Shibboleth Experts in Germany
in minutes from over 15,000 CVs with the power of AI.Hire experts who set up Shibboleth SSO, SAML federation, identity provider and service provider flows, and secure access for universities, public bodies, and enterprise apps. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Shibboleth
Frédéric Klein
Last position:
Project Manager (Enterprise Cloud Governance) at CompuGroup Medical SE & Co. KGaA
Short description: Leading a group-wide project to establish standardized cloud governance for Microsoft Azure, including policies, security and compliance controls, automation, and cost and operations management while preserving the autonomy of decentralized business units within regulatory frameworks.
Tasks and activities:
Overall responsibility for designing, building, and implementing a company-wide cloud governance structure (Azure), including target picture, roadmap, and operating model.
Managing internal and external stakeholders (C-level, IT, Security, Compliance, Cloud Architecture, DevOps), including decision and escalation management.
Planning and facilitating workshops on cloud strategy, governance principles, and the design of areas such as identity, connectivity, and platform management.
Defining, implementing, and rolling out cloud policies (Azure Policy / custom policies), security standards, and compliance requirements (including GDPR, ISO 27001, BSI C5).
Building a cloud governance framework based on the Azure Cloud Adoption Framework (CAF), including landing zone and guardrail concepts.
Introducing automation solutions for governance, security, and cost control (policy/control automation, IaC, CI/CD-based control mechanisms).
Implementing cloud security and compliance monitoring mechanisms as well as continuous improvement processes.
Establishing and operationalizing FinOps in an enterprise environment (central and decentralized FinOps teams), including cost management strategies, reporting, and guardrails.
Integrating governance policies into DevOps processes (e.g. CI/CD principles for security and compliance checks, GitLab Runner concept in spokes, GitLab CI/CD for CAF landing zones).
Implementing access concepts including RBAC design and breaking-glass mechanisms (emergency access) as well as certificate automation (ACME / step-ca).
Achievements:
Created a unified, auditable governance and control set for Azure (policies, standards, compliance mapping) and thus laid the foundation for scalable cloud use in a regulated environment.
Established repeatable automation for governance, security, and cost control (IaC + CI/CD), reducing manual effort and implementation risk.
Improved operational and decision-making capability across central and decentralized units (clearer roles, responsibilities, escalation paths, balance between autonomy and group requirements).
Significantly increased workload compliance during lift-and-shift migrations.
Technologies used:
Microsoft Azure Policy, custom policies.
Terraform, OpenTofu, Terragrunt.
step-ca (ACME).
Entra ID.
Azure Firewall.
Azure Networking, hub-and-spoke architecture.
Azure vWAN (evaluation).
Azure Front Door, Azure Application Gateway.
Azure ExpressRoute.
Azure Key Vault.
NetBox.
GitLab (on-premises).
Infrastructure, concepts used:
Cloud shared responsibility model.
Hub-and-spoke connectivity / central shared services (from hub-spoke context).
Central governance with decentralized delivery (business unit autonomy with guardrails).
Methods used:
Scrum.
Stakeholder management (C-level to engineering).
Cloud governance, Azure Cloud Adoption Framework (CAF).
DevOps, CI/CD.
Cost and FinOps approaches: tagging/chargeback models, budget/alert concepts, reserved instances/savings plans vs. on-demand scenarios, sensitivity analyses.
RBAC, breaking-glass concepts.
ACME / certificate automation.
GitLab Runner concept in spokes, GitLab CI/CD pipelines for CAF landing zones.
Alexander Schwartz
Last position:
Founder and Full-Stack Developer at TrumpPostAlert.com
- Feasibility study for quick implementation of requirements with AI-based development (vibe coding)
- Development of a single-page web app in Angular 20
- Development of a backend server application in Kotlin
- Integration with Google Cloud Platform (Firebase): authentication, Firestore NoSQL database, storage, Cloud Functions, hosting and Cloud Run
- Integration with a NEON PostgreSQL database
- Automated AI-based analysis of Donald Trump's posts on Truth Social and analysis of relevance for stock markets and geopolitical topics
- CI/CD via GitHub Actions using Docker and Google Cloud Run
- Technical environment: Angular 20 (Angular Material, RxJS), Kotlin 2.2.20, TypeScript 5.9.3, Spring Boot 3.5.6, Google Cloud Platform (Firebase, Cloud Run, Gemini, Vertex AI), ChatGPT Codex, Git, GitHub, SourceTree, IntelliJ WebStorm, IntelliJ IDEA
Ottavio Braun
Last position:
Semantic Test Framework for LLMs
Werner Keil
Last position:
Test Coordinator, Designer and Engineer at IBM
- Testing the SekIDP and related components
- Test design, execution and automation, microservices, GitHub Enterprise, Eclipse, Katalon Test Platform, API Testing, Confluence 8, JIRA/Xray, Draw.io, Swagger/OpenAPI, Postman, Docker, Kubernetes, Podman, PuTTY, E-Health, Telematik, Gematik standards, EPA, E-Rezept, sektoraler IDP, encryption, XaDES, PaDES, DICOM, HL7, FHIR, IHE, ICD, SSO, SAML/Shibboleth, OAuth, smartcards, JWT, two factor authentication Android and iOS, Wireshark, BrowserStack, Cypress, gRPC, REST, SOAP, WS-Security, Linux Shell, PowerShell, SSH/SSL, Java, Kotlin, Cordova, Gradle, Groovy, Python, TypeScript
Frederik Claus
Last position:
Freelance Fullstack Software Developer at Bundesdruckerei GmbH
Development of the digital organ donation register, commissioned by the Federal Institute for Drugs and Medical Devices (BfArM)
Implementation of user stories in multiple microservices (front- and backend)
Ensuring quality with unit, integration, and end-to-end tests
Conducting code reviews
Coordination with other development teams
Taking over software license checks and simplifying the process
Responsible for implementing and documenting domain logging
Setting up a development environment with Docker Compose
Thomas Karcher
Last position:
Lead Developer & Integrator | Process Platform Orchestration
- Focus: Developing a central platform to manage user flows and data between survey tools and marketing systems.
