Konstantinos M.

IT System Engineer / Senior Service Desk Consultant

Unterhaching, Germany

Experience

Jan 2025 - Mar 2025
3 months

IT System Engineer / Senior Service Desk Consultant

Client in the critical infrastructure sector

  • IT infrastructure service
  • IT services, networks, Exchange, Office 365 & 2016
  • IT documentation
  • Collaboration with external partners & managed provider
  • Stakeholder management
  • Technologies: MS Project 2016, Cloud, HP, DELL, ITIL v3, MS Azure, MS Office 365 Business, MS Outlook ver. 2501, MS Teams, MDM (SOPHOS), Confluence, SLA, Baramundi ver. 2023 R1, processes, CMDB-ACMP, license management, Active Directory (AD)/ AGDLP, license management with the SAM tool ACMP
May 2024 - Dec 2024
8 months

Project Manager / Overall Transition Project Manager

Client in the critical infrastructure sector (KRITISV)

In my role as overall project manager and subproject manager in a service transition project for managed services, I was responsible for the following solid, hands-on tasks and used a wide range of modern tools and standards:

  • Project and resource planning: Designing, controlling, and monitoring the project plan with MS Project 2016. Defining milestones and KPIs in line with ISO 9000 quality management.
  • Quality and service management: Implementing and optimizing service design and transition processes according to ITIL v3 and ISO/IEC 20000. Defining SLAs, monitoring them, and managing escalation processes in ServiceNow.
  • IT infrastructure consulting: Designing a hybrid cloud architecture based on MS Azure and Active Directory (AD) using the AGDLP principle. Selecting and rolling out Lenovo servers and virtualizing with CORBOX VMs.
  • Asset and license management: Consolidating all CMDB topics in ServiceNow CMDB. Introducing software asset management with the Smart Track tool from USU/Aspera.
  • Communication & collaboration: Managing stakeholders and reporting via MS Office 365 (Outlook, Teams, SharePoint) and Confluence. Leading steering committee and specialist group meetings.
  • Change and cutover planning: Developing a detailed action plan (cutover plan) including rollback scenarios, documented in Confluence. Test management and tracking handover tests with XRAY for Jira.
  • Mobile device management & security: Implementing EMM strategies with Intune and MobileIron. Hardening endpoints, patch management, and policy enforcement via Ivanti.
  • Process and tool integration: Automating and orchestrating ITSM processes in ServiceNow and Jira Service Management. Managing interfaces between Office tools, CMDB, and MDM.
  • Documentation, compliance & training: Creating standardized templates, runbooks, and manuals in SharePoint. Ensuring compliance with ISO 9000, ISO/IEC 20000, SLAs, and internal governance requirements. Knowledge transfer and training of the 2nd/3rd level support team.
  • This holistic, tool-supported approach ensured both service transition and long-term operational stability and compliance at the highest level.
  • Technologies: MS Project 2016, ISO 9000, Cloud / Active Directory (AD)/ AGDLP, ISO/IEC 20000, Lenovo, ITIL v3, MS Azure, MS Office 365, MS Outlook, MS Teams, MDM (Intune), SharePoint, Confluence, SLA, CORBOX VMs, service design, service transition, processes, CMDB topics, license management, license management with the Smart Track tool from USU/Aspera, Ivanti, XRAY from Jira, MobileIron, ServiceNow
Oct 2023 - Feb 2024
5 months

Computer Science Instructor

Zukunftsmotor GmbH

  • IT project manager in ITSM
  • IT system engineer
  • Network management (IPv4 and IPv6)
  • IT documentation
  • Business management
  • IT server administration
  • Service desk management
  • Educational institution
  • Technologies: Azure, Cisco, Cloud, firewall, HP, ITIL v3 & v4, MS Azure, MS Office 365, MS Outlook, MS Teams, SharePoint, Sophos, SQL, SQL Server, VPN, network management, data centers, operating systems
Oct 2022 - Oct 2023
1 year 1 month

Project Manager / IT System Engineer IT Infrastructure

Client in the critical infrastructure sector (BSI)

As part of a strategic mandate to develop IT infrastructure management holistically, I was responsible for the following solid, hands-on services:

