Mike B.

System and endpoint hardening

Meuselwitz, Germany

Experience

Jan 2024 - Nov 2024
11 months
Germany

System and endpoint hardening

CLAAS

  • Evaluating and assessing the current state
  • Preparing and conducting security audits
  • Characterizing vulnerabilities and risk analyses
  • Assessing, coordinating, and turning identified vulnerabilities into target states
  • Coordinating stakeholder interests
  • Developing and implementing IT security strategy for OT and IoT (continuous risk assessment and risk management, awareness, multi-layered security solutions, regular security audits, access restrictions)
  • Organizational and technical documentation
  • Presentations
  • Workshops

Skills:

  • Qualys
  • Splunk
  • Nessus
  • QRadar
  • National Vulnerability Database (NVD / NIST)
  • Open Worldwide Application Security Project (OWASP)
  • OT
  • CERT/CC
  • BSI IT baseline protection catalogs
  • ISO 27001
  • MITRE ATT&CK
  • Center for Internet Security (CIS)
  • GitHub
  • Active Directory
  • PowerShell
  • Symantec Endpoint Protection
  • Microsoft Azure and Office365 App Security
  • ITSM
Oct 2023 - Dec 2024
1 year 3 months
Germany

Vulnerability management, GPO and endpoint hardening

Thales

  • Identifying, assessing, and prioritizing vulnerabilities in Windows and Linux servers and clients
  • Implementing stakeholder and remediation processes
  • Remediation confirmation
  • Reporting
  • CIS system and application hardening
  • Rapid7 Nexpose / InsightVM lifecycle management
  • Implementing CIS Controls with CIS Community Defense Model v2 and CIS GPO Benchmarks for browsers, Windows Server / Client, SQL Server
  • Using Microsoft Security Compliance Toolkit, security baselines, and integrated tools against existing GPOs (compare, test, inject)
  • Creating technical and organizational documentation

Skills:

  • Vulnerability management with Rapid7 Nexpose / InsightVM
  • Reporting and escalation
  • Remediation
  • Target vs actual analysis and implementing NIST2, KRITIS, BSI baseline protection, VSA, VS-NfD, ISO 27001, NIS-2, CERT, OWASP, NIST, CERT/CC, NVD, MITRE ATT&CK
  • SQL query design
  • CIS Controls / Benchmarks
  • Endpoint hardening
  • IT service / business continuity management
Aug 2022 - Dec 2024
2 years 5 months
Germany

Azure, Defender and Microsoft 365 administration

DEKRA

  • Setting up secure file sharing and collaboration with Microsoft Teams
  • Planning and configuring ransomware protection in Microsoft 365
  • Providing and configuring remote workstations
  • Configuring privacy and security for Microsoft 365 Copilot
  • Configuring and administering Microsoft SharePoint and OneDrive
  • Auditing Microsoft 365 security and compliance
  • Zero Trust identity and device access configuration
  • Implementing SIEM and XDR with Microsoft 365 Sentinel and Defender for OT and IoT endpoints
  • DLP risk management and data classification in Microsoft Purview
  • Migrating Kaspersky AV to Microsoft Defender for Endpoint, Office 365, Cloud Apps
  • Administering Azure AD, Intune, M365 Security Center
  • EDR monitoring
  • SIEM Sentinel forensics
  • Incident management
  • Workshops, presentations, and documentation

Skills:

  • Azure AD
  • Intune
  • Microsoft 365 App Governance
  • Microsoft 365 Security Center
  • Microsoft 365 Admin Center
  • Vulnerability management
  • ISO 27001
  • Business impact analysis
  • IT service / business continuity management
  • Data loss prevention and privacy risk management in Microsoft Purview
  • SharePoint
  • XDR
  • SIEM
  • Log source monitoring
  • Copilot
  • Intune
  • M365 Security Center
Aug 2022 - Jul 2023
1 year
Germany

Administration and rollout of Trend Micro products

Cancom

  • Rolling out and managing Trend Micro products: Apex One, Apex Central
Oct 2021 - Dec 2023
2 years 3 months
Germany

IT security consulting

Enervie

  • Windows and Linux hotfix and security patch management for endpoints in control center network
  • Trellix endpoint and ePO administration
  • Threat and vulnerability management
  • Optimizing response measures
  • Asset and network inventory with DocuSnap
  • Reporting
  • Documentation

Skills:

