SAML Experts in Germany
in minutes from over 15,000 CVs with the power of AI.Hire experts who design SAML single sign-on, connect identity providers and service providers, and fix trust, certificate, and metadata issues in enterprise login flows. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used SAML
Frédéric Klein
Last position:
Project Manager (Enterprise Cloud Governance) at CompuGroup Medical SE & Co. KGaA
Short description: Leading a group-wide project to establish standardized cloud governance for Microsoft Azure, including policies, security and compliance controls, automation, and cost and operations management while preserving the autonomy of decentralized business units within regulatory frameworks.
Tasks and activities:
Overall responsibility for designing, building, and implementing a company-wide cloud governance structure (Azure), including target picture, roadmap, and operating model.
Managing internal and external stakeholders (C-level, IT, Security, Compliance, Cloud Architecture, DevOps), including decision and escalation management.
Planning and facilitating workshops on cloud strategy, governance principles, and the design of areas such as identity, connectivity, and platform management.
Defining, implementing, and rolling out cloud policies (Azure Policy / custom policies), security standards, and compliance requirements (including GDPR, ISO 27001, BSI C5).
Building a cloud governance framework based on the Azure Cloud Adoption Framework (CAF), including landing zone and guardrail concepts.
Introducing automation solutions for governance, security, and cost control (policy/control automation, IaC, CI/CD-based control mechanisms).
Implementing cloud security and compliance monitoring mechanisms as well as continuous improvement processes.
Establishing and operationalizing FinOps in an enterprise environment (central and decentralized FinOps teams), including cost management strategies, reporting, and guardrails.
Integrating governance policies into DevOps processes (e.g. CI/CD principles for security and compliance checks, GitLab Runner concept in spokes, GitLab CI/CD for CAF landing zones).
Implementing access concepts including RBAC design and breaking-glass mechanisms (emergency access) as well as certificate automation (ACME / step-ca).
Achievements:
Created a unified, auditable governance and control set for Azure (policies, standards, compliance mapping) and thus laid the foundation for scalable cloud use in a regulated environment.
Established repeatable automation for governance, security, and cost control (IaC + CI/CD), reducing manual effort and implementation risk.
Improved operational and decision-making capability across central and decentralized units (clearer roles, responsibilities, escalation paths, balance between autonomy and group requirements).
Significantly increased workload compliance during lift-and-shift migrations.
Technologies used:
Microsoft Azure Policy, custom policies.
Terraform, OpenTofu, Terragrunt.
step-ca (ACME).
Entra ID.
Azure Firewall.
Azure Networking, hub-and-spoke architecture.
Azure vWAN (evaluation).
Azure Front Door, Azure Application Gateway.
Azure ExpressRoute.
Azure Key Vault.
NetBox.
GitLab (on-premises).
Infrastructure, concepts used:
Cloud shared responsibility model.
Hub-and-spoke connectivity / central shared services (from hub-spoke context).
Central governance with decentralized delivery (business unit autonomy with guardrails).
Methods used:
Scrum.
Stakeholder management (C-level to engineering).
Cloud governance, Azure Cloud Adoption Framework (CAF).
DevOps, CI/CD.
Cost and FinOps approaches: tagging/chargeback models, budget/alert concepts, reserved instances/savings plans vs. on-demand scenarios, sensitivity analyses.
RBAC, breaking-glass concepts.
ACME / certificate automation.
GitLab Runner concept in spokes, GitLab CI/CD pipelines for CAF landing zones.
Panagiotis Tsafaridis
Last position:
Senior Data Engineer Consultant at GOLDNER GmbH
- Onboarded and conducted comprehensive documentation and system analysis to assess the existing data infrastructure, facilitating rapid integration and collaboration across functional data teams (modelling, processing, reporting).
- Collaboratively defined the architecture and project structure for a central data pipeline repository, including hierarchical standards, knowledge management strategies, and role-specific responsibilities, enhancing maintainability and onboarding speed.
- Evaluated and validated open-source data routing tools (Airbyte, Apache NiFi, Dragster) for ingest and sync requirements in retail analytics, including local benchmarking and error-state testing.
- Led the design and deployment of Airbyte in Kubernetes, creating customized Helm charts, securing secrets handling, and configuring Ingress with TLS and internal DNS routing, ensuring full API and UI accessibility.
- Troubleshot and resolved Ingress controller issues, iterating through multiple stages of debugging and testing, and documented setup and replication steps for scalable reuse.
