Cloud-Native & DevSecOps Engineer · Munich, Germany 🇩🇪
I build and secure Kubernetes platforms — from the Linux primitives underneath them to the policy and runtime-detection layers on top. Most of my work sits at the intersection of platform engineering and security: shipping infrastructure that developers actually want to use, without leaving the attack surface unattended.
🎤 Speaking at ContainerDays Hamburg 2026 and Cloud Identity Summit Frankfurt 2026 🏆 Global 1st Prize, Huawei ICT Competition 2025–2026 (Computing Track, Shenzhen) 🎓 CS Engineering degree (SSIR), TEK-UP University 🌍 Open to roles across DACH & Switzerland
Orchestration & Platform
Kubernetes Docker Helm ArgoCD Operators / CRDs Apache CloudStack
Cloud & IaC
AWS (EKS, EC2, IAM) Terraform Ansible GitHub Actions GitLab CI
Security
Falco Trivy Kyverno Snyk SonarQube eBPF OPA
Observability
Prometheus Grafana Loki
Languages
Go Python Bash Java TypeScript
| CKA | Certified Kubernetes Administrator |
| CKAD | Certified Kubernetes Application Developer |
| RHCSA | Red Hat Certified System Administrator |
Container Networking from Scratch — Rebuilt container networking without Docker: Linux namespaces, veth pairs, a bridge, and iptables NAT, wired together by hand. The best way I found to actually understand what a CNI plugin does.
Kubernetes Operator — ProjectClaim CRD — A custom controller that provisions self-service namespaces with quotas, RBAC, and network policies from a single declarative claim. Written in Go with controller-runtime.
cloudstack-dc — Full-stack automation platform for Apache CloudStack deployments: form-driven UI, live-streaming provisioning logs, and a Next.js + SQLite backend. Tested end-to-end on real 4-node hardware.
DevSecOps Platform on AWS — Cloud-native delivery pipeline on EKS with Terraform, ArgoCD, and GitHub Actions, with security gates at every stage (SonarCloud, Snyk, Trivy) and Falco for runtime detection.
How Clusters Fail Under Attack, and How We Detect It at Runtime with eBPF Signals ContainerDays Hamburg 2026 — Walking through reverse shells, unexpected process execution, and privilege escalation inside a live cluster, and what the kernel can tell you about them.
Identity Risk in CI/CD Pipelines Cloud Identity Summit Frankfurt 2026
🌐 mella7.me · ✉️ mellah.mohamedali@outlook.com · 💼 LinkedIn
🇨🇭 Eligible for the Switzerland–Tunisia Young Professionals Agreement — no standard visa sponsorship required for Swiss roles.
