Profil anonyme

SENIOR DEVOPS / DEVSECOPS · Expert · Vitry-sur-Seine, France

SENIOR DEVOPS / DEVSECOPS

Réf. JS-C00315
pythonAWSAzureDocker📍 Vitry-sur-Seine, France💼 10 ans d'XP
🚀 Proposer un projet
E-mail
🔒 Réservé employeur
Téléphone
🔒 Réservé employeur
LinkedIn
🔒 Réservé employeur
CV
🔒 Réservé employeur

À propos du candidat

Demonstrated capacity of designing and implementing reliable CI/CD pipelines, automating infrastructure deployments, and maintaining high-performing and secure cloud environments.

🔒 Quelques mots masquésInscrire mon entreprise pour tout voir

Compétences

pythonAWSAzureDockerKubernetesCI/CDGitDevOpsPowerShellAnsibleBashJenkins / CI-CDTerraformLinux AdministrationDevSecOpsMonitoringDatabase Management

Expérience professionnelle

I
🔒
IT Architect / Senior DevOps Engineer

• Audited and redesigned the company’s infrastructure to migrate monolithic applications to a microservices model using Docker Swarm and GitLab CI, improving application flexibility and scalability. • Optimized and refactored Ansible deployment code, reducing human errors and deployment times by 50%. • Created and implemented a complete deployment pipeline with GitLab CI, automating the deployment process for all legacy applications (PHP, Node.js), improving production update frequency. • Dockerized all legacy applications, ensuring portability and consistent execution in containerized environments. • Designed and deployed a comprehensive monitoring stack with Grafana, Promtail, Loki, and Portainer, enabling real-time monitoring of the entire platform and rapid issue identification. • Secured the platform by implementing authentication mechanisms and access management for production and development environments. • Built a geolocated web infrastructure on OVH with HAProxy and CloudFront to ensure high availability and improved application performance based on user location. • Actively intervened on incidents, providing support for production and operational issues (MCO) to maintain high platform reliability. • Conducted code audits to ensure best practices were followed and optimized application performance and security. • Installed, optimized, and implemented a Galera cluster stack and GlusterFS for high availability and storage scalability. • Led the migration from a SaaS model with a physical server for each client to an optimized, geolocated multi-tenant SaaS infrastructure, with auto-failover. This allowed us to reduce costs by 5x. • Prepared the migration of applications from Docker to Google Kubernetes Engine (GKE): conducted a proof of concept (PoC) and created necessary Kubernetes resources (manifests, services, deployments, etc.). Environnement technique : Docker, GitLab CI, Grafana, Promtail, Loki, Portainer, HAProxy, CloudFront, Galera, GlusterFS, GKE

1 janvier 2024 - Present
I
🔒
IT Architect / Senior DevOps Engineer

• Automated infrastructure provisioning and deployment processes using Terraform and Ansible,reducing manual configuration time by 90% and improving consistency.(Azure) • Led a team of 3 DevOps engineers in the design, implementation, and management of a highly scalable Kubernetes cluster for a microservices-based application hosted on Azure/Aws/GCP. • Designed and implemented CI/CD pipelines with Azure DevOps for a microservices-based application hosted on Azure/Aws. • Collaborated with developers to implement GitOps workflows for managing infrastructure changes and ensuring infrastructure as code best practices (Argocd, Helm, Kustomize) • Migrated a 30+ legacy application suite (NodeJS, Dotnet, Java) to Kubernetes, ensuring smooth transition and improved resource utilization. • Implemented automated testing for all applications resulting in 50% less manual effort. • Developed and maintenance Bash, Python and PowerShell scripts to automate application, reducing manual configuration time by 70% and speeding up deployments. • Established Git governance policies (branching, merge approvals, code reviews) and maintained a centralized knowledge base of playbooks, runbooks, and security procedures. • Acted as the internal point of reference for security and DevSecOps across 30+ projects, advising on best practices and long-term strategy for secure automation. • Embedded security controls into Infrastructure-as-Code workflows (Terraform, Ansible, Helm, Kustomize) to enforce secure configurations from development through production • Conducted comprehensive design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in both new and existing solutions. • Collaborated with developers to design and implement application test logic, focusing on performance and KO testing using tools like K6, Gatling, and others. • Configured autoscaling policies (HPA) with KEDA for dynamic resource allocation based on application demands, resulting in a 35% reduction in infrastructure costs and a 60% increase in application performance during peak traffic periods. Environnement technique : Azure, AWS, GCP, Terraform, Ansible, Kubernetes, NodeJS, Dotnet, Java, Argocd, Helm, Kustomize, Bash, Python, PowerShell