  • WSUS
  • BSI baseline protection
  • NIST
  • KRITIS
  • Inventory and reporting
  • Trellix and ePO administration
  • Threat hunting and forensics
  • Incident and change management
Jan 2021 - Jun 2021
6 months
Germany

Endpoint security – architecture and policy redesign for Symantec Endpoint Protection

Olympus

I planned and redesigned the Symantec Endpoint Protection infrastructure for over 10,000 Windows and Linux endpoints, modeled and adjusted policies for compliance, and administered and managed the endpoint security solution. Key tasks included antimalware protection, incident response, forensic analysis, malware analysis, lifecycle and patch management, reporting, and collaboration with business units in 2nd and 3rd level support. SQL jobs and scripts were tested and adjusted as needed.

Oct 2020 - Dec 2020
3 months
Germany

System administration Hyper-V data center, McAfee and Defender

Schmersal

I managed the existing Hyper-V data center and McAfee Endpoint Security with ePO while redesigning the infrastructure. The goal was to migrate on-premise McAfee Endpoint Security to Microsoft Defender. I planned strategy and implementation, created presentations with product comparison matrices, conducted workshops on Defender suite technologies, and showed how Defender 365 products reduce attack surfaces. Securing Microsoft 365 services, policy configuration, and system hardening were also key tasks.

Skills:

  • Hyper-V data center cluster administration
  • McAfee Endpoint Security management
  • Strategy planning for endpoint migration to Microsoft Defender
  • Z-Scaler
  • Citrix
  • Microsoft Azure
  • Office 365
Jan 2016 - Dec 2024
9 years
Germany

Consultant

Sparkassen Finanz Informatik

Since 2016 I worked for Sparkassen Finanz Informatik in cybersecurity/defense, compliance, information security management, business continuity, cloud security, Azure Entra ID, IT service management, audits, regulation, license management, product lifecycle, security infrastructure design and support.

For planning and implementing a Microsoft Azure security architecture I followed these steps:

  • Current vs target analysis: I did a detailed review of the existing Azure security setup, checking network security, access controls, identity and authorization structures. Then I defined target requirements based on best practices and Microsoft Cybersecurity Reference Architectures (MCRA).
  • Verifying entities: I verified virtual machines, networks, storage, and users for gaps, unused resources, and misconfigs, ensuring all entities fit the security architecture.
  • Designing Azure security with Microsoft Defender: I built a custom architecture using Defender for multi-layered protection: NSGs, Azure Firewall, WAF, Zero Trust, Defender for Endpoint, Office 365, Identity, Cloud, Cloud Apps, and Sentinel.
  • Implementation with stakeholders: I worked with IT operations, DevOps, and security teams, automating processes for consistent deployment of Defender solutions and policies.
  • Validation: I tested all measures with automated checks and manual penetration tests to ensure they meet requirements.
  • Operations and lifecycle: I handed over to operations with monitoring and reporting, regular reviews, and updates for ongoing security.

Additional tasks:

  • Azure Entra ID identity and access management
  • Purview DLP classification policies, labeling and protection, activity monitoring
  • Purview insider and privacy risk management
  • Purview Microsoft 365 App Governance, privacy and security analyses with Copilot for Security
  • Managing Exchange, SharePoint, Teams security in M365 Admin Center
  • Threat detection and analysis (IOC, IOA)
  • Sandbox attack analysis
  • And more too extensive to list.

In vulnerability management I ran Qualys, planned scans, generated reports, and escalated to stakeholders. I prepared and supported security audits for regulatory compliance. Other work:

  • Reporting
  • Endpoint hardening
  • Product lifecycle management
  • Incident, change, problem management in ServiceNow
  • Writing manuals and technical/organizational docs
  • Security architecture design
  • Presentations and workshops

Skills:

