Mike Barthel
System and Endpoint Hardening
Experience
System and Endpoint Hardening
CLAAS
- Evaluating and assessing the current state
- Preparing and conducting security audits
- Vulnerability characterization and risk analysis
- Assessing, coordinating and transforming identified vulnerabilities into target states
- Coordinating stakeholder interests
- Developing and implementing IT security strategy for OT and IoT (continuous risk assessment and risk management, awareness, multi-layered security solutions, regular security audits, access restrictions)
- Organizational and technical documentation, presentations and workshops
- Skills: Qualys, Splunk, Nessus, QRadar, National Vulnerability Database (NVD / NIST), Open Worldwide Application Security Project (OWASP), OT, CERT/CC, BSI IT-Grundschutz catalogs, ISO 27001, MITRE ATT&CK, Center for Internet Security (CIS), GitHub, Active Directory, PowerShell, Symantec Endpoint Protection, Microsoft Azure and Office365 App Security, ITSM
Vulnerability Management, GPO and Endpoint Hardening
Thales
- Identifying, assessing and prioritizing vulnerabilities in Windows and Linux server and client environments
- Implementing stakeholder and remediation processes
- Remediation confirmation, reporting and CIS system and application hardening
- Rapid7 Nexpose / InsightVM life cycle management
- Implementing CIS Controls with CIS Community Defense Model v2 and CIS GPO Benchmarks for browsers, Windows Server/Client and SQL Server
- Using Microsoft Security Compliance Toolkit and security baselines and integrated tools against existing GPOs (compare, test, inject)
- Creating technical and organizational documentation
- Skills: Vulnerability management with Rapid7 Nexpose / InsightVM, reporting and escalation, remediation, target/current state analysis and implementation of NIST2, KRITIS, BSI IT-Grundschutz, VSA, VS-NfD, ISO 27001, NIS-2, CERT, OWASP, NIST, CERT/CC, NVD, MITRE ATT&CK, SQL query design, CIS Controls / Benchmarks, endpoint hardening, IT service / business continuity management
Azure, Defender and Microsoft 365 Administration
DEKRA
- Setting up secure file sharing and collaboration with Microsoft Teams
- Planning and configuring ransomware protection in Microsoft 365
- Provisioning and configuring remote workstations
- Configuring data protection and security for Microsoft 365 Copilot
- Configuring and administering Microsoft SharePoint and OneDrive
- Auditing Microsoft 365 security and compliance
- Zero trust identity and device access configuration
- Implementing SIEM and XDR with Microsoft 365 Sentinel and Defender for OT and IoT endpoints
- DLP risk management and data classification in Microsoft Purview
- Migrating Kaspersky AV to Microsoft Defender for Endpoint
- Office 365 and cloud apps administration
- Administering Azure AD, Intune and M365 Security Center
- EDR monitoring, SIEM Sentinel forensics and incident management
- Workshops, presentations and documentation
- Skills: Azure AD, Intune, Microsoft 365 App Governance, Microsoft 365 Security Center, Microsoft 365 Admin Center, vulnerability management, ISO 27001, business impact analysis, IT service / business continuity management, data loss prevention and privacy risk management in Microsoft Purview, SharePoint, XDR, SIEM, log source monitoring, Copilot
Administration and Rollout of Trend Micro Products
Cancom
- Rollout and management of Trend Micro products
- Apex One and Apex Central
IT Security Consulting
Enervie
- Windows and Linux hotfix and security patch management for endpoints in the control center network
- Trellix endpoint and ePO administration
- Threat and vulnerability management
- Optimization of response measures
- Asset and network inventory with DocuSnap
- Reporting and documentation
- Skills: WSUS, BSI IT-Grundschutz, NIST, KRITIS, inventory and reporting, Trellix and ePO administration, threat hunting and forensics, incident and change management
Endpoint Security – Symantec Endpoint Protection Architecture and Policy Redesign
Olympus
- Planning and redesign of the Symantec Endpoint Protection infrastructure with over 10,000 Windows and Linux endpoints
- Modeling and adjusting policies according to compliance requirements, as well as administering the endpoint security solution
- Antimalware protection, incident response, forensic analysis, and malware analysis
