Skip to content
Available for selected IT projects

Hi, I am

Max HüneckeIT security & infrastructure,
that works day to day.

I plan and operate firewalls, networks, and Microsoft 365 for your company. I support your existing IT team or take direct technical responsibility as an independent consultant, with a clear handover.

Independent adviceDirect responsibilityDocumented handover

30-minute initial call · I usually respond within 24 hours

Max Hünecke, IT Security Consultant and Palo Alto Networks Certified Next-Generation Firewall Engineer for Mid-Sized Businesses in Bremen
Palo Alto Networks Certified Next-Generation Firewall Engineer Badge
Palo Alto Networks Certified SD-WAN Engineer Badge
Check Point Certified Security Administrator Badge
Location: Bremen • Consulting for Infrastructure & IT Security

Strategy. Security. Implementation.

Good IT infrastructure is built where problems are solved at the root instead of being permanently patched over with workarounds. My standard is resilient solutions that are secure, maintainable, and reliable in daily operations.

My professional foundation was built in the mid-market and developed further in demanding enterprise environments. During my dual study programme, I learned the operational and financial requirements of established IT estates. At thyssenkrupp Automation Engineering and today in firewall and proxy management at ArianeGroup, I work with infrastructure subject to stringent security, stability, and availability requirements.

I bring this experience to mid-sized businesses through an independent consultancy alongside my corporate role. My recommendations are not influenced by sales commissions or hardware margins. Palo Alto Networks is my technical focus for demanding firewall and SD-WAN environments, complemented by hands-on experience with Fortinet and WatchGuard and a Check Point CCSA certification, but technology choices follow the organisation's requirements, operating model, and budget. My objective is a maintainable, documented architecture that supports secure and reliable day-to-day operations.

My Consulting Services

What I
do for you.

Systematic analysis, controlled implementation, and documented handover, aligned with your requirements, operating model, and budget.

From risk analysis to secure go-live

Network Security & Firewall Architecture

"Our firewall is reaching end of support. Before purchasing a replacement, we want to reassess the architecture, requirements, and migration path."

The firewall is a central control point in your security architecture. I assess the network for weaknesses and design policy, segmentation, and security profiles to limit attack surfaces and reachable systems. Focusing on Palo Alto Networks, I migrate the firewall with a prepared parallel run and controlled cut-over.

Service in detail

Use existing licences, secure your tenant

M365 Security & Cloud Migration

I review your existing Microsoft 365 licences and configure the security capabilities they include, such as Defender, Conditional Access, or Intune. I also manage controlled Active Directory and Exchange migrations to the Microsoft cloud with a clear migration and rollback plan.

Service in detail

Resilient WAN connectivity for multi-site companies

SD-WAN & Site Connectivity

I design Prisma SD-WAN architectures that intelligently combine different transport links and can reduce dependency on classic MPLS connections. The system continuously assesses link quality and automatically routes business-critical applications over the best available path in case of disruption.

Service in detail

Secure network infrastructure for SMEs

Network Segmentation & LAN/WLAN

I build highly available networks to industry standards and bring structure through clean VLAN segmentation and port-based access control (802.1X NAC). This allows a compromised device to be isolated quickly, while segmentation and access controls effectively limit lateral movement.

Service in detail

AD hardening, role separation & ransomware prevention

Active Directory & Infrastructure Security

I implement the Microsoft Enterprise Access Model with strict role separation, rotating LAPS passwords, and hardened GPO baselines. This limits privileged access paths and reduces the risk of a compromised account being used to escalate to domain level.

Service in detail
Case Studies

Projects & Results

Documented projects with specific outcomes. Clients are named with their consent; otherwise, the industry remains visible. The published price ranges reflect the agreed project cost corridors.

Exchange Server 2016 → Microsoft 365

Mail Migration & Hybrid Infrastructure

~8 weeksBremen / Remote
40 mailboxes migrated, zero data lossJust an Outlook restart neededExchange maintenance eliminated

Initial Situation

At AVM Event, email still ran on a local Exchange Server 2016. With end of support approaching, the real risk was falling behind technically. An unpatched system quickly becomes an open door for attackers, a genuine problem for ageing Exchange servers. Rather than simply replacing the old hardware, management used the moment to modernize and opted for a move to Microsoft 365. Because email is business-critical, the switch had to happen without disrupting daily operations.

