External DevSecOps Engineer — CultiBayer North Africa
Bayer
Regional products do not fail because someone forgot a framework. They fail because environments are snowflakes, releases are tribal knowledge, and security is a slide deck. CultiBayer North Africa needed the opposite: infrastructure you can rebuild, pipelines you can trust, and a lifecycle someone actually owns.
Impact at a glance
100%
Infra as code (Terraform)
Full
CI/CD to production
Regional
North Africa footprint
Hardened
Gateway + WAF edge
Ops maturity employers ask about
Relative strength across the controls a hiring manager probes in DevSecOps interviews.
The brief
This is a live application serving North Africa under a Bayer-linked product umbrella. The bar is not “it works on my machine.” The bar is change control, reproducibility, and the ability to explain how an environment was built six months later. I came in as an external DevSecOps engineer to own that production lifecycle end to end — from cloud footprint to the moment a commit becomes a release someone can defend in a review.
What I built
I designed and maintain the Azure estate with Terraform and Infrastructure as Code: App Service, networking edges, WAF and gateway patterns, the boring controls that keep a regional app from becoming a click-ops museum. Environments are declared, reviewable, and reproducible. On top of that I built and run the CI/CD path that carries the application from commit to production — automated where it should be, gated where it must be. The point is not tooling fashion; it is removing the human as the single point of failure in delivery.
Security without the theatre
DevSecOps here means security is part of how we ship, not a separate season of the year. Infrastructure changes are versioned. Access and edges are intentional. Pipelines encode the checks we refuse to leave to memory. You still move at product speed — you just stop pretending that “we will harden it later” is a strategy.
What improved
Infrastructure drift became visible and fixable instead of folkloric. Deployments follow a path a new engineer can learn in days, not months of shadowing. The production lifecycle — provision, deploy, operate — has a clear owner who speaks both cloud controls and delivery pressure. For a multi-country rollout, that is the difference between scaling a product and scaling chaos.
What improved
- Azure infrastructure managed as code with Terraform — rebuildable, reviewable, explainable
- Automated CI/CD covering the full application deployment path
- End-to-end ownership of production lifecycle for a North Africa deployment
- Stronger security and change discipline without turning every release into a committee
- Less reliance on portal click-ops and hero knowledge when something needs to change fast
Tools in play
Azure · Terraform · CI/CD · DevSecOps · App Service · Application Gateway · WAF
Want something like this on your team? Let’s talk.