You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Diane LakestaniDL

Diane Lakestani

Senior Platform / DevOps Engineer

€480/day
Lyon, FR
3-7 years

Average response time: 1 hour

About Diane

Senior DevOps / Platform Engineer freelance (6 ans), j’aide les équipes produit à fiabiliser et industrialiser leurs plateformes cloud-native (Kubernetes ou serverless) avec Terraform, des pratiques CI/CD solides et une observabilité actionnable.

J’interviens dans des contextes SaaS / scale-up ou dette technique, quand il faut structurer, sécuriser et rendre opérable une plateforme complexe sans ajouter de chaos.

🎯 Projets / livrables :
• Kubernetes / serverless (AWS, GCP)
• CI/CD (GitLab CI, GitHub Actions, trunk-based, semantic release, review envs)
• IaC (Terraform, Ansible), landing zone, IAM / Zero Trust
• Observabilité (Datadog, Prometheus, Grafana, Loki, Tempo)

📍 Basée à Lyon — remote Europe / North America — missions longues / structurées.

EN: Senior DevOps / Platform Engineer (Freelance, 6 years) helping teams build reliable cloud-native platforms and industrialize CI/CD with Terraform. Remote EU/NA.
  • French

    Native or bilingual

  • English

    Fluent

  • Persian

    Basic

Can work on-site
Lyon (up to 10km), Paris (up to 10km)

Experience

  • Supervizor
    Senior DevOps / Platform Engineer
    CONSULTING AND AUDITS
    October 2025 - January 2026 (3 months)
    Paris, France
    Context: Engagement as a Senior DevOps / Platform Engineer within a SaaS fintech company, in a high-growth environment with strong requirements around reliability, security, and compliance.


    Key achievements:
    • Designed and implemented a serverless cloud platform on GCP (Cloud Run), focused on scalability and resilience
    • Delivered production and staging environments across two separate regions in two weeks (rapid ramp-up on GitHub Actions and Cloud Run)
    • Built dynamic review environments in one week
    • Industrialized CI/CD pipelines using GitHub Actions
    • Authored and implemented an ADR to set up a GCP landing zone aligned with Zero Trust principles
    • Implemented smoke tests and end-to-end tests (Playwright) integrated into CI/CD pipelines, in collaboration with the QA team
    • Semi-automated the migration of Windows VMs from Azure to GCP:
    • PowerShell startup scripts
    • Logging and Datadog integration
    • Automatic user assignment to Active Directory groups
    • Active Directory domain join and Entra ID (Azure AD) integration
    • NetBIOS renaming and customer anonymization using UUIDs
    • Implemented customer-managed encryption keys (CMEK) as part of ISO 27001 / SOC 2 compliance
    • Deployed and configured Auth0 in front of legacy customer URLs and web environments:
    • Username/password authentication
    • SSO via Entra ID and other IdPs
    • Participated in technical discussions with customers to implement their SSO and integrate their identity providers
    • Provided cross-functional support to support and development teams:
    • CI/CD coaching and enablement
    • Terraform permissions management following the principle of least privilege
    • Deployed Metabase on Cloud Run with a Cloud SQL database (SQL Server)


    Google Cloud Platform (GCP) Github Actions Google Cloud Run Auth0 Cloud Azure
  • Santévet
    DevSecOps Engineer
    BANKING AND INSURANCE
    May 2025 - September 2025 (4 months)
    Lyon, France
    Context: Hyper-growth pet health insurance company following a funding round, with architecture and practices evolving - strong need for DevOps standardization and industrialization.


    Key achievements:
    • Implemented a multi-environment front-end stack (CloudFront + S3, Secrets Manager, CloudFront Functions) aligned with Build Once, Deploy Anywhere and trunk-based development principles.
    • Advanced GitLab CI/CD industrialization: split Terraform and application pipelines (GitLab CI DAGs), centralized packaging via GitLab Package Registry.
    • Adopted trunk-based development and Semantic Release, with coaching and support for QA & dev teams (workflow, best practices, releases).
    • Deployed and configured Renovate to automate updates of in-house Helm charts, handling breaking changes via post-upgrade Python scripts.
    • Redesigned and improved reliability of the internal Helm ecosystem: version harmonization, best-practice standardization, and preparation for scaling microservices (HPA and Karpenter). Added the Goldilocks label to enable automated monitoring and prepare resource tuning.
    • Complete overhaul of GitLab repository templates:
    ◦ Fixed and updated Serverless (SAM) templates and their associated pipelines (previously non-functional templates),
    ◦ Added/updated CI best practices for PHP and TypeScript repositories (formatting, linting, hooks, quality),
    ◦ Standardized new repositories using these templates (baseline for upcoming projects).
    • Evangelized DevOps practices (trunk-based, CI quality, automation) across teams.
    Kubernetes Amazon Web Services Terraform Gitlab CI/CD Datadog
  • SOCOTEC
    DevOps Engineer
    CIVIL ENGINEERING
    December 2024 - April 2025 (4 months)
    69100 Villeurbanne, France
    Context: SOCOTEC is a major player in Testing, Inspection & Certification (TIC) for construction and infrastructure, with engineering teams working directly on-site (construction sites, structures, equipment). Within the Digital Factory in Lyon (~30 people, operating like an internalized consultancy), the challenge was to maintain and evolve critical business applications (audits, inspections, compliance, field reports, structure monitoring) used by engineers in the field, while ensuring a sovereign and stable on-prem Kubernetes platform. The infrastructure relied on multiple on-prem RKE2 clusters managed with Ansible, with strong expectations around availability, observability, and security, as the hosted services supported operational field use.


    Key achievements:
    • Built a complete Kubernetes sandbox cluster (RKE2, CNPG, External Secrets Manager, Kafka, RabbitMQ, Istio, Longhorn, HPA).
    • Implemented GitOps deployments with FluxCD, service mesh with Istio, and a gRPC backend.
    • Integrated Vault, External Secrets, and Keycloak for access management.
    • Optimized observability: Loki, Prometheus, Grafana, Tempo (cache optimization).
    • Developed and customized the company status page based on the open-source project StatPing-NG (Go, Vue.js, Keycloak, Notion automation): integrated incident management on the status page via Notion hooks → status page.
    • Provided support to dev/QA teams on GitLab CI and Kubernetes.
    Kubernetes RKE2 FluxCD Istio GO

Recommendations

Be the first to recommend Diane

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • DUT Informatique
    IUT Lyon 1
    2016
  • Licence Pro Devops
    IUT Lyon 1
    2016

Skill set

Categories