SYSTEMS ONLINE
REGION:US-EAST-1
UPTIME:99.97%
THREAT LEVEL:ZERO-TRUST
Mohamed Kaba — Portfolio v2.0
cloud & security engineering — portfolio

MohamedKaba

Infrastructure · Cloud Architecture · Zero-Trust Security

AWS Certified Azure Zero-Trust IAM SysAdmin DevSecOps
scroll
// evolution of focus
FOUNDATION
Infrastructure
Mastery

Deep roots in systems administration and enterprise networking, with hands-on experience managing the infrastructure that keeps business operations running efficiently. Skilled in maintaining system stability, supporting critical systems, and ensuring connectivity, security, and continuity across enterprise environments.

Linux / Windows Server Cisco / Fortinet Active Directory Virtualization
01
ELEVATION
Cloud
Architecture

Designing scalable, automated environments across AWS & Azure. Bridging legacy on-prem systems with high-availability cloud infrastructure through IaC, CI/CD automation, and resilient multi-region deployments that support performance, scalability, and operational continuity.

AWS / Azure Terraform Kubernetes CI/CD Pipelines
02
MISSION
Cloud
Security

Architecting Zero-Trust security frameworks and automating IAM at scale across hybrid and cloud-native environments. Focused on building resilient, adaptive security models that proactively protect systems, identities, and access layers through automation, policy enforcement, and continuous validation.

Zero-Trust IAM Automation SIEM / SOAR Compliance
03
bash — kaba@cloud-sec-node:~
kaba@node.js:~$ cat profile.json
# ──--- Profile ─────
"name": "Mohamed Kaba"
"role": "Cloud & Security Engineer"
"focus": ["Infrastructure", "CloudArch", "ZeroTrust"]
"certs": "AWS | Azure | CompTIA | Cisco"
"threat_model": "assume-breach"
"uptime_sla": 99.6%
"status": "CI/CD - Continuous Improvement Continuous Development"
kaba@node.js:~$

Things I've Built.

Dashboard
Applications
Sporting E-commerce Platform🟢 Production-ready

An enterprise-grade sporting goods e-commerce application focused on performance, scalability, and reliability. It uses a Dockerized PostgreSQL database with Prisma 7 ORM and the modern Driver Adapter pattern for type-safe, efficient data access. Built on Next.js 16 with Turbopack, it delivers fast builds and a responsive, seamless user experience.

Next.js 16PostgreSQLPrisma 7DockerFullstack development
Applications
API Powered Weather App🟢 Production-ready

Engineered hybrid-architecture web application by decoupling a static Nginx-hosted frontend from a scalable serverless backend. Utilized AWS Lambda and API Gateway to execute dynamic processing, optimizing infrastructure costs. Strengthened security by migrating sensitive API credentials to protected Lambda Environment Variables.

ApacheAWS LambdaAPI GatewayPython
Cloud Infrastructure
AWS Enterprise Migration🟢 Production-ready

Migration of a production-ready sporting goods e-commerce platform to AWS, mapping workloads to cloud-native services for performance, scalability, and reliability. Utilized Amazon EC2, Amazon RDS (PostgreSQL), Amazon S3, and Amazon VPC.

TerraformAWSControl TowerIAMS3
Cloud Infrastructure
Azure Migration Solution🟢 Production-ready

Migrated a serverless, event-driven backend architecture to Azure, focusing on scalability and security. Leveraged Azure Functions and Azure API Management to deliver a decoupled, highly scalable backend with minimal operational overhead.

ProxmoxWazuhGraylogZeekLinux
Containers
Kubernetes DockingStation 🚧 In Progress

A Kubernetes deployment of a containerized e-commerce application featuring horizontal pod autoscaling, rolling updates, service discovery, ingress-based routing, and high availability for resilient, scalable workloads.

ApacheDockerDocker ComposeLinux
Cloud Infrastructure
Multi-Region AWS Landing Zone 🚧 In Progress

Automated the provisioning of a secure, multi-account AWS environment using Terraform and AWS Control Tower to enforce governance and scalable cloud architecture. This includes Service Control Policies, IAM permission boundaries, and centralized identity management.

TerraformAWSControl TowerIAMS3
Cloud Infrastructure
Secure Infrastructure 🚧 In Progress

Designed and maintained secure infrastructure across cloud and hybrid environments, focusing on identity-first security, network hardening, and least-privilege access controls. Implemented security best practices including IAM governance and continuous monitoring.

