Skip to main content
🇩🇪GDPR-compliant
Find the perfect

SBOM Experts in Germany

in minutes from over 15,000 CVs with the power of AI.

Hire experts who create and review Software Bill of Materials, map dependency trees, and support CycloneDX or SPDX delivery for secure releases. Get fast, precise matching with vetted, available freelancers.

Meet FRATCH Experts in Germany, who have recently used SBOM

Verified expert

Arndt Maas

View profile

Project Manager for ServiceNow Vulnerability Response

Mülheim an der Ruhr
Arndt Maas

Last position:

Project Manager for ServiceNow Vulnerability Response at Union Investment Services & IT GmbH

  • Led the subproject for implementing Vulnerability Response as part of DORA
  • Documented the current processes in compliance, risk & security
  • Created the functional design for introducing application, infrastructure, and cloud vulnerabilities
  • Agile management of the integration service provider, the technical department, and the company's cross-functional teams
  • Integrated the V scanners Tenable, Qualys and Defender, as well as NVD and CISA/KEV
  • Integrated GitLab Ultimate for importing and processing SBOMs
  • Developed automation rules to match scan results with CIs in the CMDB, assign vulnerabilities and remediation tasks, handle approvals (false positives, exceptions) and closures
  • Calculated multiple risk scores and priorities
  • Defined dashboards and reports (Workspaces, Performance Analytics)
  • Aligned the new processes, especially to improve the CMDB data quality (according to CSDM)
Verified expert

Andreas Winters

View profile

Senior Solution Architect | Enterprise Architect

Clenze
Andreas Winters

Last position:

Enterprise Architect at Own development / IP of CAMCO Engineering UG

UEF 3.0 · Semantic Government Overlay (SGO) · Autonomous Systems (UAS / dual use)

  • Designed: Semantic Government Overlay (SGO) – AI-guided administration without replacing existing specialist procedures. Read-only semantic layer over registers and specialist processes based on the Federal Information Management (FIM). Decision authority remains with the case worker (architecture principle).
  • Developed: Reference architecture with source-backed, derived statements (Executable Ontologies OWL/RDF/SHACL). Technically guaranteed purpose limitation and no-write-path principle in specialist data – auditable, without a central data pool.
  • Anchored: Regulation as a design principle: EU AI Act (high-risk obligations for public-sector AI, fundamental rights impact assessment under Art. 27), GDPR, NIS2, and administrative automation limits (§ 35a VwVfG, § 31a SGB X) as technical control points in the architecture.
  • Created: Methodical tool for pilot organizations: data pipeline assessment (phase 0), compliance blueprint, and management summary as a decision-ready package for public administration.
  • Specified: UEF 3.0 as a successor architecture to TOGAF – decision paper, canonical ontology, six-layer architecture, read/actuate boundary, federation registry, terminology concordance, and release delta as a closed specification status.
  • Architected: AI-native mission OS for autonomous UAS and ground robotics as a tactical layer on top of a separately approved autopilot. Run-time assurance according to ASTM F3269-21 (Simplex pattern): the verified safety controller keeps authority, the AI function provides suggestions.
  • Designed: Three-tier architecture – Tier 0 autopilot with 650 Hz flight control on RTOS, Tier 1 AI OS with semantic world model and multi-agent cluster, Tier 2 swarm and ground mesh. Zenoh as the primary fabric, MAVLink as the only authenticated command path (single writer). Result: graceful degradation – loss of the mission, not of the aircraft.
  • Secured: Two-gate chain on the read/actuate boundary – governance gate (can-question: AI Act risk class per actuation, enforced human oversight under Art. 14, immutable log) before the RTA safety monitor (is-it-correct question: flight envelope, geofence, energy reserve) with revert to the baseline controller.
  • Anchored: Dual-use architecture with common core and build-time fork instead of runtime switch. Three separate legal levels: civil variant – UAS under the EASA Basic Regulation (EU) 2018/1139 with the limited applicability under Art. 2(2) of the AI Act, ground robotics under the Machinery Regulation 2023/1230 with the full high-risk obligation chain, Cyber Resilience Act for both; unarmed carrier variant as defense material under AWG/AWV and Dual-Use Regulation 2021/821 (BAFA approval); armed variant under KrWaffKontrG. Each variant lives under exactly one dominant legal regime. Evidence base: AI BOM, SBOM, and complete data lineage.
  • Analyzed: System analysis and realignment of grown engineering system landscapes. Approach concept for consolidation without migration – semantic layer over the existing sources instead of data transfer. Result: decision-ready implementation concept including an evaluation model for the target architecture.
Verified expert

