Skip to main content
🇩🇪GDPR-compliant
Find the perfect

SOAR Experts in Germany

in minutes from over 15,000 CVs with the power of AI

Hire experts who automate incident response, connect SIEM and ticketing tools, and build playbooks for Security Orchestration, Automation and Response. Get fast, precise matching with vetted, available freelancers.

Meet FRATCH Experts in Germany, who have recently used SOAR

Verified expert

Florian Schröder

View profile

Information Security Officer / IT Security Architect / Awareness Expert

Norderstedt
Florian Schröder

Last position:

Information Security Officer / Designated InfoSec Officer at Oil Company

  • Complete overhaul of the ISMS according to ISO 27001
  • Conducted a comprehensive gap analysis
  • Reduced ISMS documentation by 30% through consolidation and process optimization
  • Introduced a full PDCA cycle for continuous improvement
  • Established the ISMS within the company
  • Implemented the necessary processes
  • Managed and conducted internal and external audits
  • Developed and implemented a company-wide risk management system
  • Deployed an ISMS tool including process design and training
  • KRITIS compliance: Prepared and provided required evidence, liaised with regulatory authorities, planned, documented, and implemented an attack detection system (SIEM), co-led the BCMS/ITSCM implementation subproject
  • NIS-2 implementation: Gap analysis, risk assessments, training for executives and staff
  • Led a cybersecurity team of 3 members
  • Conducted various internal and external audits, managed providers, introduced continuous improvement
  • Project consulting: closely coordinated with business and system owners, launched an online shop, a mobile app, and a customer portal
  • Redesigned the security architecture, reducing administrative efforts by 20%
  • Implemented ITIL processes (e.g., change management)
  • Revised service agreements with internal and external providers
  • Developed a security awareness strategy, ran social engineering tests, introduced and monitored phishing simulations, created various awareness materials, gave presentations
  • Managed a budget of one million euros
Verified expert

Tan Pham

View profile

DevOps & Fullstack Engineer

Hanau
Tan Pham

Last position:

DevOps Engineer in the DevOps Team at Rise-World

  • Implementation of specified DevOps solutions to automate infrastructure (Terraform, Bicep, CloudFormation, Ansible) on-premises datacenter (Ovirt, Proxmox, Ceph Cluster, MinIO) and private cloud.
  • Administration, configuration and implementation of CI/CD DevOps pipelines (GitLab, GitFlow) to support development process (Artifactory, Prometheus, Istio, service mesh, Helm Chart, OpenShift (Red Hat Enterprise) / Kubernetes cluster), Red Hat Satellite.
  • Administration, setup, monitoring and patching of Linux infrastructure based on Red Hat Enterprise for Dev, Test and QA.
  • Use of Scrum and Kanban methods.
  • Administration, configuration and implementation of security standards for deploying on Dev, Test, QA and Prod stages of the new ePA applications.
  • Development of new plugins and add-ons needed on current infrastructure.
  • Database support.
  • Data analytics support (Python, Spark, Pandas, Power BI, Splunk Enterprise).
  • Implementation of best practices for DevSecOps and BizDevOps using GitOps (ArgoCD), Streamlit framework, Semaphore Ansible UI.
  • Configuration and testing of iperf, uperf, sysbench using benchmark-operator for external source data and IoT/MDM devices, creating reports via ELK / OpenSearch.
  • Building a new Databricks platform to collect and analyze big data from different sources and IoT devices into Hadoop framework (Python, Pandas, PySpark, Power BI, Apache Airflow).
  • Building backend data aggregation and processing to automate configuration deployment between different OpenShift clusters and big data framework (Python, Pandas, PySpark, Apache Spark, PostgreSQL, Django 2, Ansible Automation, Jira JSM).
  • Building a new ML pipeline platform using Kubeflow, TensorFlow, KServe.
  • Data extraction, transformation and loading from different data sources including structured and unstructured data to analytic DWH / big data cluster using Python, Pandas, Polars, Power BI, Django backend and PostgreSQL.
  • Setup of new DevOps Test and QA HashiCorp Vault cluster for PKI and IAM.
  • Configuration and testing of automated patching based on CVSS score, SIEM-integrated CVEs.
  • Use of Nexpose and InsightVM to scan vulnerability events in network, host, container and application.
  • Design and implementation of secure and scalable AWS architectures including VPC, EC2, S3, RDS and Route53 and similar setups on Azure and GCP.
  • Automated system provisioning and deployment using CloudFormation templates.
  • Configuration of IAM roles, policies and permissions to ensure secure access control.
  • Patch management, backup automation and disaster recovery setup on AWS infrastructure.
  • Monitoring and optimization of system performance using AWS CloudWatch and AWS Trusted Advisor.
  • Support of VMware services (vSphere, Aria, Horizon) and the virtual desktop environment.
  • Development and maintenance of CI/CD pipelines using Jenkins, GitLab CI/CD and AWS CodePipeline with interface to Nutanix.
  • Configuration of AWS CloudWatch to monitor application performance and system events.
  • Planning and execution of migration of on-premises applications to AWS cloud platforms.
  • Deployment of containerized applications using Docker and Kubernetes in AWS environments.
  • Deployment of internal software packages between availability zones using AWS CodeDeploy.
  • Building and deploying ML models using Scikit-learn, XGBoost and Spark MLlib including hyperparameter tuning, model evaluation and production deployment.
Verified expert