- Mapped data models to ARTS standard, supporting schema alignment for ERP and reporting use cases, and coordinated review loops to align future data processing logic.
- Drafted strategic 1-pagers comparing MinIO, Pub/Sub, and routing architectures, providing technical guidance for architectural decisions and investment planning.
- Enabled secure access and authentication mechanisms, including initial evaluation for SAML integration, cluster-level configuration reviews, and service annotation improvements.
Sebastian Kanzow
Last position:
Senior Lead Developer, System Architecture at AVL DITEST
- Redesign of a legacy Windows app for vehicle diagnostics as an AWS cloud application
- Creating build pipelines and conducting code reviews using Kotlin, Spring Boot, Micronaut, Jenkins, and GitHub
Yaroslav Shargorodskiy
Last position:
Senior Low-Code Consultant at Freelancer
Structured analysis and evaluation of business processes
Gathering, documenting, and prioritizing requirements
Creating business-friendly and technically executable process models
Use of Camunda tools
Deriving requirements and interfaces from BPMN diagrams
Coordination with stakeholders and business units
Translating business requirements into technical solution designs
Implementing efficient and tailored applications
Systematic collection, analysis, and documentation of requirements
Prioritizing and validating requirements in close collaboration with stakeholders
Alignment between business and development to ensure shared objectives
Creating use cases, user stories, and acceptance criteria
Continuous requirements and change management throughout the project lifecycle
Define project goals and create project plans
Delegate tasks and monitor project progress
Monitor budgets and inform stakeholders
Mendix: Architecture, development, and maintenance of custom applications (Microflows, Domain Model, Security, XPath)
Modeling Mendix workflows for process optimization
Develop scalable apps with Mendix including REST/SOAP integration with SAP, SQL, Azure & SharePoint
UI design for Mendix using Atlas UI, Fluent UI, HTML, CSS, JavaScript
Develop web & mobile apps with Mendix using agile methods (Scrum, Kanban)
Implement business logic with Mendix Microflows and Nanoflows
Performance optimization and architecture improvements for Mendix applications
Conduct Mendix training
Create technical documentation and best practices for Mendix
Coaching and mentoring for low-code development with Mendix
Alex Volnov
Last position:
CTO, Co-Founder, Cryptography(incl. Post-Quantum Cryptography) and AI Security Expertise at AISLEIPNIR
- Integration of Post-Quantum Cryptography (PQC) algorithms into high level protocols.
- Security of implementations of Post-Quantum Cryptography algorithms.
- Transition to Post-Quantum public key infrastructures.
- Security evaluations of Post-Quantum Cryptography (PQC) primitives.
- Drone Cybersecurity
- Satellite Cybersecurity
- AI Security
Vitaliy Ryumshyn
Last position:
DevOps GitOps (temp) at Signal Iduna
- Responsible for Openshift/Kubernetes on-prem administration and developer support.
- Developed URP infrastructure automation with Python, Ansible, Kustomize and ArgoCD, Argo Workflow/Events stack.
- Wrote smoke and load tests for URP infrastructure utilizing Python, Kustomize and ApplicationSets.
- Helped to set up and deploy URP infrastructure in Google Cloud, GKE.
- Set up monitoring for URP and ArgoCD stack with Splunk Cloud.
- Performed system administration tasks across RedHat Linux, Kubernetes/Openshift, ArgoCD, GitLab, Bitbucket Enterprise, Kafka and MongoDB.
