Cloud | DevOps | SRE & PLATFORM ENGINEER

Mamadou
Mouhamed
SOW.

kubectl get infra --all-namespaces | grep "production-grade"

Building and operating production-grade cloud-native infrastructure. Bare-metal OpenStack · Kubernetes at scale · GitOps · SIEM/SOC automation. Dakar, Senegal — remote-ready worldwide.

3+
YEARS EXPERIENCE
12+
PROJECTS SHIPPED
14×
CERTIFICATIONS
35%
INCIDENT REDUCTION
Mamadou Mouhamed SOW
Mamadou M. SOW
Cloud · Platform · SRE Engineer
📍 Dakar, Senegal · Remote-ready 🌍
mamadou@platform ~ zsh
kubectl get nodes
NAME STATUS ROLES
prod-control-01 Ready control-plane
prod-worker-01 Ready worker
prod-worker-02 Ready worker
argocd app list
NAME SYNC HEALTH
prod-stack Synced Healthy
monitoring Synced Healthy
wazuh-soc Synced Healthy
openstack server list --all
12 instances running on OpenStack 2024.2
Ceph: HEALTH_OK | PGs: 128 active+clean
01 //

Core Skills

Cloud & IaaS
OpenStack 2024.2KayobeCephAWSProxmoxNutanixVMware
Kubernetes & Platform
Cluster APICAPI-CAPOvClusterArgoCDFleetHelmCalico CNI
🔭
Observability & SRE
PrometheusGrafanaLokiOpenTelemetrySLO/SLAPagerDuty
🛡
Security & DevSecOps
Wazuh SIEMSnort/SuricataFortinetNessusIAMCEH
IaC & Automation
TerraformAnsibleGitHub ActionsGitLab CIJenkinsGitOps
💻
Scripting & Languages
PythonBashPowerShellGo (basics)HCLYAML
🌐
Networking
BGPOSPFVXLANVLAN802.1XDNS/DHCPCisco/Juniper
📊
Virtualization & Storage
Ceph RBD/CephFSHP ProLiantBare-metalDockerContainerd
🔗
Service Mesh & API Gateway
IstioTraefikKongNGINXIngress
📦
Registries & Artifact Management
HarborTrivyDocker HubGitLab RegistryNexus
🗄
Databases & Messaging
PostgreSQLMySQLRedisKafkaRabbitMQ
02 //

Experience

Cloud, Platform & SRE Engineer
Tech Company · Dakar, Senegal
Jan 2025 – Present
Designed and deployed a production-grade private cloud from scratch using Infrastructure as Code (Kayobe + Ansible) — compute, networking, distributed storage, fully automated, zero managed cloud dependency.
CaaS Self-Service Portal enabling engineers to provision Kubernetes clusters on private cloud via Cluster API — full lifecycle management (create, scale, upgrade, decommission), cutting provisioning time from days to minutes.
Multi-cluster GitOps with ArgoCD Fleet managing dev/staging/prod environments from a single Git source of truth — zero configuration drift, instant rollback capability across all clusters.
vCluster tenant isolation — Kubernetes-in-Kubernetes virtual clusters for engineering teams, enabling self-service namespaces and reducing platform team toil by ~50%.
SIEM/SOC automation platform with automated threat detection, rule tuning, alerting pipelines, and incident response playbooks covering the full infrastructure stack.
SLO/SLA-driven observability stack (Prometheus + Grafana + Loki + OpenTelemetry) — reduced MTTD by ~40% and major incidents by 35%.
End-to-end CI/CD automation (GitHub Actions + Terraform + ArgoCD) across 10+ microservices — ~40% reduction in manual operations and deployment failures.
Security hardening at every layer — IAM least-privilege, VPC micro-segmentation, Calico network policy enforcement, Harbor image scanning, and automated vulnerability reporting.
Service Mesh implementation with Istio — mTLS between all services, traffic shaping, circuit breaking, and distributed tracing via OpenTelemetry.
Network & System Administrator
Hotel Fleur de Lys Plateau · Dakar, Senegal
Jan 2024 – Dec 2024
Administered a mixed Windows Server / Linux environment — Active Directory, DNS, DHCP — for 100+ users across hotel operations with zero tolerance for downtime.
Deployed centralized monitoring (Prometheus + Grafana + Zabbix) enabling proactive anomaly detection before any guest or staff impact.
Reduced recurring network incidents by 60% through full VLAN redesign, firewall policy auditing, and IPSec VPN hardening.
Implemented multi-layer security — Fortinet firewall policies, VLAN segmentation, automated daily backups with regularly tested disaster recovery procedures.
Automated infrastructure provisioning with Ansible playbooks — reduced server setup time by 70% and eliminated configuration inconsistencies across sites.
Managed SSL certificates, VPN access, and Wi-Fi infrastructure (Cisco Meraki) across all hotel floors and conference rooms.
Junior IT Engineer – Networks, Systems & Security
Semos Informatics · Dakar, Senegal
Sep – Dec 2023
Configured multi-vendor network environments (Cisco, Huawei, Juniper) — OSPF/BGP routing, STP loop prevention, 802.1X port-based authentication.
Deployed IDS/IPS solutions (Snort/Suricata) with custom detection rules, and automated vulnerability scanning pipelines (Nessus/OpenVAS).
Led network redesign initiative — replaced flat legacy topologies with a segmented 3-tier architecture, improving security isolation and traffic management.
Wrote technical documentation and runbooks for network operations, reducing onboarding time for new engineers.
IT Support Level 2
Senegal Numerique SA (ex. ADIE) · Dakar, Senegal
Mar – Aug 2023
Level 2 support for 500+ government employees — resolved VPN, DNS, and Active Directory incidents within SLA across multiple ministry sites.
Automated recurring administrative tasks (PowerShell + Bash scripts), saving ~5 hours/week of manual effort and reducing human error.
Built an internal knowledge base with documented runbooks and troubleshooting guides — reduced average ticket resolution time by 20%.
Assisted in patch management and OS hardening across a fleet of 300+ Windows workstations and servers.
03 //