  • Microsoft Azure
  • Microsoft Entra ID
  • Identity and access management
  • Microsoft Purview
  • Data loss prevention
  • Intune
  • Active Directory
  • Microsoft Defender products
  • Microsoft Sentinel
  • M365 App Security
  • Trellix ePolicy Orchestrator / Endpoint
  • EDR / XDR
  • Symantec Endpoint Security
  • BlueCoat Proxy
  • SQL scripting and query design
  • PowerShell scripting
  • Patch and release management
  • Qualys vulnerability management
  • SOC
  • Endpoint hardening
  • Architecture design
  • Financial sector regulatory and security consulting (DORA)
  • ECB / TüVSec audits
  • License, rights and policy management
  • Privileged access management
  • Splunk SIEM
  • Incident analysis
  • IOC/IOA evaluation (MITRE ATT&CK)
  • Creating security concepts, manuals, docs
  • KPI reporting
  • Product lifecycle management
  • Market and product screening
  • CIS GPO benchmarking
  • REST API
  • BSI KRITIS
  • SecOps
  • BSI baseline protection
  • NIS-2
  • BSI C5
  • ISO 27001
  • ISMS
  • IT service / business continuity management
  • ServiceNow incident, change, problem management
  • 2nd and 3rd level support
  • Workshops
  • CMDB and stakeholder management
  • Escalation management
Dec 2014 - Sep 2020
5 years 10 months
Braunschweig, Germany

McAfee Enterprise Security Management

Volkswagen AG Wolfsburg / Volkswagen Financial Services Braunschweig

I handled governance, risk & compliance and IT operations at VW locations: Managing encryption and signature updates on endpoints, migrating ePO from version 4 to 5, evaluating and deploying MOVE AV in Citrix VDI, domain controller security with McAfee Change & Application Control, McAfee SIEM administration, creating product comparison matrices, migrating F-Secure and Symantec to McAfee, SIEM reporting, evaluating Rapid7/Qualys/Nessus/IBM SIEM, gateway administration, documentation, incident & escalation management, patch & release management with Microsoft System Center, and 2nd/3rd level support.

Skills:

  • McAfee ePolicy Orchestrator
  • Virus Scan Enterprise
  • MOVE AV
  • McAfee Host Intrusion Prevention
  • Security for Microsoft Exchange
  • Security for Microsoft SharePoint
  • Change Control
  • Application Control
  • Data Loss Prevention
  • Encryption for Files and Folders
  • Device Control
  • Security and Event Monitoring
  • Vulnerability Manager
  • Global Threat Intelligence Proxy
  • Firewall Enterprise
  • Hyper-V 2012 Core
  • System Center Operations Manager 2012
  • System Center Configuration Manager 2012
  • System Center Virtual Machine Manager 2012
  • Server 2008-2012
  • SQL Server 2012-2014
  • Windows 7-10
  • Exchange 2010
  • SharePoint 2013
  • Active Directory
  • IPsec
  • Group Policy
  • Qualys vulnerability management
  • Rapid7 Nexpose
  • Nessus
  • HP Service Manager
  • CyberArk
  • Alcatel-Lucent VitalQIP
  • VMware
  • Citrix
  • Planta
  • Symantec Endpoint Protection
  • F-Secure
  • Sophos AV
  • TrendMicro
  • Avast
  • Avira
  • Kaspersky
  • Panda
  • IBM QRadar
Jan 2012 - Jul 2014
2 years 7 months
Hamburg, Germany

Backoffice and enterprise security

Wincor-Nixdorf

My core work included central management of McAfee ePolicy Orchestrator servers and infrastructure, API scripting, SQL scripting, migrations and updates, policy, task, antivirus, intrusion, firewall rule automation, vulnerability and disk encryption management, IT disaster planning, enforcing and reviewing policies, reporting, and test environments. I recently completed migrating ePO from v4.x to v5.x for a multi-tenant antivirus system, handling heterogeneous environments, replacing Symantec with McAfee on 5000 units, working with virtualization, networking, databases, and security teams. I optimized performance by 30–50%, and replaced SQL Server 2005 with a clustered SQL Server 2008 R2 solution. I manage ODBC, users, security, roles, rights, maintenance plans, emergency planning, queries, performance with PowerShell and SQL Monitor, analyze IPsec traffic, and report to stakeholders. In daily ops I handle vulnerability management, audits, reporting, documentation, updates, custom scans, logs, incident response, lifecycle, licensing, policies, SCCM packaging, and escalations.

