You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Steve FermatSF

Steve Fermat

Supermalter

AWS, Cloudflare, Scaleway Specialist

€590/day
28 projects
Orléans, FR
15+ years

Average response time: 1 hour

Freelancer profile translated to English.
Back to original language

About Steve

AWS | Cloudflare | Scaleway Expert

I solve thestability and performanceissues of yourcloudinfrastructureAWS, Scaleway, Linux, and**Cloudflare**
andreduce the mental load of your developersby creatinghigh-value CI/CD pipelines
(canary, blue/green, rollback, snapshot DB, etc..)

-Web Applications(Prestashop, WordPress..) and complex web platforms (IOT..)
- Improvement of database performance and query optimization

My Approach
I assist your development teams constructively: I identify problems with metrology tools that I provide (Datadog, OpenTelemetry, Sentry..), I clearly explain the causes, and I propose immediately applicable recommendations.

Strengths
• I use your tools or mine (Datadog,Sentry, OpenTelemetry) for metrology / observability
• Economical with your Cloud expenses
• Attentive to your business challenges
• Remote intervention, hourly or fixed rate

Technical Expertise
• Multi-Cloud: AWS, Scaleway, DigitalOcean, OVH, Exoscale, as well as PaaS (e.g., Qovery..)
• Linux Systems, Docker, Kubernetes, Helm Chart, KS/ECS, S3 Cloud Storage and Block Storage
• Web: nginx, Apache, php-fpm, Node.js, React, Laravel, Symfony, Django, Cloudflare (CDN, cache optimization, anti-bot, SSL/TLS, worker, CacheRule)
• Automation: Bash, Python, Terraform, Ansible, CI/CD (GitHub Actions, GitLab CI, BitBucket ArgoCD), Terraform & CloudFormation

Commitment
I work with clients of all technical maturity levels, in a spirit of sharing and skill transfer.
I can diagnose quickly, provide my own metrology/observability tools, and intervene on urgent missions.
  • French

    Native or bilingual

  • English

    Fluent

Remote only
Primarily works remotely

Experience

  • XERFI DATA
    Malt logoOn Malt
    AWS RDS Expertise
    BANKING AND INSURANCE
    May 2026 - May 2026
    Paris, France

    Support for a team in optimizing their relational database infrastructure on AWS RDS, with a focus on performance, security, and resilience.


    Scope of Intervention
    Leading an expertise workshop around Amazon RDS (MySQL, PostgreSQL, Aurora), integrating related AWS services (VPC, KMS, CloudWatch, IAM, Secrets Manager, AWS Backup).
    Performance
    Audit and recommendations on instance sizing (db.r6g, db.m6i classes), activation of GP3 storage with IOPS/throughput tuning, configuration of Read Scaling via multi-region read replicas.
    Implementation of RDS Proxy for connection pooling and reduction of application latency.
    Optimization of parameter groups (innodb_buffer_pool, work_mem) and use of Performance Insights coupled with Enhanced Monitoring for analyzing wait events.
    Security
    Configuration of encryption at-rest via AWS KMS (CMK), encryption in-transit (forced SSL/TLS), network isolation in a private VPC with restrictive Security Groups. Integration with AWS IAM for database authentication without static passwords, automatic secret rotation via AWS Secrets Manager. Access audit with CloudTrail and RDS Activity Streams.
    Redundancy & High Availability
    Multi-AZ deployment (synchronous standby), configuration of maintenance windows and automated backup. PITR (Point-in-Time Recovery) strategy and centralized snapshots via AWS Backup. For critical workloads, migration to Aurora Global Database for an RTO < 1 min in case of regional failure.
    Amazon Web Services AWS RDS Amazon RDS Amazon Aurora MySQL
  • XERFI DATA
    Malt logoOn Malt
    AWS Landing Zone Expertise
    BANKING AND INSURANCE
    April 2026 - May 2026
    Paris, France

    Design of a robust Landing Zone, aligned with the AWS Well-Architected Framework: governance, segmentation, large-scale compliance.

