Terraform Experts in Germany
in minutes from over 15,000 CVs with vetted, available specialists.Hire experts who design Terraform modules, manage infrastructure as code, and build safe cloud environments across AWS, Azure, and Google Cloud. Get fast, precise matching with vetted, available freelancers.
Meet FRATCH Experts in Germany, who have recently used Terraform
Khalid El Mansouri
Last position:
Lead Architect & Developer at kem-consulting
Development of an agent-based governance platform for the automated assurance of EU AI Act compliance and ODA-compliant orchestration of AI services in complex enterprise environments.
Design and implementation of an agent-based "Mission Control" framework (Aletheia Conductor) for autonomous state monitoring and process control.
Development of "Compliance-as-Code" (CaC) solutions based on OPA/Rego for system-wide enforcement of regulatory guardrails.
Integration of TM Forum ODA standards (TMF630, TMF622, TMF642) to ensure interoperability and standardization.
Building a highly available event-driven architecture using Redpanda and CloudEvents v1.0 for near-real-time event processing.
Implementation of an audit-proof "Evidence Chain" through cryptographic linking of trace logs in preparation for automated audits.
Tech Stack: Java 21 (Quarkus Native), TypeScript (Next.js), Redpanda (Kafka API), CloudEvents v1.0, OPA (Open Policy Agent) & Rego, TimescaleDB, ZincSearch, Redis, TM Forum ODA, Git, GitHub, Clean Code Development, Like-C4.
Jens Henneberg
Last position:
Interim CTO (occasional assignments) at Fujitsu / FSAS
Stabilizing an Azure/.NET landscape in live operation.
- Architecture, DevOps, and operational readiness; technical decisions under time pressure
- Azure DevOps, monitoring, ETL/ELT, cloud security, FinOps, and data-mesh-related topics
Technologies: Azure DevOps, .NET, CI/CD, monitoring, FinOps
Ornel Franck Wora Yeno
Last position:
Purchasing Manager, Logistics & IT Manager at Onlinehandler
Proactive support of management in business field development & innovation management
New development of a suite of business applications for analyzing valuation, P&L, and market price risk data
Automation of all internal and external business and work processes
Development of AI-based and AI-supported ETL processes as well as data analysis
Business use-case development
Business and work process optimization
Enterprise architecture management
Sales data analysis and forecasting as well as capture
Inventory management & reordering
Supplier management and communication
Customs processing & clearance
Shipping handling & warehouse coordination
Interface management
Technologies used: Microsoft Office 365, Microsoft Teams, JTL-Wawi, JTL-WMS, OTTO Partner Connect (OPC), Amazon Seller Central, DHL Global Forwarding, Jira, Draw.IO, Java (8,17,21,25), Jenkins, SonarQube, Git, Gitea, Spring Boot, Spring Batch, Vaadin, H2, PostgreSQL, Docker, Local LLMs, Postman, JasperSoft Studio, JasperReports
Collin Kempkes
Last position:
Lead Fullstack Developer at Freelance
- Development of cloud native applications to provide a multi-vendor marketplace for different digital assets (e.g. NFTs)
- Design and operation of a microservice architecture using Nest.js, MySQL, Redis, Hasura, Algolia, Docker and Serverless
- Design and operation of a streaming data architecture using Kafka (with JSON Schemas)
- Creation of CI/CD pipelines with GitHub Actions for automated deployment of applications
- Testing and evaluating new technologies for more stable, faster, safer and more sustainable application development
- Building the full infrastructure with Terraform in AWS
- Integration of Stripe to handle international payments
- Use of Algolia for real-time search of digital assets on the platform
- Presenting results to stakeholders and running internal meetups
- Federation of services with GraphQL and Hasura
- Discussions about architecture decisions in the IT landscape and their impact
- Use of message queues for app-internal communication and component encapsulation
- Advising internal staff on the implementation of business and technical requirements
- Test Driven Development: unit, integration and E2E testing using JUnit
- Use of Next.js/React with SASS/SCSS for frontend applications
- Use of Vue.js with SASS/SCSS for frontend applications
- Integration of security-related mechanisms (JWT tokens with Auth0, OAuth, OIDC, IP guards, BOLA, secret vaults)
- Creation of microfrontends using Retool for fast prototyping and testing of functionality
- Use of nx monorepo with nrwl
Harold Tela
Last position:
CPU Watcher — Cloud-Native Monitoring Application at SEUYTEL
Developed a CPU monitoring application using Spring Boot and React, containerized with Docker Compose, with automated infrastructure provisioning using Terraform on AWS.
