Available for DevOps & Cloud roles

Infrastructure that just runs.

I'm Abdur Raafeh Mahmood, a DevOps & Cloud Engineer who turns fragile, manual ops into reproducible, self-service platforms. Kubernetes, Terraform, multi-cloud. 6+ years, three countries.

⚑ 6+ years building cloud infrastructure🌍 Multi-country experience: Pakistan β†’ Turkey β†’ AustraliaπŸŽ“ Computer Engineering, Izmir Institute of Technology
career_status
9
Certifications & badges
6+
Years in production
Now Β· Active engagement
DevOps Consultant at Systems Ltd
Multi-Cloud Kubernetes Β· Zero-Trust Β· Self-Service
Engagements

What I can do for you

Concrete pieces of work I've delivered before and can run again. Each one is backed by something I've actually shipped.

CI/CD Pipeline Setup

Build, test, and deploy automated end to end, with approvals, quality gates, and rollbacks that make releases boring.

Cut deployment time from ~1 week to under an hour at Fraim

GitHub ActionsAzure DevOpsGitLab CI

Infrastructure as Code

Replace click-ops with reviewable, reproducible Terraform. Real dev/staging/production separation instead of one fragile environment.

Imported a live manual environment into Terraform with no downtime

TerraformHelmAnsible

Kubernetes Platforms

Multi-cloud clusters teams can actually self-serve: modular blueprints, guardrails, and add-ons that make creation, upgrades, and teardown routine.

Standardized an AWS + Azure platform at Systems Ltd

KubernetesAWSAzureHelm

Cloud Migration

Move workloads off self-hosted or legacy setups onto managed services, planned around reliability and operational burden rather than just lift-and-shift.

Drove self-hosted Ant Media β†’ AWS IVS for reliability and lower ops load

AWSGCPAzureDocker

Security & Compliance

Zero-trust defaults, least-privilege RBAC, secret management, and audit-ready process, from edge networking up to compliance evidence.

Drove SOC2 Type 1 readiness at Fraim

SOC2RBACWireGuardSOPS

Observability & Reliability

Instrumentation and alerting that surface problems before users do, plus the debugging work to find what's actually breaking.

Traced a 500+ connection DB exhaustion to its root cause at GoArt

PrometheusGrafanaSentryNewRelic

Something here match what you need? Let's talk β†’

Capabilities

What I bring to your platform

Six years of hands-on infrastructure work, distilled into the areas I'm relied on for.

☁️

Cloud Platforms

Multi-cloud environments built for reproducibility, from networking up to managed services.

AWSAzureGCPMulti-CloudServerlessCloud MigrationSecret Manager / Key Vault
☸️

Containers & Orchestration

Cluster platforms teams can self-serve, with upgrades and teardown as routine as creation.

KubernetesDockerHelmKustomizeEKSAKSLinux
πŸ“

Infrastructure as Code

Reviewable, reproducible infrastructure instead of click-ops and one fragile environment.

TerraformTerraform ModulesState ManagementAnsibleTerratestSOPS
πŸ”

CI/CD & Delivery

Pipelines that cut deployment time from a week to hours, with guardrails built in.

GitHub ActionsAzure DevOpsGitLab CILaunchDarklyEASBash / Scripting
πŸ“ˆ

Observability

Instrumentation and alerting that surface problems before users do.

PrometheusGrafanaSentryPosthogNewRelicAlerting
πŸ›Ÿ

Reliability & Operations

Keeping production up, and finding the real cause quickly when it isn't.

High AvailabilityDisaster RecoveryBusiness ContinuityRoot Cause AnalysisPerformance Optimization
πŸ›‘οΈ

Networking & Security

Edge-to-cloud tunneling, firewalling, and zero-trust defaults, plus hands-on vulnerability testing.

WireGuardOpenVPN / IPseciptables / nftablesZero-TrustRBACCalicoTrivyVulnerability TestingSOC2 / Compliance
🐍

Languages & Data

Comfortable owning the backend and its datastores, not just the infrastructure around them.

PythonTypeScriptFlaskREST APIsRedisMariaDB / MySQLPytest
Track record

Deployment history

5 roles across Turkey, Australia and Pakistan.

