SBOM Experts in Germany
in minutes from over 15,000 CVs with the power of AI.Hire experts who create and review Software Bill of Materials, map dependency trees, and support CycloneDX or SPDX delivery for secure releases. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used SBOM
Halil Oeztoprak
Last position:
Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD) at KfW Bankengruppe
Regulated environment within a German banking group (approx. 8,500 employees, hybrid cloud strategy).
Responsible for operating, provisioning, and continuously securing business-critical platforms – including a GenAI chat application, a big data/AI platform, and data science workspaces based on Azure Virtual Desktops and VMs. Ownership of Azure DevOps projects for ShaiHulud and React2Shell, as well as BSI alerts – Security Operations improvements across the SDLC.
Deployment responsibility for the GenAI chat application, big data/AI platform (BDAI), and data science workspaces (AVD/VM-based) in the respective landing zones.
Deployment & release management: end-to-end responsibility for deploying portal and service applications across multiple Azure landing zones, including technical approvals, compliance with development team deployment guidelines, and ensuring ITIL-based change and release processes via ServiceNow.
Azure landing zones & network architecture: design, provisioning, and operation of Azure landing zones for 3-tier web applications with enhanced network segmentation, VNet peering, hub-and-spoke architectures, private endpoints, and firewall integration across separate subscriptions and tenants.
Azure DevOps governance & operations: ownership of the Azure DevOps organization, including projects, repositories, and CI/CD pipelines; implementation of governance requirements such as branch policies, approval gates, permission models, and audit-ready operating structures.
Infrastructure as Code (Terraform): design, implementation, and operation of a modular Terraform architecture for standardized cloud infrastructure deployment, including state management, provider versioning, reusability, and policy-as-code approaches.
CI/CD pipeline engineering: design, operation, and optimization of complex YAML-based CI/CD pipelines with multi-stage deployments, template standardization, self-hosted agents, integrated secret management, and automated quality and security checks.
Git migration & platform consolidation: planning and execution of repository and pipeline migration from Azure DevOps to GitLab CI/CD, including automated scripts, full Git history transfer, pipeline porting, and platform consolidation.
Container & platform operations (AKS): operation and security assessment of containerized workloads on Azure Kubernetes Service, centralization of on-premises container registries for ACR.
OpenShift (OCP) security reviews: security assessment of code baselines, build pipelines, and deployment processes for on-premises OpenShift clusters with critical applications, and derivation of specific hardening recommendations.
Shift-left security & DevSecOps transformation: introduction of a company-wide shift-left approach for early security integration in development and deployment processes, enabling developers to perform self-led security checks and sustainably reduce vulnerabilities before production (IDE integrations, pre-commit hooks, local scanners).
Software supply chain security: analysis and mitigation of supply chain risks in NPM- and Yarn-based applications through dependency audits, CI/CD pipeline hardening, token rotation, and restriction of risky build and lifecycle mechanisms.
Frontend & framework security (React / Next.js): security assessment and coordination of critical vulnerability remediation across platform applications and web frameworks, including coordination and complementary technical mitigations with all teams following BSI alerts.
Software composition analysis (SCA): introduction and operation of automated vulnerability scans for container images, pipelines/artifacts, and third-party dependencies, including SBOM exports within CI/CD pipelines.
SAST/DAST integration: design and piloting of static and dynamic application security tests in close collaboration with security architecture and development teams, for continuous improvement of code and runtime security, and establishing operational acceptance tests.
Artifact & registry consolidation: analysis and consolidation of all package and container repositories for service applications and AKS workloads, aiming for a centralized, secured registry strategy with centralized vulnerability scanning and governance.
Dependency-Track & SBOM strategy: advising the compliance board on introducing a central SBOM and vulnerability management platform to increase enterprise-wide dependency transparency and accelerate CVE response capability.
CI/CD pipeline hardening: security analysis and cleanup of the existing pipeline landscape by removing unused pipelines, improving secrets hygiene, implementing least-privilege principles, and isolating build agent environments.
Azure Web Application Firewall (WAF) optimization: analysis and tuning of existing Azure WAF rules (OWASP Top 10 Core Rule Set, DSR/SDC, custom rules) to defend against known vulnerabilities and exploit patterns, including reducing false positives and improving threat detection.