Stack: Spring Boot, React, PostgreSQL, REST API, Docker Compose, Terraform, AWS
Matthias Spiller
Last position:
Software Developer and Consultant at CLADE GmbH
- Analysis of the existing CAN communication between microcontrollers
- Analysis of the sensors used and the measured values collected
- Planning the CAN messages for transmitting the measured values
- Iterative adjustment of the microcontroller code to the new CAN messages
- Cross-compilation from x64 to arm64
Marijn Scholtens
Last position:
Senior Software Engineer at Puls Security GmbH
Optimizing and acceleration of our Gitlab CI pipeline
Conceptual work for the PoC of the Zero Trust system
Extension of the policy-engine backend in Go
Extension of the policy-testing mechanism in Python
Architectural design of the PEP component of Zero Trust
Documentation of the product
Technologies: Zero Trust, Go, Python, Gitlab CI, Docker, JWT, Domain-Driven Design
Shamaila Mahmood
Last position:
MCP, Kubernetes, Helm, Docker, Terraform, Typescript, Java, SpringBoot, Go Lang, React at Kubekanvas
- Development of a browser-based platform for no-code deployment and cluster management in Kubernetes
- Implementation of a CLI tool in TypeScript to provision resources directly from the browser interface into the cluster
- Development of a expression parser in Go and delivery as a microservice to extract Helm expressions from values files
- Use of LLMs to turn user intent into Kubernetes diagrams
- Technology stack: Java, Go, OpenAI API, React, Azure, Next.js, Strapi, Stripe Connect
Alejandro Prieto
Last position:
DevOps Consultant at Freelance
- Kubernetes: EKS management, cluster upgrades and stability improvements, Infrastructure-as-Code reviews and updates, AWS support, and cost optimization.
Martin Hermann
Last position:
Lead Product Owner at Energy
- Team leadership: Prioritization and coordination of four cross-functional teams.
- Platform strategy: Development and implementation of strategies to optimize existing IT platforms.
- Stakeholder management: Active management of expectations and communication with internal and external stakeholders.
- Program and innovation management: Prioritization and coordination of cross-department projects as well as innovation initiatives.
- Product Owner consulting: Advising Product Owners with a focus on product development and continuous product improvement.
- Organizational development: Improving communication and decision-making structures across all organizational levels.
- Change management: Implementing best-practice change management methods to ensure continuous optimization and innovation.
- Quality assurance: Ensuring high quality standards in processes, services, and deliverables.
Ali Aminian
Last position:
Platform Engineer & Software Architect at Yatta GmbH
- Architected the Yatta Integration Layer – a config-driven integration platform on Java 25, Spring Boot 4 (WebFlux), Temporal, gRPC and Kafka, enabling new third-party integrations (e.g. AVS fulfillment) via declarative JSON configs with zero code changes.
- Designed and implemented Tink integration with 0Auth IBAN verification to enhance fraud prevention and account validation workflows with Adyen payByBank.
- Architected and implemented an OpenFGA-based authorization model for centralized management of users, groups, and fine-grained access control in the vendor portal.
- Architected and led delivery of the Yatta API Gateway platform using GraphQL Federation, providing a unified enterprise API layer across distributed microservices with centralized authentication, authorization and request orchestration.
- Replaced NGINX + NLB with Istio service mesh and AWS ALB; rolled out WAF, OAuth (Cognito), IP whitelisting and RBAC across environments.