- Lifecycle and patch management, as well as reporting
- Collaborating with business units in 2nd and 3rd level support
- Reviewing and adjusting SQL jobs and scripts
System Administration Hyper-V Data Center, McAfee and Defender
Schmersal
- Managing the existing Hyper-V data center and McAfee Endpoint Security with ePO
- Infrastructure redesign for migrating the on-premise McAfee solution to Microsoft Defender
- Planning strategy and implementation, including creating product comparison matrices
- Conducting workshops to teach Defender Suite technology
- Demonstrating attack surface reduction using the Microsoft Defender 365 suite
- Securing Microsoft 365 services, policy configurations, and system hardening
- Skills: Hyper-V data center cluster administration, McAfee Endpoint Security management, endpoint migration strategy planning, Zscaler, Citrix, Microsoft Azure, Office 365
Consultant
Sparkassen Finanz Informatik
- Working on cybersecurity/defense, compliance, information security management, business continuity, cloud security, Azure Entra ID, IT service management, audits, regulations, license management, and product lifecycle
- Planning and implementing a Microsoft Azure security architecture using a structured approach
- Performing a target vs. actual analysis of the existing Azure security infrastructure based on Microsoft Cybersecurity Reference Architectures (MCRA)
- Verifying identified entities such as virtual machines, networks, storage resources, and users for security gaps
- Conceptualizing and designing the Azure security architecture with Microsoft Defender (Network Security Groups, Azure Firewall, WAF, Zero Trust, Sentinel)
- Project planning and implementation in collaboration with stakeholders like IT operations, DevOps teams, and the security department
- Validating the security architecture through automated checks and manual penetration tests
- Transitioning the security architecture into ongoing operations with continuous monitoring and reporting
- Azure Entra ID identity and access management, as well as Purview design and management
- Applying data loss prevention, data classification, and activity monitoring
- Purview insider and data privacy risk management, as well as Microsoft 365 app governance with Microsoft Copilot for Security
- Managing Exchange, SharePoint, and Teams security in the Microsoft 365 admin center
- Detecting and analyzing attack vectors (IOC, IOA) and sandbox attack history analyses
- Administering the Qualys platform for vulnerability management and handling escalations to mitigate vulnerabilities
- Technical preparation and support for security audits against regulatory compliance requirements
- Creating reports, endpoint hardening, product lifecycle management, and incident, change, and problem management in ServiceNow
- Developing operation manuals, technical and organizational documentation, and conducting presentations and workshops
- Skills: Microsoft Azure, Microsoft Entra ID, identity and access management, Microsoft Purview, data loss prevention, Intune, Microsoft Active Directory, Microsoft Defender, Microsoft Sentinel, Microsoft 365 app security, Trellix ePolicy Orchestrator/Endpoint, EDR/XDR, Symantec Endpoint Security, BlueCoat Proxy, SQL scripting and query design, PowerShell scripting, patch and release management, Qualys vulnerability management, SOC, endpoint hardening, architecture design, advisory on regulatory and security requirements for the financial sector (DORA), ECB/TüVSec audits, license, permission, and policy management, privileged access management, Splunk SIEM, MITRE ATT&CK, BSI KRITIS, SecOps, BSI basic protection, NIS-2, BSI C5, ISO 27001, ISMS, IT service/business continuity management, ServiceNow incident, change, and problem management
McAfee Enterprise Security Management
Volkswagen AG / Volkswagen Financial Services
- Managing endpoint encryption and virus scan signatures
- Migrating McAfee ePO from version 4 to version 5
- Evaluating MOVE AV and implementing it in Citrix VDI
- Implementing and managing domain controller security with McAfee Change Control and Application Control
- Administering and managing McAfee SIEM and SIEM reporting
- Creating a product comparison matrix and evaluating antivirus products
- Migrating from F-Secure and Symantec Endpoint Protection to McAfee
- Evaluating Rapid7, Qualys, Nessus, and IBM SIEM
