About
From Tunis to Paris, through production
A product only exists once it runs in production.

Île-de-France · France
It all starts in Tunis. An engineering student at INSAT — DevOps & Cloud Computing degree earned in 2020 — I didn't wait for graduation to start working: interfaces and UX at Speegar, mobile applications at Peaksource Vision, then full-stack development and building a DevOps culture at Vynd. Today I live in Île-de-France and work across France and Europe.
The field then taught me everything: migrating Zaion from bare metal to AWS, with Kubernetes clusters running more than 1,000 pods; leading 17 engineers at BNP Paribas to move 140 machines to the cloud, in a regulated banking environment; operating a DevOps platform at ENGIE serving more than 600 organizations and 10,000 users; auditing the multi-cluster OpenShift infrastructure of the Government of Monaco, spanning AWS and a sovereign cloud.
I never chose between infrastructure and product. I wrote web applications, APIs, and an iOS app before diving into Kubernetes — and I still write code today: tooling in Go and Python, Next.js applications, all in service of the platforms I operate. This dual profile lets me deliver a complete product, from the idea all the way to running in production.
One conviction serves as my compass: a product only exists once it runs in production. It is what drove me to earn the 16 certifications of the Golden Kubestronaut track — to master every layer of the system, from networking to observability — and it is what frames every engagement: an architecture is only worth what it becomes once deployed, monitored, and operated.
Career
10 years in the field
Nov 2025 — present · Monacoin progress
Gouvernement de Monaco
OpenShift Tech Lead / Senior Cloud & DevOps Consultant
I support the DSN/DSI of the Government of Monaco: auditing a multi-cluster OpenShift infrastructure spanning AWS and the Monaco Cloud sovereign cloud, then designing the target hybrid architecture.
- In-depth audit of a multi-cluster OpenShift infrastructure (OCP 4.x) spanning AWS and the Monaco Cloud sovereign cloud — C3 classified data, IPsec VPN
- Led the Architecture, Day-2 Ops, and Security & Compliance workshops
- Comparative study of 4 hosting scenarios and design of the target hybrid architecture, landing zone included
- Opportunity & ROI study
- 13 technical briefs, an audit report, and a formal recommendation
AWS · OpenShift (OCP 4.x) · Monaco Cloud · VPN IPsec
Jul 2024 — presentin progress
ENGIE Digital & IT
DevOps / Platform Engineer
I operate and evolve the DevOps platform serving 600+ organizations and 10,000+ users: 6 production EKS clusters, 97 Terraform stacks, end-to-end Grafana observability.
- 6 production Kubernetes (EKS) clusters, 200+ VMs, 97 Terraform stacks across multiple AWS accounts
- DevOps platform — GitHub Enterprise, Jenkins, Artifactory/Xray, SonarQube, Jira/Confluence — serving 600+ organizations and 10,000+ users
- Cluster Autoscaler → Karpenter migration; GitHub Actions runners (ARC) and in-cluster Jenkins controllers
- Full Grafana observability stack: Alloy, Vector, Prometheus, Mimir, Loki, Tempo
- Internal tooling: alert centralization in Python, runner management in Go, a Next.js + Go monitoring application
- −60% intervention time thanks to automation
AWS · Terraform · Karpenter · Jenkins · Grafana · Alloy · Vector · Prometheus · Mimir · Loki · Tempo · Go · Python · Next.js · Kubernetes (EKS) · GitHub Actions (ARC)
Sep 2023 — Jul 2024
BNP Paribas
DevOps Tech Lead
I led a team of 17 engineers to migrate 140 legacy machines to IBM DMZR Cloud, in a regulated banking environment.
- Led and mentored a team of 17 engineers in a regulated banking environment (PCI-DSS, ISO 27001)
- Migrated 140 legacy machines to IBM DMZR Cloud (Kubernetes/OpenShift), strangler pattern
- Multi-zone DR and pod-to-pod mTLS
- GitOps with Helm + ArgoCD, GitLab CI pipelines
- Dynatrace monitoring, Kube-bench and Falco audits
Kubernetes · Helm · ArgoCD · GitLab CI · Kube-bench · Falco · OpenShift · IBM DMZR Cloud · Dynatrace
Jun 2023 — Dec 2025
Neurones IT
DevOps Architect & Multi-cloud Squad Leader
I led the multi-cloud Containerization & Orchestration squad and designed Nkube, the multi-cloud platform for creating and managing Kubernetes clusters.
- Led the multi-cloud Containerization & Orchestration squad
- −30% costs on the company's Azure infrastructure
- Design and technical lead of Nkube, a multi-cloud Kubernetes cluster platform
- Kubernetes-as-a-Service solution published on the Outscale marketplace
- GCP migration: 3 GKE clusters, Rancher, Cloud SQL HA
Kubernetes · Azure · Outscale · GCP (GKE) · Rancher · Cloud SQL
Mar 2021 — Jun 2023
Zaion
DevOps Engineer
I migrated the platform from OVH bare metal to AWS and industrialized deployments: 100+ servers, clusters running 1,000+ pods, 45+ GitLab CI pipelines.