- Migrated CDC from Confluent Cloud connectors to a self-hosted Kafka Connect + Debezium stack, reducing operational cost by ~80% across multiple environments.
- Implemented the Transactional Outbox pattern with Debezium for reliable, exactly-once event publishing to Kafka with Avro and Schema Registry.
- Migrated dunning/payment-recovery workflows from Airflow to Temporal, achieving 99.9% reliability for settlement handling.
- Optimised Apache Airflow with deferrable sensors to handle 1000+ concurrent DAG runs without scaling the worker pool.
- Refactored a monolithic Terraform codebase into 3 modular projects, cutting deployment time by ~45%.
- Stood up full observability with OpenTelemetry, Tempo, Prometheus and Loki; automated dev/staging/prod with ArgoCD, Image Updater and Helm.
- Collaborated with product, operations and engineering stakeholders to define scalable platform architecture and integration standards aligned with long-term business and operational goals.
Niklas Witzel
Last position:
AI Engineer at Tensora GmbH
- Designed and developed a multi-tenant SaaS platform enabling organizations to build their own knowledge bases and chat with brand-customized AI assistants (white-label approach with dynamic branding per organization).
- Implemented a scalable RAG architecture with a GPT-4o tool-use loop, hybrid semantic search, and strict tenant isolation at database and search index level.
- Built persistent, project-like chat sessions including a streaming API (SSE), multilingual support, and speech input/output (STT/TTS).
- Delivered the cloud infrastructure as Infrastructure-as-Code, fully automated per-customer CI/CD pipelines, and an onboarding process for new tenants.
Technologies used: Python, FastAPI, Pydantic (v2 noted), Next.js, React, TypeScript, Tailwind CSS, OpenAI / LLMs (GPT-4o), Azure AI Search, Cosmos DB, Azure Blob Storage, Azure Cognitive Services Speech, Azure App Service, Azure Container Registry, Retrieval-Augmented Generation (RAG), Server-Sent Events (SSE), Docker, Terraform, GitHub Actions, REST, OpenID Connect (OIDC), Multi-Tenancy
Boris Solos
Last position:
Generalist expert for software development at Mercor
- Training the AI models, evaluating images and texts for UI/UX, turning the provided data into insights via OpenAI Feather as part of the machine learning workflow
Technologies: OpenAI Feather
Frédéric Klein
Last position:
Project Manager (Enterprise Cloud Governance) at CompuGroup Medical SE & Co. KGaA
Short description: Leading a group-wide project to establish standardized cloud governance for Microsoft Azure, including policies, security and compliance controls, automation, and cost and operations management while preserving the autonomy of decentralized business units within regulatory frameworks.
Tasks and activities:
Overall responsibility for designing, building, and implementing a company-wide cloud governance structure (Azure), including target picture, roadmap, and operating model.
Managing internal and external stakeholders (C-level, IT, Security, Compliance, Cloud Architecture, DevOps), including decision and escalation management.
Planning and facilitating workshops on cloud strategy, governance principles, and the design of areas such as identity, connectivity, and platform management.
Defining, implementing, and rolling out cloud policies (Azure Policy / custom policies), security standards, and compliance requirements (including GDPR, ISO 27001, BSI C5).
Building a cloud governance framework based on the Azure Cloud Adoption Framework (CAF), including landing zone and guardrail concepts.
Introducing automation solutions for governance, security, and cost control (policy/control automation, IaC, CI/CD-based control mechanisms).
Implementing cloud security and compliance monitoring mechanisms as well as continuous improvement processes.
Establishing and operationalizing FinOps in an enterprise environment (central and decentralized FinOps teams), including cost management strategies, reporting, and guardrails.
Integrating governance policies into DevOps processes (e.g. CI/CD principles for security and compliance checks, GitLab Runner concept in spokes, GitLab CI/CD for CAF landing zones).