- Gateway administration and creating technical documentation
- Incident and escalation management, as well as monitoring
- Infrastructure patch and release management with Microsoft System Center
- 2nd and 3rd level support
- Skills: McAfee ePolicy Orchestrator, Virus Scan Enterprise, MOVE AV, McAfee Host Intrusion Prevention, Security for Microsoft Exchange/SharePoint, Change Control, Application Control, DLP, Encryption for Files and Folders, Device Control, SIEM, Vulnerability Manager, Global Threat Intelligence Proxy, Firewall Enterprise, Hyper-V, System Center, Server 2008-2012, SQL Server, Windows 7-10, Active Directory, IPsec, Qualys, Nexpose, Nessus, CyberArk, VMware, Citrix, Symantec Endpoint Protection, Sophos, TrendMicro, Kaspersky, IBM Security QRadar
Backoffice and Enterprise Security
Wincor-Nixdorf
- Central management of McAfee ePolicy Orchestrator servers and system infrastructure
- API scripting, SQL scripting, and carrying out migrations and updates
- Managing policies, tasks, antivirus, intrusion, firewall rules, and system encryption
- IT emergency planning and management, as well as enforcing corporate policies
- Successfully migrating McAfee ePolicy Orchestrator from 4.x to 5.x for a central antivirus management system
- Replacing Symantec Endpoint Protection with McAfee VirusScan and McAfee MOVE AV on approximately 5,000 units
- Evaluating and rolling out McAfee MOVE Antivirus multiplatform to improve performance on virtualized systems by 30-50%
- Consolidating database management onto a scalable Microsoft SQL Server 2008 R2 cluster solution
- Administering the SQL server (ODBC, security, roles, maintenance plans) and monitoring performance with PowerShell
- Conducting vulnerability assessments with McAfee Vulnerability Manager and incident response
- Creating reports, test environments, product documentation, and knowledge bases
- Skills: McAfee, Symantec, TrendMicro, SEP to McAfee migration, database and storage management, Oracle, DB2, MSSQL Server, SQL clustering, patch and release management, Wireshark, SiteAdvisor Enterprise, Installation Designer, SCCM
2nd/3rd Level Support
Unisys Outsourcing
- Technical and administrative support for the Bavarian judiciary and the State Ministry
- Planning and executing the migration from Windows XP/Office 2003 to Windows 7/Office 2010/Server 2008 R2
- User and role management and maintenance of Group Policy Objects (GPO)
- Client/server patch and release management
- Monitoring network components availability using Nagios and Microsoft System Center
- Incident management following the guidelines of the BSI IT-Grundschutz Catalogue
- File and print server administration, Exchange administration, and SQL database server administration
- Involvement in the design process for virtualization solutions (VMware, Citrix)
- Skills: user support, Citrix XenApp 6, Terminal Server administration, license management, Group Policies, rights management, application virtualization, System Center Operations and Configuration Manager, MS SQL Server, BSI IT-Grundschutz
Project administration and support for McAfee ePolicy Orchestrator 4.5
Brose Automotive
- Central management of about 10,000 clients and 1,000 servers in back office and production
- Migration from McAfee ePolicy Orchestrator 3.x to 4.x, including policies, tasks, and agents
- Integration and adjustment of the ePO structure to the global Active Directory scheme
- Analysis and evaluation of security incidents and remediation in a production environment
- SIEM analysis with SOC and administration of SQL Server 2005/2008 (migration, scripting, backup)
- Incident, change, and request management according to ITIL and technical support for international branches
- Creating documentation, reports, statistics, and conducting user training
- Designing and implementing a Windows Server 2008 R2 Hyper-V cluster with iSCSI storage connection
- Skills: McAfee Agent, VirusScan, Host Intrusion Prevention, Endpoint Encryption, GroupShield, SiteAdvisor, SQL Server, Hyper-V cluster, iSCSI, Virtual Machine Manager
Project implementation of domain infrastructure migration Windows Server 2000 / 2003 to Windows Server 2008, antivirus solution
- Server consolidation to VMware ESX 4.0 vSphere and training staff
- Setting up domain controllers, terminal servers, and application servers
- Providing remote applications and migrating computer and user accounts
