patch management for Windows
- Permissions and license management in Entra
- Process improvement and documentation
Tools and methods used: Windows Server 2016 / 2019, Active Directory, Windows 11, Office 365, Azure / Entra, Ivanti, VMWare & ESX, Dell & Kyocera Minolta & Zeus hardware support
Matthias Kühnlein
Last position:
Business Owner at AKM
Management of several MFA methods for central authentication within a group company. Interface between different stakeholders such as support, finance and accounting, developers, and security departments. Budget controlling and monitoring of KPIs as well as SLAs. Review of operating documentation
Alex Volnov
Last position:
CTO, Co-Founder, Cryptography(incl. Post-Quantum Cryptography) and AI Security Expertise at AISLEIPNIR
- Integration of Post-Quantum Cryptography (PQC) algorithms into high level protocols.
- Security of implementations of Post-Quantum Cryptography algorithms.
- Transition to Post-Quantum public key infrastructures.
- Security evaluations of Post-Quantum Cryptography (PQC) primitives.
- Drone Cybersecurity
- Satellite Cybersecurity
- AI Security
Tobias Stötzer
Last position:
SAP S/4 Public Cloud Role Model Expert with License Optimization at TIMETOACT Group
To achieve savings and optimize compliance, apps were restructured to align with identity management assignments, restrictions were defined, and overuse costs were cut. Communication with stakeholders, permission validation with users, and technical implementation provided significant added value for the group. Documentation was also prepared for the financial audit.
Arno Glatz
Last position:
IAM Consultant for GIAM Onboarding at Allianz Kunde und Markt GmbH
- Planning and control: Responsible for the timely integration of 50 applications into the company-wide GIAM platform
- Stakeholder workshops: Organizing and moderating workshops with technical and business contacts (application owners, compliance, QA, GIAM core team)
- Technical analysis: Review and analysis of existing role and permission models, mapping to the GIAM structure, selection of the right onboarding track
- Concept adaptation: Further development of the GIAM onboarding framework while taking regulatory requirements and individual application needs into account
- Process integration: Embedding the new IAM processes into existing operations, release, and support processes without service interruption
- Communication and reporting: Ongoing coordination with stakeholders, management of feedback and changes, progress and risk reporting
- Quality assurance: Definition of test strategies, execution of functional and interface tests, documentation of all onboarding steps
Thorsten Otremba
Last position:
Workstream Lead (WS) at Bank-Verlag GmbH
- Introduction of giro card with Visa Debit card payment function (Combocard) for Commerzbank
- Support for the Card Processing Team (card processing; Clearing & Settlement incl. Dispute Management teams) in project work
- Creation of requirements for the Clearing & Settlement team, Authorization team (AZ) and Card Production team (KP) as part of a requirements catalog
- Requirements engineering (requirements management) with business contact person
- Participation in workstream meetings between VISA Inc., SRC Security Research & Consulting GmbH, Commerzbank AG and consulting firms (PwC and Senacor Technologies AG)
- Sprint planning with Jira tickets of type Task and use of Confluence
- Creation and presentation of weekly status reports for the Clearing & Settlement, Dispute Management and Reporting & GUI workstreams
- Coordination with network and file transfer teams for connection tests of new interfaces, e.g. setup of host keys, use of VPN or sipnet connections
- Coordination of the delivery of test files, e.g. exchange rates (FX rates; TC 56 of VISA rates), VISA Debit and Credit transactions (format Base II) and EANSS/ISS Base II clearing files to the Debit Clearing System (DCS)
- Conducting coordination meetings on the use of Visanet Settlement Service (VSS) and PSD2 reports and payment traffic statistics (ZVS)
- Organizing workshops with FiServ (First Data) on Dispute Management and complaint handling
- Setup and maintenance of Open Point List (OPL) in Confluence
- Technologies/methods: Jira, Confluence, giro card, VISA Debit card, payments, Kanban board, BIN, routing, CIQ, VPAY, ScalaTest, Dispute Management
Holger Görz
Last position:
IAM Expert for current-state analysis and migration concept from bi-Cube to IdentityIQ (SailPoint) at Stadtwerke
- Creation of a current-state analysis of the bi-Cube system with the goal of delivering a concept incl. recommendations on how the bi-Cube system can be replaced by IdentityIQ (SailPoint) while ensuring ongoing operations and taking into account the processes and the modification of the IAM workflow by third parties.
- On-site IAM workshop to carry out an IAM system analysis.