Implementing access concepts including RBAC design and breaking-glass mechanisms (emergency access) as well as certificate automation (ACME / step-ca).
Achievements:
Created a unified, auditable governance and control set for Azure (policies, standards, compliance mapping) and thus laid the foundation for scalable cloud use in a regulated environment.
Established repeatable automation for governance, security, and cost control (IaC + CI/CD), reducing manual effort and implementation risk.
Improved operational and decision-making capability across central and decentralized units (clearer roles, responsibilities, escalation paths, balance between autonomy and group requirements).
Significantly increased workload compliance during lift-and-shift migrations.
Technologies used:
Microsoft Azure Policy, custom policies.
Terraform, OpenTofu, Terragrunt.
step-ca (ACME).
Entra ID.
Azure Firewall.
Azure Networking, hub-and-spoke architecture.
Azure vWAN (evaluation).
Azure Front Door, Azure Application Gateway.
Azure ExpressRoute.
Azure Key Vault.
NetBox.
GitLab (on-premises).
Infrastructure, concepts used:
Cloud shared responsibility model.
Hub-and-spoke connectivity / central shared services (from hub-spoke context).
Central governance with decentralized delivery (business unit autonomy with guardrails).
Methods used:
Scrum.
Stakeholder management (C-level to engineering).
Cloud governance, Azure Cloud Adoption Framework (CAF).
DevOps, CI/CD.
Cost and FinOps approaches: tagging/chargeback models, budget/alert concepts, reserved instances/savings plans vs. on-demand scenarios, sensitivity analyses.
RBAC, breaking-glass concepts.
ACME / certificate automation.
GitLab Runner concept in spokes, GitLab CI/CD pipelines for CAF landing zones.
Halil Oeztoprak
Last position:
Senior Cloud Operations & DevSecOps Engineer (Azure / Terraform / CI-CD) at KfW Bankengruppe
Regulated environment within a German banking group (approx. 8,500 employees, hybrid cloud strategy).
Responsible for operating, provisioning, and continuously securing business-critical platforms – including a GenAI chat application, a big data/AI platform, and data science workspaces based on Azure Virtual Desktops and VMs. Ownership of Azure DevOps projects for ShaiHulud and React2Shell, as well as BSI alerts – Security Operations improvements across the SDLC.
Deployment responsibility for the GenAI chat application, big data/AI platform (BDAI), and data science workspaces (AVD/VM-based) in the respective landing zones.
Deployment & release management: end-to-end responsibility for deploying portal and service applications across multiple Azure landing zones, including technical approvals, compliance with development team deployment guidelines, and ensuring ITIL-based change and release processes via ServiceNow.
Azure landing zones & network architecture: design, provisioning, and operation of Azure landing zones for 3-tier web applications with enhanced network segmentation, VNet peering, hub-and-spoke architectures, private endpoints, and firewall integration across separate subscriptions and tenants.
Azure DevOps governance & operations: ownership of the Azure DevOps organization, including projects, repositories, and CI/CD pipelines; implementation of governance requirements such as branch policies, approval gates, permission models, and audit-ready operating structures.
Infrastructure as Code (Terraform): design, implementation, and operation of a modular Terraform architecture for standardized cloud infrastructure deployment, including state management, provider versioning, reusability, and policy-as-code approaches.
CI/CD pipeline engineering: design, operation, and optimization of complex YAML-based CI/CD pipelines with multi-stage deployments, template standardization, self-hosted agents, integrated secret management, and automated quality and security checks.
Git migration & platform consolidation: planning and execution of repository and pipeline migration from Azure DevOps to GitLab CI/CD, including automated scripts, full Git history transfer, pipeline porting, and platform consolidation.
Container & platform operations (AKS): operation and security assessment of containerized workloads on Azure Kubernetes Service, centralization of on-premises container registries for ACR.
OpenShift (OCP) security reviews: security assessment of code baselines, build pipelines, and deployment processes for on-premises OpenShift clusters with critical applications, and derivation of specific hardening recommendations.