Concept & Implementation

To keep day-to-day operations safe, I chose a staged, hybrid transition instead of a hard cut-over on a single date. Before the actual migration, I first cleaned up the existing user management to rule out typical error sources early on. Mailboxes were then moved to the Microsoft cloud in controlled batches. For older systems like printers and scanners, I installed a lightweight on-premises solution to replace the previous Exchange Server, which is still in use today. Access to the new cloud mailboxes was secured with multi-factor authentication (MFA) from day one.

Result

All 40 mailboxes and public folders were migrated without data loss. For employees, the switch meant little more than restarting Outlook and signing in with their new Microsoft account. Retiring the local server removed the patching and maintenance overhead. It also eliminates the attack vector tied to that self-hosted infrastructure. Mandatory MFA further improved account security. The existing Microsoft 365 licensing also gives the team tools for more modern ways of working, including Microsoft Teams, SharePoint, and Planner. Both the migration and the final setup were handed over fully documented. That leaves AVM Event free to come back to me for future support, or to bring in a different IT provider.

Exchange 2016Microsoft 365Hybrid MigrationMFA
IndustryEvent Technology
Employees~30 employees
Project Price~€4,000 to €6,000 net

Similar situation in your company?

My Background

Background &
Experience

From rebuilding infrastructure after a cyberattack to operating demanding enterprise environments. My focus is on scalable, well-documented infrastructure where security is considered from the design stage. I bring together architecture, technical implementation, and operational requirements.

02.2026 – PresentCurrentSelf-employed

Freelance IT Consultant

Self-employed (Part-time)

My focus is secure, maintainable IT infrastructure for small and medium-sized businesses. This includes high-performance local networks, resilient site connectivity, and modern Microsoft 365 environments. I provide this consultancy alongside my corporate role as a systems administrator. Requirements and technical dependencies are assessed systematically, and each solution is implemented so that it can be documented, operated, and developed further by the responsible team.

Project delivery: Design, migration, and traceable operational documentation of firewall infrastructure
Managed Services: Predictable patch management and ongoing technical support to reduce operational risk
Hardening & Modernisation: Modernising Active Directory, M365 environments, networks, and servers to established security and operational standards, covering segmentation, backup concepts, and cloud migrations
Holistic consulting: Independent evaluation of service providers and transition to modern security standards
IT SecurityNetwork SecurityFirewall MigrationMicrosoft 365Cloud MigrationServer MigrationActive DirectoryIT Infrastructure SME
03.2025 – PresentCurrentPermanent

Network Administrator Firewall & Proxy Management

ArianeGroup GmbH

Operation of business-critical infrastructures in a European aerospace company under strict confidentiality and stability requirements. My focus is on administration, troubleshooting, and the technical development of firewall, proxy, and core infrastructure services. Based on daily practice, I proactively derive improvements and roll them out together with the architecture department.

Stable operation of complex security environments including enterprise firewalls, web application firewalls, and proxy servers
Ensuring stable, highly available operation of critical baseline services such as DNS and DHCP in highly sensitive networks
Analysis of complex incidents and implementation of measures to restore or stabilize operations
Close technical coordination with the architecture team for secure and seamless technology rollouts
Enterprise FirewallProxy ManagementDNS & DHCPWAFTroubleshooting
07.2024 – 02.2025Permanent

IT Network Engineer

thyssenkrupp Automation Engineering GmbH

Contributed to the development and standardization of the international network and security infrastructure of an international automotive specialist. Provided technical support for TISAX requirements through standardization and hardening of the infrastructure, and modernized global site connectivity.

Global standardisation of the Palo Alto Networks firewall infrastructure through centralised Panorama management
Complex SD-WAN migration of a site in China, including a high-availability solution and Smart DNS routing for local and global services while accounting for regulatory requirements
Architecture design and strategic phase-out of legacy MPLS lines: independent planning of SD-WAN topology, provider evaluation, and development of the migration concept
Independent execution of site tech refreshes to modernize outdated hardware at international locations
Panorama DeploymentSD-WAN ArchitectureTISAXIntl. RolloutsMPLS Phase-out
08.2023 – 06.2024Permanent

IT Systems Engineer

ERCE-Beteiligungs GmbH

Seamless transition after my dual studies into the holding company of the FRERICHS GLAS group. As part of the central IT Shared Services team, I shared responsibility with colleagues for the operation and development of the critical infrastructure for all affiliated companies, with the goal of keeping business- and production-critical systems at each site reliably available.