Documentation & stakeholder communication: creating and maintaining technical documentation, runbooks, and architecture overviews in Jira and Confluence, as well as active knowledge transfer between operations, development, security, and compliance stakeholders.
Arndt Maas
Last position:
Project Manager for ServiceNow Vulnerability Response at Union Investment Services & IT GmbH
- Led the subproject for implementing Vulnerability Response as part of DORA
- Documented the current processes in compliance, risk & security
- Created the functional design for introducing application, infrastructure, and cloud vulnerabilities
- Agile management of the integration service provider, the technical department, and the company's cross-functional teams
- Integrated the V scanners Tenable, Qualys and Defender, as well as NVD and CISA/KEV
- Integrated GitLab Ultimate for importing and processing SBOMs
- Developed automation rules to match scan results with CIs in the CMDB, assign vulnerabilities and remediation tasks, handle approvals (false positives, exceptions) and closures
- Calculated multiple risk scores and priorities
- Defined dashboards and reports (Workspaces, Performance Analytics)
- Aligned the new processes, especially to improve the CMDB data quality (according to CSDM)
Andreas Winters
Last position:
Enterprise Architect at Own development / IP of CAMCO Engineering UG
UEF 3.0 · Semantic Government Overlay (SGO) · Autonomous Systems (UAS / dual use)
- Designed: Semantic Government Overlay (SGO) – AI-guided administration without replacing existing specialist procedures. Read-only semantic layer over registers and specialist processes based on the Federal Information Management (FIM). Decision authority remains with the case worker (architecture principle).
- Developed: Reference architecture with source-backed, derived statements (Executable Ontologies OWL/RDF/SHACL). Technically guaranteed purpose limitation and no-write-path principle in specialist data – auditable, without a central data pool.
- Anchored: Regulation as a design principle: EU AI Act (high-risk obligations for public-sector AI, fundamental rights impact assessment under Art. 27), GDPR, NIS2, and administrative automation limits (§ 35a VwVfG, § 31a SGB X) as technical control points in the architecture.
- Created: Methodical tool for pilot organizations: data pipeline assessment (phase 0), compliance blueprint, and management summary as a decision-ready package for public administration.
- Specified: UEF 3.0 as a successor architecture to TOGAF – decision paper, canonical ontology, six-layer architecture, read/actuate boundary, federation registry, terminology concordance, and release delta as a closed specification status.
- Architected: AI-native mission OS for autonomous UAS and ground robotics as a tactical layer on top of a separately approved autopilot. Run-time assurance according to ASTM F3269-21 (Simplex pattern): the verified safety controller keeps authority, the AI function provides suggestions.
- Designed: Three-tier architecture – Tier 0 autopilot with 650 Hz flight control on RTOS, Tier 1 AI OS with semantic world model and multi-agent cluster, Tier 2 swarm and ground mesh. Zenoh as the primary fabric, MAVLink as the only authenticated command path (single writer). Result: graceful degradation – loss of the mission, not of the aircraft.
- Secured: Two-gate chain on the read/actuate boundary – governance gate (can-question: AI Act risk class per actuation, enforced human oversight under Art. 14, immutable log) before the RTA safety monitor (is-it-correct question: flight envelope, geofence, energy reserve) with revert to the baseline controller.
- Anchored: Dual-use architecture with common core and build-time fork instead of runtime switch. Three separate legal levels: civil variant – UAS under the EASA Basic Regulation (EU) 2018/1139 with the limited applicability under Art. 2(2) of the AI Act, ground robotics under the Machinery Regulation 2023/1230 with the full high-risk obligation chain, Cyber Resilience Act for both; unarmed carrier variant as defense material under AWG/AWV and Dual-Use Regulation 2021/821 (BAFA approval); armed variant under KrWaffKontrG. Each variant lives under exactly one dominant legal regime. Evidence base: AI BOM, SBOM, and complete data lineage.
- Analyzed: System analysis and realignment of grown engineering system landscapes. Approach concept for consolidation without migration – semantic layer over the existing sources instead of data transfer. Result: decision-ready implementation concept including an evaluation model for the target architecture.
Dimitri Wolinski
Last position:
Software Architect at Environmental services company (cooperation with Sitegeist Media Solutions GmbH)
Conceptual design and implementation of a modular customer portal based on Laravel.