TerraformAWSControl TowerIAMS3
Security
Container DevSecOps 🚧 In Progress

Cloud based CI/CD pipeline that automatically builds, tests, scans, and verifies Docker images for vulnerabilities before they can ever be deployed. Terraform script to spin up the cloud infrastructure in Azure Container Registry.

ApacheAzure Container RegistryTerraform CI/CD
Cloud Infrastructure
Centralized Analytics Dashboard 🚧 In Progress

Monitor, aggregate data, and observe an entire ecosystem. will stream telemetry data—like HTTP request counts, game scores, application errors, or container health—into this central pipeline. Visualization Layer (Grafana)

TerraformAWSControl TowerIAMS3
Cloud Infrastructure
FinOps Platform 🚧 In Progress

Cloud cost governance platform providing real-time spend visibility, budget management, chargeback/showback reporting, resource optimization, and actionable savings recommendations across multi-cloud environments.

AzureAWSPower BITerraformFinOps
DRaaS / BaaS
Disaster Recovery 🚧 In Progress

Designed a cloud-based disaster recovery and backup solution with automated backup policies, cross-region replication, recovery orchestration, and rapid failover to improve business continuity while minimizing downtime.

Azure Site RecoveryAzure BackupRecovery VaultTerraform
Cloud Infrastructure
Azure Landing Zones 🚧 In Progress

Provisioned an enterprise-ready Azure Landing Zone using Terraform with management groups, Azure Policy, RBAC, networking, logging, and governance controls to establish a secure, scalable cloud foundation.

TerraformAzureManagement GroupsAzure PolicyRBAC
← Back to Projects
Fullstack Development

Sporting E-commerce Platform

A production-ready sporting goods e-commerce platform built with separate Next.js storefront and administration applications, Google OAuth and email/password authentication, Docker support, nginx, PostgreSQL, and Prisma 7 ORM.

Production-ready
Next.js 16PostgreSQLPrisma 7nginxDockerGoogle OAuth
Architecture Diagram
Sporting E-commerce Platform architecture showing storefront, admin, authentication, PostgreSQL, Prisma, Docker, and nginx.
Select the project from the Projects tab to open this expanded architecture view.
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Applications

API Powered Weather App

A hybrid web application that separates a static frontend from an AWS serverless backend. API Gateway invokes Lambda for dynamic processing while credentials remain protected in Lambda.

Production-ready
ApacheAWS LambdaAPI GatewayPython
Architecture Diagram
API-powered weather app serverless architecture showing frontend, API management, serverless functions, secrets, monitoring, and external weather API.
Select the project from the Projects tab to open this expanded architecture view.
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Containers

Kubernetes DockingStation

A Kubernetes deployment of a containerized e-commerce workload demonstrating ingress routing, service discovery, rolling updates, horizontal pod autoscaling, and high availability.

In progress
KubernetesDockerIngressHPALinux
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Cloud Infrastructure

Multi-Region AWS Landing Zone

A governed multi-account AWS foundation using Terraform and AWS Control Tower with centralized identity, Service Control Policies, permission boundaries, logging, and regional guardrails.

In progress
TerraformAWSControl TowerIAMOrganizations
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Cloud Security

Secure Infrastructure

A secure cloud and hybrid infrastructure design centered on identity-first controls, network segmentation, least privilege, centralized monitoring, and policy enforcement.

In progress
TerraformAWSIAMZero TrustMonitoring
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Security

Container DevSecOps

A secure container delivery pipeline that builds, tests, scans, verifies, and publishes Docker images to Azure Container Registry before deployment.

In progress
Azure Container RegistryTerraformDockerCI/CDSecurity Scanning
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Cloud Infrastructure

AWS Enterprise Migration

A production-style migration of the e-commerce platform to AWS using Terraform, EC2 Auto Scaling, an Application Load Balancer, VPC networking, object storage, and PostgreSQL.

Production-ready
TerraformAWSEC2ALBPostgreSQLS3
Architecture Diagram
AWS Enterprise Migration architecture showing Terraform, Route 53, ALB, Auto Scaling EC2 instances, IAM, AMIs, S3, target groups, and monitoring.
Select the project from the Projects tab to open this expanded architecture view.
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Cloud Infrastructure

Azure Migration Solution

An Azure migration solution using Azure Functions and API Management to provide a scalable, decoupled backend with managed security and minimal server administration.

