<style> .film__track { height: auto !important; } .film__stage { position: static !important; height: auto !important; /* Ohne diese Zeile ist der Rückfall LEER: container-type: size bemisst die Bühne nicht mehr nach ihrem Inhalt, und overflow: hidden schneidet alles weg. */ container-type: normal !important; } .film__poster { position: absolute !important; } .film__content [data-film-anchor] { position: static !important; transform: none !important; opacity: 1 !important; margin: 2.5rem clamp(1rem, 5vw, 4rem) !important; max-width: 34rem; } </style>
AI-generated image

For development teams, agencies & product teams · DevSecOps practice

DevSecOps Freelancer for CI/CD, Deployment and Hardening of Existing Web Applications

I reinforce existing development teams where the code leaves the repository: build pipelines, containers, secrets, servers and release processes – as an external, clearly scoped development service.

Work on existing pipelines and serversNo operator responsibility, no on-call duty

When it fits

When external DevSecOps reinforcement makes sense

Not every team needs its own platform department. Often what is missing is one person taking care of exactly this part for a few weeks.

Deployments are done by hand

Releases run on manual steps, uploads or a script that only one person on the team truly understands.

The pipeline slows you down instead of carrying you

Builds take too long, fail in ways nobody can reproduce, or end up testing something other than the artifact that actually ships.

Security is on the list, never in the sprint

Headers, secrets, dependencies and access rights are known gaps – nobody just has the head space for them.

It works locally, not in production

Differences between the development and production environment produce failures that only become visible after the deployment.

Scope

What I take on

Everything between commit and production – built so your team can keep running it without me afterwards.

CI/CD pipelines

GitHub Actions with separate build and deploy jobs, YAML workflows, self-hosted runners and a rollback that is one button rather than one night shift.

Docker & containers

Multi-stage builds, reproducible images and isolated services, so the development and production environments stop drifting apart.

Secrets & environment separation

Environment variables, Docker secrets and a clean separation of development and production data – none of it in the repository.

Linux servers & Nginx

Ubuntu and VPS setups, reverse proxy, TLS configuration and production-ready routing instead of individually grown exceptions.

Security headers & CSP

Content Security Policy, HSTS and Permissions-Policy set so they protect the application without silently dismantling it in the production build.

Release processes & automation

Shell scripts, maintenance routines and documented procedures – so the path to production does not live in one person's head.

Not sure where your biggest lever is?

A short technical conversation about pipeline, environment and release answers that faster than any list of services.

Collaboration

Clear roles. Scoped access.

External, project-based development work – clearly scoped, documented and traceable at any time.

Project integration

I work inside your existing infrastructure and your repository, on defined tasks and with the access those tasks require – no more than that.

Terms of engagement

  • Work on existing pipelines, servers and repositories
  • Project-based or hourly billing
  • No operator responsibility, no on-call duty
  • Access is time-limited, documented and revoked at the end

Process

How an engagement starts

First understand what happens today when you deploy. Then decide what is worth doing.

  1. Assessment

    I look at the repository, the pipeline and the target environment and describe what actually happens on a deployment – without changing anything.

  2. Prioritisation

    The findings turn into a short, ordered list: what has immediate effect, what can wait, and what you are better off keeping in-house.

  3. Implementation

    Scoped work packages, every change traceable in the repository, no rebuilding of running systems without agreement.

  4. Handover

    What I built is documented and operable without me. That is the goal of the collaboration, not its farewell.

Limits

What I am not the right person for

Five points that are better settled now than in invoice number three.

Not in scope

  • Round-the-clock on-call duty and shift-based incident response
  • Operator responsibility for your systems
  • Attested audits or certifications (ISO 27001, BSI Grundschutz)
  • Penetration tests with a formal report
  • Large-scale Kubernetes platforms

Why this is on the page

Because a DevSecOps engagement goes wrong exactly here: the expectation is not the same as the assignment. If you need one of these, I say so in the first conversation – and say where it is better placed.

Proves — booking platforms & PMS

LeaseLoop – Property Management System

LeaseLoop

Property Management System

A complete property management system for holiday rentals, guest houses and small hotels — an owner dashboard for properties, units and bookings, plus a public booking flow for guests.

System
Owner dashboard + public booking page
Stack
Angular · Django REST · PostgreSQL
Invoicing
WeasyPrint (PDF generation)
Updated
March 2026
  • 2026

    Thailand Vloggers

    Headless platform for Thailand travel YouTubers with an SEO-optimised content engine and nightly data sync.

    Angular 21 · Django 5 · Celery · YouTube Data API

    Details View Live
  • 2025

    Videoflix

    Streaming platform with server-side video processing and segmented delivery.

    Angular 18 · Django REST · FFmpeg · Redis

    Details View Live
  • 2026

    Coderr

    Marketplace with offer management, a rating system and separate profiles for providers and clients.

    Angular · Django REST · JWT · PostgreSQL

    Details View Live
  • 2025

    DABubble

    Real-time chat with structured channel logic and direct messages.

    Angular · TypeScript · Firebase

    Details View Live
  • 2025

    Join

    Project management tool with drag-and-drop, subtasks and contact management.

    Vanilla JS · Django REST · PostgreSQL

    Details View Live

Same building blocks, different application.

These systems run on the same pipelines, containers and servers we would be talking about.

Verified Expertise

Four state-recognised (AZAV) certificates – each verifiable as a PDF. For you that means: your project is delivered by someone who has formally proven security, data protection and modern development skills – complementing real project work, not replacing it.

Benjamin Tietz, full-stack developer at BTECH SOLUTIONS
Benjamin TietzFull-Stack Developer & DevSecOps
AI-generated image

Let's talk about your path to production.

Free initial consultation. Honest assessment. Clear next steps.

Project inquiry