- Migration from OVH bare metal to AWS — 100+ servers
- Kubernetes clusters running 1,000+ pods
- 45+ GitLab CI pipelines: Docker, Trivy, SonarQube, ECR
- Centralized EFK logging
- Internal Go tool (Helm SDK) for on-demand deployments
Kubernetes · AWS · OVH · GitLab CI · Docker · Trivy · Go · Helm · SonarQube · ECR · EFK
2017 — 2021 · Tunis
Vynd
DevOps Tech Lead (2018–2021) & Full-stack Developer (2017–2021)
Full-stack developer from 2017, then DevOps Tech Lead starting in 2018: I established the DevOps culture there — +44% performance, −45% hosting costs.
- Established the DevOps culture: +44% performance, −45% hosting costs
- Azure DevOps pipelines; Docker, Kubernetes, Helm infrastructure on AWS
- Web development: .NET Core, Node, Angular
- iOS application in Swift 5
Azure DevOps · Docker · Kubernetes · Helm · AWS · .NET Core · Node · Angular · Swift 5
2018 — 2019
Peaksource Vision
Mobile Developer
I developed Android and iOS mobile applications, from Bridgestone to Carrefour Anniversary.
- Development of Android and iOS mobile applications
- Apps: Bridgestone, Karhabtek Labess, Aprofort, El Menara, Carrefour Anniversary
Android · iOS
2016 — 2017
Speegar
Frontend Developer & UX/UI Designer
My professional beginnings: frontend development and UX/UI design.
- Frontend development
- UX/UI design
Skills
What I practice daily
Kubernetes & containers
Kubernetes · OpenShift (OCP) · EKS/GKE/AKS · Helm · Kustomize · Docker · containerd
GitOps & Policy as Code
ArgoCD · Argo Workflows · FluxCD · Kyverno · OPA/Gatekeeper
Networking & service mesh
Cilium (eBPF) · Istio · Calico · Network Policies
Autoscaling & FinOps
Karpenter · Cluster Autoscaler · KEDA · HPA/VPA · Cost optimization
Observability
Grafana · Mimir · Loki · Tempo · Alloy · Prometheus · OpenTelemetry · Vector · ELK
CI/CD
GitHub Actions (at scale, ARC) · GitLab CI · Jenkins · Azure DevOps · Tekton
IaC & automation
Terraform · Terragrunt · Pulumi · Ansible · Packer
Cloud
AWS · Azure · GCP · OVH · Scaleway · Outscale · Monaco Cloud (sovereign)
Security & compliance
Vault · Keycloak · Trivy · Falco · Kube-bench · PCI-DSS · ISO 27001 · Classified environments
Development
Go · Python · TypeScript/JavaScript · Next.js · NestJS · .NET · Node.js · Swift (iOS) · Bash
Databases & middleware
PostgreSQL · MySQL · MongoDB · Redis · Elasticsearch · RabbitMQ · Nginx/HAProxy
Consulting
Infrastructure audit · Target cloud/hybrid architecture · Workshops · Opportunity & ROI studies
Certifications
The certification wall
16
The CNCF's highest level of recognition: every CNCF certification plus the LFCS — 16 certifications in all. Lifetime status — Kubestronaut since December 2025.
A few hundred holders worldwide. TODO(Khalil): check the current figure on cncf.io before publishing.
All 16 certifications of the Golden Kubestronaut track — CNCF + LFCS, complete.
CKA
Certified Kubernetes Administrator
CKAD
Certified Kubernetes Application Developer
CKS
Certified Kubernetes Security Specialist
KCNA
Kubernetes and Cloud Native Associate
KCSA
Kubernetes and Cloud Native Security Associate
LFCS
Linux Foundation Certified System Administrator
PCA
Prometheus Certified Associate
ICA
Istio Certified Associate
CCA
Cilium Certified Associate
CAPA
Certified Argo Project Associate
CGOA
Certified GitOps Associate
KCA
Kyverno Certified Associate
OTCA
OpenTelemetry Certified Associate
CNPA
Certified Cloud Native Platform Engineering Associate
CNPE
Certified Cloud Native Platform Engineer
CBA
Certified Backstage Associate
Microsoft
AZ-400
DevOps Engineer Expert
Expert
AZ-204
Azure Developer Associate
Associate
AZ-900
Azure Fundamentals
Fundamentals
TODO(Khalil): Credly links and exact dates to be provided
Languages
- Frenchnative
- Englishfluent
- Arabicnative
Education
2015–2020
National Engineering Degree — DevOps & Cloud Computing
INSAT, Tunis
TODO(Khalil): fournir le PDF — généré automatiquement depuis ce contenu en phase 2
Let’s talk
Let's talk about your project
Audit, platform, product, or training: tell me about your context, I reply within 24 to 48 h.