- Deploying print services and printer rollout via GPO
- Managing Windows Server 2008 AD DS Group Policies and DFS/DFS-R shares
- Implementing a bidirectional trust between old and new domain
- Integrating the TrendMicro OfficeScan server and rolling out clients
- Implementing a backup concept for an HP tape library using CA Arcserve Backup 12.5
- Providing first, second, and third level support and documentation
Project CRM, Exchange, and Active Directory services
Regionally based companies
- Setting up, administering, and handing over a support hotline with the vTiger CRM system
- Training and educating staff on SUSE Linux Enterprise Server 10
- Extending the Active Directory schema and Group Policy management on Windows Server 2003 R2 and 2008
- Building a virtual Exchange Server 2007 infrastructure on VMware Infrastructure 3.5
- Implementing McAfee VirusScan 8.5 Enterprise and antivirus management with McAfee ePolicy Orchestrator 3.x
Project merger of nationwide control center networks and data center infrastructure
Group4Securicor / Securitas
- IT systems technician in the central emergency service control center during the merger
- Integrating nationwide network segments (LAN, WAN, WLAN, FC) into the central data center architecture
- Administration and management of active and passive network components
- Process optimization in the office area and creating a CMS wiki based on Drupal (PHP)
- Migrating and managing clients and servers from Windows 2000/XP to XP/Vista and Server 2008
- Consolidating the server infrastructure to VMware ESX Server 3.5 and ensuring high availability
- 24x7 first, second, and third level support including on-call duty and ticket management (OTRS)
- Monitoring the infrastructure using Nagios and GFI Network Server Monitor
- Application distribution via Citrix MetaFrame on Windows Terminal Server farms
- Active monitoring of network security with products from Symantec, McAfee, Trend Micro, SonicWall, and Cisco
- Administration, reporting, and backup of MS SQL Server 2000/2005/2008 and Exchange servers
Project planning, integration, and management of the IT infrastructure
Group4Securicor
- Procurement and provisioning of hardware from leading vendors (Dell, HP, IBM, Cisco, SonicWall)
- Design and architecture of Active Directory infrastructure
- Setup of database infrastructure with MS SQL Server 2000 and 2005
- Client and server migration from Windows 2000 to Windows XP/Windows Server 2003 R2
- Terminal Services administration (MS-TS, Citrix MetaFrame, ThinPrint)
- SQL Server administration including monitoring, reporting, backup, and security
- Management of backup tape libraries and administration of Exchange servers
- Client and server monitoring with GFI NSS and Nagios
- Implementation and management of VMware infrastructure
Project: Data center infrastructure setup
Group4Securicor
- Setup of Windows Terminal Server and Citrix MetaFrame server farm
- Ensuring printer driver compatibility and implementing load balancing
- Development of domain concept and Active Directory structure
- Migration of nationwide cash logistics centers to 32-bit management software
- Documentation and archiving according to ITIL guidelines
- Firewall administration and SonicWall VPN remote access
- Setup of a Small Business Server 2003 infrastructure including Exchange and mobile remote
- Implementation of Microsoft Software Update Service (WSUS) for automatic updates
- Network inventory with MOM and database administration of MS SQL 2000
- Backup strategy based on Arcserve 11 backup software
IT documentation
Mehler Bau GmbH
- System and network documentation in preparation for the ISO 9000 certification audit
WLAN planning and installation
Stadtverwaltung Meuselwitz
- Connecting a branch office to the central network using WLAN technology
- Verifying and monitoring security and performance
School network infrastructure planning
Gymnasium Borna
- Deployment and administration of Linux servers
- Firewalls and network security management
- Creation of network documentation and policy concept
Administration/IT
TSG Stuttgart
Administration/IT
TGB Peres
Measurement and Control Technology
TGB G.-Dreieck
Industries Experience
See where this freelancer has spent most of their professional time. Longer bars indicate deeper hands-on experience, while shorter ones reflect targeted or project-based work.