2017 - 2022 β—† 5 years continuous
LOKI Voluntary Intern β†’ Systems Engineer
Izmir, Turkey Β· July 2017 - August 2021 Β· 4 years
β–Έ Full role detail
  • Started as voluntary intern; grew to sole backend owner after lead engineer left. Delivered custom Linux images and kernel builds for DPI traffic filtering on a physical UTM device.
  • Built network automation for iptables, nftables, arptables, hostapd, Squid, and IPS/IDS; configured bridges, PPPoE, static IP, client isolation, and VPN. Wrote Python APIs and automation to generate and apply configs and ensure services ran on startup.
  • Integrated hardware control board for LAN/Internet LED indicators and soft boot; implemented button-triggered firewall exception for time-limited SSH access to support servers, then restricted to established connections for security.
  • Ported the stack to OpenWRT, Raspberry Pi, Orange Pi, and FreeBSD/pfSense with a unified interface so changes reflected in both native pfSense and our custom UI. Delivered Ubiquiti Edge integration for a client project.
  • Built an ncurses terminal UI for techs: Redis worker queues, live log exploration, and user/settings inspection over SSH to simplify debugging in the field.
  • Added GRUB-based hardware validation so the system would decrypt and boot only on authorized hardware, preventing tampering or unauthorized part swaps.
  • Pivoted to a SaaS security platform on Hetzner: Terraform for provisioning, WireGuard/OpenVPN/IPsec for edge-to-cloud, custom Linux images and OAuth-like edge-to-cloud binding. Ran self-hosted Bitbucket, then GitLab and Confluence.
PythonFlaskRESTJinja2RedisMariaDBBashLinuxTerraformWireGuardOpenVPNIPseciptablesnftableshostapdSquidGitLabConfluence
↳ LOKI merged into Logo Cyber. Same team, same product, new entity.
Logo Cyber Senior Software Engineer
Turkey Β· 2021 - 2022 Β· 1 year
β–Έ Full role detail
  • Evolved image provisioning into a backward-compatible Debian packaging system: kernel and service packages with pre/post install and uninstall scripts for clean upgrades and rollbacks.
  • Implemented MPTCP for WAN aggregation and failover (not just failover), so edge devices could combine bandwidth and fail over seamlessly to cloud controllers.
  • Secured the stack by compiling Python to C and obfuscating with Nuitka; reduced exposure of proprietary logic on edge devices.
  • Designed and implemented a licensing system: cloud service for certificate creation, signing, and authentication; edge-side validation and feature locking via signed certificates checked against the cloud.
  • Integrated PPPoE, GRE TAPs, and ClamAV into the platform for connectivity and security at the edge.
DebianPythonCNuitkaLinuxClamAVPPPoEGRE TAPs
new company
2022 - 2023 GoArt Β· ~1 year
GoArt Infrastructure Engineer β†’ Senior Infrastructure Engineer
Turkey Β· 2022 - 2023 Β· ~1 year
  • Owned infrastructure for a browser-based virtual conferencing product: Unreal Engine-rendered stages, real-time interaction, reactions, and chat. Managed and maintained the Azure Kubernetes cluster and services.
  • Used Azure DevOps for CI/CD and learned it on the job; orchestrated Ant Media servers and related services for streaming.
  • Diagnosed a critical database connection exhaustion: 250 concurrent users drove 500+ connections and overloaded the dev database. Traced backend pod and service logs to the PHP backend opening new connections without timeouts or proper cleanup; recommended and implemented fixes to stabilize and scale.
  • Proposed and drove migration from self-hosted Ant Media to AWS IVS for higher reliability and lower operational burden; coordinated front-end and backend work (Next.js, Nuxt, PHP) around the new pipeline.
KubernetesAzureAzure DevOpsAWS IVSPHPNext.jsNuxtDockerAnt Media
new company
2023 - 2024 Fraim Β· ~1 year
Fraim Cloud Engineer
Australia Β· 2023 - 2024 Β· ~1 year
  • Owned all cloud management and automation. Introduced clear dev, staging, and production separation; primary workloads on GCP serverless (Cloud Run, Cloud Tasks, Cloud Functions) with AI models on Azure.
  • Transformed a single manually deployed environment into Terraform-managed IaC: imported existing state, then added automated staging and production. Cut deployment time from about a week to hours; learned and adopted GitHub Actions for lint, build, test, deploy, and infrastructure changes.
  • Introduced TypeScript database migrations (Kysely) and containerized migration pipelines to validate backward compatibility so schema changes and upgrades/downgrades could be applied safely.
  • Set up Android and iOS build and release to store and test tracks via EAS; integrated LaunchDarkly for feature flags so releases could gate and roll out features and disable them from the dashboard without new builds.
  • Drove SOC2 Type 1 readiness: status pages, backup and disaster recovery, and business continuity documentation and processes.
  • Managed Google Workspace, user onboarding/offboarding, and MDM for the company.
GCPCloud RunCloud TasksCloud FunctionsAzureTerraformGitHub ActionsTypeScriptKyselyEASLaunchDarklyDocker
new company
2025 - Present Systems Ltd
Systems Ltd DevOps Consultant
Pakistan Β· 2025 - Present Β· Present
  • Building reproducible Kubernetes platforms on AWS and Azure with modular blueprints, input validation, and guardrails for consistent cluster creation, upgrades, and teardown.
  • Enabling self-service via Helm add-ons, templates, and documentation; applying zero-trust security defaults and Azure DevOps pipelines for infrastructure and application delivery.
KubernetesAWSAzureTerraformHelmAzure DevOps
Side projects

What I build for myself

TerraQuote

Go-based CLI that parses Terraform plans to estimate multi-cloud infrastructure costs (AWS/Azure/GCP) with CI/CD-friendly outputs.

GO
View repository β†’

VenueBook

Offline first financial management application.

Dart
View repository β†’

Let's build something that doesn't page you at 3am.

Open to DevOps, Platform, and Cloud Engineering roles, remote or Pakistan-based.