- Creation of an implementation concept and recommendations for the transition from bi-Cube to IdentityIQ (SailPoint) while ensuring ongoing operations and taking into account the processes and the modification of the IAM workflow by third parties.
- Evaluation and further development of the role model for the migration, taking activities/functions and SoD rules into account.
- Creation of detailed technical documentation according to UML standards in Confluence (Atlassian).
Holger Meinecke
Last position:
Onboarding Applications Expert at Aareal Bank
- Developing and approving authorization concepts
- Onboarding high privileged users (HPU) via CyberArk
- Onboarding non-personal accounts (NPA)
Haci Karakurt
Last position:
Consultant BW, Authorizations, Fiori at Bundesagentur Nürnberg
- Setup and monitoring of critical authorization combinations in the SAP BW environment
- Analysis and management of users with privileged access
- Quality control through regular review of authorization assignments and role structures
- Design and adaptation of SAP Fiori roles to meet specific requirements from the ticket system
- Implementation of efficient identity management processes
Johannes Knörzer
Last position:
Software Developer at Hoffmann Engineering Services GmbH
- Software development
- Technical design of software architecture and design (considering functional and non-functional requirements)
- Frontend and Backend
- Refactorings
- Code reviews
- Unit tests
- Automated integration tests
- E2E tests
Global Identity Services (GIS) is the identity provider for the Digital Services Platform (DSP). GIS is responsible for authenticating and authorizing end users and other DSP services by issuing security tokens. This includes:
- Identity management (e.g., user registration, password reset and change, user profiles)
- Management of roles and permissions
- Single Sign-On (SSO) across DSP services
- Management of OAuth resources and terms and conditions
Alagi Mansaray
Last position:
Senior S/4HANA Project Manager in the Energy Sector at RKU Informations- und Telekommunikationsdienste
- Coordination and monitoring of required tasks and resources
- Coordination and ensuring the flow of information between involved departments
- Windows 10/11
- Time management and project control
- Integration of S/4HANA solutions in collaboration with business units
- Microsoft Project
- Confluence
- Jira
- Microsoft Office
- Microsoft Planner
- Responsible expert for client management environment services and patch management
- Coordination of interfaces and integration with existing systems
- Enable and enforce multi-factor authentication (MFA)
- Ensuring data migration and quality during the S/4HANA implementation
- Creation of a project structure plan
- Optimization of the design and implementation of service and client management processes
- Azure AD
- Project management & risk management
- Regular updates and drafting of decision documents for decision-makers
- Set up of an additional Linux-based infrastructure for administrative purposes
- Advising program management on transformation and migration projects
- PowerShell scripting
- Enhancement, maintenance and troubleshooting of the existing ERP application
- Synchronization with on-premises directories (Azure AD Connect)
- Conducting concept development and planning
- Procurement, integration, and deployment of MacBooks
- Autopilot
- Integration of systems into a client management system (Intune), Microsoft Defender, and Azure AD
- Implementation of single sign-on for mobile devices & PCs
- Migration from Active Directory to MS Intune
- Implementation and integration of SAP S/4HANA solutions
- Software packaging (MSI)
- Mobile device management with MS Intune and Mobile Iron
- Management of servers and services using Ansible
- MIM (Microsoft Identity Manager)
- Identity and permission management
- Access management
George Gambourg
Last position:
SAP Authorization Consultant/ SAP Authorization Consulting (Freelancer/SAP Consultant) at Publicly Listed Pharmaceutical Company
- Consulting on SAP authorizations and governance
- Conducting governance consultations, iteration support and project coordination
- Developing solutions for effective control and monitoring of SAP authorizations
- Creating concepts and recommendations
- Drafting detailed concepts to improve the assignment and management of SAP authorizations
- Providing clear recommendations based on established methods and best practices
- Creating/customizing authorizations for MM including MDG/MDM as well as FI, PP including AIRC Services within SAP Finance
- Reviewing existing structures and processes
- Analyzing and evaluating current SAP authorization structures and processes
- Identifying weaknesses and developing optimization strategies
- Conducting trainings and workshops
- Planning and delivering trainings and workshops for awareness
- Sharing knowledge in SAP authorizations, including role assignment, support during iterations and consulting on role development in the pharmaceutical environment.
Discover over 15,000 top freelancers
Statistics of experts using One Identity Manager
Aggregated from the professional profiles of matched freelancers.