  • IT infrastructure consulting and governance: Providing technical and methodological guidance for realigning infrastructure management. This included defining policies, KPIs, and metrics for continuous performance and cost control.
  • Current state analysis and target concept: Systematically capturing the existing infrastructure topology, OS and storage versions, and virtualization platforms. Using gap analysis and benchmarking, I developed a detailed target vision covering performance, security, and compliance requirements.
  • System engineering for cloud & on-premises: Implementing and operating Windows Server clusters (2016/2019), SAN and NAS storage systems (NetApp, EMC), and virtualization environments (VMware vSphere, Microsoft Hyper-V). Automating deployments and configuration management with Ansible and PowerShell DSC.
  • Network transformation and IPv6 migration: Designing, planning, and executing the switch from layer-2 switching and layer-3 routing from IPv4 to IPv6. Creating a cutover and rollback plan that considered dual-stack architectures, 6to4 tunneling, and NAT64/DNS64 translation methods for seamless protocol coexistence.
  • Interface and requirements management: Acting as intermediary between departments, central IT teams, and external service providers. Applying agile methods (Scrum/Kanban) in requirements engineering, with documentation in Jira and Confluence.
  • Agile ITSM and project management: Introducing iterative project workflows in Jira Service Management, including sprint planning and retrospective reviews. Coordinating change advisory board meetings following ITIL v3 & v4 to ensure quick decision-making.
  • Digital workplace planning: Defining and reviewing requirements for a modern digital workplace: automated Baramundi unattended installations, support strategies for Skype for Business and Microsoft Teams in parallel operation, and self-service portals to ease end-user support.
  • Quality assurance and documentation: Defining test and review scenarios in the quality assurance manual. Continuously monitoring process quality through audits and KPI reports, with automated tracking in ServiceNow.
  • Technical concept development for data centers: Creating detailed process and network blueprints for both on-premises data centers and Azure Entra ID-based cloud environments. Including dual-stacking at layer 2/3 and failover and high-availability architectures.
  • Service process optimization and emergency management: Adjusting existing incident, change, and problem management processes. Creating runbooks and playbooks for business continuity. Conducting table-top exercises and training for 2nd/3rd-level support teams.
  • 2nd & 3rd level support and CAB membership: Managing incident, change, and problem tickets in infrastructure and CMS/CMDB. Actively participating in the Change Advisory Board (ITIL v3 & v4) to approve complex infrastructure changes.
  • Project management & IT infrastructure analysis: Designing and managing the overall project using PRINCE2/Scrum, including setting up extensive infrastructure assessments (servers, storage, network) with discovery tools and performance monitoring.
  • Operational IT service management: Establishing and running cloud- and on-premises-based ITSM processes according to ITIL v3/v4. Coordinating daily operations, monitoring SLAs, and handling escalations through Jira Service Management.
  • Strategy consulting & data center architecture: Developing a data center strategy, defining target designs, and mapping all relevant assets in the CMDB (e.g., FNT Command, ServiceNow CMDB) for full transparency and lifecycle governance.
  • Mobile device management & enterprise mobility: Planning and implementing EMM profiles with Samsung Knox Mobile Enrollment (Android Enterprise) and Esper MDM. Configuring and administering Ivanti/Magenta Admin for device-based policy enforcement and compliance.
  • Exchange migration on-premises → Microsoft 365: Creating and executing a detailed cutover plan to migrate Exchange Server on-premises to Microsoft 365 Exchange Online. Migrating mailboxes, public folders, and archives while ensuring data integrity.
  • Managed service provider (MSP) profile management: Defining and managing MSP service profiles, configuring them in central management portals for automated service delivery.
  • Security and email protection: Integrating and operating Proofpoint for email security, threat intelligence, and advanced threat protection.
  • Microsoft 365 suite administration: Managing users and licenses in the Microsoft 365 admin center, handling Exchange, SharePoint, and OneDrive policies, configuring security features (MFA, Conditional Access), monitoring and reporting via Microsoft 365 Compliance Center.
  • Microsoft Exchange Admin Center: Managing mailboxes, distribution and resource groups, security settings, and monitoring and reporting on the Exchange infrastructure.
  • Microsoft Teams & Skype for Business administration: Migrating from Skype for Business on-premises to Microsoft Teams, managing users and policies in the Teams admin center, app management, and real-time monitoring of presence and messaging services.
  • Identity & access management: Administering Azure Entra ID, Active Directory, ADFS farms, and FSMO roles in the data center; implementing conditional access policies and privileged identity management (PIM).
  • Power Platform governance: Configuring and monitoring in the Power Platform admin center, governance models for Power Apps, Power Automate, and Dataverse.
  • Endpoint management with Baramundi Management Suite: Unattended installations and software deployment, patch management, mobile device management (MDM), license management, reporting, and monitoring.
  • Help line ITSM/CSM: 2nd/3rd level support for incident, change, and problem management (with an active role in the Change Advisory Board according to ITIL v3 & v4), knowledge management, and ongoing analysis and reporting for service optimization.
  • Technologies: Entra-ID (Azure), Cisco, Cloud, Baramundi, firewall, HP, ITIL v3 & v4 CAB, MS Office 2016, MS Outlook, MS Teams, requirements engineering, Ivanti (MDM tool), Active Directory (AD)/AGDLP, PSI Penta (ERP system), SharePoint, Selektron (warehouse management system), Skype for Business & Teams, Dynamic Forms Workflow (workflow & information system), Microsoft Dynamics CRM (CRM system for sales and customer service), CMDB, KeyTech14 DMS (DMS system), Cisco IOS, Juniper JunOS, MikroTik, FRRouting (FRR), EDR, SIEM, MS-TIER, NESSUS, Azure security, SharePoint 2016, AGIL ITIL v3, M365/AZURE (Exchange, Teams, AAD, all M365 services), SQL Server 2016, VPN – FortiClient SAML
Oct 2021 - Sep 2022
1 year

