Abraham Reich-Dultz

Endpoint-Management, IT-Compliance und Automatisierung für Apple- und Linux-Umgebungen. Endpoint management, IT compliance and automation for Apple and Linux environments.

Derzeit Werkstudent IT-Systemadministration bei Cap3 in Kiel, verantwortlich für die MDM-Seite der ISO-27001-Umsetzung. Parallel B.Sc. Wirtschaftsinformatik an der FH Kiel. Deutsch und Englisch auf muttersprachlichem Niveau. Kiel, hybrid oder remote in der EU. Currently a working student in IT systems administration at Cap3 in Kiel, owning the MDM side of our ISO 27001 implementation. Alongside it, a B.Sc. in Information Systems at Kiel UAS. Native German and English. Kiel, hybrid, or remote within the EU.

SchwerpunkteFocus areas

🖥️

Endpoint & MDMEndpoint & MDM

Verwaltung von Apple-Flotten über Linux-basierte MDM-Server: Enrollment, Konfigurationsprofile, Richtliniendurchsetzung. BYOD-Offboarding mit Microsoft Intune. Managing Apple fleets from Linux-based MDM servers: enrollment, configuration profiles, policy enforcement. BYOD offboarding via Microsoft Intune.

🛡️

IT-ComplianceIT compliance

Umsetzung endpointbezogener ISO-27001-Anforderungen: Gerätehärtung, Nachweisführung und Einhaltung von Datenaufbewahrungsfristen. Implementing endpoint-side ISO 27001 controls: device hardening, evidence collection and data-retention compliance.

⚙️

AutomatisierungAutomation

Wiederkehrende Admin- und Compliance-Aufgaben als Workflow statt Handarbeit — n8n, Python, PowerShell, Microsoft Graph API. Turning recurring admin and compliance chores into workflows instead of manual work — n8n, Python, PowerShell, Microsoft Graph API.

📈

Linux & MonitoringLinux & monitoring

Betrieb virtualisierter Linux-Systeme (Proxmox, vSphere), Docker-Deployments, RADIUS-Authentifizierung sowie Monitoring mit Grafana und Nagios. Running virtualised Linux systems (Proxmox, vSphere), Docker deployments, RADIUS authentication, and monitoring with Grafana and Nagios.

Ausgewählte ArbeitenSelected work

MDM-Einführung für eine Apple-FlotteMDM rollout for an Apple fleet

Cap3 · 2025—

Aufbau eines Device-Management-Setups für macOS-Clients auf Basis von Linux-Servern — Enrollment, Konfigurationsprofile und Richtliniendurchsetzung als Grundlage für die endpointbezogenen ISO-27001-Anforderungen. Built a device-management setup for macOS clients on Linux servers — enrollment, configuration profiles and policy enforcement, forming the basis for the endpoint-side ISO 27001 controls.

macOSMDMLinuxISO 27001

Compliance-Automatisierung mit n8nCompliance automation with n8n

Cap3 · 2025—

Workflows für die Einhaltung von Datenaufbewahrungsfristen sowie automatisches Alerting, wenn BYOD-Geräte aus Microsoft Intune entfernt werden — Compliance-Prüfungen laufen damit kontinuierlich statt stichprobenartig. Workflows enforcing data-retention deadlines plus automatic alerting when BYOD devices drop out of Microsoft Intune — turning periodic compliance spot-checks into continuous ones.

n8nMicrosoft IntuneGraph APIBYOD

Automatisierte Prüfung der AssetverwaltungAutomated asset-inventory reconciliation

macio · 2023

Azure Logic App, die den Gerätebestand gegen Snipe-IT und die Microsoft Graph API abgleicht und Abweichungen meldet — statt manueller Inventurläufe. An Azure Logic App reconciling the device inventory against Snipe-IT and the Microsoft Graph API and flagging discrepancies — replacing manual inventory runs.

PythonPowerShellAzure Logic AppsSnipe-IT

Monitoring auf Raspberry-Pi-BasisRaspberry Pi based monitoring

macio · 2023

Erweiterung des Nagios-Monitorings auf einem Raspberry Pi inklusive USV-Anbindung, damit der Ausfall der Stromversorgung selbst überwacht und gemeldet wird. Extended Nagios monitoring on a Raspberry Pi including UPS integration, so that a power failure is itself monitored and reported.

NagiosLinuxRaspberry PiUSV / UPS

Diese WebsiteThis website

2025—

Vollständig selbst betrieben: statische Seite in einem Docker-Container hinter Traefik auf einem Hetzner-VPS, TLS über Let's Encrypt, DNS und Caching über Cloudflare. Entirely self-operated: a static site in a Docker container behind Traefik on a Hetzner VPS, TLS via Let's Encrypt, DNS and caching through Cloudflare.

HetznerDockerTraefikCloudflare

TechnologienStack

Endpoint
MDM (macOS / Apple), Microsoft Intune, Microsoft Entra ID, Active Directory, M365 Admin Center
Compliance
ISO 27001 (Endpoint-Controls), Gerätehärtung, BYOD-Offboarding, Datenaufbewahrung ISO 27001 (endpoint controls), device hardening, BYOD offboarding, data retention
AutomatisierungAutomation
n8n, Python, PowerShell, Bash, Microsoft Graph API, Azure Logic Apps
InfrastrukturInfrastructure
Linux (Debian, Ubuntu), macOS, Windows Server, Proxmox, VMware vSphere, Docker, Traefik, Hetzner
Monitoring & NetzwerkMonitoring & network
Grafana, Nagios, RADIUS, VPN, MFA, Sophos Firewall, IPFire, Cloudflare
WerkzeugeTooling
Git, GitLab, GitHub, Jira, Confluence, Snipe-IT, SQL

KontaktContact