Dimitri Wolinski

View profile

Senior IT Consultant, Software Architect, Pimcore Enterprise Consultant and Developer, Backend Web Developer

Mainz
Dimitri Wolinski

Last position:

Software Architect at Environmental services company (cooperation with Sitegeist Media Solutions GmbH)

Conceptual design and implementation of a modular customer portal based on Laravel.

The focus was on defining a maintainable system architecture with broad use of Domain-Driven Design principles (within the Laravel architecture), introducing automated quality assurance processes (test strategy, CI integration), and preparing an auditable operation (logging, traceability of changes) in an AWS-based infrastructure, taking IT security standards according to NIST and process requirements according to ISO 9001 into account.

Achievements:

  • Analysis and structuring of business requirements in close coordination with stakeholders
  • Documentation of the system architecture and infrastructure incl. change and release management
  • Design and implementation of an interface for integrating SAP systems
  • Planning and implementation of automated tests for quality assurance
  • Implementation of security and compliance requirements, including SBOM generation, software license management, and QA processes
  • Technical consulting and support for the internal IT team
  • Introduction and establishment of AI-supported development processes (Spec-Driven Development), including AI-readable specifications, integration of AI instructions into the development environment, and training developers for productive use

Technologies and tools: SAP, Docker, ddev, PHP 8.4, Laravel, Filament, C4 Model, Architecture Decision Records (ADR), Mermaid, PlantUML, Spec-Driven Development, Claude, GitHub Copilot, Codex

Verified expert

Jens Rehsack

View profile

Technical Product Owner

Kerpen
Jens Rehsack

Last position:

Technical Product Owner at App Development

  • Development of a mobile app to slow down the progression of dementia

  • Coordination of software development (TPO – Technical Product Owner)

  • agile requirements management (agile requirements engineering)

  • prioritization of tasks in consultation with stakeholders

  • stakeholder management

  • documentation and management of the software architecture

  • conducting PoC for technology decisions

  • Documentation as Code

  • docToolchain, arc42, req42, aim42, tpo42, C4 model, Archimate

  • ADR, Architecture Decision Records

  • Docker

  • Pre-Commit, Conventional Commits, Semantic Versioning

  • Liberating Structures, Agile Principles, Holacracy, Sociocracy 3.0

  • Mobile frameworks

  • AI developing interfaces, LLM

  • Cordova, Unity

  • Google Gemini, OpenAI, Character.AI

  • Prompt development

Verified expert

Manuel Engelhardt

View profile

External Technical Lead for CI/CD, Architecture & Technical Governance

Essen
Manuel Engelhardt

Last position:

External Technical Lead for CI/CD, Architecture & Technical Governance at Insurance

  • Technical lead for CI/CD modernization in the "Group Archive 4.0" system
  • Architecture and steering responsibility according to the statement of work
  • Setting up modern build and deployment processes
  • CI/CD coaching and enablement of the internal development team
  • Integration of modern DevOps, security, and compliance standards
  • Ensuring technical governance, including collaboration with internal audit and BaFin
  • Independently executing the modernization measures
  • Supporting the team in adopting new technologies and methods
Verified expert