    Context
    Supporting a client in structuring their multi-account AWS environment: design of a Landing Zone aligned with the AWS Well-Architected Framework, with the objectives of large-scale governance, access segmentation, and continuous compliance.
    Achievements
    AWS Organizations & Segmentation
    Design of the OU hierarchy (Security, Infrastructure, Workloads/Prod, Sandbox…), strict segregation of the Management Account, implementation of an Account Vending Machine via Control Tower for automated onboarding of member accounts.
    IAM Identity Center
    Federation with the enterprise IdP (SAML 2.0 / SCIM), design of Permission Sets by business role, MFA enforced, propagation of access via Account Assignments across the entire organization.
    Service Control Policies (SCPs)
    Library of SCPs covering: region restriction (aws:RequestedRegion), CloudTrail/GuardDuty/Config protection, blocking public S3 access, prevention of organization exit.
    Guardrails & Compliance
    Deployment of Config Rules (CIS AWS Foundations Benchmark, FSBP), automatic remediation via SSM Automation, centralization of alerts in Security Hub with multi-account aggregation.
    Results
    Reduced attack surface, continuous GDPR/CIS compliance, accelerated time-to-production for new teams.
    Amazon Web Services AWS AWS VPC Administration réseaux AWS IAM
  • XERFI DATA
    Malt logoOn Malt
    AWS, Cloudflare Consulting
    BANKING AND INSURANCE
    April 2026 - May 2026 (1 month)
    Orléans, France

    AWS Tutoring & Consulting — Cloud Architecture, Security & Best Practices


    Technical support for a team of developers in upskilling on AWS, with practical training sessions and architecture consulting focused on security, multi-account governance, and production best practices.

    Scope & Achievements

    Design and delivery of hands-on tutoring sessions on AWS fundamentals and advanced uses. Approach focused on concrete cases with practical workshops in real environments.

    Networking & network security: multi-tier VPC architecture (public/private/isolated subnets), security groups, NACLs, VPC peering, and Transit Gateway. Implementation of best practices for network isolation between dev, staging, and production environments.

    Governance & identity management: AWS Organizations configuration with multi-account structure, implementation of AWS IAM Identity Center (SSO) for centralized access management. Definition of IAM policies according to the principle of least privilege, management of cross-account roles and SCPs at the Organization level.

    Databases & compute: RDS best practices (Multi-AZ, snapshots, parameter groups, credential management via Secrets Manager), EC2 sizing and optimization (instance types, reserved vs. on-demand, Auto Scaling Groups).

    Architecture review and audit of existing infrastructures with documented recommendations aligned with the AWS Well-Architected Framework.

    Results
    4 developers autonomous on AWS in 3 months
    40% reduction in infrastructure costs following optimization recommendations
    100% elimination of root access and long-lived IAM keys in production
    Multi-account architecture implemented with complete environment segregation

    Technical Environment
    AWS (VPC, IAM, Identity Center, Organizations, RDS, EC2, Secrets Manager, CloudTrail, Config), Terraform, AWS Well-Architected Framework
    AWS AWS RDS AWS IAM Amazon Web Services Terraform

Reviews

5.0

Out of 12 ratings

M

Martin

Audit DevOps - Breek

Several days project

-

Reviewed on 4/20/2026

Steve is very responsive and a great communicator, he's a true professional who knows how to listen while guiding his client towards what's essential. He audited our deployment with clear and prioritized areas for improvement.
A

Abdellatif

paramétrage cloudfare et reseau - TOTS DESIGN

Reviewed on 12/8/2025

Thank you to Steve for his quick intervention and excellent expertise.

Recommendations

Be the first to recommend Steve

Help this freelancer shine by sharing your experience working together.

These freelancer profiles also match your criteria

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Education

  • Engineer
    Mines de Nantes
    2006

Certifications

  • Certified Cloud Practitioner
    AWS
    2021

Skill set

Categories