Projects

Kubernetes CaaS Self-Service Portal
Self-service web portal for provisioning and managing Kubernetes clusters on a private cloud via Cluster API (CAPI). Full lifecycle: create, scale, monitor, decommission.
PythonJavaScriptCluster APIPrivate CloudKubernetes
🏗
Private Cloud Datacenter IaC
Production-grade private cloud built entirely with Infrastructure as Code. Full lifecycle managed as code: compute, networking, block storage, and image service — zero manual provisioning.
KayobeAnsiblePrivate CloudDistributed Storage
🛡
SIEM / SOC Automation Platform
Automated SIEM with agent enrollment, rule tuning, alerting pipelines. SOC dashboards and incident response playbooks covering all infrastructure and K8s workloads.
WazuhDockerKubernetesAnsiblePython
🚀
Private Cloud CI/CD Pipeline
CI/CD pipeline for automated private cloud environment testing and deployment validation before reaching production bare-metal clusters.
GitLab CIPrivate CloudAnsibleKayobe
🌐
Multi-Cluster GitOps (Fleet)
Multi-cluster GitOps with ArgoCD Fleet — single Git source of truth for dev/staging/prod K8s clusters. Zero configuration drift, declarative everything.
ArgoCD FleetKubernetesHelmGitOps
Smart Hash Tool
Auto-detects hash type (MD5/SHA256/NTLM) and encoding. Runs as hardened non-root Kubernetes Job — addresses the K8s Secrets base64 exposure vector.
PythonDockerKubernetes JobsDevSecOps
GitOps CI/CD Lab
Complete GitOps pipeline: Jenkins CI (build, Docker push, manifest update) + ArgoCD CD (auto-sync to cluster). Rolling deployments with one-click rollback.
JenkinsArgoCDKubernetesPython/FlaskDocker
🏢
Kubernetes Tenant Isolation (vCluster)
vCluster deployment for K8s-in-K8s tenant isolation — virtual clusters with full API compatibility, minimal overhead, self-service namespaces.
vClusterKubernetesHelmMulti-tenancy
🔭
Full-Stack Observability Platform
End-to-end observability stack deployed on Kubernetes — metrics (Prometheus + Thanos), logs (Loki + Promtail), traces (Tempo + OpenTelemetry), dashboards (Grafana). SLO/SLA alerting with PagerDuty integration.
PrometheusGrafanaLokiTempoOpenTelemetry
🌐
Service Mesh with Istio
Production Istio service mesh — mutual TLS (mTLS) between all microservices, traffic shaping, canary deployments, circuit breaking, and distributed tracing. Integrated with Kiali for topology visualization.
IstioKubernetesmTLSKialiOpenTelemetry
🤖
Network Automation Lab
Python + Ansible-based network automation framework for multi-vendor environments (Cisco, Juniper). Automated config backup, compliance checks, VLAN provisioning, and change management with audit trails.
PythonAnsibleNetmikoNAPALMNornir
04 //

Certifications — 14 total

// 2026
Certified Calico Operator – AWS Expert
Tigera
Issued Feb 2026 · Valid Jan 2030
Certified Calico Operator – Level 1
Tigera
Issued Jan 2026 · Valid Jan 2030
🐧
LFS158: Introduction to Kubernetes
The Linux Foundation
Jan 2026 · ID: LF3hfq7hnl3x
🐧
LFS157: Introduction to Serverless on Kubernetes
The Linux Foundation
Jan 2026 · ID: LF1v64q5sxmh
// 2025
🛡
CEH – Cisco Ethical Hacker
Cisco
Issued Jul 2025 · Valid Jul 2028
AWS Certified Cloud Practitioner
Amazon Web Services
Issued Jul 2025 · Valid Jul 2028
// 2024
🔒
Fortinet Certified Associate Cybersecurity
Fortinet
Issued Oct 2024 · Valid Oct 2026
🔒
Fortinet FortiGate 7.4 Operator
Fortinet
Issued Oct 2024 · Valid Oct 2026
Create Your First Custom VPC in AWS
Coursera / AWS
Aug 2024 · ID: WKOAHYC9AM18
🐍
Introduction to Python
Coursera
Aug 2024 · ID: BY4DVPLKMX3K
🌐
Securing Cisco Switches with Port Security
Coursera / Cisco
Aug 2024 · ID: EDJDHVY3LSGC
AWS S3 Basics
Coursera / AWS
Jul 2024 · ID: M2BDLHJ5YVEP
🐧
Linux: SSH & Networking Basics for DevOps
Coursera
Jul 2024 · ID: VFSYABVVEJFR
🛡
Introduction to Cybersecurity
Cisco
Dec 2023
For remote opportunities worldwide
Let's build something
production-grade.

Open to DevOps | SRE, Platform Engineer, and Cloud Infrastructure roles. GMT timezone.