Hichem Blagui

View profile

IT Security Consultant & Data Engineer / Freelancer

Augsburg
Hichem Blagui

Last position:

IT Security Consultant & Data Engineer / Freelancer at datadefend GmbH

  • Analysis and further development of the security architecture.
  • Design and development of Splunk apps and technical add-ons (TAs).
  • Development and implementation of security use cases in the Splunk SIEM.
  • Creation and maintenance of incident response playbooks in Cortex XSOAR.
  • Support of technical proof-of-concepts to assess new detection technologies.
  • Lifecycle management and operational support for Splunk and Cribl systems.
  • Deployment and scaling of Splunk indexers in hybrid data center environments.
  • Maintenance, update planning, and optimization of Cribl Stream & Edge for log ingestion and data routing.
  • Creation of dashboards and reports to visualize security posture and system availability.
  • Technical analysis to assess network topologies and data flows.
  • Integration of new data sources via Cribl Stream/Edge and heavy forwarders in cloud and on-prem environments.
  • Integration of external security components such as Cortex XSOAR (SOAR) and user behavior analytics (UBA).
  • Implementation of complex correlation rules in Splunk Enterprise Security (ES).
  • Connection of external ticketing systems via mail gateways and REST APIs.
  • Automated deployment of use cases, dashboards, and detection rules via Git and Ansible.
Verified expert

Werner Keil

View profile

Test Coordinator, Designer and Engineer

Bad Homburg
Werner Keil

Last position:

Test Coordinator, Designer and Engineer at IBM

  • Testing the SekIDP and related components
  • Test design, execution and automation, microservices, GitHub Enterprise, Eclipse, Katalon Test Platform, API Testing, Confluence 8, JIRA/Xray, Draw.io, Swagger/OpenAPI, Postman, Docker, Kubernetes, Podman, PuTTY, E-Health, Telematik, Gematik standards, EPA, E-Rezept, sektoraler IDP, encryption, XaDES, PaDES, DICOM, HL7, FHIR, IHE, ICD, SSO, SAML/Shibboleth, OAuth, smartcards, JWT, two factor authentication Android and iOS, Wireshark, BrowserStack, Cypress, gRPC, REST, SOAP, WS-Security, Linux Shell, PowerShell, SSH/SSL, Java, Kotlin, Cordova, Gradle, Groovy, Python, TypeScript
Verified expert

Pierre Gronau

View profile

Ansible Automation, Windows Third Level Support

Cologne
Pierre Gronau

Last position:

Ansible Automation, Windows Third Level Support at DB InfraGO AG

  • PRISMA project
  • Ansible automation
  • Windows third level support for Windows NT, Windows 2000, Windows 2013, Windows 2016, Windows 2019
Verified expert

Jürgen Hertweck

View profile

iOS App Development (AI-based)

Ottobrunn
Jürgen Hertweck

Last position:

iOS App Development (AI-based) at Refreco GmbH

  • Development of iOS apps in Swift
  • AI-supported SW development using Vibe Coding with Claude Code
  • Web applications through Vibe Programming
  • Use of Swift, Xcode 15, Claude Code, Proxmox, GitLab, Visual Studio Code, Cursor, Doors, ClearCase
  • Use of MS Project, OpenShift, Docker, Project Server, PageMaker, CRM, MS SQL Server
  • SW techniques: UML, BPMN 2.0, ERD, client/server technology
Verified expert

Jochen Hinrichsen

View profile

Managing Director

Eschborn
Jochen Hinrichsen

Last position:

DevSecOps Expert at DB InfraGO

  • Central build and delivery for 20+ applications, 100+ pipelines/day, 700+ GitLab projects
  • Build pipelines for Go, Java and JavaScript
  • Provisioning of 100+ components
  • Quality assurance via GitLab Code Quality and SonarQube
  • Checks for dependencies, licensing and vulnerabilities
  • Release creation via Jira and ServiceNow
  • SBOM, Supply Chain Security, distroless images
  • PoC GitLab Runner: Nomad vs. Kubernetes
  • Technologies: Artifactory, buildah, GitLab Premium, Go, Gradle, Jenkins, Mend, Podman
Verified expert

