← All work

External DevSecOps Engineer — CultiBayer North Africa

Bayer

2024 — Present · Remote / North Africa

Regional products do not fail because someone forgot a framework. They fail because environments are snowflakes, releases are tribal knowledge, and security is a slide deck. CultiBayer North Africa needed the opposite: infrastructure you can rebuild, pipelines you can trust, and a lifecycle someone actually owns.

Impact at a glance

100%

Infra as code (Terraform)

Full

CI/CD to production

Regional

North Africa footprint

Hardened

Gateway + WAF edge

Ops maturity employers ask about

Relative strength across the controls a hiring manager probes in DevSecOps interviews.

  • Reproducible environmentsHigh
  • Automated path to prodHigh
  • Change audit trailHigh
  • Security in deliverySolid
  • Click-ops / tribal releaseLow

The brief

This is a live application serving North Africa under a Bayer-linked product umbrella. The bar is not “it works on my machine.” The bar is change control, reproducibility, and the ability to explain how an environment was built six months later. I came in as an external DevSecOps engineer to own that production lifecycle end to end — from cloud footprint to the moment a commit becomes a release someone can defend in a review.

What I built

I designed and maintain the Azure estate with Terraform and Infrastructure as Code: App Service, networking edges, WAF and gateway patterns, the boring controls that keep a regional app from becoming a click-ops museum. Environments are declared, reviewable, and reproducible. On top of that I built and run the CI/CD path that carries the application from commit to production — automated where it should be, gated where it must be. The point is not tooling fashion; it is removing the human as the single point of failure in delivery.

Security without the theatre

DevSecOps here means security is part of how we ship, not a separate season of the year. Infrastructure changes are versioned. Access and edges are intentional. Pipelines encode the checks we refuse to leave to memory. You still move at product speed — you just stop pretending that “we will harden it later” is a strategy.

What improved

Infrastructure drift became visible and fixable instead of folkloric. Deployments follow a path a new engineer can learn in days, not months of shadowing. The production lifecycle — provision, deploy, operate — has a clear owner who speaks both cloud controls and delivery pressure. For a multi-country rollout, that is the difference between scaling a product and scaling chaos.

What improved

  • Azure infrastructure managed as code with Terraform — rebuildable, reviewable, explainable
  • Automated CI/CD covering the full application deployment path
  • End-to-end ownership of production lifecycle for a North Africa deployment
  • Stronger security and change discipline without turning every release into a committee
  • Less reliance on portal click-ops and hero knowledge when something needs to change fast

Azure · Terraform · CI/CD · DevSecOps · App Service · Application Gateway · WAF

Want something like this on your team? Let’s talk.