Experienced in Information Technology (26 years), Banking and Finance (10 years), Automotive (7 years), Sport (6 years), Professional Services (3.5 years), and Manufacturing (2.5 years).
Business Areas Experience
The graph below provides a cumulative view of the freelancer's experience across multiple business areas, calculated from completed and active engagements. It highlights the areas where the freelancer has most frequently contributed to planning, execution, and delivery of business outcomes.
Experienced in Information Technology (37 years), Operations (21.5 years), Project Management (12.5 years), Audit (9 years), Product Development (1.5 years), and Customer Service (0.5 years).
Summary
Through my long-standing experience as a system administrator in Windows environments and in project management, I have strong assertiveness, stress resilience, social skills, and good communication with customers and colleagues.
Skills
- Cloud Computing
- Siem
- Splunk
- Iso 29001
- Bsi Kritis
- Bsi C5
- Itsm
- Bsi Standard
- Bcm
- Endpoint Security
- Risk And Compliance Management
Operating Systems
- Windows
- Linux / Unix
- Mac
- Android
Hardware
- Bus Systems
- Printers
- Embedded Systems
- Measurement Devices
- Microcontrollers
- Siemens
- Plotters
- Proprietary Hardware
- Scanners
- Sensors
- Single And Multi Cpu Systems
- Control And Regulation Systems
- Tape Drives
- Video Systems
- Alarm Management Systems
- Ibm
- Sonicwall
- 3com
- Hp
- Cisco
- Linksys
- Diva Server
- Adapters
- Baystack
- Dell
- Avm
- Mobile Devices
- Microsoft
Programming Languages
- Visual Basic
- C++, C#
- Java
- Perl
- Php
- Html
- Pl/sql
- Sql
- Shell
Databases
- Ms Access
- Ms Sql Server
- Mysql
- Oracle
Data Communication
- Ethernet
- Hdsl
- Intranet
- Isdn
- Scsi
- Iscsi
- San
- Nas
- Das
- Iso
- Osi
- Lan
- Wlan
- Wan
- Mpls
- Atm
- Fc
- Dlan
- Ipx/spx
- Rfc
- Routing
- Rpc
- Rs232
- Tcp/ip
- Winsock
- X.400
- X.25
- X.225
- X.75
Knowledge
- Administration Citrix Xenapp 6 (Management And Centralization Of Applications In The Data Center, Installation And Configuration Of Citrix Xenapp 6 And Plug-ins On Windows Server 2008 R2, Use Of Administrative Consoles And Tools, Management Of Resources, Policies, Servers, Server Farm Settings, Printers And Virtualized Applications)
- Windows Client And Server Operating Systems / All Products (Migration, Rollout, Distribution, Administration And Management)
- Microsoft System Center Product Suite (Deployment, Planning And Management, Planning And Setup Of Sites And Client Integration, Software Distribution Configuration, Operating System Deployment And Software Update Management, Use Of Remote Tools And Mobile Device Management, Site Hierarchy Planning And Configuration)
- Incident And Change Management Systems
- Bmc Remedy, Iet It-service Management, Assyst, Ars
- Microsoft Office Suite (Migration, Document Management, Application Distribution, Security, Usability)
- Microsoft Sharepoint Portal Server (Planning, Design, Integration And Management Of Intranet Sites)
- Administration And Management Of Exchange Server Communication Infrastructure (Mailboxes, Transport, Connectors, Branch Offices, Owa, Windows Mobile Push, Policies)
- Planning, Design, Implementation And Administration Of Microsoft Windows Active Directory Services Infrastructure (Organizational Design, Group Policy, Access Rights Management, Server Management, High Availability, Security)
- Planning, Design, Implementation, Administration And Management Of Virtualized Infrastructures On Vmware Infrastructure Services And Vmware Esx/esxi Server, Vmware Workstation And Vmware Server (Development Of Virtualization Project Plan, Licensing, Requirements, Migration Of Existing Systems, High Availability)
- Database Administration Microsoft Sql Server And Ms Access (Design And Implementation, Access Projects With Sql Server, Performance Monitoring And Tuning, High Availability And Backup, Programming, Business Intelligence, Security, Recovery, Reporting, Administration)
- Oracle Dbms Administration (Good Basic Knowledge)
- Enterprise Security Management
- Mcafee, Symantec, F-secure, Trendmicro, Microsoft
- Administration Microsoft Terminal Server Farm With Citrix Metaframe Presentation Server And Thinprint
- Administration Of Various Linux/unix Variants (Debian, Red Hat, Ubuntu, Suse, Bsd)
- Novell Netware Administration (Good Basic Knowledge)
- Administration And Management Of Suse Linux Enterprise Server (Samba, Apache, Mysql, Crm Vtiger, Cms Drupal)
- Operator In 24/7 Support Hotline (User Support For Ms Office Applications, Technical Help Desk For Hardware And External Customer Support, Printer Management, Active Directory Password And Rights Management, Ticket Management, On-call Duty)
- Installation, Configuration And Management Of Vtiger Crm And Drupal Cms
- Administration Of Gfi Faxmaker For Exchange And Smtp
- Client Life Cycle Management (Clm) And Windows Server Update Services (Wsus) (Ms Systems Management Server, Microsoft Operations Manager)
- Tape Library Management With Backup Solutions Arcserve And Backupexec
- Facility Management (Monitoring And Management Of Emergency Power, Access Control Systems, Video Systems, Air Conditioning)
- Design And Integration Of Vpn, Vlan And Radius Authentication Mechanisms With Windows Server (Sonicwall, Alliedtelesyn, Cisco, Lancom, Hp)
- Setup And Management Of Network Infrastructures (Lan, Wan, Wlan, Dlan, Vpn, Vlan, Fibre Channel, San)
- Administration Microsoft Internet Information Server
- Implementation, Configuration And Management Of San, Das And Nas (Dell And Hp)
- Administration Of Vds-certified Emergency Call Center Infrastructure (Nsl) And Cash Center
- Planning And Implementation Of Organizational Policies For It Security, Data Protection And Compliance According To Bsi Gshb
- Administration Of Alarm Management And Video Surveillance Systems
- System Building For Special Applications, Service And Hardware Repair
- System And Network Inventory, License Management, Documentation And Reporting
- Hardware And Software Procurement, Purchasing
- Knowledge Management For Wiki Knowledge Base And User Training
Languages
Education
TSG Stuttgart
Administration/IT · Backnang, Germany
TGB Peres
Administration/IT
TGB G.-Dreieck
Instrumentation and Control Technology
Certifications & licenses
McAfee Application Control
Basic Administration For Citrix XenApp 6
MCP/MCSE/MCDBA Certification
Profile
Frequently asked questions
Do you have questions? Here you can find further information.
Where is Mike based?
What languages does Mike speak?
How many years of experience does Mike have?
What roles would Mike be best suited for?
What is Mike's latest experience?
What companies has Mike worked for in recent years?
Which industries is Mike most experienced in?
Which business areas is Mike most experienced in?
Which industries has Mike worked in recently?
Which business areas has Mike worked in recently?
What is Mike's education?
Does Mike have any certificates?
What is the availability of Mike?
What is the rate of Mike?
How to hire Mike?
Average rates for similar positions
Rates are based on recent contracts and do not include FRATCH margin.
Similar Freelancers
Discover other experts with similar qualifications and experience
Experts recently working on similar projects
Freelancers with hands-on experience in comparable project as a System and Endpoint Hardening
Nearby freelancers
Professionals working in or nearby Meuselwitz, Germany