
Boubacar Soumaré
DevOps and Platform Engineer · AWS and Azure cloud, AWS certified
Toulouse, France · contact@boubacarsoumare.com · linkedin.com/in/boubacar-soumare
Profile
DevOps, Cloud and Platform engineer with four years of experience on critical industrial infrastructure (aerospace, agricultural machinery, commercial vehicles). Specialised in multi-service AWS and Azure environments, I industrialise CI/CD and DevSecOps chains (Jenkins, GitLab CI, Checkmarx) and drive cloud efficiency: a measured 65 to 75 % reduction in AWS costs at a European aircraft manufacturer, with no production interruption. With a software engineering background (Python and multi-language tooling), I treat infrastructure as modular, tested code (Terraform). Alongside, I run a self-hosted infrastructure platform in continuous 24/7 production (containers, AI automation, agents), with the same operational rigour.
Technical skills
- Platform engineering
- self-service internal platforms, generated and reconciled state, catalogues of reusable capabilities, explicit usage rules, test benches, user documentation.
- AI and automation
- Claude Agent SDK, MCP (Model Context Protocol), n8n, Claude API, Gemini, local LLM, speech-to-text, RAG, vector memory, LLM FinOps.
- AWS cloud
- EKS, ECS, EC2, Lambda, S3, CloudFront, RDS · Aurora, API Gateway, Glue, EventBridge, Cognito, SNS, SageMaker, CloudWatch, CloudFormation, Secrets Manager, KMS, WAF and Shield, Budgets.
- Azure and GCP
- Azure DevOps, Azure Cloud Services, network security, secrets management, Google Cloud Platform, Gemini.
- Infrastructure as code
- Terraform, OpenTofu, CloudFormation.
- Containers and Kubernetes
- Docker, Amazon ECS; EKS platform run on the security and cost side; GitOps; Kubernetes administration in training (CKA in preparation).
- CI/CD and artefacts
- Jenkins, Azure DevOps Pipelines, GitLab CI, JFrog Artifactory.
- Security and quality
- Checkmarx (SAST), SonarQube, Cypress (E2E), Jest, WAF and Shield, Secrets Manager, KMS, end-to-end encryption.
- Observability and FinOps
- CloudWatch, security and performance alarms, AWS Budgets, cost alerting.
- Languages
- Python (FastAPI, Flask), JavaScript · TypeScript, C# · .NET, Java (Spring), SQL, Bash, React, Angular, Node.js.
- Methods and tools
- Agile SAFe, Scrum, GitHub, GitLab, Confluence, Jira.
Professional experience
DevOps engineer on a multi-service cloud platform, in an aerospace environment.
- AWS costs cut by 65 to 75 % depending on the service: audit of real provisioning service by service, then a reduction in two one-week steps with CloudWatch validation between them, with zero production incidents.
- Securing the multi-service platform (EKS, ECS, Lambda, RDS · Aurora, S3, CloudFront, Cognito, SNS, SageMaker): WAF and Shield hardening, centralised secrets management (Secrets Manager, KMS), security and performance alarms.
- Design of the data ingestion pipelines: AWS Glue jobs scheduled by EventBridge, S3 storage, secrets managed by Secrets Manager.
- Development of an AI-augmented search bar (RAG) on Google Cloud Platform and Gemini.
- Quality and security industrialisation of the pipelines: Checkmarx (SAST), SonarQube and Cypress built into CI/CD, detected vulnerabilities fixed, artefacts managed in JFrog Artifactory, Jenkins jobs parallelised.
- Database migration with KMS encryption, Terraform refactoring, CloudFormation deployments, several production releases delivered.
- Application support and tooling in Python · FastAPI (back end) and React (front end).
Environment : AWS, GCP, Gemini, Terraform, CloudFormation, Checkmarx, SonarQube, Cypress, Jenkins, JFrog Artifactory, React, Python, FastAPI.
DevOps engineer, full ownership of the project’s cloud environments.
- End-to-end ownership of the Azure environments: development, test and a fully isolated sandbox, set up from day one of the project.
- Definition and enforcement of network security rules across all environments.
- Set-up of a FinOps alerting system for real-time cloud cost tracking, and centralised secrets management.
Environment : Microsoft Azure, Azure DevOps, CI/CD.
Software engineer, Agile SAFe framework. Critical apps for tracking, maintaining and repairing agricultural machinery.
- Technical debt reduced by about 80 % through refactoring and a GitLab repository clean-up script that removed more than 800 obsolete branches.
- Cordova to Capacitor technology migration, with a detailed impact analysis on the plugins and the app.
- Mobile CI/CD chain set up (Jenkins for iOS builds, Azure DevOps), full release cycle management and six quarterly releases on Google Play and the App Store.
- Delivery of a Jenkins pipeline POC to Azure and TestFlight, with turnkey documentation for the client (variables, secured certificates, deployment procedures).
- Integration of Firebase Crashlytics, Matomo, iOS and Android push notifications and Google Maps.
Environment : Ionic, Angular, Capacitor, Cordova, Java Spring, Jenkins, Azure DevOps, GitLab, Firebase, TestFlight.
Software engineer, Agile SAFe framework. An international project of over one hundred people between France and India.
- Major technology migration of the monitoring web application, from AngularJS to Angular 16.
- Business features developed with the France and India teams, production maintenance, legacy code refactoring and unit tests.
Environment : Angular, AngularJS, Java Spring, Jenkins, GitLab, Jira.
COVID-19 context. End-to-end responsibility: design, development, deployment and production release.
- Design of the complete AWS infrastructure: back end on Beanstalk, front end on S3 and CloudFront, RDS database with auto-scaling, replication and automated backups.
- Development of an SEO-optimised serverless PWA (Angular Universal, Node.js, AWS Lambda, API Gateway), Docker containerisation and Azure DevOps CI/CD.
- Stripe payment module, real-time chat over WebSockets, releases on Google Play and the App Store, cost control with AWS Budgets.
Environment : Angular, Ionic, .NET Core · C#, AWS, Docker, Azure DevOps, Stripe.
Designed, built and run alone, in 24/7 production.
- Platform engineering: an internal platform whose consumers are AI agents. The constraint is that of a team of developers: they must be able to act without me. Hence an automatically generated system state, a catalogue of reusable capabilities, explicit usage rules and test benches.
- Platform tooling: Python micro-services (Flask, FastAPI) in containers, an MCP connector exposing capabilities to an external model, webhook-driven generation workflows, multi-channel ingestion (text, voice, image, PDF, URL, email).
- Privacy by design: two-lane deterministic routing, public data to a cloud LLM, data marked private kept in place, with no model or external API at all.
- Security: encrypted private access, allow-lists, a secret guard before anything leaves, encrypted off-site backups, a written recovery procedure.
- SRE-style operations and LLM FinOps: automatic restarts, failure alerting armed and verified in production, diagnosis of a silent failure. A GPU workload moved to an on-demand service, at a measured cost of $0.041 per run, about $6 a month.
- Delivery chain: multi-architecture continuous integration, infrastructure as code (OpenTofu) and GitOps for Kubernetes, written and bench-tested; runbooks and blameless post-mortems.
Environment : Docker, n8n, OpenTofu, Python, Claude Agent SDK, MCP, Git.
Certifications
AWS Certified Cloud Practitioner (2024)
CKA, Certified Kubernetes Administrator (in preparation)
Education
MSc in application development, Epitech Toulouse (2022)
BSc in computer science, Université de Haute-Alsace, Mulhouse (2020)
Languages
French, native
Professional English (B2): four years in an international environment, daily meetings with teams in France and India