Shift-left security & DevSecOps transformation: introduction of a company-wide shift-left approach for early security integration in development and deployment processes, enabling developers to perform self-led security checks and sustainably reduce vulnerabilities before production (IDE integrations, pre-commit hooks, local scanners).
Software supply chain security: analysis and mitigation of supply chain risks in NPM- and Yarn-based applications through dependency audits, CI/CD pipeline hardening, token rotation, and restriction of risky build and lifecycle mechanisms.
Frontend & framework security (React / Next.js): security assessment and coordination of critical vulnerability remediation across platform applications and web frameworks, including coordination and complementary technical mitigations with all teams following BSI alerts.
Software composition analysis (SCA): introduction and operation of automated vulnerability scans for container images, pipelines/artifacts, and third-party dependencies, including SBOM exports within CI/CD pipelines.
SAST/DAST integration: design and piloting of static and dynamic application security tests in close collaboration with security architecture and development teams, for continuous improvement of code and runtime security, and establishing operational acceptance tests.
Artifact & registry consolidation: analysis and consolidation of all package and container repositories for service applications and AKS workloads, aiming for a centralized, secured registry strategy with centralized vulnerability scanning and governance.
Dependency-Track & SBOM strategy: advising the compliance board on introducing a central SBOM and vulnerability management platform to increase enterprise-wide dependency transparency and accelerate CVE response capability.
CI/CD pipeline hardening: security analysis and cleanup of the existing pipeline landscape by removing unused pipelines, improving secrets hygiene, implementing least-privilege principles, and isolating build agent environments.
Azure Web Application Firewall (WAF) optimization: analysis and tuning of existing Azure WAF rules (OWASP Top 10 Core Rule Set, DSR/SDC, custom rules) to defend against known vulnerabilities and exploit patterns, including reducing false positives and improving threat detection.
Documentation & stakeholder communication: creating and maintaining technical documentation, runbooks, and architecture overviews in Jira and Confluence, as well as active knowledge transfer between operations, development, security, and compliance stakeholders.
Discover over 15,000 top freelancers
Statistics of experts using Terraform
Aggregated from the professional profiles of matched freelancers.
Experience
16 years
Position duration
2 years
Positions per freelancer
11
Top business areas
Information Technology, Product Development, Operations
Top industries
Information Technology, Banking and Finance, Automotive
Certification focus areas
Information Technology, Product Development, Project Management
Bachelor's degree or higher
90%
Master's degree or higher
56%
Doctorate
8%
Certifications per freelancer
3
Most common languages
English, German, Spanish
Speak two or more languages
97%
Based on our profile pool as of 30 Aug 2026.
Daily rate distribution
The chart shows how the daily rates of freelancers in this technology in Germany are distributed, based on recent contracts on our platform. Each bar covers a rate range — its height shows how many freelancers charge within that range.
Average rates of experts in Germany using Terraform
Rates are based on recent contracts and do not include FRATCH margin.
The average daily rate is the mean of all daily rates from recent contracts of comparable freelancers on our platform.
The median daily rate is the middle value of all daily rates — half of comparable freelancers charge less, half charge more. Unlike the average, it is barely affected by outliers.
Calculated based on our freelancers’ daily rates as of 30 Aug 2026. Actual rates may vary depending on seniority level, experience, skill specialization, project complexity, and engagement length.
About the technology
Infrastructure as code
Terraform is used to define cloud and platform infrastructure in code. Teams use it to create repeatable environments, keep changes reviewable, and reduce manual setup across development, test, and production.
What experts deliver
- Cloud networks, compute, storage, and IAM
- Reusable modules for shared infrastructure patterns
- Environment provisioning for AWS, Azure, and Google Cloud
- State management, remote backends, and safe change plans
Ecosystem and tooling
Strong professionals work with Terraform CLI, providers, modules, workspaces, and state files. They also know how to pair it with Git, CI pipelines, secret handling, and policy checks so infrastructure changes stay controlled and traceable.
