
Zohaib Ahmed
DevSecOps CloudNative Engineer
Skills

See my services


Portfolio
Work experience
Azure Devops Engineer
MetaSol pk • Full-time
Mar 2026 - Present • 6 mos
Building and running cloud infrastructure for client-facing production systems. A lot of the work was architecture. Designing setups on AWS and Azure that could handle growth without a rewrite every six months, and documenting the reasoning so the next person didn't have to guess. Multi-environment layouts, high availability across zones, disaster recovery plans that were actually tested rather than just written down. Ran infrastructure as code end to end with Terraform. Took over several environments that had been built by hand in the console and moved them into versioned modules, which cut provisioning from days of clicking to a single apply. Ansible handled configuration management and patching across the fleet. Containers and orchestration were a constant. Docker builds, Kubernetes clusters on EKS and AKS, deployments via Helm and Argo CD. I did a fair bit of cost work too, rightsizing overprovisioned resources and cleaning up things nobody had noticed were still running. Also spent time on the security side: IAM policies tightened to least privilege, network segmentation, secrets pulled out of config files and into proper secret stores, and scanning built into pipelines. Mentored two junior engineers and handled client-facing technical discussions, which is where I learned to explain tradeoffs in plain terms instead of hiding behind tooling names.
Devops Engineer
Al Nafi Cloud • Full-time
Feb 2025 - Mar 2026 • 1 yr 1 mo
Spent year on the infrastructure and delivery side of a team shipping production applications on AWS and Azure. Most of my time went to CI/CD. I built and maintained pipelines in GitHub Actions and GitLab CI covering build, test, security scan and deploy, and spent a fair amount of effort on the unglamorous part, making flaky pipelines reliable and slow ones faster. Cutting build times meant developers stopped avoiding the pipeline and working around it. On the container side I wrote and optimized Dockerfiles, moved services onto Kubernetes, and set up deployments with Helm. I handled image hardening too: minimal base images, non-root users, and vulnerability scanning wired into the build so problems surfaced before deploy rather than after. Infrastructure was managed as code with Terraform, along with Ansible for server configuration and patching. Rewriting hand-built infrastructure into Terraform modules made environments reproducible and removed a whole category of "it works in staging" surprises. I also handled monitoring and alerting, and took part in on-call rotation. Being on the receiving end of your own alerts changes how you design things. It's where I learned that most incidents trace back to a configuration decision made quickly months earlier. Worked closely with developers throughout, less as a gatekeeper and more as the person who made releases boring. That was the goal.