Project Manager / IT System Engineer – CMDB / ITIL v3 & v4

Client in the critical infrastructure sector according to BaFin

Within my consulting role in CMS/CMDB management, I took on the following solid and practical tasks:

  • Analysis and target concept: Systematically capturing the current state of all CMS/CMDB instances – including data models, integration points (REST APIs, LDAP interfaces), and data quality metrics – and developing a holistic target vision using Jira and Confluence for requirements engineering.
  • System engineering for Windows, storage, and virtualization: Planning, implementing, and operating Windows Server 2016/2019, SAN storage systems (NetApp, EMC), and virtualization platforms (VMware vSphere, Microsoft Hyper-V). Continuously improving the infrastructure using Ansible playbooks and PowerShell DSC.
  • Operation and expansion of IT infrastructure: Establishing agile ITSM processes with Scrum/Kanban and introducing iterative project management with Jira Service Management. Responsible for uninterrupted operation as well as capacity and performance management with Zabbix and Nagios.
  • Interface and requirements management: Mediating between central departments, external service providers, and the IT architecture team. Leading workshops to prioritize and validate requirements, documented in Confluence.
  • CMDB design and development: Designing a modular data model for on-premises and cloud assets (AWS/Azure), including attribute harmonization and topology mapping in ServiceNow CMDB or FNT Command. Planning future requirements using Terraform and Ansible scripts.
  • Network and emergency management: Creating and documenting technical concepts for the operation performance network (OPN) and all leased lines (MPLS, VPLS) and optical transmission paths (CWDM, DWDM). Developing failover and disaster recovery scenarios for the data center.
  • Provider and stakeholder management: Managing external providers, building and maintaining customer relationships, and providing regular status and risk reports to management.
  • 3rd level support & ITIL v3 governance: Responsible for incident, change, and problem management in the CMS environment (BMC Remedy), active member of the change advisory board (CAB), and continuously adapting service processes. Creating QA documents and transferring knowledge through workshops and training.
  • Technical analysis and troubleshooting: Conducting in-depth fault analysis at infrastructure and application level, deriving sustainable solutions, and documenting runbooks and best practice guides.
  • Project manager and IT infrastructure analysis
  • Operational configuration management
  • Data center strategy
  • Establishment of tools & interfaces
  • Stabilizing ITSM suite (testing the CMDB)
  • Two migrations from BMC
  • Project IS002281 CMS revision
  • Project transition T-Systems
  • Technologies: Azure, Cisco, Cloud, firewall, HP, ITIL CAB, MS Office 2016, MS Outlook, MS Teams, requirements engineering, ServiceNow, SharePoint, AGIL Operations ver. 7.0.94, RANCID (Really Awesome New Cisco config Differ), Atlassian Confluence ver. 7.3.3, BMC Atrium CMDB ver. 20.03, BMC Service Management Remedy ver. 7.4.3, SharePoint 2016, AGIL ITIL v3, ServiceNow London, SQL Server 2016, VPN
Mar 2021 - Sep 2021
7 months

IT System Engineer - Data Center Architect / Project Manager

Client belongs to critical infrastructures

As part of a strategic mandate to comprehensively optimize the data center and cloud architecture, I delivered the following services:

  • Business and requirements analysis: Conducted a detailed business impact analysis and facilitated workshops with stakeholders to gather functional and non-functional requirements for the data center. I used requirements engineering methods (use case modeling, MoSCoW prioritization) and tools like Jira and Confluence.
  • Evaluation and optimization of cloud services (IaaS, PaaS, SaaS): Analyzed existing cloud offerings using AWS CloudWatch, Azure Monitor, and Google Cloud Operations to determine capacity needs, scalability, security requirements, and budget constraints. Defined a target blueprint for right-sizing resources and introduced automation recommendations via CloudHealth.
  • Physical infrastructure analysis and DCIM design: Assessed server rooms, network topologies, storage layers (SAN/NAS), cooling and power systems, and physical security measures (access control, CCTV). Employed DCIM solutions like Schneider Electric StruxureWare and Nlyte to identify optimization potential in PUE (Power Usage Effectiveness) and rack utilization.
  • Integrity verification of virtualization and automation technologies: Verified requirements for VMware vSphere, Microsoft Hyper-V, and Proxmox environments, and evaluated infrastructure as code approaches using Terraform and Ansible to ensure consistency and repeatability of deployments.
  • Network design and high-availability architecture: Designed and expanded a resilient LAN/WAN framework based on Cisco Nexus, Juniper MX, and HPE Aruba. Implemented redundancy and failover mechanisms (VRRP, OSPF multihoming, BGP redundancy) and load balancing with F5 BIG-IP to improve latency and throughput metrics.
  • Security analysis and BSI compliance: Reviewed and updated the security concept according to BSI standards (IT baseline protection), including physical safeguards, role-based access control (RBAC), data encryption (AES-256), threat detection (IDS/IPS with Snort/Suricata), and identity and access management (Azure AD PIM, Okta). Developed and implemented security policies aligned with ISO 27001.
  • Operations and maintenance procedures: Created a comprehensive framework for patch management (WSUS, Red Hat Satellite), backup and recovery (Veeam, Commvault), performance monitoring (Zabbix, Prometheus with Grafana), and capacity planning. Set up automated escalation and reporting workflows via ServiceNow and Jira Service Management.
  • Training, emergency and crisis management: Designed and delivered training for the service team on incident and problem management, failover scenarios, and business continuity plans (ISO 22301). Developed playbooks, runbooks, and conducted table-top exercises to ensure smooth recovery processes.
  • Scaling and growth planning: Documented modular architecture blueprints for future growth, including micro-segmentation approaches and SD-WAN strategy. Recommended flexible resource pools (Kubernetes, Docker Swarm) for on-demand scaling.
  • Continuous service and infrastructure improvement (CSI): Introduced a CSI framework based on ITIL v3 for incident, change (including CAB), and problem management. Established a cycle of metrics monitoring, lessons learned workshops, and targeted optimization measures to sustainably improve efficiency, performance, and reliability.
  • Technologies: BSI, critical infrastructures
Jan 2021 - Feb 2021
2 months
Switzerland

IT System Engineer / IT Service Engineer

Bouygues E&S InTec Schweiz AG

During my mandate with a major client, I was responsible for the following tasks in highly complex cloud and IT environments. We used modern technologies and proven tools to ensure maximum availability, security, and scalability:

  • Administration and governance of complex cloud and ICT systems: Planning, organizing, and overseeing all administrative activities in hybrid cloud architectures (IaaS/PaaS) and on-premises data centers, applying DevOps principles and infrastructure as code.
  • End-to-end process and interface management: Holistic analysis and optimization of existing workflows, as well as design and control of interfaces between software modules. Coordinated and migrated applications using deployment pipelines (e.g., Jenkins, GitLab CI/CD).
  • Identity and access management (IAM) and collaboration: Designed and implemented a single sign-on solution using Microsoft ADFS, restructured and harmonized the Active Directory setup in combination with Azure AD, and integrated Microsoft Teams as a video and web conferencing platform.
  • Requirements engineering and security concepts: Collected and specified functional and non-functional requirements for a Sophos firewall site-to-site VPN and created the specifications document, ensuring ISO 27001 compliance.
  • Risk management: Established a proactive risk framework (based on ISO 31000) with regular risk assessments, documentation, and derivation of appropriate countermeasures.
  • Network design and expansion: Architected, sized, and expanded LAN, WAN, and VPN structures, defining routing and switching strategies based on Cisco Catalyst and HP Aruba hardware.
  • Technologies: Azure, Cisco, cloud, firewall, HP, ITIL v3 & v4, MS Azure, MS Office 2016, MS Outlook, MS Teams, Active Directory (AD)/AGDLP, requirements engineering, ServiceNow, SharePoint, Sophos, SQL, SQL Server 2016, VPN
Mar 2019 - May 2020
1 year 3 months

IT Service & Infrastructure Analyst

Fujitsu TDS GmbH

As part of a migration and outsourcing project in the IT infrastructure area, I took on the following in-depth and practical tasks:

  • IT infrastructure analysis for migration preparation: Systematically collected and assessed existing hardware and network components (servers, storage, virtualization layers). Used monitoring and discovery tools (e.g., Nagios, Zabbix, CMDB Scanner) to inventory and establish a performance baseline.
  • Restructuring and consolidation of the CMS/CMDB landscape: Conceptual redesign of all configuration management databases, considering hybrid data center architectures (on-premises & cloud). Harmonized data schemas and attribute models in an ITIL-compliant CMDB (e.g., BMC Atrium CMDB, ServiceNow CMDB).
  • As-is analysis of all CMS databases including interfaces: Documented and classified existing CMDB instances and their integration points (e.g., REST APIs, SQL views). Created a quality assurance guide to define data quality metrics (completeness, consistency, timeliness).
  • Identification of optimization potential in service management: Benchmarked processes against ITIL v3 best practices and derived concrete fields for improvement. Facilitated workshops with the Change Advisory Board (CAB) to prioritize process enhancements.
  • Stakeholder management and communication control: Closely coordinated with top management, specialist departments, and external service providers. Provided regular status reports and executive briefings to ensure transparency and minimize risks.
  • Planning and (partial) automation of IT processes: Developed ETL-based staging area pipelines for data migration and harmonization. Implemented automation workflows using tools like Ansible, PowerShell DSC, and Talend Open Studio.
  • Analysis and optimization of the incident management tool (BMC Remedy): Captured and modeled all incident and problem workflows. Documented APIs and connectors (LDAP, SNMP, SMTP) and automated minor routine tasks. Provided technical recommendations to improve first call resolution and reduce MTTR.
  • This holistic approach laid the groundwork for a smooth software migration and achieved significant efficiency gains in ongoing IT operations.
  • Technologies: FNT Command ver. 9.8.1, AGIL Operations ver. 7.0.94, RANCID (Really Awesome New Cisco config Differ), Confluence by Atlassian ver. 7.3.3, BMC Atrium CMDB ver. 18.08, BMC, SAN & NAS Archive, Service Management Remedy ver. 7.4.3, SharePoint 2016, AGIL ITIL, ServiceNow London, UC4 ver. 11 & 12, FNT Staging Area ver. 4.5 & 5.0, Nintex Workflow 2013, Cisco Jabber ver. 11.9.3 (installation, configuration) build 60004, Skype for Business 2016 (installation, configuration) (16.0.4978.1000), Outlook 2016, Microsoft SQL Server 2016, Oracle SQL Developer ver. 4.0.0, MS Office 365, Jira ver. 7.0.5
Aug 2018 - Jan 2019
6 months

Network Management for Experts including Cisco CCNA

Training

  • Experience with complex network infrastructures (mainly Cisco) and topologies in small, medium, and large companies, covering planning, design, and administration, as well as IPv4 and IPv6 knowledge. Migration scenarios and dual-stacking for IPv4 & IPv6.
  • Knowledge of Network as a Platform (NaaP), intranet access technologies, covered networks, BYOD (bring your own device), online collaboration, unified communications, UCaaS (unified communications as a service), cloud computing, data centers, network security, threats, solutions, and Cisco network architectures.
  • Programming and configuration of Cisco routers and switches, using all relevant protocols.
  • Deep knowledge of network protocols and techniques: MEF (Metro Ethernet Forum), WDM (wavelength division multiplexing, Coarse WDM & Dense WDM & Wide WDM), hierarchical network design, planning, design, network protocols and communications, network access control (NAC), Ethernet, CE (Carrier Ethernet, E-Line, E-LAN, E-Tree), IP/MPLS (multi-protocol label switching), MPLS-TP (transport profile), IPv4/IPv6 (addressing, subnetting), OSI and DoD reference models, switched networks and configuration, implementing VLANs, trunking protocols, LAN redundancy STP, link aggregation, inter-VLAN routing and concepts, static and dynamic routing, RIP (routing information protocol), OSPF (open shortest path first), EIGRP (enhanced interior gateway routing protocol), NAT for IPv4 and NAT-PT (dual-stack & tunneling), multiple routing protocols on a network, first hop redundancy protocols (FHRP), ACLs (access control lists), WAN, securing site-to-site connectivity, DMVPN (dynamic multipoint VPN), transitioning IPv4 to IPv6, BGP (border gateway protocol), ISP connectivity, network monitoring (SNMPv1 and SNMPv2c, NetFlow), SPAN and VSPAN, IPsec tunneling, deploying and managing enterprise VPNs, securing WAN infrastructure, IoT (Internet of Things).
  • Technologies: access, BGP, routers, cloud, DHCP, EIGRP, Ethernet, gateway, Internet, intranet, IOS, IP, IPsec, IPv4, IPv6, LAN/WAN, link aggregation, monitoring, MPLS, NetFlow, QoS, security, STP, switches, VLAN, VPN.
  • Routing & switching: Cisco IOS, Juniper JunOS, MikroTik, FRRouting (FRR).
  • Network security: Fortinet, pfSense, Palo Alto, Cisco ASA, firewall and IDS/IPS systems, OpenVPN, Cisco AnyConnect, WireGuard.
  • Automation, CRM & log management: Wireshark, PRTG Network Monitor, Nagios, Zabbix, SolarWinds NPM, NetBox, Splunk, Grafana, Prometheus, ELK stack.
  • Protocols & standards: Ansible, Terraform, Python scripts for network automation.
Mar 2017 - Jul 2018
1 year 5 months

Project and IT Business Manager / Configuration Manager / Configuration Librarian

Client is classified as critical infrastructure according to BSI

In my mandate with our client, I was responsible for the following services, achieving measurable increases in transparency, quality, and efficiency across the service lifecycle:

  • Governance and operation of service asset and configuration management (SACM): I designed and managed the central administration of SACM according to ITIL v3 (2011 revision). This involved a configuration management system (CMS) combined with a configuration management database (CMDB), implemented via FNT Command.
  • Comprehensive CMDB data quality: I ensured continuous identification, control, persistence, and the correctness and completeness of all technical configuration items, including service and infrastructure relationships and organizational metadata in on-premises and cloud data centers.
  • Process analysis and ITIL optimization: Through systematic reviews, I evaluated existing configuration and change processes, identified optimization potentials, and adjusted workflows to ITIL v3 best practices to close governance gaps and consistently meet SLA targets.
  • Service transition and configuration control: During service transition, I distinguished outsourcing status and business requirements (configuration identification) across the entire data center infrastructure for outsourced customers and implemented these in the CMS/CMDB module for effective configuration control.
  • Verification, audit, and quality assurance: At the end of the project phase, I conducted comprehensive configuration verifications and audits, established QA reports, and continuously monitored data quality. The result was a significantly reduced error rate in infrastructure changes.
  • Service operation and continual service improvement (CSI): By introducing optimized service operation processes, I supported change and problem management with accurate CMDB data. This allowed the CSI program to be sustainably anchored according to the company's overarching service strategy.
  • Network design and documentation: I developed technical concepts, design specifications, and process documentation for the performance network (OPN) and all LAN, WAN, MPLS, VPLS, CWDM, and DWDM infrastructures, integrating them into the CMDB via FNT Command.
  • Tenant-specific transparency in security incidents: Thanks to the networked CMDB, we could perform tenant-specific impact analyses in real time and quickly identify affected customers during security incidents.
  • Data provider for operational processes: The CMS served as a reliable data source for change and problem management: stakeholders were informed precisely, tickets were created automatically, and asset quality was documented and communicated through QA reports.
  • Technologies: FNT Command ver. 9.8.1 & 10, SharePoint 2013, ServiceNow London, staging area ver. 5.5 & 5.0, Skype for Business 2016 (16.0.4978.1000), Outlook 2010, Microsoft SQL Server 2010, Oracle SQL Server & Developer ver. 4.0.0, MS Office Pro & 365, 2010-16 and more.
Sep 2016 - Jan 2017
5 months

Project and IT Security Manager

Client classified as critical infrastructure according to the BSI

As part of a group-wide security and infrastructure project, I was responsible, in close coordination with another security architect, for the holistic design, implementation, and continuous optimization of hybrid IT environments (cloud and on-premises), with special focus on security architecture and the maturity level of security controls:

  • Architecture and rollout management: Developing and implementing security architectures for cloud (e.g., AWS Security Hub, Azure Security Center) and on-premises environments (VMware vSphere, Microsoft System Center). Managing rollouts using infrastructure as code (Terraform, Ansible) and CI/CD pipelines (Jenkins, GitLab CI).
  • Monitoring & performance: Establishing a comprehensive monitoring and SIEM system (Splunk, QRadar) for continuous monitoring of performance and security KPIs. Using network performance tools (SolarWinds, Nagios) for proactive detection of bottlenecks.
  • Collaboration with service providers and departments: Managing external managed security service providers (MSSPs) and closely coordinating with internal IT teams using defined service level agreements (SLAs) and escalation processes according to ITIL® 2011.
  • Gap analyses & documentation: Conducting structured gap assessments, target-to-actual comparisons, and risk analyses. Documenting all results in the compliance management software DocSetMind, including deriving and prioritizing actions.
  • Firewall and IPv6 migration: Reviewing and adjusting stateful firewalls (Cisco ASA, Palo Alto Networks) for IPv4 to IPv6 migration scenarios. Validating IPv6 readiness of all configuration items using Nessus and Qualys, recording results in the CMDB.
  • IAM development & security analysis: Contributing to the design and implementation of a company-wide identity and access management tools (DirX, LDAP, ADFS). Performing threat and vulnerability assessments to secure authentication and authorization processes.
  • Asymmetric encryption & PKI: Implementing double-key encryption (DKE) based on asymmetric key algorithms (RSA, ECC). Designing and operating a public key infrastructure (PKI) for SSL/TLS certificate management (DigiCert, Let’s Encrypt).
  • Hardware security checks: Reviewing and approving packet filters, application layer gateways (ALG), VPN crypto gateways, IDS/IPS systems (Snort, Sourcefire), and load balancers (F5 Big-IP).
  • Email security: Securing email communication by implementing PGP (GnuPG), S/MIME, and TLS for SMTP connections.
  • Service process optimization & knowledge transfer: Adjusting ITIL-based service processes, creating a detailed security measures catalog, and conducting knowledge transfer workshops.
  • Reporting & documentation: Producing regular management reports and security dashboards for transparent communication of project progress, as well as developing comprehensive technical documentation and recommendations.
  • Technologies: Authentication techniques like identity life cycle processes and authorization methods (RBAC, ABAC, IAM), Active Directory (AD)/AGDLP, knowledge of common security standards for cloud and mobile and common security protocols (WS-*, SAML, OATH, X.509, XACML, SSL, 802.1X, Kerberos), application of security methods and technologies according to BSI (PKI, encryption, security monitoring, AES256, etc.), IT architectures in host, client/server, web-mobile, SOA, and cloud environments, Microsoft AD, AD-FS, Azure, DirX, SAML, BSI, Microsoft Security Response Center, global IAM, Office 365
Feb 2016 - Jun 2016
5 months