1 octobre 2023 - Present
D
🔒
Devops/DevSecOps | Cloud | Kubernetes | Freelance

• Migrated a 50+ legacy application suite (java) to Kubernetes, resulting in a 60% reduction in infrastructure costs and a 40% increase in application performance. • Designed and implemented CI/CD pipelines with Azure DevOps for a microservices-baseqd application hosted on Azure (dual run AKS/GKE) • Organized the DevSecOps upskilling and supported the deployment and established the training plan for the application teams concerned. • Monitored major incidents and implemented effective remediation plans. • Managed and updated a comprehensive knowledge base, providing clear and concise instructions for end-users. • Ensured ongoing operational efficiency by implementing lean principles and conducting regular process reviews. • Developed and implemented a suite of governance KPIs that drove a 30% improvement in cloud IT operations efficiency. • Implemented a comprehensive DevSecOps strategy: Detection of sensitive data in the code, scan, patch and signature of Docker images, check DAST and SAST (OWASP), use secret providers on Kubernetes to secure access to sensitive data from the pods, the implementation of RBAC strategies, networkPolicy as well as all the tools necessary for securing applications in Kubernetes (Trivy, Clair, Neuvector, Kubebench, kubehunter, m9sweeper, Kyverno, etc ..) • Collaborated with developers to design and implement application test logic, focusing on performance and KO testing using tools like K6, Gatling, and others. • Embedded security controls into Infrastructure-as-Code workflows (Terraform, Ansible, Helm, Kustomize) to enforce secure configurations from development through production • Conducted comprehensive design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in both new and existing solutions. • Led the design and implementation of a scalable and performant web architecture, utilizing DNS, CDN, routing, API management, and load balancing solutions. • Automated infrastructure provisioning and deployment processes using Terraform and Ansible,reducing manual configuration time by 90%. • Provided PostgreSQL database administration, including installation, configuration, backup and recovery procedures, and performance tuning. • Provided Level 3 support, diagnosing and resolving complex application and infrastructure issues. Environnement technique : Azure, Kubernetes, Terraform, Ansible, Docker, PostgreSQL, Trivy, Clair, Neuvector, GitLab

1 janvier 2023 - 1 octobre 2023
L
🔒
Linux system engineer | Devops | Free-lance

• Designed, installed, and managed Hashicorp Vault clusters in both development and production environments, securing sensitive secrets infrastructure access. • Designed secure and scalable infrastructure in AWS, including: EC2, VPC, IAM, S3, CloudWatch, and Route53. • Automated infrastructure provisioning and deployment processes using Terraform and Ansible. • Migrated +5 legacy application suite (java) to a containerized architecture using Docker and Amazon Elastic Kubernetes Service (EKS). • Optimized Dockerfile build process to reduce build size and improve image layer caching, resulting in faster build times and reduced image size (Kaniko, Gitlab-CI) • Provided Level 3 support, troubleshooting complex system issues, identifying root causes, and implementing solutions to ensure system uptime and performance. • Implemented an internal PKI for the management of internal certificates, streamlining certificate management and improving security posture. • Enhanced the security of Docker images and the supply chain through the implementation of a comprehensive DevSecOps strategy. • Detected sensitive data in the code to prevent the accidental inclusion of secrets or credentials in Docker images. • Scanned, patched, and signed Docker images to ensure they meet security standards and best practices. • Secured image builds to maintain the integrity of the supply chain, using tools such as Trivy, Clair, and NeuVector for vulnerability scanning and monitoring. • Focused on creating rootless and distroless Docker images, reducing the attack surface by eliminating unnecessary components. • Ensured containers ran with the least privileges, minimizing the risk of potential exploits. • Improved overall security by ensuring Docker images included only essential runtime components. • Consolidated HTTP web traffic management using Traefik, Haproxy, and Let's Encrypt, improving efficiency and centralized control over traffic flow, reducing latency by 40%. • Reduced storage costs by 30% by optimizing S3 storage space utilization and streamlining document management processes. Environnement technique : AWS, Docker, Terraform, Ansible, Hashicorp Vault, Trivy, Clair, NeuVector