Patrick Waldschmitt
Last position:
AI Software Engineer at IppenMedia
- Analysis
- Consulting
- Software design
- Development
- Automation
- Testing
- Deployment
- Architecture, development and deployment of various proof-of-concept applications around the integration of current AI interfaces including conversational, realtime voice, images and videos
- Developed best practices for working with agentic systems and AI in practice
- Created code templates
Hicham Mokhtari
Last position:
Freelance Software Developer at Buhl Data Service GmbH
- Backend development: .Net 8, C#, PostgreSQL, Entity Framework Core, REST Web APIs, Docker, Kubernetes, Kafka, Open API Swagger, Apache Airflow, Resharper, Git, Microservices, SOAP, gRPC, Hangfire, OAuth 2, GraphQL
- Interface development for document processing with SmartFix, Softexpansion and Natif.ai: C#, REST API, Resharper, Git
- Deployment: Azure DevOps YAML, Vanilla Helmchart, Rancher, Kubernetes Cluster, Linux Docker, Windows VM, Python
- Unit tests and integration tests
- Telemetry, Kibana, Grafana, Elastic Search
- Work in a Kanban team of 8 developers, 1 tester and one Product Owner
Mario Jelinski
Last position:
Architect / Developer at handyhase
- Overhaul of the entire design and implementation of new UI/UX aspects using React
- Planning of the software architecture and structuring of the project for long-term scalability using Git for version control
Kamel Ben Yedder
Last position:
Senior TYPO3 Developer at IHK für München und Oberbayern
- Planning and implementing the upgrade of the existing TYPO3 installation to TYPO3 11, including switching to a Composer setup (Composer-based deployment)
- Migrating the underlying MySQL database
Will Orrantia
Last position:
Solution Architect at Stuttgart Police Authority
Designing the migration strategy for WLS applications to the BKA cloud and Stack IT
Creating a hybrid cloud for internal testing and development with Kubernetes
Transforming the IT landscape from a legacy monolithic architecture to a cloud-based architecture
Integrating new CI/CD processes using Azure Pipelines
Quadrupled the throughput of personnel security checks
Migrated personnel security clearance applications to Docker-based applications
Built CI/deploy pipelines with Azure DevOps
Environment: Java Spring Boot, Kubernetes, Oracle WebLogic, OpenID, Camunda, JUnit, TOGAF
Felix Schmitt
Last position:
System Consultant / Consultant at Freelance work
- Projects in the area of Identity and Access Management, Single Sign-On, and LDAP directories
- Development of Java modules
- Development and administration of Java/J2EE-based applications on different application servers
- Administration of Unix systems (Linux, Solaris, AIX) and applications
- Migration of systems
Ottavio Braun
Last position:
Semantic Test Framework for LLMs
Selvaraj Kannaiyan
Last position:
Senior Full Stack & Cloud Architect at HCLTech
- Led end-to-end implementation of the Miles and More Credit Card Service integrating with TSYS systems on Microsoft Azure
- Architected secure, scalable APIs and microservices using Spring Boot, Camunda, and Apache Kafka (Confluent Platform) for real-time event streaming and process automation on Azure Kubernetes Service
- Managed full development lifecycle of the credit card system on Azure Cloud including fraud detection, payment processing, account management, and Kafka-based event-driven data pipelines
- Designed and implemented Kafka Connect integrations and Schema Registry for seamless data flow between microservices and legacy systems
- Introduced Agile best practices, improving team efficiency by 30% and reducing project delivery time
- Directed and mentored a team of 15+ developers fostering a collaborative, cloud-first, and innovation-driven culture
- Managed client relationships achieving 95% satisfaction and securing follow-up projects through consistent delivery excellence
- Designed and deployed BPMN/DMN models in Camunda for complex business workflows and automation
- Configured Camunda Engine with advanced features such as error handling, RPA integration, and multi-version deployments
- Integrated Camunda and Kafka-based messaging with core banking systems ensuring high availability and data consistency
- Managed multi-database schema configurations on Azure and optimized system performance for high throughput and fault tolerance
- Designed and implemented cloud architecture patterns on Azure focusing on multi-region resilience, data sovereignty, and event-driven scalability for critical financial workloads
Bertrand Rothen
Last position:
Interim IAM Product Owner (Identity Management) at REWE digital GmbH
- Establishing Identity & Directory Management as a new (split-off) team & product within the IAM cluster.
- Leading the “Identity & Directory Management” product (8 people) as Product Owner.
- Concept for ‘Digital Identities’, i.e. IDs with n users/accounts and strategy for a modernized product offering.
- Upgrading APIs, migrating to a containerized infrastructure, rolling out international markets & standardized solutions across the REWE enterprise group.
- Tech: OpenText™ (NetIQ) eDirectory & Identity Manager, LDAP, SAP HR/HCM, Docker/Kubernetes/Podman, REST APIs, Microsoft Active Directory & Entra ID, postgresDB, Keycloak, Ansible, Cyberark (PAM), Apache Kafka, Jira, Confluence, Miro.
Discover over 15,000 top freelancers
Statistics of experts using SAML
Aggregated from the professional profiles of matched freelancers.
Experience
20 years
Position duration
2.1 years
Positions per freelancer
13
Top business areas
Information Technology, Product Development, Project Management
Top industries
Information Technology, Banking and Finance, Retail
Certification focus areas
Information Technology, Project Management, Product Development
Bachelor's degree or higher
71%
Master's degree or higher
39%
Doctorate
10%
Certifications per freelancer
3
Most common languages
German, English, French
Speak two or more languages
98%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using SAML
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
SAML in practice
SAML, short for Security Assertion Markup Language, is used for federated login and single sign-on between identity providers and service providers. In German companies, it often sits behind employee portals, partner access, and secure SaaS sign-in.