Project Management

GFN AG

  • Topics:
  • Project management according to PRINCE2®, ITIL® 2011, MS Project, SCRUM, SAP Business Suite, SAP CO
  • Data protection in project management
  • Communication for managers
  • Certifications:
  • PRINCE2® Foundation & Practitioner, ITIL® 2011 Foundation, SCRUM, SAP Business Suite, SAP CO (AC040)
  • Technologies: ITIL, PRINCE2, project management, SAP, SAP CO, SCRUM
Sep 2015 - Jan 2016
5 months

IT Infrastructure Manager / NE2 Technical Planner / Project Manager

Client classified as critical infrastructure according to the BSI

As part of a complex infrastructure project for a well-known client, I took responsibility for planning, implementing, and quality assurance of various network components and integrating them into existing operations. The focus was on network modernization in the context of IPv6, structured documentation, and operational support in the data center environment.

  • ITIL-based project planning: Executing planning and implementation tasks according to ITIL® 2011 guidelines, especially for network expansion at multiple hub locations in Germany. Emphasis was on structured handover points and consistent documentation in the Configuration Management Database (CMDB).
  • Network technologies & hardware deployment: Responsible for planning and configuring network components, especially Cisco ASR 9000 series routers and Cisco Catalyst 2960 series switches. Performing routing and switching tasks for IPv4 and IPv6 networks, including systematic testing of IPv6 compatibility for all Cisco components. Documenting test results in the technical CMDB.
  • IPv6 capability analysis & documentation: Comprehensive analysis of the IPv6 readiness of the network infrastructure. Implementing a standardized process for capturing this information in the FNT Command CMDB.
  • Knowledge transfer & training: Delivering target-group oriented training sessions in the NOC (Network Operation Center) to ensure operation of the new components and technologies.
  • Project "NextGen-TV" – cabling & planning: Responsible for cabling planning and quality assurance in the NextGen-TV project, including creating detailed cabling overviews, developing patch lists, drafting technical detail plans, and conducting technical reviews. The scope covered the entire data center and all colocation rooms.
  • Network design & documentation: Designing a holistic network model including processes and topologies for OPN networks, leased lines, MPLS, VPLS, CWDM (Coarse Wavelength Division Multiplexing), and DWDM (Dense Wavelength Division Multiplexing). Fully documenting the logical and physical networks in the FNT Command database.
  • Integration & system coordination: Planning and coordinating the integration of new system components into the existing IT infrastructure, considering operational dependencies, redundancy concepts, and failover strategies.
  • Management reporting: Preparing regular progress and status reports for senior management. Presenting technical KPIs and project risks and deriving recommended actions.
  • Operational support / 3rd level support: Providing technical support for incidents and complex issues at the 3rd level, especially for Cisco Systems products. Strong hands-on mentality and direct access to the core infrastructure.
  • Cost efficiency through infrastructure modernization: Achieved a significant reduction in ongoing IT operations and infrastructure costs through targeted optimization measures, without impacting availability or security.
  • Role: Project Manager / NextGen Project - IT Infrastructure, Network Design and Project Coordination
  • Technologies: Cisco, CMDB, FNT-Command, ITILv3 & CAB, MS Office 2010, routers, switches, core routers, scramblers, multiplexers, acquisition, transrater, transcoder, Cisco ASR9000v core, IBM 3550, Cisco Catalyst 2960 core switch
May 2010 - Jul 2015
5 years 3 months

Head of IT Service Desk / Project Manager

Rohde & Schwarz GmbH & Co. KG

As part of a company-wide transformation project to strategically realign the IT infrastructure, I took responsibility for key areas within the department and coordination with other departments and external service providers.