Marc Haid

View profile

Senior Architect, Coach and Developer

Sörgenloch
Marc Haid

Last position:

Senior Architect, Coach and Developer

  • Fixing issues in the application logic

  • Covering the changes with component tests

  • Analyzing and documenting the data structure of the different applications

  • Analyzing and documenting the parameters for configuring the applications

  • Analyzing and documenting the necessary measures to ensure the operation of the applications

  • Analyzing and designing the separation of the individual database structures

  • Analyzing and estimating the effort for planned enhancements

  • Analysis, maintenance and documentation of a heterogeneous legacy system landscape for a print media service provider

  • Technology: C#, VB.NET, C, Python, Microsoft SQL Server, Visual Studio 2010, JetBrains Rider, Visual Studio Code, arc42, Draw.io, Jira, GitLab

Verified expert

Kun Pang

View profile

Working Student - Open-Source Compliance & Tooling

Heidelberg
Kun Pang

Last position:

Working Student - Open-Source Compliance & Tooling at SAP SE

  • Developed internal tools using React, Node.js and Python for automating FOSS license analysis and compliance workflows
  • Also served as an IP Analyst for IP Scans and SBOM management
  • Contributed to SAP’s open source CI/CD project Piper (Golang), supporting engineering teams in integrating IP Scan steps into their pipelines
Verified expert

Nils Klawitter

View profile

Vulnerability Management and Secure SDLC

Lübeck
Nils Klawitter

Last position:

Vulnerability Management and Secure SDLC at DB InfraGO AG

  • Successfully implemented vulnerability management with DefectDojo
  • Advised on and implemented technical and procedural aspects of vulnerability management with DefectDojo
  • Provided guidance on implementing a secure software development lifecycle
  • Skills: GitLab, DefectDojo, Vulnerability Management, SCA, SAST, DAST, Python, Kubernetes, Argo CD, Docker, AWS, Azure, WhiteSource/Mend, Greenbone
Verified expert

Christian Gebhardt

View profile

Deputy Chief Information Security Officer

Köln
Christian Gebhardt

Last position:

Deputy Chief Information Security Officer at Gothaer Solutions GmbH

  • Deputy lead of the 10-member information security management team in a highly regulated environment (DORA, VAIT, BAIT)
  • Direct reporting lines to the CIO of the Gothaer Group and the management board of Gothaer Solutions
  • Regular member of the Group Risk Committee and the Compliance Committee
  • Managing and coordinating information security processes within the company and with IT service providers
  • Leading task forces for handling information security incidents
  • Contributing to IT emergency and business continuity management

Discover over 15,000 top freelancers

Statistics of experts using SBOM

Aggregated from the professional profiles of matched freelancers.

Experience

21 years

Position duration

1.8 years

Positions per freelancer

23

Top business areas

Information Technology, Product Development, Project Management

Top industries

Information Technology, Banking and Finance, Transportation

Certification focus areas

Information Technology, Quality Assurance, Audit

Bachelor's degree or higher

75%

Master's degree or higher

42%

Certifications per freelancer

6

Most common languages

German, English, French

Speak two or more languages

93%

Based on our profile pool as of 30 Aug 2026.

Daily rate distribution

0 2 4 6 8
<€640 €640-​800 €800-​960 €960-​1120 €1120-​1280 €1280+

The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates of experts in Germany using SBOM

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 865 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 840 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

About the technology

What SBOM means

An SBOM, or Software Bill of Materials, is a structured list of software components, dependencies, and suppliers. It helps teams see what is inside an application, package, image, or firmware build. Strong specialists turn that inventory into something teams can use in release, security, and procurement work.