Production-ready
Azure FunctionsAPI ManagementTerraformAzureMonitoring
Architecture Diagram
Azure Migration Solution architecture showing Terraform, Azure Container Apps, Azure Container Registry, Log Analytics, networking, managed identity, and monitoring.
Select the project from the Projects tab to open this expanded architecture view.
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Observability

Centralized Analytics Dashboard

A centralized telemetry platform designed to ingest infrastructure and application data, process it through a shared pipeline, and visualize health, usage, errors, and operational trends.

In progress
GrafanaTelemetryTerraformAWSMonitoring
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
FinOps

FinOps Platform

A multi-cloud cost governance platform providing spend visibility, budgets, chargeback and showback, optimization findings, and actionable savings recommendations.

In progress
AzureAWSPower BITerraformFinOps
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
DRaaS / BaaS

Disaster Recovery

A cloud-based backup and disaster recovery design with policy-driven backups, cross-region replication, recovery orchestration, testing, and failover.

In progress
Azure Site RecoveryAzure BackupRecovery Services VaultTerraform
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

← Back to Projects
Cloud Infrastructure

Azure Landing Zones

An enterprise-ready Azure Landing Zone built with Terraform, management groups, Azure Policy, RBAC, central logging, networking, governance controls, and GitHub OIDC.

In progress
TerraformAzureManagement GroupsAzure PolicyRBACGitHub OIDC
Architecture Diagram
Demo / Documentation

Architecture

The diagram summarizes the primary traffic flow, application components, security controls, automation, and data services used by the project.

Engineering Focus

This project is presented as an engineering case study focused on reliability, scalability, security, repeatability, and operational clarity.

Documentation Roadmap

Add implementation screenshots, Terraform plans, deployment output, monitoring views, design trade-offs, and lessons learned as the project progresses.

credential verification

Validated Expertise.

cryptographic check // trusted entities
Amazon Web Services
AWS Solutions Architect Professional

Validates advanced technical skills and experience in designing distributed applications and systems on the AWS platform. Focuses on complex multi-tier architecture strategy, cost optimization, scaling, and enterprise migration frameworks.

Advanced ArchitectureCost OptimizationEnterprise Migration
Amazon Web Services
AWS Certified SysOps Administrator

Validates technical expertise in deployment, management, security, and operations on the AWS platform. Confirms a strong understanding of system health monitoring, infrastructure automation, and resource provisioning.

OperationsDeployment AutomationMonitoring
Amazon Web Services
AWS Solutions Architect Associate

Demonstrates comprehensive knowledge of designing high-availability, cost-effective, and fault-tolerant distributed systems across AWS core services, focusing on compute, storage, networking, and security layers.

Cloud Systems DesignCore ServicesHigh Availability
Amazon Web Services
AWS Developer Associate

Demonstrates technical proficiency in developing, deploying, and debugging cloud-native applications using AWS development tools, SDKs, serverless resources, and CI/CD pipelines.

Serverless AppsCI/CD AutomationCloud Development
Cisco
Cisco Certified Network Associate (CCNA)

Validates foundational knowledge of network infrastructure, covering IP connectivity, IP services, security fundamentals, automation, programmability, and routing/switching protocols.

Routing & SwitchingNetwork SecurityIP Infrastructure
CompTIA
CompTIA Network+

Validates the technical skills needed to securely establish, maintain, troubleshoot, and optimize essential corporate networks across various hardware configurations and environments.

Network OpsTroubleshootingTopology
Microsoft Azure
Azure Administrator Associate AZ-104 In Progress

Validates enterprise-level skills required to implement, manage, and monitor identity, governance, storage, compute, and virtual networks in a cloud environment.

Hybrid IdentityVirtual NetworkingAzure Administration
Microsoft Azure
Azure Fundamentals AZ-900

Demonstrates baseline foundational understanding of cloud concepts, core Azure architecture models, management tools, compliance frameworks, and network security infrastructure options.

Azure BasicsCloud ConceptsGovernance
HashiCorp
Terraform Associate (004)

Demonstrates baseline foundational understanding of cloud concepts, core Azure architecture models, management tools, compliance frameworks, and network security infrastructure options.

IaCCloud DeploymentGovernance
secure handshake

Let's Connect.

Establish a secure communication line or explore professional links.