Design and introduction of a strict NAC concept (802.1X) for central network access control
Preparing and executing the NAC rollout in production with staged testing, phased activation, and continuous certificate monitoring
Ongoing firewall administration and IPsec VPN operations including coordination with external service providers
Reliable operation of the enterprise-wide storage and backup infrastructure
NAC / 802.1XFirewallIPSec VPNBackup & StorageShared Services
09.2020 – 07.2023Permanent

Dual Student Business Informatics

FRERICHS GLAS GmbH

This is where I built my IT foundation, from user support and troubleshooting to server and service migrations and the rebuild after a critical security incident. A Hafnium zero-day attack paralysed the company. Alongside my studies, our team rebuilt significant parts of the infrastructure with a hardened Active Directory, clear network segmentation, and a revised security architecture.

Broad IT foundation: user support, troubleshooting, and server and service migration as the basis of my hands-on experience
Co-developed and technically implemented the Active Directory rebuild together with my mentor, including a strict tiering model and hardened GPOs
Implementation of consistent network segmentation to significantly limit lateral movement between network zones
Rollout of Zero Trust Endpoint Protection with strict sandboxing of unknown processes, balanced against operational application requirements
Successful establishment of a consistent Defense-in-Depth approach as the new foundation
Active DirectoryZero TrustNetwork SegmentationDefense in DepthGreenfield Rebuild

The beginning of an exciting journey...

Qualifications & Certificates

Certified Expertise

Practical expertise backed by vendor certifications, structured project management, and an academic foundation in business informatics.

Professional Certifications
Palo Alto Networks Certified Next-Generation Firewall Engineer Badge
Certified

Palo Alto Networks Certified Next-Generation Firewall Engineer

Palo Alto Networks

Vendor certification from Palo Alto Networks at an advanced level, confirming in-depth knowledge of design, operations, and troubleshooting for modern NGFW environments from App-ID policies to TLS decryption. It is highly regarded in the security industry and is the basis for securely configuring and operating production firewall environments.

Palo Alto Networks Certified SD-WAN Engineer Badge
Certified

Palo Alto Networks Certified SD-WAN Engineer

Palo Alto Networks

Vendor certification from Palo Alto Networks at an advanced level, confirming in-depth knowledge of design, implementation, and operations for Prisma SD-WAN, including central visibility and security integration. It is highly regarded in the security industry and is the basis for application-aware WAN architectures as an MPLS alternative.

Check Point Certified Security Administrator Badge
Certified

Check Point Certified Security Administrator (CCSA) R82

Check Point Software Technologies Ltd.

Vendor certification from Check Point covering configuration and management of Security Gateways and the management platform: policy and layer management, Identity Awareness, and Threat Prevention. Complements the Palo Alto Networks specialization with cross-vendor firewall competence.

Certified

EfficientIP Certified DDI Administrator v8

EfficientIP

Vendor certification for operating DNS, DHCP, and IP address management at enterprise scale. DDI is the invisible foundation every network depends on: when something breaks here, everyone notices. The certification reflects hands-on experience from real enterprise operations.

Certified

Basic Certificate in Project Management

GPM German Association for Project Management

Foundation certification in structured project management following GPM/IPMA methodology. Shows that IT projects are managed not just technically but also organizationally: with clear phases, transparent communication, and a documented handover into operations.

Academic Education
Bachelor of Science (B.Sc.)

Business Informatics

Leibniz University of Applied Sciences Hannover

Dual study program in Business Informatics: three years of theory combined with direct involvement in live data center operations. The mix of business and technical education helps evaluate IT projects not only on technical merit, but also in terms of cost-effectiveness and operational fit.

Frequently Asked Questions

Clear answers to the most important questions about working together. No jargon, straight to the point.

Let's talk.

Tell me about your current situation. You will receive an initial technical assessment and a proposal for the next steps.

On-site in Bremen and the surrounding region · Remote throughout Germany

* Fields marked with * are required.

All product and company names mentioned are the property of their respective owners and are used solely to describe qualifications and professional experience. No commercial or contractual relationship exists between me and any of the companies or brands referenced.

© 2026 Max Hünecke. All rights reserved.