Skills:

  • Working with McAfee, Symantec and TrendMicro management platforms
  • SEP to McAfee migration
  • Endpoint security management
  • Monitoring and reporting
  • Database and storage management
  • Threat prevention and detection
  • Protection tuning
  • Product evaluation and release management
  • License management
  • Backup, recovery and disaster planning
  • Technical documentation
  • Oracle, DB2, MSSQL Server administration
  • Storage design
  • SQL clustering
  • Security, patch and release management
  • Documentation
Jan 2011 - Dec 2012
2 years
Munich, Germany

2nd/3rd level support

Unisys Outsourcing

From January 2011 to December 2012 I worked freelance for Unisys in Munich in 2nd/3rd level support. I supported the Bavarian justice system and ministry, migrating Windows XP/Office 2003/Server 2003 to Windows 7/Office 2010/Server 2008 R2. I provided technical and admin support to teams, user and role management, GPO maintenance, cross-site integration, patch & release management, ensured network availability with Nagios and System Center, followed BSI baseline guidelines for SLAs and incident management, managed file/print servers, Exchange, data security and recovery, SQL server admin, and helped design infrastructure with VMware and Citrix.

Skills:

  • User support
  • File and print server administration
  • Citrix XenApp 6 management on Windows Server 2008 R2
  • Citrix license management and troubleshooting
  • Print management
  • Group Policy
  • Rights management
  • Citrix application virtualization
  • Profiling and streaming
  • Windows Server patch management
  • System Center Operations & Config Manager
  • MS SQL Server
  • Incident management and escalation
  • Technical architecture and processes
  • Documentation and reporting
Sep 2009 - Dec 2010
1 year 4 months
Coburg, Germany

Project administration and support of McAfee ePolicy Orchestrator 4.5

Brose Automotive

I worked with the security team to migrate ePO from 3.x to 4.x: policies, tasks, agents and antivirus components. I integrated and adjusted ePO structure with global AD schema, created client/server tasks, user auditing, server/auth config, incident analysis and remediation, SQL Server 2005/2008 admin, database migration, instance setup, performance tuning, backups, ITIL incident/change management, documentation, reporting, and training for international branches.

Skills:

  • Managing ~10,000 clients and 1,000 servers with McAfee Agent, VirusScan, Host Intrusion Prevention, Endpoint Encryption, GroupShield for Exchange, SiteAdvisor, Rogue System Detection
  • ePO 3.x to 4.x migration
  • ePO integration and scripting with AD
  • Incident response and remediation
  • SQL Server admin and scripting
  • ITIL change management
  • Documentation, reports, statistics, and training
Sep 2009 - Dec 2010
1 year 4 months
Germany

Consultant for Hyper-V cluster implementation

Local mid-sized company

Parallel to Brose Automotive project I:

  • Designed and implemented a Windows Server 2008 R2 Hyper-V cluster with iSCSI storage and clustered shared volumes for ~350 staff
  • Migrated existing infrastructure in phases to the virtualized high-availability platform on two HP Proliant DL385 G6
  • Managed virtual environment with SCVMM 2008 R2
  • Connected storage via iSCSI to Windows Storage Server 2008
Jul 2009 - Aug 2009
2 months
St. Gallen, Switzerland

Project implementation of domain infrastructure migration Windows Server 2000/2003 to 2008, antivirus rollout

I ran both old and new domains concurrently via a bidirectional trust and DFS namespace with Robocopy jobs for data sync. I defined and rolled out GPOs, deployed printers via PushPrinterConnect.exe, set up RemoteApps on terminal servers, migrated users with ADMT retaining old SIDs for CRM, implemented a new backup for HP Tape Library with CA Arcserve Backup 12.5 on Server 2008, and provided user support and documentation.

Skills:

  • VMware ESX 4.0 vSphere consolidation
  • Setting up domain controllers, terminal and app servers
  • Deploying RemoteApps
  • Migrating accounts to new domain
  • Printer rollout via GPO
  • ADDS GPO management
  • DFS/DFS-R
  • ADS trust between domains
  • TrendMicro OfficeScan deployment
  • New backup concept with CA Arcserve Backup
  • 1st/2nd/3rd level support and documentation
Jan 2009 - Jun 2009
6 months
Germany

CRM, Exchange and Active Directory services project

  • Built, managed, and handed over a support hotline with vTiger CRM on SUSE Linux Enterprise Server 10, including training
  • Extended AD schema and GPO management on Windows Server 2003 R2 and 2008
  • Built Exchange Server 2007 on VMware Infrastructure 3.5
  • Administered Exchange 2007
  • Deployed McAfee VirusScan 8.5 Enterprise and ePO 3.x management
Jul 2008 - Dec 2008
6 months
Germany

