A security engineer for hire
Security automation on contract.
If you are looking for outside capacity for technical security implementation or SecOps automation, this is what I do. I work on engagement, with a written scope, broken into milestones, either directly for you or as a subcontractor to your consultancy.
Last updated: 22 August 2026
Two ways people engage me
The same work, in two contract setups.
For end-user companies
Direct engagement
You have an audit finding, a remediation plan or an alert flood your team can't keep up with. I contract with you, build in your environment, and at the end your own operations team carries it forward. No account manager between us, and no junior the work gets handed to after kickoff.
For consultancies and system integrators
Subcontracting
You sold an assessment or a compliance project, and you need someone who actually does the technical part. I step in as a subcontractor, under your name, without touching your client relationship. This is the setup I work in most often, and where most of my references come from.
What it means concretely
Automation is not a product. It is six specific pains removed.
Alert triage and enrichment
Before
Every alert reaches a human, and most of the day goes on ruling out false positives.
After
Alerts get context automatically: asset owner, vulnerability state, previous occurrences, threat intel. What remains is genuinely a human decision. In practice: 500 alerts in, three that need a person.
Log pipelines and detection tuning
Before
Everything goes into the SIEM, cost climbs, and the signal drowns in the noise.
After
A log flow filtered, normalised and routed at the source, with tuned detection rules. Less stored data, more usable alerts.
Evidence collection for audits
Before
Before every audit, someone spends two weeks collecting screenshots and exports by hand.
After
Evidence generates on schedule and lands versioned in storage. When the auditor arrives it is already there, and it will be there next cycle too.
Access reviews
Before
The access review is a spreadsheet someone circulates quarterly and nobody reads.
After
Automated collection, owner mapping and drift alerts: dormant privileged accounts, permission creep, logins bypassing MFA.
Configuration drift detection
Before
The system was compliant when it was handed over. Six months later nobody knows if it still is.
After
Control state is measured continuously, and drift raises an alert. That is what keeps compliance from being a snapshot.
Restore testing
Before
The backup runs. Whether it restores tends to be discovered in production.
After
Scheduled, documented restore drills with records: 3-2-1-1-0, with an immutable copy.
What I don't take on
So it doesn't surface on the third call.
- I don't sell licences and I don't bring in a platform I earn commission on. I build on proven open-source components, so you pay for engineering.
- I don't issue audit opinions and I don't certify. Certification is done by the designated body; I build what it examines.
- I don't run 24/7 on-call. If you need continuous monitoring coverage, an MDR provider supplies it; I integrate and tune it for you.
Frequently asked questions
Do you work as a subcontractor, or only on direct engagements?
Both. Consultancies and system integrators regularly bring me in as implementation capacity: you own the client relationship, I deliver the technical work within your framework. An NDA is standard, and I don't approach your client behind your back.
How much does an automation engagement cost?
The assessment starts from €1,200 fixed, in two to three days, so you have the number before you commit. A focused build of a single automation area is from €2,500 fixed. Full implementation is a milestone-based proposal from roughly €6,000. Continuous controls monitoring runs from €700 per month. In a subcontracting setup, day-rate billing works too.
How much capacity can you bring?
Honestly: I am not a twenty-person team and I don't price like one. I run one larger implementation at a time, with continuous monitoring engagements alongside. If your deadline needs more than that, I say so on the first call, not in month three.
What technologies do you build on?
Whatever the environment justifies. My day job is SIEM engineering and detection tuning at a national telecom provider, alongside access management, network segmentation and backup architecture. I have also worked in manufacturing OT/IT environments where downtime is not an option.
Do we need to buy licences?
In most cases, no. I build from proven open-source components, and what gets built is yours: configuration, scripts, evidence pipelines, documented so your own team can operate it without me.
Still wondering whether the regulation reaches you at all? Four questions settle it, and full NIS2 implementation has its own page. Past work and the full service list are on the home page.