- Technology: Laravel middleware with Keycloak integration.
Discover over 15,000 top freelancers
Statistics of experts using Shibboleth
Aggregated from the professional profiles of matched freelancers.
Experience
12 years
Position duration
1.3 years
Positions per freelancer
11
Top business areas
Information Technology, Product Development, Quality Assurance
Top industries
Information Technology, Banking and Finance, Healthcare
Bachelor's degree or higher
40%
Master's degree or higher
20%
Certifications per freelancer
1
Most common languages
German, English, French
Speak two or more languages
100%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Shibboleth
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
SSO and federation
Shibboleth is used for single sign-on and identity federation. It connects identity providers and service providers so users can access many systems with one login. That makes it a common choice for portals, research networks, intranets, and partner-facing applications.
Core components
- Shibboleth IdP for authentication and attribute release
- Shibboleth SP for protecting applications and content
- SAML metadata, certificates, and trust setup
- Attribute mapping for roles, groups, and affiliations
Strong specialists know how these parts fit together and how to keep them stable when policies change.
Where it fits
Shibboleth often sits between internal apps, SaaS tools, and external identity systems. It is common in higher education, public sector environments, and enterprise setups that need controlled access across domains. In Germany, companies also bring in experts when teams must align local user flows with international federation partners.
Typical engagements
- New identity provider or service provider rollout
- Migration from older SSO flows to SAML-based access
- Metadata exchange and certificate rotation
- Attribute release policy review
- Troubleshooting login failures and consent issues
Freelance help is useful when deadlines are tight or the existing team knows the app side but not federation details.
Skills that matter
Good Shibboleth professionals understand SAML, XML, certificates, LDAP or Active Directory, and how applications consume attributes. They should also read logs well, test end-to-end login flows, and work with security and infrastructure teams. Experience with Shibboleth IdP, Shibboleth SP, and related federation standards is a strong sign of depth.
What strong experts deliver
Strong experts do more than make login work once. They document trust relationships, clean up metadata handling, harden signing and encryption settings, and reduce support tickets caused by broken attributes or expired certificates. They also help teams keep integrations maintainable when apps, directories, or federation rules evolve.
Frequently asked questions
Need clarity? These are the questions we hear most often about Shibboleth.
Shibboleth is used for single sign-on and identity federation. It lets users authenticate once and then access multiple services through trusted identity and service provider relationships. Companies use it when they need controlled access across internal systems, partner portals, or external research and education networks.
Shibboleth is most often chosen for SAML-based federation, especially where existing identity and attribute exchange models already exist. OAuth and OpenID Connect are common for modern app login and API authorization, while Shibboleth often fits established enterprise or academic federation setups. A good specialist can explain when to keep SAML and when to add another protocol.
A strong Shibboleth specialist usually knows SAML, XML, certificates, metadata, and directory services such as LDAP or Active Directory. They should also understand attribute release rules, trust chains, and how service providers consume identity data. Good log analysis skills matter because many issues only show up during end-to-end login tests.
The answer depends on your setup. Shibboleth IdP work focuses on authentication, user attributes, and policy, while Shibboleth SP work focuses on protecting applications and consuming assertions. Many projects need both sides understood, even if the freelancer only implements one of them.
A Shibboleth project needs someone who has already handled real federation work, not just read the docs. Login flows look simple until metadata, certificates, attributes, and session handling all have to line up. If your app touches external identity providers or many downstream systems, depth matters more than broad general IT experience.
Yes. Most Shibboleth work can be done remotely because it involves configuration, metadata exchange, testing, and log review. For teams in Germany, remote collaboration works well if there is clear access to test systems and someone local who can coordinate security and infrastructure decisions when needed.
Look for evidence of production federation work, not only training or lab setups. A good Shibboleth professional can explain certificate handling, attribute release, troubleshooting steps, and how they reduced login failures in past work. Clear documentation and structured testing are strong signs of quality.
The most common Shibboleth issues are broken metadata, expired certificates, missing attributes, clock skew, and application settings that do not match the assertion format. SSO can fail at several points, so a good specialist checks the full flow instead of only one log file. This is why federation experience matters so much.
The average hourly rate of freelancers in Germany who have used Shibboleth in their recent projects is 108 €, which corresponds to a daily rate of about 868 € based on an 8-hour working day.
Of the freelancers in Germany who have used Shibboleth in their recent projects, 40% hold at least a Bachelor's degree and 20% hold at least a Master's degree.
On average, freelancers in Germany who have used Shibboleth in their recent projects have 12 years of professional experience, with a single engagement typically lasting around 1.3 years.
The most common languages among freelancers in Germany who have used Shibboleth in their recent projects are German (100%), English (100%), and French (33%).
The most common industries among freelancers in Germany who have used Shibboleth in their recent projects are Information Technology (100%), Banking and Finance (67%), and Healthcare (67%).
The most common business areas among freelancers in Germany who have used Shibboleth in their recent projects are Information Technology (100%), Product Development (100%), and Quality Assurance (100%).
Main locations of FRATCH Experts, who have recently used Shibboleth
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!