The focus was on defining a maintainable system architecture with broad use of Domain-Driven Design principles (within the Laravel architecture), introducing automated quality assurance processes (test strategy, CI integration), and preparing an auditable operation (logging, traceability of changes) in an AWS-based infrastructure, taking IT security standards according to NIST and process requirements according to ISO 9001 into account.
Achievements:
- Analysis and structuring of business requirements in close coordination with stakeholders
- Documentation of the system architecture and infrastructure incl. change and release management
- Design and implementation of an interface for integrating SAP systems
- Planning and implementation of automated tests for quality assurance
- Implementation of security and compliance requirements, including SBOM generation, software license management, and QA processes
- Technical consulting and support for the internal IT team
- Introduction and establishment of AI-supported development processes (Spec-Driven Development), including AI-readable specifications, integration of AI instructions into the development environment, and training developers for productive use
Technologies and tools: SAP, Docker, ddev, PHP 8.4, Laravel, Filament, C4 Model, Architecture Decision Records (ADR), Mermaid, PlantUML, Spec-Driven Development, Claude, GitHub Copilot, Codex
Jens Rehsack
Last position:
Technical Product Owner at App Development
Development of a mobile app to slow down the progression of dementia
Coordination of software development (TPO – Technical Product Owner)
agile requirements management (agile requirements engineering)
prioritization of tasks in consultation with stakeholders
stakeholder management
documentation and management of the software architecture
conducting PoC for technology decisions
Documentation as Code
docToolchain, arc42, req42, aim42, tpo42, C4 model, Archimate
ADR, Architecture Decision Records
Docker
Pre-Commit, Conventional Commits, Semantic Versioning
Liberating Structures, Agile Principles, Holacracy, Sociocracy 3.0
Mobile frameworks
AI developing interfaces, LLM
Cordova, Unity
Google Gemini, OpenAI, Character.AI
Prompt development
Manuel Engelhardt
Last position:
External Technical Lead for CI/CD, Architecture & Technical Governance at Insurance
- Technical lead for CI/CD modernization in the "Group Archive 4.0" system
- Architecture and steering responsibility according to the statement of work
- Setting up modern build and deployment processes
- CI/CD coaching and enablement of the internal development team
- Integration of modern DevOps, security, and compliance standards
- Ensuring technical governance, including collaboration with internal audit and BaFin
- Independently executing the modernization measures
- Supporting the team in adopting new technologies and methods
Hichem Blagui
Last position:
IT Security Consultant & Data Engineer / Freelancer at datadefend GmbH
- Analysis and further development of the security architecture.
- Design and development of Splunk apps and technical add-ons (TAs).
- Development and implementation of security use cases in the Splunk SIEM.
- Creation and maintenance of incident response playbooks in Cortex XSOAR.
- Support of technical proof-of-concepts to assess new detection technologies.
- Lifecycle management and operational support for Splunk and Cribl systems.
- Deployment and scaling of Splunk indexers in hybrid data center environments.
- Maintenance, update planning, and optimization of Cribl Stream & Edge for log ingestion and data routing.
- Creation of dashboards and reports to visualize security posture and system availability.
- Technical analysis to assess network topologies and data flows.
- Integration of new data sources via Cribl Stream/Edge and heavy forwarders in cloud and on-prem environments.
- Integration of external security components such as Cortex XSOAR (SOAR) and user behavior analytics (UBA).
- Implementation of complex correlation rules in Splunk Enterprise Security (ES).
- Connection of external ticketing systems via mail gateways and REST APIs.
- Automated deployment of use cases, dashboards, and detection rules via Git and Ansible.