IT system technician

Group4Securicor / Securitas

I worked as an IT technician in Germany’s largest private security service center during a merger. I integrated diverse LAN, WAN, WLAN, FC segments into the central data center, managed active and passive network components, optimized office processes for incompatible file formats, proposed a Drupal-based CMS wiki, migrated clients/servers from Windows 2000/XP to XP/Vista and Windows Server 2000/2003 to 2003/2008, migrated servers to VMware ESX 3.5, supported 24x7 helpdesk with OTRS, monitored with Nagios and GFI Network Server Monitor, managed AD, GPO, print, remote sites, Office users, Citrix Metaframe, network security with Symantec, McAfee, TrendMicro, SonicWall, Cisco, and administered SQL Server 2000/2005/2008, Exchange 2003/2007. I combined technical skill, teamwork, and communication to drive efficient workflows.

Skills:

  • Support hotline (Office support, printer admin, ticketing, password resets)
  • Deploying Windows Server 2008 and SQL Server 2008
  • Migrating XP to Vista
  • Facility management (infrastructure, power, HVAC, access control)
  • Client/server manufacturing for specialized apps
  • Monitoring critical processes
  • VMware ESX consolidation
  • Citrix Metaframe application delivery
  • Office process optimization
  • Drupal CMS wiki in PHP
  • Network documentation and performance analysis
  • Backup and disaster recovery planning
  • Hardware/software inventory
  • Security tech support (BMA, EMA, video)
  • Alarm management and operator client admin
  • SQL Server 2005/2008 admin
  • Exchange 2003/2007 admin
  • AD management
  • Symantec, eTrust and TrendMicro antivirus admin
Feb 2005 - Jun 2008
3 years 5 months
Germany

Project planning, integration and management of IT infrastructure

G4F / Group4Securicor Data Center

  • Procuring hardware (Dell, HP, IBM, Fujitsu-Siemens, Cisco, AlliedTelesyn, Digital, APC, SonicWall)
  • Designing AD infrastructure
  • Setting up MS SQL Server 2000/2005 databases
  • Migrating clients/servers from Windows 2000 to XP/Server 2003 R2
  • Administering terminal services (MS-TS, Citrix Metaframe, ThinPrint)
  • SQL Server admin (monitoring, reports, backup, security)
  • Managing tape libraries
  • Exchange admin
  • Monitoring with GFI NSS and Nagios
  • Network security, spam and antivirus
  • Client lifecycle management (SCMS)
  • Implementing and managing VMware infrastructure
Jan 2004 - Jan 2005
1 year 1 month
Germany

Project building data center infrastructure

G4F Deutschland

  • Windows terminal servers, Citrix Metaframe farm, ThinPrint servers and clients
  • Ensuring printer driver compatibility
  • Load balancing
  • User accounting
  • Domain concept and AD
  • Firebird database server
  • Upgrading nationwide cash logistics centers from 16-bit to 32-bit software
  • Documentation and archiving per ITIL
  • SonicWall VPN admin
  • Helpdesk and on-site support
  • Printer concept planning and rollout
  • Backup concept with Arcserve 11
  • GFI Faxmaker admin
  • eTrust Antivirus enterprise
  • Exchange admin
  • SBS 2003 setup with Exchange and mobile remote
  • WSUS implementation
  • Network inventory with MOM
  • SQL 2000 admin
Apr 2003 - Dec 2003
9 months
Germany

IT documentation (ISO 9000 certification)

Mehler Bau GmbH

  • System and network documentation for ISO 9000 audit preparation
Oct 2002 - Feb 2003
5 months
Meuselwitz, Germany

Planning and installing WLAN

City administration Meuselwitz

  • Connecting a remote office to the central network via WLAN and verifying security and performance
May 2002 - Aug 2002
4 months
Borna, Germany

Planning school network infrastructure

Gymnasium Borna Am Breiten Teich House 1

  • Deploying and administering Linux servers, firewalls and network security
  • Creating network documentation and policy concept

Languages

German
Native
English
Advanced

Education

Mar 1996 - Dec 2001

TSG Stuttgart

Administration / IT · Stuttgart, Germany

Jan 1986 - Dec 1995

TGB Peres

Administration / IT

Jul 1984 - Dec 1985

TGB G.-Dreieck

Measurement and control technology

Certifications & licenses

McAfee Application Control

McAfee

Basic Administration for Citrix XenApp 6

Citrix

MCDBA

Microsoft

MCP

Microsoft

MCSE

Microsoft

Need a freelancer? Find your match in seconds.
Try FRATCH GPT
More actions