1 juin 2022 - 1 janvier 2023
L
🔒
Linux system engineer | Devops Cloud

• Involved in migrating customers physical (Linux) servers and applications to cloud (AWS) and test it. Designed an Architectural Diagram for different applications before migrating into amazon cloud for flexible, cost-effective, reliable, scalable, high-performance and secured. • Optimized containerized applications running on Amazon Elastic Kubernetes Service (EKS) for improved performance and scalability. • Administered VMware ESX clusters, including VM provisioning, HA/DRS configuration, performance monitoring, and resource optimization. • Automated the CI/CD pipeline using AWS CodeBuild and CodePipeline, enabling continuous integration and deployment with minimal downtime • Automated infrastructure provisioning and configuration using IaC tools, Terraform, Ansible, reducing manual configuration time by 90%. • Collaborated with development and operations teams to troubleshoot production issues and streamline deployment processes. • Maintained and optimized Elasticsearch clusters • Assisted customers in optimizing their applications by performing application and infrastructure fine-tuning, which resulted in a 30% performance improvement and a 20%. Environnement technique : AWS, EKS, Terraform, Ansible, VMware ESX, Elasticsearch

1 octobre 2021 - 1 juin 2022
L
🔒
Linux system engineer | Devops

• The environment is : 100% Linux implemented, and managed a scalable object storage infrastructure using Scaleway and OpenIo. • Maintained highly available and secure AWS/GCP environment for a large-scale application. • deployed, and maintained 4 large-scale (100+ nodes) on-premises Kubernetes clusters. • Automated infrastructure provisioning and configuration using SaltStack and ansible, reducing manual configuration time by 80%. • Performed routine maintenance tasks including deployment management, package updates, and security patching. • Managed a fleet of +500 Linux servers supporting web servers. • Design, implement and maintain the tools and processes necessary to deliver high quality software products. • Provide Devops support to the development team and ensure that the software development infrastructure is reliable and scalable. • Increased operational efficiency by 30% by developing Python scripts to automate Kubernetes and storage operations, including deployments, scaling, and maintenance. • Led the successful migration of a large portfolio (50+ projects) of Helm charts from version 2 to version 3, ensuring compatibility and smooth transition. • Enhanced infrastructure and application visibility by implementing comprehensive Datadog monitoring, enabling proactive identification and resolution of issues. Environnement technique : Linux, Scaleway, OpenIo, AWS, GCP, Kubernetes, SaltStack, Ansible, Python, Datadog

1 juillet 2018 - 1 juin 2021
L
🔒
Linux system engineer | Devops | SysOps

• Managed the installation, configuration, and maintenance (of 200+ servers) of Linux systems, security settings, directories, network configurations, and storage solutions, meeting project and operational requirements, increasing system uptime by 45% while reducing network latency issues. • Scripted automation tools for Linux systems administration tasks such as backup management, software installation & patching that saved 16 hours per week in manual work at peak times throughout the year. • Monitored the health of all Linux-based systems on a daily basis using various monitoring tools like Nagios & Zabbix; proactively identified potential issues before they impacted operations or customers. • Troubleshot complex technical issues related to Linux OSs and applications; reduced server downtime by 40%. • Implemented a robust backup and recovery strategy, reducing data loss incidents by 60% and ensuring business continuity. • Assisted in the development of disaster recovery plans. Environnement technique : Linux, Nagios, Zabbix

1 avril 2015 - 1 juin 2018
L
🔒
Linux Systems Administrator

• Design and implementation of a log management solution: Flume, Elasticsearch and Kibana. • Design and implementation of a log management solution: Flume, Elasticsearch and Kibana. • Installation, configuration and operation of web infrastructures: Apache, PHP, MySQL. • Management and maintenance of Smile's virtualization infrastructure: Openvz and KVM. • Setting up a videoconferencing solution based on BigBlueButton, Tomcat • The implementation of a redundant Mysql architecture: HAproxy. • Technical support for Smile users and Customers: GLPI. • Installation and configuration of a virtualization platform: Proxmox. • Optimization of Smile's internal backup solutions: Bacula, Duplicity. • Setting up an Apache cluster: load balancing and failover. • Creating Centreon templates: Clapi. • Solving problems on shared infrastructures. • Installation and implementation of mail servers: Bluemind, Postfix. Environnement technique : Flume, Elasticsearch, Kibana, Apache, PHP, MySQL, Openvz, KVM, BigBlueButton, Tomcat, HAproxy, GLPI, Proxmox, Bacula, Duplicity

1 novembre 2014 - 1 avril 2015

Formation

C
Certification
CKA
1 octobre 2020 - 1 octobre 2020
M
Université Evry Val d'Essonne
Master 2
1 septembre 2012 - 1 août 2014
B
ISET, SFax
B.S. in Computer Science
1 septembre 2008 - 1 juin 2011
Ce profil vous intéresse ?
Inscrivez votre société pour voir l'identité, le CV et les coordonnées.
Créer mon compte entreprise →