Werner Keil
Last position:
Test Coordinator, Designer and Engineer at IBM
- Testing the SekIDP and related components
- Test design, execution and automation, microservices, GitHub Enterprise, Eclipse, Katalon Test Platform, API Testing, Confluence 8, JIRA/Xray, Draw.io, Swagger/OpenAPI, Postman, Docker, Kubernetes, Podman, PuTTY, E-Health, Telematik, Gematik standards, EPA, E-Rezept, sektoraler IDP, encryption, XaDES, PaDES, DICOM, HL7, FHIR, IHE, ICD, SSO, SAML/Shibboleth, OAuth, smartcards, JWT, two factor authentication Android and iOS, Wireshark, BrowserStack, Cypress, gRPC, REST, SOAP, WS-Security, Linux Shell, PowerShell, SSH/SSL, Java, Kotlin, Cordova, Gradle, Groovy, Python, TypeScript
Pierre Gronau
Last position:
Ansible Automation, Windows Third Level Support at DB InfraGO AG
- PRISMA project
- Ansible automation
- Windows third level support for Windows NT, Windows 2000, Windows 2013, Windows 2016, Windows 2019
Jürgen Hertweck
Last position:
iOS App Development (AI-based) at Refreco GmbH
- Development of iOS apps in Swift
- AI-supported SW development using Vibe Coding with Claude Code
- Web applications through Vibe Programming
- Use of Swift, Xcode 15, Claude Code, Proxmox, GitLab, Visual Studio Code, Cursor, Doors, ClearCase
- Use of MS Project, OpenShift, Docker, Project Server, PageMaker, CRM, MS SQL Server
- SW techniques: UML, BPMN 2.0, ERD, client/server technology
Jochen Hinrichsen
Last position:
DevSecOps Expert at DB InfraGO
- Central build and delivery for 20+ applications, 100+ pipelines/day, 700+ GitLab projects
- Build pipelines for Go, Java and JavaScript
- Provisioning of 100+ components
- Quality assurance via GitLab Code Quality and SonarQube
- Checks for dependencies, licensing and vulnerabilities
- Release creation via Jira and ServiceNow
- SBOM, Supply Chain Security, distroless images
- PoC GitLab Runner: Nomad vs. Kubernetes
- Technologies: Artifactory, buildah, GitLab Premium, Go, Gradle, Jenkins, Mend, Podman
Marc Haid
Last position:
Senior Architect, Coach and Developer
Fixing issues in the application logic
Covering the changes with component tests
Analyzing and documenting the data structure of the different applications
Analyzing and documenting the parameters for configuring the applications
Analyzing and documenting the necessary measures to ensure the operation of the applications
Analyzing and designing the separation of the individual database structures
Analyzing and estimating the effort for planned enhancements
Analysis, maintenance and documentation of a heterogeneous legacy system landscape for a print media service provider
Technology: C#, VB.NET, C, Python, Microsoft SQL Server, Visual Studio 2010, JetBrains Rider, Visual Studio Code, arc42, Draw.io, Jira, GitLab
Kun Pang
Last position:
Working Student - Open-Source Compliance & Tooling at SAP SE
- Developed internal tools using React, Node.js and Python for automating FOSS license analysis and compliance workflows
- Also served as an IP Analyst for IP Scans and SBOM management
- Contributed to SAP’s open source CI/CD project Piper (Golang), supporting engineering teams in integrating IP Scan steps into their pipelines
Nils Klawitter
Last position:
Vulnerability Management and Secure SDLC at DB InfraGO AG
- Successfully implemented vulnerability management with DefectDojo
- Advised on and implemented technical and procedural aspects of vulnerability management with DefectDojo
- Provided guidance on implementing a secure software development lifecycle
- Skills: GitLab, DefectDojo, Vulnerability Management, SCA, SAST, DAST, Python, Kubernetes, Argo CD, Docker, AWS, Azure, WhiteSource/Mend, Greenbone
Christian Gebhardt
Last position:
Deputy Chief Information Security Officer at Gothaer Solutions GmbH
- Deputy lead of the 10-member information security management team in a highly regulated environment (DORA, VAIT, BAIT)
- Direct reporting lines to the CIO of the Gothaer Group and the management board of Gothaer Solutions
- Regular member of the Group Risk Committee and the Compliance Committee
- Managing and coordinating information security processes within the company and with IT service providers
- Leading task forces for handling information security incidents
- Contributing to IT emergency and business continuity management
Discover over 15,000 top freelancers
Statistics of experts using SBOM
Aggregated from the professional profiles of matched freelancers.