Where it is used

  • Open source dependency tracking
  • Product release documentation
  • Vulnerability response and triage
  • Supplier and customer security reviews
  • Embedded, cloud, and container software

Common formats

The work often centers on CycloneDX and SPDX, plus the tools that generate, validate, and consume them. Experts also need to understand package managers, build pipelines, and signing or provenance data. The best professionals know how to keep the output machine-readable and useful for both security and engineering teams.

Why companies hire help

Companies bring in freelance SBOM specialists when they need clean inventories for a product launch, a customer request, or an audit response. They also step in when dependency data is incomplete, builds are inconsistent, or teams across Germany need a common standard for software transparency. Clear documentation matters as much as tooling.

What strong experts do

  • Trace direct and transitive dependencies
  • Reconcile source, build, and runtime views
  • Define data fields, naming, and version rules
  • Align security, product, and procurement needs
  • Improve repeatability in CI and release flows

What good delivery looks like

A strong specialist does more than export a file. They make sure the SBOM fits the product, the build process, and the audience that will read it. That may mean helping with policy, integrating checks into CI, or explaining gaps in the data so teams can act with confidence.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

The facts hiring teams ask for most often when it comes to SBOM.

SBOM is used to show which components, versions, and suppliers are inside a software product. Companies use it for security reviews, release records, and customer or partner requests. It is especially useful when the software includes many open source libraries or is shipped to regulated buyers.

A Software Bill of Materials is the goal; CycloneDX and SPDX are two common formats used to express it. CycloneDX is often chosen for security-focused workflows, while SPDX is widely used for license and supply chain data as well. A good specialist knows when each format fits the project.

A strong SBOM specialist usually knows dependency analysis, build pipelines, package managers, and vulnerability data. Many also work with container images, signing, provenance, and policy rules. Clear writing matters too, because the output has to make sense to security, product, and procurement teams.

A Software Bill of Materials effort can be simple if the stack is stable and the build is well documented. It becomes harder when there are many services, generated artifacts, or multiple release pipelines. For complex products, companies usually want someone who has already handled messy dependency trees and release edge cases.

Bring in a SBOM freelancer when internal teams need help building a repeatable process, cleaning up component data, or answering a customer request quickly. It also helps when a launch depends on supply chain transparency and the in-house team is busy. Short, focused support can unblock the release without changing the whole organization.

Yes. SBOM work is often remote because the core tasks are about source code, build systems, and documentation, not a physical site. For German teams, remote collaboration is common, but on-site workshops can help when several groups need to agree on naming rules or release steps.

Look for someone who can explain where the data comes from and where it can be incomplete. A good Software Bill of Materials specialist will talk about source, build, and runtime views, not just produce a file. Ask for examples of how they handled duplicate packages, nested dependencies, or unclear version data.

A careful SBOM professional will ask which products, formats, and release stages are in scope. They should also ask who will consume the output, whether license data matters, and how the team wants gaps reported. That avoids rework and keeps the deliverable aligned with real use.

The average hourly rate of freelancers in Germany who have used SBOM in their recent projects is 108 €, which corresponds to a daily rate of about 865 € based on an 8-hour working day.

Of the freelancers in Germany who have used SBOM in their recent projects, 75% hold at least a Bachelor's degree and 42% hold at least a Master's degree.

On average, freelancers in Germany who have used SBOM in their recent projects have 21 years of professional experience, with a single engagement typically lasting around 1.8 years.

The most common languages among freelancers in Germany who have used SBOM in their recent projects are German (100%), English (93%), and French (20%).

The most common industries among freelancers in Germany who have used SBOM in their recent projects are Information Technology (100%), Banking and Finance (67%), and Transportation (67%).

The most common business areas among freelancers in Germany who have used SBOM in their recent projects are Information Technology (100%), Product Development (93%), and Project Management (80%).

Main locations of FRATCH Experts, who have recently used SBOM

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH