Public Key Infrastructure Experts in Germany
matched in minutes from vetted and available freelancers with the power of AIHire experts who design trust chains, certificate lifecycles, and CA operations for internal systems, customer portals, VPNs, and device fleets. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Public Key Infrastructure
Christian Fritsch
Last position:
Architecture Management at Agency
Expert in the company's architecture management area
Support for standardizing the company's IT landscape
Further development of architecture management
Shaping the company's business architecture
Restructuring, administration and maintenance of all IT assets
Support in creating a unified software asset management and CMDB
Creation of unified document management (e-file)
Transition of documents into a central DMS structure
Link between architecture management and the department's internal business process management
Support in developing strategic and tactical development plans
Organizing communication with key stakeholders
Support in the conception, organization and coordination of the architecture office to be built up
Accompanying and advising the entire architecture management process
Advising the company's business units on architectural topics and their framework conditions
MS Office, Windows 10, VBA
ITIL, TOGAF, PowerBi, Kanban, Scrum
Internal agency tools
Open Touch Conversation, Webex, wire, bdbos
MS Sharepoint, JIRA, Confluence
ARIS, Archimate, BPMN
Matthias Schneider
Last position:
Overall Project Coordinator at Bundeswehr Informatik (BWI GmbH)
- PMO lead for Security Clearance 2 (SÜ2) cleared
- Reporting to sub-program management GMN
- System maintenance 25+
- Functional control and coordination of Jira setup
- Preparation of decision papers (e.g. project planning, steering model, communication plans, controlling models, role and responsibility matrices)
- Development of program-wide knowledge management using Confluence, creation of Jira concept
- Development of an access concept for all project tools
- Analyzing existing processes, identifying improvement potential, and designing solutions to increase efficiency and effectiveness
- Development of a concept for introducing automation approaches in existing tools
- Creating intranet articles as project marketing
- Responsible for project governance through reporting and resource planning in the sub-program
- Agile further development of the project method
- Gathering customer requirements (requirements engineering)
- Preparation and support of contract negotiations (7-year term, budget of over 500 million)
Thorsten Henneberg
Last position:
OCM (Overall Construction Manager) for HVAC at Engie Deutschland GmbH
- Overall planning and supervision of the relevant HVAC and sanitation installations across multiple construction phases.
- Leading installation teams and subcontractors.
- Ensuring adherence to schedules, budgets and quality standards.
- Coordination with other trades.
- Lean Construction Management, preparing and moderating the Last Planner Method.
- Supporting schedule planning and moderating workshops in the IPA project environment.
- Planning, organizing and supervising all HVAC and sanitation work on site.
- Managing own installers and coordinating subcontractors.
- Ensuring that all work meets quality standards, safety regulations and the schedule.
- Aligning with other trades, authorities and the client representative.
- Creating plans and reviewing invoices.
- Monitoring the proper application of construction techniques and compliance with safety regulations.
Robert Karash
Last position:
Interim Manager | Group Leader in the IT Operations & Digitalization Division "Databases, Operations & Support" (DOS) at Landwirtschaftliche RentenBank
- Technical leadership and further development of a team of 28 IT staff (internal & external) in the areas HelpDesk/HelpLine, RHEL (Red Hat), MUREX (trading system & applications), SAP basis operations
- Managing external service providers (including FI-TS for SAP basis operations)
- Personnel, resource and budget planning for the IT department and projects
- Introducing and establishing regular communication formats (weekly status meetings, team and cross-department meetings)
- Ensuring application operations in a hybrid environment (Windows/Linux with database and web/application servers)
- Supporting transformation projects to modernize the application landscape (e.g. DevOps approaches)
- Setting up and implementing a digital IT procurement for hardware & software (e.g. with DELL)
- Developing and managing the "IT Operations DOS" department based on corporate strategy
- Preparing management reports & decision papers on IT projects, optimization potential and automation opportunities
- Representing the department in the advisory boards of the Rentenbank and ensuring regulatory compliance (BaFin §44, GDPR, BSI, MaRisk)
Cherif Sahraoui
Last position:
DevOps Specialist – SCM & CI Platform at Freelancer
- Designed and developed the architecture of an enterprise SCM/CI platform for Kubernetes-native delivery and GitOps workflows.
- Implemented infrastructure automation and Vault & IAM integration for secure, compliant pipelines.
- Coordinated cross-functional teams to improve DevOps, security, and architecture in release processes.
- Increased platform adoption and developer experience by automating onboarding and artifact pipelines.
Stefan Amann
Last position:
Sole Architect and Developer at Bauernhof-Eis Stangl GbR
Design and implementation of a compact ERP, CRM, accounting, and production-planning platform for a German food manufacturer. The system replaces Rechnung11, self-built Excel sheets, and manual processes for fewer than 10 internal users.
- Designed and implemented the full platform architecture as sole architect and developer.
- Built modules for customer management, B2B order handling, invoicing, production planning, and accounting support.
- Implemented DATEV export, ZUGFeRD/XRechnung e-invoicing, FinTS bank statement synchronization, and GoBD audit trail concepts.
- Used AI-supported workflows for prototyping, test support, and implementation acceleration while retaining full architecture, review, testing strategy, and technical ownership.
Technology: Java 23, Spring Boot 3, Spring Data JPA, Spring Security, Vue 3, TypeScript, PostgreSQL, Flyway, REST, OpenAPI, JWT, TOTP, RBAC, DATEV, FinTS, ZUGFeRD, XRechnung, GoBD, JUnit, Mockito, Testcontainers, Playwright, Docker, GitLab CI/CD
Mohamad Dib-Skhni
Last position:
DevOps Engineer & IT-Security-Architect at BMW Group
- Set up Azure Kubernetes clusters (AKS) with network policies, security groups, and RBAC
- Developed Terraform-based infrastructure as code for secure, reproducible deployments in the BMW Azure cloud
- Hardened CI/CD pipelines using Jenkins, SonarQube, Fortify SSC, and Contrast AST
- Integrated SAP BTP/Kyma and ServiceNow GRC
George Ojog-Schulze
Last position:
IT Senior Consultant at Data Group
- IT Senior Consultant (bank infrastructure, Active Directory, Azure, security, PKI)
- Planning, design, and implementation of cloud solutions based on Microsoft Azure / M365
- Teams, M365, and cloud services
- Vulnerabilities, threats, attacks
- Security analysis, security policy, security architecture
- Conducting meetings and presentations at various management levels
- Organizing and leading team meetings to improve internal communication
- Tools: PowerShell, Active Directory, GPO, DNS, DHCP, scripting
André Howe
Last position:
Linux IT Admin at ReiserST
- Development and maintenance of IT architectures with embedded Linux systems.
- Designing, implementing, and optimizing backend applications and script-based solutions.
- Analyzing and resolving issues, including troubleshooting and user support.
- Developing and implementing security concepts for cloud solutions.
- Administering networks (DHCP, DNS, NTP, VPN).
- Technologies: Linux, PowerShell, Bash, Python, Ansible, Kubernetes, GitLab CI.
- Methods: Kanban.
Olaf Radicke
Last position:
DevOps Architect / Consultant at Authority with increased security requirements
- Identification of requirements (legal, organizational, and technical)
- Design of solution architectures
- Evaluation of concepts and technologies
- Preparation of decision templates
- Architectural Decision Records (ADR)
- Coordination of implementation
- Review of implementations
- Documentation
Rainer Pardon
Last position:
Senior Windows Administrator at Douglas Group Technology GmbH & Co. KG
- Expanding disk capacities
- Setting up and configuring new virtual machines
- Troubleshooting and resolution
- Synchronizing domain controllers
- Communicating with the business
- Creating and maintaining documentation
Tan Pham
Last position:
DevOps Engineer in the DevOps Team at Rise-World
- Implementation of specified DevOps solutions to automate infrastructure (Terraform, Bicep, CloudFormation, Ansible) on-premises datacenter (Ovirt, Proxmox, Ceph Cluster, MinIO) and private cloud.
- Administration, configuration and implementation of CI/CD DevOps pipelines (GitLab, GitFlow) to support development process (Artifactory, Prometheus, Istio, service mesh, Helm Chart, OpenShift (Red Hat Enterprise) / Kubernetes cluster), Red Hat Satellite.
- Administration, setup, monitoring and patching of Linux infrastructure based on Red Hat Enterprise for Dev, Test and QA.
- Use of Scrum and Kanban methods.
- Administration, configuration and implementation of security standards for deploying on Dev, Test, QA and Prod stages of the new ePA applications.
- Development of new plugins and add-ons needed on current infrastructure.
- Database support.
- Data analytics support (Python, Spark, Pandas, Power BI, Splunk Enterprise).
- Implementation of best practices for DevSecOps and BizDevOps using GitOps (ArgoCD), Streamlit framework, Semaphore Ansible UI.
- Configuration and testing of iperf, uperf, sysbench using benchmark-operator for external source data and IoT/MDM devices, creating reports via ELK / OpenSearch.
- Building a new Databricks platform to collect and analyze big data from different sources and IoT devices into Hadoop framework (Python, Pandas, PySpark, Power BI, Apache Airflow).
- Building backend data aggregation and processing to automate configuration deployment between different OpenShift clusters and big data framework (Python, Pandas, PySpark, Apache Spark, PostgreSQL, Django 2, Ansible Automation, Jira JSM).
- Building a new ML pipeline platform using Kubeflow, TensorFlow, KServe.
- Data extraction, transformation and loading from different data sources including structured and unstructured data to analytic DWH / big data cluster using Python, Pandas, Polars, Power BI, Django backend and PostgreSQL.
- Setup of new DevOps Test and QA HashiCorp Vault cluster for PKI and IAM.
- Configuration and testing of automated patching based on CVSS score, SIEM-integrated CVEs.
- Use of Nexpose and InsightVM to scan vulnerability events in network, host, container and application.
- Design and implementation of secure and scalable AWS architectures including VPC, EC2, S3, RDS and Route53 and similar setups on Azure and GCP.
- Automated system provisioning and deployment using CloudFormation templates.
- Configuration of IAM roles, policies and permissions to ensure secure access control.
- Patch management, backup automation and disaster recovery setup on AWS infrastructure.
- Monitoring and optimization of system performance using AWS CloudWatch and AWS Trusted Advisor.
- Support of VMware services (vSphere, Aria, Horizon) and the virtual desktop environment.
- Development and maintenance of CI/CD pipelines using Jenkins, GitLab CI/CD and AWS CodePipeline with interface to Nutanix.
- Configuration of AWS CloudWatch to monitor application performance and system events.
- Planning and execution of migration of on-premises applications to AWS cloud platforms.
- Deployment of containerized applications using Docker and Kubernetes in AWS environments.
- Deployment of internal software packages between availability zones using AWS CodeDeploy.
- Building and deploying ML models using Scikit-learn, XGBoost and Spark MLlib including hyperparameter tuning, model evaluation and production deployment.
Alex Volnov
Last position:
CTO, Co-Founder, Cryptography(incl. Post-Quantum Cryptography) and AI Security Expertise at AISLEIPNIR
- Integration of Post-Quantum Cryptography (PQC) algorithms into high level protocols.
- Security of implementations of Post-Quantum Cryptography algorithms.
- Transition to Post-Quantum public key infrastructures.
- Security evaluations of Post-Quantum Cryptography (PQC) primitives.
- Drone Cybersecurity
- Satellite Cybersecurity
- AI Security
André Beran
Last position:
External Attack Surface Assessment & Cybersecurity Readiness Checks at Graydaxe Cybersecurity GmbH
- Conducting cybersecurity readiness checks based on an in-house assessment methodology
- Analyzing the external attack surface using the Graydaxe EASM platform
- Assessing maturity levels and deriving prioritized recommendations for action
Stanislaus Stelle
Last position:
Security Consultant at Rohde & Schwarz AG at Star Labs GmbH
- Worked on FPGA enhanced network encryption device with secure boot, TPM2.0 and smart card integration for BSI approved usage with Post Quantum Cryptography
- Developed and audited Linux drivers
- Collaborated using GitLab, Gerrit, Confluence and Jira
- Technologies: C, C++, Secure Boot
Discover over 15,000 top freelancers
Statistics of experts using Public Key Infrastructure
Aggregated from the professional profiles of matched freelancers.
Experience
25 years
Position duration
1.9 years
Positions per freelancer
18
Top business areas
Information Technology, Project Management, Operations
Top industries
Information Technology, Automotive, Manufacturing
Certification focus areas
Information Technology, Project Management, Product Development
Bachelor's degree or higher
85%
Master's degree or higher
59%
Doctorate
13%
Certifications per freelancer
6
Most common languages
German, English, French
Speak two or more languages
98%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Public Key Infrastructure
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Trust model
Public Key Infrastructure, often called PKI, is the trust layer behind certificates, keys, and digital identity. It lets systems prove who they are and encrypt traffic with confidence. Companies use it to secure websites, APIs, email, devices, and internal services.
Core building blocks
A strong setup usually includes:
- Certificate authorities and issuing rules
- Registration and approval flows
- Certificate lifecycle and renewal logic
- Revocation with CRLs or OCSP
- Key storage, rotation, and backup
Where it is used
PKI shows up anywhere trust must be verified. Typical projects include VPN access, mTLS between services, code signing, S/MIME email, and device onboarding. In Germany, it is common in regulated enterprise environments, manufacturing networks, and identity-heavy internal systems.
What specialists deliver
Freelance specialists are often brought in to design certificate hierarchies, fix expired or misissued certificates, and clean up weak trust chains. They also help with CA migration, HSM integration, and policy design. When teams need stable operations, PKI expertise reduces outages and audit friction.
Signs you need help
- Certificates expire too often
- Teams do not know who owns the CA
- Revocation checks are unreliable
- mTLS or device trust is hard to roll out
- You need a safer certificate policy
What strong professionals know
Good PKI professionals understand X.509, certificate profiles, key protection, and the practical limits of trust chains. They work comfortably with OpenSSL, enterprise CAs, HSMs, and automation around issuance and renewal. They also document clean procedures so operations stays predictable.
Frequently asked questions
Questions about Public Key Infrastructure? Start with the answers below.
Public Key Infrastructure is used to prove identity and protect communication with certificates and keys. It supports HTTPS, VPN access, secure email, code signing, and mutual TLS between services. The main goal is to create a trust chain that systems can verify automatically.
PKI is broader than just storing a certificate on a server. It defines how certificates are issued, approved, renewed, revoked, and trusted across many systems. Simple certificate handling works for small setups, but PKI is what keeps larger environments consistent and manageable.
A strong Public Key Infrastructure specialist usually knows X.509, OpenSSL, certificate authorities, key rotation, and revocation methods such as CRLs and OCSP. Familiarity with HSMs, IAM, networking, and automation tools is also valuable. In Germany, clear documentation and careful handover matter just as much as technical depth.
Companies usually bring in PKI expertise when certificate renewals become risky, trust chains are unclear, or a CA migration is on the table. It also helps when mTLS, device onboarding, or code signing must be introduced without disrupting operations. External specialists are useful when the internal team knows the systems but not the trust model.
A small Public Key Infrastructure task can often be handled by one experienced specialist, but complex environments need someone who has seen CA design, revocation, and automation before. The risk is not the first setup alone; it is the long tail of renewals, policy changes, and incident recovery. Pick someone who has operated the same kind of trust chain before.
Most PKI work can be done remotely because design, policy, scripting, and review are document-driven. On-site time can help when a company needs access to internal systems, HSMs, or sensitive approval flows. In Germany, many teams mix remote delivery with a few in-person sessions for workshops and handover.
A good Public Key Infrastructure professional explains the trust chain in plain words and shows how certificates will be issued, rotated, revoked, and audited. Look for practical experience with production incidents, not just theory. Strong work leaves behind clear runbooks, ownership rules, and automation that reduces manual steps.
A useful PKI brief names the systems involved, the certificate types, the current CA setup, and any deadlines tied to expiry or migration. It should also mention whether the work touches internal apps, public web services, devices, or email. That gives the specialist enough context to assess risk and plan the rollout.
The average hourly rate of freelancers in Germany who have used Public Key Infrastructure in their recent projects is 105 €, which corresponds to a daily rate of about 842 € based on an 8-hour working day.
Of the freelancers in Germany who have used Public Key Infrastructure in their recent projects, 85% hold at least a Bachelor's degree, 59% hold at least a Master's degree, and 13% hold a doctorate.
On average, freelancers in Germany who have used Public Key Infrastructure in their recent projects have 25 years of professional experience, with a single engagement typically lasting around 1.9 years.
The most common languages among freelancers in Germany who have used Public Key Infrastructure in their recent projects are German (100%), English (97%), and French (21%).
The most common industries among freelancers in Germany who have used Public Key Infrastructure in their recent projects are Information Technology (98%), Automotive (56%), and Manufacturing (56%).
The most common business areas among freelancers in Germany who have used Public Key Infrastructure in their recent projects are Information Technology (98%), Project Management (89%), and Operations (76%).
Main locations of FRATCH Experts, who have recently used Public Key Infrastructure
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Hamburg
Munich
Cologne
Frankfurt
Stuttgart