Typical work
- Set up SAML 2.0 trust between identity and service systems
- Map user attributes, groups, and roles into application claims
- Test logout, session handling, and certificate rotation
- Troubleshoot metadata, signing, and assertion validation
Ecosystem fit
Strong SAML specialists know the surrounding identity stack: IdP and SP configuration, XML signatures, certificates, and claim mapping. They often work alongside Azure AD, Okta, ADFS, Keycloak, Ping Identity, and common Java, .NET, or cloud apps that consume SAML assertions.
When to bring help
Companies usually bring in freelance SAML experts when login breaks after an IdP change, when a new SaaS app needs secure federation, or when multiple business units need one sign-in path. They are also useful during mergers, partner onboarding, and access policy cleanup in Germany-based teams working across sites or remotely.
What good specialists do
Good professionals read SAML traces, compare metadata, and spot mismatches in audience, issuer, NameID, or clock settings. They write clear handover notes, work with security and application teams, and keep the setup stable when certificates or endpoints change.
Signs you need one
- Users cannot sign in after a certificate update
- New applications need SAML setup without unsafe shortcuts
- Assertions arrive but roles or attributes are wrong
- Logout or relay state behaves inconsistently
- Internal teams need a clean review of the trust flow
Frequently asked questions
Key details about SAML, drawn from the questions we get asked most.
A strong SAML specialist sets up secure single sign-on between an identity provider and a service provider. That includes metadata exchange, attribute mapping, certificate handling, and testing the full login and logout flow. They also help when federation breaks after a change in Azure AD, Okta, ADFS, Keycloak, or another identity system.
SAML is mainly used for enterprise federation and browser-based single sign-on. OAuth and OpenID Connect are more common for modern app authorization and consumer-style login flows. If your goal is internal workforce access or partner access to older or enterprise apps, SAML is often the right fit.
A SAML project usually involves an identity provider, a service provider, certificates, XML signing, and user attribute mapping. In practice, specialists often work with Azure AD, Okta, ADFS, Keycloak, Ping Identity, and the target application’s auth settings. Good understanding of user directories and access policies is also important.
A SAML freelancer can start quickly if you can share the identity provider, the service provider, the current metadata, and the exact login issue or target flow. Access to test accounts and a clear view of required attributes makes the work much faster. The more complex the trust chain, the more useful a short discovery session becomes.
Yes, SAML projects often work very well with remote collaboration. Many companies in Germany use mixed setups across office and distributed teams, so clear documentation, test access, and agreed change windows matter more than location. On-site help is mainly useful when several internal systems must be adjusted at once.
A good SAML expert does not just make login work once. They explain the trust flow, verify assertions and certificates, test edge cases like logout and expired metadata, and leave behind clean setup notes. If they can describe how to diagnose common failures without guesswork, that is a strong sign.
SAML still makes sense when you need enterprise single sign-on for workforce or partner access, especially with established business software. For new consumer apps or API-first products, OpenID Connect may be a better default. A solid specialist can help you choose without forcing SAML where it does not fit.
A SAML engagement often benefits from skills in IAM, directory services, certificate management, XML, and application security. Knowledge of Azure AD, Okta, ADFS, Keycloak, or Ping Identity is often useful, as is experience with Java, .NET, or cloud application integration. Clear communication with security and application teams matters just as much.
The average hourly rate of freelancers in Germany who have used SAML in their recent projects is 102 €, which corresponds to a daily rate of about 814 € based on an 8-hour working day.
Of the freelancers in Germany who have used SAML in their recent projects, 71% hold at least a Bachelor's degree, 39% hold at least a Master's degree, and 10% hold a doctorate.
On average, freelancers in Germany who have used SAML in their recent projects have 20 years of professional experience, with a single engagement typically lasting around 2.1 years.
The most common languages among freelancers in Germany who have used SAML in their recent projects are German (100%), English (98%), and French (24%).
The most common industries among freelancers in Germany who have used SAML in their recent projects are Information Technology (98%), Banking and Finance (69%), and Retail (42%).
The most common business areas among freelancers in Germany who have used SAML in their recent projects are Information Technology (100%), Product Development (78%), and Project Management (78%).
Main locations of FRATCH Experts, who have recently used SAML
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Munich