Alex Volnov

View profile

CTO, Co-Founder, Cryptography(incl. Post-Quantum Cryptography) and AI Security Expertise

Alex Volnov

Last position:

CTO, Co-Founder, Cryptography(incl. Post-Quantum Cryptography) and AI Security Expertise at AISLEIPNIR

  • Integration of Post-Quantum Cryptography (PQC) algorithms into high level protocols.
  • Security of implementations of Post-Quantum Cryptography algorithms.
  • Transition to Post-Quantum public key infrastructures.
  • Security evaluations of Post-Quantum Cryptography (PQC) primitives.
  • Drone Cybersecurity
  • Satellite Cybersecurity
  • AI Security
Verified expert

Federico Leefhelm

View profile

ISO – Senior Consultant Quality & Information Security

Düsseldorf
Federico Leefhelm

Last position:

Senior IAM Manager & Single Point of Contact for Information Security at EnBW Energie Baden-Württemberg AG

As the only large integrated energy company in Germany, EnBW covers the entire value chain - from energy production through distribution to customers. It expands its renewable energy sources, advocates for a socially responsible coal exit, and drives key technologies like green hydrogen. A rapid energy transition and achieving climate neutrality by 2035 are priorities for EnBW.  Developed and implemented a holistic process view covering both technical and organizational aspects  Ensured end-to-end control of all IAM-related technical services  Established clear responsibilities and accountabilities within the IAM landscape  Collaborated with different departments to identify and optimize a holistic architecture and act as Single Point of Contact (SPoC) for Information Security  Introduced and monitored governance policies to ensure compliance and security  Continuously improved IAM processes and systems through regular audits and evaluations  Participated in external audits of the process as part of official ISO audits  Further developed the policy for setting administrative requirements and procedures and aligned it with administrative units  Conceptually advanced the KPI system to measure process quality

Verified expert

Andreas Ilias

View profile

Senior Cybersecurity Governance & ISMS Consultant

Frankfurt am Main
Andreas Ilias

Last position:

Cybersecurity Specialist Assessor at Bundesnetzagentur

  • Recognition of national notified bodies
  • Preparation of cybersecurity competency reports
  • EU Radio Equipment Directive
Verified expert

Sergey Komarov

View profile

Managing Director Cybersecurity

Stuttgart
Sergey Komarov

Last position:

Managing Director Cybersecurity at CBA-Cybersecurity and Business Advisory GmbH

  • Development of comprehensive services in cybersecurity, IT governance, and AI
  • Building and delivering strategic security solutions such as vCISO service, ISMS, SOC-as-a-Service (SIEM, SOAR, use cases, playbooks, threat hunting, incident response), AI-driven risk and compliance tools, and frameworks for outsourcing and third-party risks
  • Supporting companies in meeting regulatory requirements and certifications (ISMS, NIS-2, DORA, CRA, KRITIS, ISO 27001, TISAX, BSI IT Baseline Protection, EU AI Act)
  • Promoting innovations in cybersecurity automation, AI governance, and secure digital transformation
  • Responsible for company growth, client relations, and strategic partnerships
Verified expert

Hichem Blagui

View profile

IT Security Consultant & Data Engineer / Freelancer

Augsburg
Hichem Blagui

Last position:

IT Security Consultant & Data Engineer / Freelancer at datadefend GmbH

  • Analysis and further development of the security architecture.
  • Design and development of Splunk apps and technical add-ons (TAs).
  • Development and implementation of security use cases in the Splunk SIEM.
  • Creation and maintenance of incident response playbooks in Cortex XSOAR.
  • Support of technical proof-of-concepts to assess new detection technologies.
  • Lifecycle management and operational support for Splunk and Cribl systems.
  • Deployment and scaling of Splunk indexers in hybrid data center environments.
  • Maintenance, update planning, and optimization of Cribl Stream & Edge for log ingestion and data routing.
  • Creation of dashboards and reports to visualize security posture and system availability.
  • Technical analysis to assess network topologies and data flows.
  • Integration of new data sources via Cribl Stream/Edge and heavy forwarders in cloud and on-prem environments.
  • Integration of external security components such as Cortex XSOAR (SOAR) and user behavior analytics (UBA).
  • Implementation of complex correlation rules in Splunk Enterprise Security (ES).
  • Connection of external ticketing systems via mail gateways and REST APIs.
  • Automated deployment of use cases, dashboards, and detection rules via Git and Ansible.
Verified expert

Bernhard Bowitz

View profile

Senior Security Architect

Wiesbaden
Bernhard Bowitz

Last position:

Senior Security Architect at Intermediate Beratung

  • Consulting on an ongoing IT security architecture project
  • Documenting past progress and planning next steps
  • Applying and implementing the BSI IT baseline protection
  • Building and maintaining security management systems
  • Applying the ISO 27001 standard series
  • Integrating ITIL processes into security architectures
  • Collaborating with public clients, regulatory authorities and internal and external service providers
Verified expert

Jan Kopia

View profile

Consultant for Information Security & Auditor

Berlin
Jan Kopia

Last position:

Consultant for Information Security & Auditor at Kopiasonsulting GmbH

  • Operational management of the company: building teams and infrastructure, developing products, analysis and implementation of IT security measures

  • Project assignments in the IT security environment focusing on establishing blue teaming activities (defensive processes and technologies) to defend against cyber attacks

  • Conducting red teaming processes, including penetration tests and security analyses for companies

  • Consulting on setting up Security Operation Centers and implementing SIEM systems, and building Computer Incident Response Teams (CSIRT)

  • Auditor for ISO 9001 and ISO 27001, § 8a, ISO 27019, § 11 1a EnWG, TISAX

  • Advising companies in critical infrastructures on information security and compliance with the IT Security Act

  • Building SIEM/SOC processes and SOC analyst work (Splunk, ELK-Stack)

  • Integrating data into monitoring tools (Prometheus, Grafana)

  • Consulting on BSI IT baseline protection, ISO 9001, ISO 27001, BCM, ITIL and risk management

  • Security assessments and penetration testing of IT and network architectures

Verified expert

Henryk Orantek

View profile

Security Consultant

Blankenfelde-Mahlow
Henryk Orantek

Last position:

Security Consultant at Daimler AG

  • Development of a cloud security strategy
  • Implementation of cloud security governance to comply with ISO/IEC 27017 and the CSA CCM
  • Creation of a management system to control cloud security with a focus on process design as well as roles and responsibilities
  • Definition of security measures to safeguard cloud solutions
  • Conducting requirements analyses and defining the scope for cloud security projects
  • Achievements: Established an effective NIS2-compliant cloud security governance that meets industry-specific requirements and effectively minimizes cloud security risks

Discover over 15,000 top freelancers

Statistics of experts using SOAR

Aggregated from the professional profiles of matched freelancers.

Experience

24 years

Position duration

1.8 years

Positions per freelancer

17

Top business areas

Information Technology, Project Management, Operations

Top industries

Information Technology, Automotive, Banking and Finance

Certification focus areas

Information Technology, Audit, Project Management

Bachelor's degree or higher

100%

Master's degree or higher

73%

Doctorate

27%

Certifications per freelancer

9

Most common languages

German, English, Spanish

Speak two or more languages

100%

Based on our profile pool as of 30 Aug 2026.

Daily rate distribution

0 1 2 3 4
<€640 €640-​800 €800-​960 €960-​1120 €1120+

The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.

Average rates of experts in Germany using SOAR

Rates are based on recent contracts and do not include FRATCH margin.

1000
750
500
250
Rate comparison chart
Daily rate avg. 868 €

The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.

1000
750
500
250
Rate comparison chart
Median rate 800 €

The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.

Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.

About the technology

What SOAR does

SOAR stands for Security Orchestration, Automation and Response. It helps security teams turn alerts into repeatable actions, so common incidents can be triaged, enriched, assigned, and closed with less manual work. In practice, it sits between SIEM, ticketing, threat intel, and endpoint tools.

Typical use cases

  • Alert triage and deduplication
  • Enrichment with threat intel and asset data
  • Phishing and malware response playbooks
  • Case management and audit trails
  • Hand-offs between security and IT teams

These workflows are often the first reason companies bring in freelance SOAR specialists.

