Anouar Mohamed

Cloud-native DevSecOps Engineer


Summary

Final-year engineering student focused on cloud-native infrastructure, DevSecOps, Kubernetes diagnostics, CI/CD hardening, observability, and backend systems. I build practical operations tooling in Go, TypeScript, Python, and Java, with production internship experience across Docker Swarm, Portainer, Traefik, Nginx, uptime monitoring, CodeQL, dependency scanning, and deployment documentation. I am targeting Cloud/DevSecOps, infrastructure, Kubernetes, and backend roles where operational rigor matters.

Experience

I have worked on real infrastructure deployments, monitoring dashboards, secure CI/CD workflows, hospital workflow digitization, and open-source cloud-native systems.

ITODevSecOps and Infrastructure Intern

Pre-hire internship focused on production infrastructure, service migration, deployment automation, CI/CD hardening, monitoring, and operational documentation.

  • Administered VPS infrastructure and migrated roughly 6 application services to Docker Swarm, Portainer, Traefik, then Nginx.

  • Hardened CI/CD with tests, CodeQL, dependency scanning, API monitoring, and production uptime supervision.

  • Reduced recurring manual pre-deployment checks by roughly 30% through automation and documented deployment procedures.

  • Set up observability and uptime controls to accelerate incident diagnosis in production environments.

Finatech GroupDeployment, Virtualization, and Monitoring Intern

Infrastructure internship covering virtualized environments, monitoring dashboards, alerting, network segmentation, hardening, and operations documentation.

  • Deployed 8 virtualized environments and 4 monitoring dashboards with alerting for internal services.

  • Contributed to network segmentation across 3 logical zones and hardened baseline configurations.

  • Documented deployment and monitoring procedures for repeatable operations.

  • Reduced recurring manual monitoring checks by roughly 30%.

CHP CasablancaDigitalization and Workflows Intern

Digitized patient workflows around registrations, transfers, queues, and operational dashboards, improving traceability in a real hospital environment with strong operational constraints.

Key Project Highlights

KubeLens AI: AI-assisted Kubernetes diagnostics platform with inventory, deterministic incident analysis, runbooks, controlled remediation, postmortems, Prometheus/Grafana observability, Jaeger tracing, audit trails, and assistant workflows. View

StateSight: GitOps forensic platform still in active development. It compares Git desired state with live Kubernetes state, records provenance, groups drift into incidents, and keeps remediation intentional rather than automatic. View

DockerSwarmLens: Docker Swarm operations console with live inventory, deterministic diagnostics, incident workflows, approvals, assistant SSE streaming, append-only audit logs, telemetry, and production deployment docs. View

PentestBoard: Authorized web security assessment platform covering scope, targets, OWASP-style checklists, findings, evidence metadata, remediation tracking, activity logs, report approval, and C++ evidence processing. View

TCP Command Channel: Go TCP command channel with TLS, token auth, length-prefixed frames, allowlisted execution, single-session control, heartbeat handling, output caps, reconnect logic, and NDJSON audit logs. View

AWS/Zabbix Hybrid Monitoring: AWS-hosted Zabbix 7.0 monitoring lab over Docker Compose, supervising Linux and Windows Server infrastructure with VPC/security-group design, passive agent polling, dashboards, and alerting. View

Mundiapolis Library: Production university library platform with Next.js, React, TypeScript, PostgreSQL, borrowing, renewals, reviews, admin approvals, circulation, fines, reminders, analytics, exports, and CI. View

More selected work can be found on the projects page.

Open Source

NVIDIA Nodewright / Skyhook: Major contribution area of roughly 10K lines according to my CV, across fixes, workflows, tests, stability improvements, and Kubernetes operator behavior. The project is explicitly being renamed from Skyhook to Nodewright. Source

BigWheels, GKE Policy Automation, Kubernetes: Contribution areas around PRs, tests, documentation, and review, with roughly 1K lines each tracked in my CV. Source

Additional professional codebases: Worked across Flipt, Oracle FDR, cronet-transport-for-okhttp, aws-xray-sdk-node, GPU Operator, and other public repositories visible on my GitHub profile. Source

Operational Strengths

Production and exploitation: Real deployments, reverse proxies, VPS administration, Docker Compose, Docker Swarm, uptime controls, monitoring, and deployment documentation.

Diagnostics: Incident analysis, log reading, metric correlation, deterministic findings, runbook writing, and evidence-first operational workflows.

Security: Dependency control, CodeQL, Trivy, OWASP practices, RBAC, TLS, audit logs, container hardening, secrets handling, and safer write-action gates.

Collaboration: Open-source PRs, tests, reproducible fixes, code review, technical documentation, and communication across professional codebases.

Achievements

GitHub certifications: Completed GitHub Foundations, Actions, Advanced Security, and Administration.

Open source: Contributed to Nodewright/Skyhook, Bigwheels, GKE Policy Automation, Kubernetes, Flipt, Oracle FDR, cronet-transport-for-okhttp, and aws-xray-sdk-node.

Cloud and data certifications: AWS Cloud Practitioner, Huawei Cloud, and Cisco Data Analytics Essentials.

Leadership: Founding president of the Mundiapolis Chess Club and active Library Club contributor.

Education

Engineering Degree in Computer ScienceCloud-native, DevSecOps, infrastructure

Mundiapolis University, Casablanca, 2024 to present

Integrated Preparatory ClassesComputer science foundations

Mundiapolis University, 2022 to 2024

Baccalaureate in Physical SciencesCasablanca

2022