When companies bring them in
Teams call in freelance Terraform specialists when infrastructure has become inconsistent, slow to change, or hard to audit. This is common in cloud migrations, multi-account setups, platform standardization, and release automation.
What good specialists know
A strong Terraform expert writes clear modules, avoids state drift, and understands provider behavior. They plan for dependency order, locking, versioning, and safe rollouts, not just getting resources created.
Germany projects
In Germany, Terraform work often supports cloud platforms, regulated environments, and internal enterprise tooling. Companies usually want experts who can collaborate in English and align with local teams, whether the work is remote or partly on-site.
Frequently asked questions
Quick answers to the questions that come up most around Terraform.
Terraform is used to define and manage cloud infrastructure as code. Companies use it for networks, servers, databases, IAM, and platform services that need to be created the same way every time. It is also common for environment setup, module reuse, and controlled infrastructure changes.
Terraform is strongest when you want one workflow across several cloud providers and services. Compared with CloudFormation, it is not tied to AWS, and compared with Ansible it is more focused on provisioning than configuration tasks. Many teams use Terraform for infrastructure and keep Ansible for software setup where needed.
A strong Terraform specialist usually knows a major cloud provider such as AWS, Azure, or Google Cloud. Useful adjacent skills include Git, CI pipelines, Linux basics, networking, IAM, and secret management. For larger estates, module design and state handling are especially important.
A Terraform project can start with a single specialist if the environment is small and well defined. Larger estates need someone who can handle modules, state, provider versions, and change safety across teams. The more cloud accounts and environments you have, the more important real hands-on depth becomes.
Yes, Terraform work is often done remotely, especially when the tasks are code review, module design, or pipeline integration. For German companies, the main question is usually how well the specialist can coordinate with local teams and security rules. On-site time is sometimes useful for workshops, but it is rarely required for day-to-day work.
A good Terraform deliverable is readable, modular, and safe to change. Look for clear naming, reusable modules, sensible state layout, and plans that do not create surprises. The best specialists also document dependencies and explain how future changes should be applied.
If infrastructure changes are handled by hand, drift keeps appearing, or no one trusts the state of the environment, Terraform help is usually overdue. Other signs are duplicated configs, broken pipelines, and modules that are hard to reuse. A specialist can often stabilize the setup before the next release cycle.
For many teams, Terraform is still a strong choice for new infrastructure because it has a broad provider ecosystem and a mature workflow. It is especially practical when you need repeatable provisioning across several services or cloud vendors. If your main need is application configuration rather than infrastructure, another tool may fit better.
The average hourly rate of freelancers in Germany who have used Terraform in their recent projects is 101 €, which corresponds to a daily rate of about 807 € based on an 8-hour working day.
Of the freelancers in Germany who have used Terraform in their recent projects, 90% hold at least a Bachelor's degree, 56% hold at least a Master's degree, and 8% hold a doctorate.
On average, freelancers in Germany who have used Terraform in their recent projects have 16 years of professional experience, with a single engagement typically lasting around 2 years.
The most common languages among freelancers in Germany who have used Terraform in their recent projects are English (98%), German (97%), and Spanish (15%).
The most common industries among freelancers in Germany who have used Terraform in their recent projects are Information Technology (98%), Banking and Finance (46%), and Automotive (36%).
The most common business areas among freelancers in Germany who have used Terraform in their recent projects are Information Technology (100%), Product Development (82%), and Operations (57%).
Main locations of FRATCH Experts, who have recently used Terraform
Our freelancers and interim experts are at home across the DACH region — available on-site in the major business hubs or fully remote. Choose a location to discover matched specialists, local market insights and up-to-date availability.
Request a free demo
Get in touch with the FRATCH team and we will get back to you within 4 hours.
Would you rather directly get in touch?
We always have the time for a call or email!

Berlin
Hamburg
Munich
Cologne
Frankfurt
Stuttgart
Dusseldorf
Dortmund
Essen