Experience
22 years
Position duration
1.3 years
Positions per freelancer
18
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Banking and Finance, Professional Services
Certification focus areas
Information Technology, Project Management, Quality Assurance
Bachelor's degree or higher
71%
Master's degree or higher
53%
Doctorate
12%
Certifications per freelancer
5
Most common languages
German, English, French
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using One Identity Manager
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Access governance
One Identity Manager is used to control who gets access to which systems, applications, and data. It helps companies define roles, approvals, and compliance rules in one place. Strong specialists turn business policy into clear technical controls.
Core tasks
Typical work with One Identity Manager includes:
- role and entitlement modeling
- joiner, mover, leaver processes
- approval workflows and attestation
- connector setup for target systems
- troubleshooting sync and provisioning
These tasks usually touch HR, IAM, security, and application owners at the same time.
Ecosystem
The product sits in a broader identity stack and often works with Active Directory, SAP, cloud services, and directory services. Many experts also know how to handle database layers, scripting, and transport of custom rules. Experience with Quest One Identity Manager older project setups can still matter in long-running environments.
When to bring help
Companies usually look for freelance help when a rollout is stuck, a custom process breaks, or a major cleanup is needed before an audit. In Germany, this often comes up in regulated sectors, shared service centers, and large mixed IT landscapes. Remote work is common, but workshops and access reviews may benefit from on-site sessions.
What good specialists do
Good One Identity Manager specialists are precise and disciplined. They document changes, test end-to-end identity flows, and understand how policy, data quality, and system connectors affect each other. They also talk clearly with security and business teams, not just technical staff.
Common deliverables
A solid engagement often ends with:
- implemented request and approval flows
- clean role and entitlement structures
- stable provisioning logic
- documented admin handover
- support for go-live and hypercare
The best experts leave the system understandable for the next team, not only working on release day.
Frequently asked questions
Key details about One Identity Manager, drawn from the questions we get asked most.
One Identity Manager is used to manage identity lifecycle, access requests, role design, and compliance controls. Companies rely on it to make sure access is granted, changed, and removed in a controlled way. It is especially useful where many systems must follow the same approval and audit rules.
One Identity Manager is the current official product name, and many searchers also use OneIM as a shorthand. Older project documents may still say Quest One Identity Manager, because that was a common former name. When hiring, make sure the specialist has worked with the current product version and its surrounding identity processes.
A strong One Identity Manager specialist usually also understands identity governance, directory services, databases, and access policy design. Knowledge of Active Directory, SAP integrations, and scripting is often valuable too. The best professionals can connect business rules with technical provisioning without creating fragile custom logic.
Ask for examples of role modeling, connector work, workflow changes, and troubleshooting in One Identity Manager. Good professionals explain how they handled data quality, approvals, testing, and go-live support. If they can describe real trade-offs and not just features, that is a strong sign.
Not always. Many One Identity Manager tasks can be done remotely, especially analysis, configuration, and documentation. On-site time can still help for workshops, access review sessions, or complex stakeholder alignment in German-speaking organizations.
One Identity Manager is often chosen when a company wants strong identity governance, role management, and configurable workflows in one suite. Other IAM tools may fit simpler provisioning needs or different vendor ecosystems better. The right choice depends on the target systems, reporting needs, and how much process control the business wants.
A good One Identity Manager engagement usually produces working workflows, stable provisioning logic, clear role structures, and documentation. You should also expect testing support and handover notes for internal teams. For larger programs, specialists often help with cleanup before go-live and fixes after deployment.
For a basic enhancement, you may only need someone who knows One Identity Manager well and can work inside your existing setup. For a migration, redesign, or audit-driven cleanup, you need a specialist who has handled end-to-end identity processes before. The more systems and approvals are involved, the more important practical project experience becomes.
The average hourly rate of freelancers in Germany who have used One Identity Manager in their recent projects is 113 €, which corresponds to a daily rate of about 906 € based on an 8-hour working day.
Of the freelancers in Germany who have used One Identity Manager in their recent projects, 71% hold at least a Bachelor's degree, 53% hold at least a Master's degree, and 12% hold a doctorate.
On average, freelancers in Germany who have used One Identity Manager in their recent projects have 22 years of professional experience, with a single engagement typically lasting around 1.3 years.
The most common languages among freelancers in Germany who have used One Identity Manager in their recent projects are German (100%), English (100%), and French (33%).
The most common industries among freelancers in Germany who have used One Identity Manager in their recent projects are Information Technology (100%), Banking and Finance (79%), and Professional Services (63%).
The most common business areas among freelancers in Germany who have used One Identity Manager in their recent projects are Information Technology (100%), Project Management (79%), and Operations (75%).
Main locations of FRATCH Experts, who have recently used One Identity Manager
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