  • Strategic project responsibility: Leading role in IT strategy, including the design and implementation of strategic IT vision for both data centers.
  • Consulting and project planning: Advising at management and department level on planning and executing complex migration and rollout projects, including technical, organizational, and business considerations.
  • Infrastructure and feasibility analysis: Conducting a comprehensive analysis of the existing IT landscape. Developing a feasibility study to identify technical, organizational, and business success factors. Special focus on integrating NetApp backup solutions.
  • Project management: Overall responsibility for project budget and controlling project execution with decision-making authority according to defined governance structures. Applying methods such as PRINCE2, PMI, or similar standards.
  • Introduction of controlling metrics: Developing and implementing a KPI system to manage and measure the success of the IT department.
  • Quality management for end-user workstations: Defining and implementing quality improvement measures, including standardizing and optimizing workstation architecture.
  • Collaboration with external service providers: Technical management and coordination of external partners and ensuring quality of service delivery.
  • System and integration testing: Actively participating in planning, executing, and evaluating test runs for system deployments and migrations.
  • IT rollouts: Supporting and operationally executing the deployment of new systems and services.
  • Data center infrastructure consolidation: Merging and standardizing existing data center solutions, considering high availability, disaster recovery, and scalability.
  • Leadership and communication: Strong customer focus, communication skills, and consulting and leadership abilities at specialist and management levels.
  • Requirements management: Gathering, analyzing, and prioritizing software, hardware, and infrastructure requirements in close coordination with departments.
  • Trainer activities: Conducting internal training sessions on new technologies, processes, and security requirements.
  • Service level agreements: Defining, aligning, and implementing SLAs for mission-critical services.
  • Process optimization: Adjusting and optimizing IT service management processes according to ITIL and redesigning data center processes.
  • IT security: Significantly raising the security level by introducing improved encryption technologies and security policies.
  • Service and escalation management: Managing support processes at 2nd and 3rd level, including escalation management and user support.
  • Remote support tools: Implementing Microsoft Remote Help Assistant for more efficient remote maintenance.
  • Communication tools and platforms: Replacing outdated systems by migrating from WebEx, Skype for Business (legacy), SameTime, NetViewer (Cisco), and Polycom HDX. Introducing ARKADIN as the global conferencing tool.
  • VPN / SRA (Secure Remote Access): Implementing a new VPN solution for secure remote access outside the main site.
  • New communication platform: Introducing Skype for Business On-Premise as the company-wide standard for audio/video conferencing. This included deploying front-end servers, edge servers, backend databases, and monitoring components. Integration into the Office 2010 suite.
  • Efficiency gains through system consolidation: Merging and replacing five existing communication platforms led to sustainable efficiency improvements and reduced support effort.
  • IT security and asset management: Further developing and maintaining security policies and asset management according to ISO/IEC 27001.
  • IAM development: Working in the development team for a new identity & access management (IAM) tool, aiming to meet modern role and permission model requirements.
  • Project "Identify Management": Designing a group-based role model based on DirX (IAM solution) and contributing to its implementation.
  • Rollout & migration: Planning and executing rollouts and migrations of Microsoft-based operating systems and performing requirements management in collaboration with the supply chain management team.
  • Technologies: Access, Cisco, Citrix, cloud, CRM, Skype for Business, HP, Dell, Jenkins, Linux, Lotus Notes & Archive, MS Project, NetApp, project management, R, S/MIME, SAP, security, VMware, VPN, Windows, Active Directory (AD)/AGDLP, SAN & NAS archivers, MO disk & tape archives, flash storage archives
Jan 2006 - Apr 2010
4 years 4 months

Project Lead / Project Manager

Rohde & Schwarz GmbH & Co. KG

  • Expanding the support structure in central IT
  • Also acting as part of the project lead for introducing the ITIL framework and the ITSM tool
  • Infrastructure: LAN/WAN network
  • Replacing all switches and routers in the data center (switching and routing for IPv4 and IPv6 with a cutover plan for Linux migration)
  • Planning and cabling according to EN 50173 in the data center
  • Colocation room connections: activation, planning
  • Technologies: ITIL, ITSM (IT Service Management)
Jul 2004 - Dec 2005
1 year 6 months

Project Lead / Project Manager

Rohde & Schwarz GmbH & Co. KG

  • Set up support in central IT
  • Sub-project manager for the client migration from Novell to Windows
  • Technologies: Windows

Summary

I have a solid background in IT infrastructure and system engineering, specializing in service transitions, CMDB management, and ITSM optimization for critical environments. I design and implement secure, scalable architectures using cloud and on-premise technologies, and I’m skilled in steering complex projects with ITIL, PRINCE2, and agile approaches.

My experience covers network management, licensing, and stakeholder collaboration, as well as advanced IT security and virtualization. I continuously adopt modern methodologies to deliver efficient, robust solutions that align business and technology needs.

Languages

German
Native
Greek
Native
English
Intermediate
Italian
Elementary

Certifications & licenses

FNT Staging Area

FNT

Cisco CCNA

Data Center Technician (Client / Server Management)

IBM Certified Professional Domino – Lotus Notes

IT-Security Specialist (for Linux, Windows and Cisco)

ITIL ver3 Foundation Certificate in IT Service Management

ITIL2011 Foundation

Microsoft Certified System Expert (MCSE)

Microsoft Certified Trainer (MCT)

PRINCE2 Foundation

PRINCE2 Practitioner

SAP Business Suite

SAP CO (AC040)

SCRUM

ServiceNow Fundamentals

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions