YB
Available

Freelance Senior DevOps & DevSecOps Engineer · Cloud Solutions Architect · SRE

Whatever you're shipping, I build the platform underneath it.

Yahia Mohamed Benabbou. Four years designing, migrating, securing and operating production infrastructure across AWS, Azure, Oracle Cloud and on-premises estates — Kubernetes at fleet scale, Terraform everywhere, CI/CD that ships daily, and the observability to prove any of it works. Available as a freelance DevOps engineer for contract and consulting work, remote on European hours.

  • Senior DevOps Engineer
  • Senior DevSecOps Engineer
  • Cloud Security Engineer
  • Cloud Solutions Architect
  • Site Reliability Engineer
  • Platform Engineer
99.9%Service availability
across production estates
−70%Provisioning time
Terraform + Ansible
50+Kubernetes clusters
under management
18Cloud & platform
certifications

Selected work

Six systems I designed, migrated, or kept alive.

Client names are withheld under NDA. Architecture, scope and outcomes are available in detail on a call.

Delivery platform2026
CI/CD · Pipeline security

One CI/CD platform for thirty-plus microservices

Replaced fragmented per-team pipelines with a centralised, templated delivery platform. Security scanning, dependency checks and policy gates run on every build, so problems surface at merge time rather than in a quarterly audit.

Azure DevOps · Jenkins · GitHub Actions · SAST/SCA · HashiCorp Vault · Helm

+60%deployment frequency

−80%vulnerabilities reaching production

95%findings remediated pre-production

Cloud build-out2025
Bare metal · Sovereign

Morocco's first Compute Cloud@Customer deployment

Delivered the country's first full-rack Oracle C3 installation alongside Oracle's architects, then onboarded ten-plus organisations onto the platform — workloads that legally could not leave national territory.

OCI Compute Cloud@Customer · Terraform · Ansible · OCI DevOps · GitHub Actions

10+organisations onboarded

1stC3 deployment in the country

100%data residency maintained

Compute platform2025
GPU · Kubernetes

GPU clusters for inference and compute-intensive workloads

Built and tuned NVIDIA GPU environments on OCI for rendering, simulation and large-model inference — autoscaling, network and topology tuning, and monitoring dashboards that make expensive silicon accountable per workload.

OCI GPU shapes · NVIDIA · vLLM · Kubernetes · Terraform · OCI Monitoring

Scaleautoscaled multi-node GPU fleet

Costper-workload attribution and tuning

ISO27001 / PCI DSS certified facility

Cloud migration2024 – 2026
VMware exit · Landing zones

Core workloads off VMware, onto multi-cloud

Led migration of core applications from on-premises VMware estates to OCI and AWS. Designed the landing zones, network topology and cutover runbooks, then ran the cutovers — in environments where an outage is a regulatory event.

OCI · AWS · VMware · Terraform · Ansible · OKE

−35%infrastructure cost after migration

99.9%availability held through cutover

0unplanned outages from migration

Platform engineering2023 – 2026
Kubernetes · Observability

Kubernetes at fleet scale, with the observability to prove it

Designed and ran a production Kubernetes platform spanning fifty-plus clusters with automated lifecycle management, golden-path Helm charts and a shared observability stack. Teams ship to it without filing a ticket.

Kubernetes · Helm · Istio · Prometheus · Grafana · Loki · ELK

50+clusters, automated lifecycle

SOC 2controls implemented and evidenced

−70%request to running environment

Product engineering2022 – 2024
Full-stack · AWS

Full-stack product work, then the pipelines to ship it

Built and maintained cloud-native applications in Node.js, React and Next.js for a London product team, then took over delivery: CI/CD, AWS infrastructure and automated testing. The reason my platform work lands with developers instead of at them.

Node.js · React · Next.js · GitLab CI · AWS (EC2, S3, RDS) · MySQL

+25%application performance

CI/CDintroduced from scratch

SASTand dependency scanning in-pipeline

Security in practice

Three of those engagements, in security terms.

The same systems, re-cut by the controls I built and ran inside them — identity, secrets, service-to-service trust, and the gates standing in front of production.

Identity & zero trust2024 – 2025
Banking · Multi-cloud

Zero-trust access and service identity for a banking platform

Core banking applications moved to OCI and AWS, and the trust model moved with them: identity-based access control instead of flat network trust, microsegmentation between workloads, mutual TLS for east-west traffic through the service mesh, and Vault as the single source for secrets, dynamic database credentials and certificate issuance. Compliance checks run continuously against the regulatory baseline rather than the week before an audit.

HashiCorp Vault · Istio mTLS · Kubernetes RBAC · microsegmentation · OCI Cloud Guard · AWS GuardDuty · Terraform · Ansible

500K+daily transactions on the platform

99.9%environment consistency, drift eliminated

mTLSservice-to-service by default

Pipeline & container security2026
DevSecOps · Kubernetes

Security gates on every build, and clusters that enforce them

Centralised delivery for thirty-plus microservices with SAST, DAST, dependency analysis, container scanning and secrets detection wired into every pipeline — then the runtime half most teams skip: image scanning, admission control, network policies and RBAC on the clusters receiving those artefacts. Findings route to the owning team with severity thresholds attached, not into a quarterly spreadsheet.

SonarQube · Trivy · SAST/DAST/SCA · secrets detection · admission control · network policies · Kubernetes RBAC · GitHub Actions · ArgoCD · Helm · OpenShift

−45%production incidents

30+microservices on one hardened path

−50%engineer onboarding time

Application security2022 – 2024
AuthN / AuthZ · Node · Java

Authentication and authorisation inside the application

A cloud-native SaaS platform in React, Node.js and Java microservices on EKS, where the security work sat in the code rather than around it: token-based authentication with OAuth 2.0 and OIDC, role-based authorisation enforced per service, and the application-layer defences that get dropped under delivery pressure — input validation and injection prevention, output encoding against XSS, and CSRF protection on state-changing routes.

Node.js · Java · React · OAuth 2.0 · OIDC · bearer tokens · AWS EKS · GitLab CI · SAST

OAuth 2.0and OIDC token-based auth

−60%mean time to resolution

AppSecinjection, XSS and CSRF defences

How I work with clients

Six things I get hired to do.

I take engagements where the infrastructure has to keep working while it changes. Discovery call first, written scope second, no exceptions.

DevOps & CI/CD automationShip on every commit, safely

CI/CD pipelines built from scratch or rescued from sprawl — GitOps delivery, deployment automation, infrastructure as code, and the golden paths that let teams ship without filing a ticket.

  • CI/CD pipelines
  • GitOps
  • Deployment automation
  • Terraform · Ansible

Cloud architecture & engineeringDesign decisions that hold up for years, not just at go-live

Reference architectures, multi-cloud design and platform decisions across AWS, Azure and Oracle Cloud — capacity planning, cost modelling and advice shaped by what I've actually run in production, not by a single vendor's playbook.

  • Reference architecture
  • Multi-cloud design
  • Capacity & cost planning

Migration & landing zonesGet onto cloud without a bad quarter

Assessment, target architecture and execution for moves from on-premises or VMware onto AWS, Azure or OCI. Multi-account structure, network design, identity baseline, cost guardrails, and a cutover plan you can hand to an auditor.

  • Landing zone
  • VMware exit
  • Cutover runbooks
  • Cost guardrails

Platform & KubernetesGive your engineers a paved road

Production-grade clusters, GitOps delivery, reusable Terraform modules and an internal developer platform, so teams provision what they need themselves with the guardrails already baked in.

  • EKS · AKS · OKE
  • GitOps
  • Helm golden paths
  • Autoscaling

Reliability engineeringMake the pager quieter

SLIs, SLOs and error budgets that mean something. Observability across logs, metrics and traces. Incident response, blameless postmortems, capacity planning and tested disaster recovery — not a DR document nobody has opened.

  • SLO design
  • Prometheus · Grafana
  • Incident response
  • DR testing

DevSecOpsMove security left, for real

Security gates inside the pipeline instead of bolted on after: IaC scanning, container and dependency analysis, secrets management, policy-as-code, and a remediation workflow engineering teams will actually follow. Application side too — authentication and authorisation design, injection and XSS/CSRF prevention, and secure service-to-service communication over TLS and mTLS.

  • Pipeline gates
  • IaC scanning
  • AuthN / AuthZ
  • Vault · KMS
  • mTLS
  • Policy-as-code

Technologies I work with

Tools I have run in production, not just read about.

Cloud platforms

AWS (EC2, EKS, Lambda, RDS, Aurora, DynamoDB, S3, VPC, IAM, CloudWatch, Step Functions) · Azure (VMs, AKS, Storage, Monitor, Azure DevOps) · Oracle Cloud Infrastructure · Compute Cloud@Customer · GCP

Containers & orchestration

Kubernetes · Docker · EKS · AKS · OKE · ECS · Fargate · OpenShift · Rancher · Helm · Istio · microservices architecture

Infrastructure as code

Terraform (modules, remote state, multi-environment) · Ansible · AWS CloudFormation · AWS CDK · immutable infrastructure · configuration drift elimination

CI/CD & delivery

Azure Pipelines · Jenkins · GitHub Actions · GitLab CI · OCI DevOps · GitFlow · progressive delivery · deployment automation

Observability

Prometheus · Grafana · Loki · ELK and Elasticsearch · Kibana · CloudWatch · AWS X-Ray · OpenSearch · Azure Monitor · SLI and SLO instrumentation

Identity & access

IAM and least privilege · role-based access control · Kubernetes RBAC · OAuth 2.0, OIDC and SAML federation · X.509 certificates · mutual TLS between services · Zero Trust principles · access review and permission governance

Secrets, crypto & network

HashiCorp Vault and dynamic secrets · AWS KMS and Secrets Manager · certificate lifecycle and key rotation · encryption at rest and in transit · vulnerability scanning and remediation · VPC design · ALB and NLB · NGINX · HAProxy · security groups and NACLs

Data & streaming

Kafka and event-driven architecture · RDS (MySQL, PostgreSQL) · Aurora · DynamoDB · MongoDB · Redis · S3 and Azure Blob · high-throughput ingestion pipelines

Compute & virtualisation

VMware and on-premises estates · KVM · NVIDIA GPU shapes · HPC and bare metal · capacity planning · hybrid connectivity · datacenter operations

Credentials

Eighteen certifications across four clouds.

Engineering degree (Bac+5) in Networks, Systems and Programmable Services — École Nationale des Sciences Appliquées, Marrakech. A five-year integrated engineering track under the Moroccan system, broadly equivalent to a Master's degree.

Kubernetes & Cloud Native Security Associate (KCSA) Linux Foundation · CNCF

AWS Certified DevOps Engineer Professional · Amazon Web Services

AWS Certified Solutions Architect Associate · Amazon Web Services

AWS Certified Developer Associate · Amazon Web Services

Certified Kubernetes Administrator (CKA) Linux Foundation · CNCF

Kubernetes & Cloud Native Associate (KCNA) Linux Foundation · CNCF

Azure Network Engineer Associate · Microsoft

OCI Foundations Associate ×3 Oracle

Oracle Cloud Data Management & AI Foundations Oracle

Certification names link to the issuer's public verification page. Certified Kubernetes Administrator (CKA), OCI Foundations Associate ×3 and Oracle Cloud Data Management & AI Foundations are left unlinked pending a confirmed badge URL — verifiable on request in the meantime.

In preparation — not yet held

  • Certified Kubernetes Security Specialist (CKS) Linux Foundation · CNCF

    In progress
  • AWS Certified Security Specialty · Amazon Web Services

    In progress
  • AWS Certified Solutions Architect Professional · Amazon Web Services

    Planned
  • Certified Cloud Security Professional (CCSP) ISC2

    Planned

These are on the roadmap, not on the wall. They are listed so you know where the practice is heading — and so nothing above this line is ever in doubt. Every certification in the list above is held today and can be verified on request.

References

People who have shipped alongside me.

"It has been a great pleasure working with Yahia. A great professional with extraordinary technical skills."
Stéphane GuelfoSVP Business Solutions — Cloud Transformation,
Sovereign Cloud, GPU & AI Platforms
"Yahia has an exceptional ability to get to the bottom of any problem his team faces, whether technical or human. That is rare in one person, especially combined with how business-oriented he is given his level of technical expertise."
Salwa El OuattabCloud Security Engineer — AWS ×2, AZ-500, SC-100
"J'ai collaboré avec Yahia dans un contexte exigeant où performance et réactivité étaient essentielles. Son expertise dans le domaine du cloud et sa capacité à travailler efficacement en équipe ont contribué de manière significative au succès de nos projets."
Soukaina HilaliFRIT Project Manager — PMP, PRINCE2 V7,
Scrum Master, COBIT 5, ITIL V3

Engagement

How the work is scoped, run and handed back.

Infrastructure work fails on process more often than on technology. These are the terms I work under, before anyone writes a line of Terraform.

Engagement models
4–12 week delivery projects  ·  fractional platform lead, 2–3 days per week  ·  architecture review and advisory retainer.
How it starts
Discovery call, then a written scope — deliverables, milestones, and a fixed price or day rate — agreed before work begins. No scope, no start.
Access & least privilege
I work inside your tenancy and your repositories, using scoped, time-bound credentials you issue and can revoke at any moment. Production data stays in your environment. No credentials retained after handover.
Confidentiality
Your NDA is signed before technical discovery. Every client on this page is withheld under NDA — you get the same treatment, permanently.
Handover
Every engagement ends with runbooks, architecture decision records and a live handover session. If your team cannot operate it without me, the work is not finished.
Contracting
Direct engagement, or through your existing contractor-management or employer-of-record provider where procurement requires it.
Working hours
Rabat, GMT+1. Full overlap with European teams, morning overlap with US East. On-site across EMEA on request.
Languages
English  ·  French  ·  Arabic.

Questions

What people ask before they engage me.

If your question isn't here, it belongs on a call, not guessed at on a page — just ask.

Are you available right now?

Check the status dot in the rail/topbar and the Contact section below — both stay current. If it says available, I am taking on contract and consulting engagements.

Do you work on-site, or remote only?

Remote-first, based in Rabat (GMT+1) with full overlap with European teams and morning overlap with US East. On-site across EMEA on request — see Engagement.

Can I verify your certifications myself?

Yes — every certification in Credentials links to the issuer's public verification page. The few not yet linked are called out explicitly rather than left to look verified when they aren't.

Do you sign an NDA before discussing our systems?

Yes, always, before any architecture, code or infrastructure detail is shared. Every client on this page is withheld under NDA as a result — you'd get the same treatment.

What industries have you worked in?

Banking and fintech, sovereign cloud, GPU compute, platform engineering and product engineering — see Work. No single-industry lock-in; the discipline carries across sectors.

Is this the same as Nearvic?

Yes — nearvic.com is the company-level version of the same practice, for buyers who need to engage a named business rather than an individual. Same work, same person, different framing for different procurement needs.

Contact

Tell me what is breaking, or what you are about to build.

I reply to every serious enquiry within one working day. If your problem is outside what I do well, I will say so and point you somewhere better.

General enquiries
info@nearvic.com
Based in
Rabat, Morocco  ·  GMT+1  ·  remote-first, EMEA on-site on request
Status
Taking on contract and consulting engagements