Experience
21 years
Position duration
1.8 years
Positions per freelancer
23
Top business areas
Information Technology, Product Development, Project Management
Top industries
Information Technology, Banking and Finance, Transportation
Certification focus areas
Information Technology, Quality Assurance, Audit
Bachelor's degree or higher
75%
Master's degree or higher
42%
Certifications per freelancer
6
Most common languages
German, English, French
Speak two or more languages
93%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using SBOM
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
What SBOM means
An SBOM, or Software Bill of Materials, is a structured list of software components, dependencies, and suppliers. It helps teams see what is inside an application, package, image, or firmware build. Strong specialists turn that inventory into something teams can use in release, security, and procurement work.
Where it is used
- Open source dependency tracking
- Product release documentation
- Vulnerability response and triage
- Supplier and customer security reviews
- Embedded, cloud, and container software
Common formats
The work often centers on CycloneDX and SPDX, plus the tools that generate, validate, and consume them. Experts also need to understand package managers, build pipelines, and signing or provenance data. The best professionals know how to keep the output machine-readable and useful for both security and engineering teams.
Why companies hire help
Companies bring in freelance SBOM specialists when they need clean inventories for a product launch, a customer request, or an audit response. They also step in when dependency data is incomplete, builds are inconsistent, or teams across Germany need a common standard for software transparency. Clear documentation matters as much as tooling.
What strong experts do
- Trace direct and transitive dependencies
- Reconcile source, build, and runtime views
- Define data fields, naming, and version rules
- Align security, product, and procurement needs
- Improve repeatability in CI and release flows
What good delivery looks like
A strong specialist does more than export a file. They make sure the SBOM fits the product, the build process, and the audience that will read it. That may mean helping with policy, integrating checks into CI, or explaining gaps in the data so teams can act with confidence.
Frequently asked questions
The facts hiring teams ask for most often when it comes to SBOM.
SBOM is used to show which components, versions, and suppliers are inside a software product. Companies use it for security reviews, release records, and customer or partner requests. It is especially useful when the software includes many open source libraries or is shipped to regulated buyers.
A Software Bill of Materials is the goal; CycloneDX and SPDX are two common formats used to express it. CycloneDX is often chosen for security-focused workflows, while SPDX is widely used for license and supply chain data as well. A good specialist knows when each format fits the project.
A strong SBOM specialist usually knows dependency analysis, build pipelines, package managers, and vulnerability data. Many also work with container images, signing, provenance, and policy rules. Clear writing matters too, because the output has to make sense to security, product, and procurement teams.
A Software Bill of Materials effort can be simple if the stack is stable and the build is well documented. It becomes harder when there are many services, generated artifacts, or multiple release pipelines. For complex products, companies usually want someone who has already handled messy dependency trees and release edge cases.
Bring in a SBOM freelancer when internal teams need help building a repeatable process, cleaning up component data, or answering a customer request quickly. It also helps when a launch depends on supply chain transparency and the in-house team is busy. Short, focused support can unblock the release without changing the whole organization.
Yes. SBOM work is often remote because the core tasks are about source code, build systems, and documentation, not a physical site. For German teams, remote collaboration is common, but on-site workshops can help when several groups need to agree on naming rules or release steps.
Look for someone who can explain where the data comes from and where it can be incomplete. A good Software Bill of Materials specialist will talk about source, build, and runtime views, not just produce a file. Ask for examples of how they handled duplicate packages, nested dependencies, or unclear version data.
A careful SBOM professional will ask which products, formats, and release stages are in scope. They should also ask who will consume the output, whether license data matters, and how the team wants gaps reported. That avoids rework and keeps the deliverable aligned with real use.
The average hourly rate of freelancers in Germany who have used SBOM in their recent projects is 108 €, which corresponds to a daily rate of about 865 € based on an 8-hour working day.
Of the freelancers in Germany who have used SBOM in their recent projects, 75% hold at least a Bachelor's degree and 42% hold at least a Master's degree.
On average, freelancers in Germany who have used SBOM in their recent projects have 21 years of professional experience, with a single engagement typically lasting around 1.8 years.
The most common languages among freelancers in Germany who have used SBOM in their recent projects are German (100%), English (93%), and French (20%).
The most common industries among freelancers in Germany who have used SBOM in their recent projects are Information Technology (100%), Banking and Finance (67%), and Transportation (67%).
The most common business areas among freelancers in Germany who have used SBOM in their recent projects are Information Technology (100%), Product Development (93%), and Project Management (80%).
Main locations of FRATCH Experts, who have recently used SBOM
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