Tooling and ecosystem

Strong SOAR work usually means more than one product. Common stacks include Palo Alto Networks Cortex XSOAR, Splunk SOAR, and IBM Security QRadar SOAR, plus integrations with SIEM, EDR, email security, identity, and service desk systems. Experts also need to understand APIs, webhooks, JSON, and the limits of each connector.

What strong experts deliver

A good SOAR specialist designs playbooks that are clear, safe, and easy to maintain. They document escalation paths, test failure cases, tune approvals, and make sure automation does not create new risk. They also know when a step should stay manual.

When companies need help

Freelance support is useful when a SOC is growing, a tool rollout is stuck, or existing automations are messy and hard to trust. Teams in Germany often look for help on remote playbook work, but on-site sessions can matter for workshops, process mapping, and stakeholder sign-off. Clear English is common in the tooling; German helps in local operations.

How to judge fit

Look for experts who can explain both the security process and the technical build. They should show real examples of incident workflows, integration work, and change control, not just product names. For SOAR, the best professionals reduce noise, keep analysts in control, and leave behind automation the team can actually run.

Published on:
FRATCH GPT

FRATCH GPT delivers freelancer proposals with clear reasoning and transparent pricing in minutes, helping your hiring department quickly and compliantly find the best talent.

Give it a try:

Try FRATCH GPT

Frequently asked questions

Quick answers to the questions that come up most around SOAR.

SOAR stands for Security Orchestration, Automation and Response. It is used to connect tools, enrich alerts, and run repeatable response steps for phishing, malware, account abuse, and other incidents. Good implementations reduce manual handoffs and make response more consistent.

SOAR does not replace a SIEM; it usually works with one. A SIEM collects and correlates security data, while SOAR helps teams act on the alerts, run playbooks, and track response tasks. Many projects pair the two so analysts can move from detection to action faster.

SOAR is often used as the umbrella term, but searchers also mean products such as Cortex XSOAR, Splunk SOAR, and IBM Security QRadar SOAR. Older references may still mention Phantom or Demisto, which are former names in the same space. A strong freelancer knows the product and the workflow behind it.

A strong SOAR freelancer usually understands APIs, JSON, regex, webhooks, and basic scripting. Security process knowledge matters too, especially incident handling, threat intel, IAM, EDR, and service desk workflows. Without those skills, automations tend to break in real operations.

A SOAR project needs more than tool familiarity if it touches live incident handling. You want someone who has built playbooks, tested edge cases, and worked with analysts who will use the workflow every day. For a first rollout, process experience is often more important than product badges.

Yes, SOAR work is often done remotely because most tasks happen in the platform, in tickets, and in integration reviews. For teams in Germany, remote collaboration works well when processes are documented and stakeholders can review playbooks asynchronously. On-site time can still help at the start of a rollout or during workshop-heavy phases.

A good SOAR specialist explains why each step exists, not just how to click through the tool. Look for clean playbooks, safe approvals, solid logging, and examples of failed-path testing. If they can reduce noise and keep analysts in control, they are on the right track.

A thoughtful SOAR freelancer will ask about incident volumes, current tools, approval rules, and the team’s tolerance for automation. They should also ask who owns each integration and who signs off on changes. Those answers shape whether the work is a quick fix, a new build, or a cleanup of legacy automations.

The average hourly rate of freelancers in Germany who have used SOAR in their recent projects is 108 €, which corresponds to a daily rate of about 868 € based on an 8-hour working day.

Of the freelancers in Germany who have used SOAR in their recent projects, 100% hold at least a Bachelor's degree, 73% hold at least a Master's degree, and 27% hold a doctorate.

On average, freelancers in Germany who have used SOAR in their recent projects have 24 years of professional experience, with a single engagement typically lasting around 1.8 years.

The most common languages among freelancers in Germany who have used SOAR in their recent projects are German (100%), English (100%), and Spanish (27%).

The most common industries among freelancers in Germany who have used SOAR in their recent projects are Information Technology (91%), Automotive (64%), and Banking and Finance (64%).

The most common business areas among freelancers in Germany who have used SOAR in their recent projects are Information Technology (100%), Project Management (82%), and Operations (73%).

Main locations of FRATCH Experts, who have recently used SOAR

Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.

Berlin Hamburg Munich Cologne Frankfurt Stuttgart Dusseldorf Leipzig Dortmund Essen Bremen Dresden Hanover Nuremberg

Request a free demo

Get in touch with the FRATCH team and we will get back to you within 4 hours.

Contact form

Would you rather directly get in touch?
We always have the time for a call or email!

FRATCH CEO avatar

Philipp Thomaschewski

FRATCH CEO

LinkedInFRATCH