DevOps Engineer (DevLabs by AngelHack)
About the Role
We are looking for an experienced DevOps Engineer to join our infrastructure/platform team. You will design, build, and maintain scalable cloud infrastructure and CI/CD pipelines, with a strong focus on AWS and Red Hat OpenShift environments. This role has a strong DevSecOps component — you will be expected to embed security practices throughout the development and deployment lifecycle, not treat it as an afterthought.
Key Responsibilities
Infrastructure & Platform
- Design, implement, and maintain infrastructure-as-code (IaC) for AWS cloud environments
- Deploy, manage, and optimize containerized applications on Red Hat OpenShift (OKD/OCP)
- Manage Kubernetes/OpenShift clusters, including scaling, upgrades, and patching
- Troubleshoot and resolve infrastructure, networking, and deployment issues
CI/CD & Automation
- Build and maintain CI/CD pipelines to support development and release cycles
- Automate repetitive operational tasks to improve deployment speed and reliability
- Implement pipeline security gates (e.g., automated approval blocks on failed scans)
DevSecOps / Security Integration
- Embed security checks across the SDLC ("shift left") — including static application security testing (SAST), dynamic testing (DAST), and software composition analysis (SCA)
- Perform container/image vulnerability scanning before deployment to OpenShift (e.g., Trivy, Clair, Red Hat ACS/StackRox)
- Manage secrets securely using tools like HashiCorp Vault, AWS Secrets Manager, or OpenShift Secrets
- Implement policy-as-code and compliance-as-code (e.g., Open Policy Agent, OPA Gatekeeper) to enforce security and governance guardrails
- Apply IAM least-privilege principles across AWS and OpenShift RBAC configurations
- Monitor for security vulnerabilities, misconfigurations, and compliance drift in infrastructure and pipelines
- Support security audits, vulnerability remediation, and incident response processes
- Collaborate with security teams to align with organizational compliance frameworks
Monitoring & Reliability
- Implement and maintain monitoring, logging, and alerting solutions (e.g., Prometheus, Grafana, ELK/EFK)
- Support disaster recovery, backup strategies, and incident response procedures
- Document infrastructure architecture, security controls, runbooks, and operational procedures
Requirements
- Singapore Citizen, based in Singapore
- 3–5 years of relevant DevOps/DevSecOps/Platform Engineering experience
- Hands-on experience with AWS (EC2, S3, VPC, IAM, Lambda, RDS, CloudFormation/Terraform, etc.)
- Practical experience with Red Hat OpenShift (deployment, cluster management, operators, RBAC)
- Solid understanding of containerization technologies (Docker, Kubernetes)
- Experience with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions, Tekton)
- Working knowledge of security scanning tools (SAST/DAST/SCA — e.g., SonarQube, Snyk, Checkmarx, OWASP ZAP)
- Experience with container/image scanning tools (Trivy, Clair, Aqua, or Red Hat ACS)
- Familiarity with secrets management tools (Vault, AWS Secrets Manager)
- Proficiency in scripting languages (Bash, Python, or Go)
- Familiarity with configuration management tools (Ansible, Chef, or Puppet)
- Understanding of networking fundamentals (DNS, load balancing, firewalls, VPNs)
- Experience with monitoring/logging tools (Prometheus, Grafana, ELK/EFK stack)
- Strong problem-solving skills and ability to work independently under pressure
- Good communication skills and ability to collaborate across Dev, Ops, and Security teams
Good to Have
- AWS Certification (Solutions Architect, DevOps Engineer, or SysOps Administrator)
- Red Hat Certified Specialist in OpenShift Administration (or equivalent)
- Security certifications (e.g., CompTIA Security+, Certified Kubernetes Security Specialist - CKS)
- Experience with GitOps tools (ArgoCD, Flux)
- Exposure to compliance frameworks relevant to your industry (e.g., MAS TRM, ISO 27001, PCI-DSS)
- Experience working in Agile/Scrum environments
Skills
- Agile
- Ansible
- Argo CD
- Automation
- AWS
- Bash
- CI/CD
- Cloud
- CloudFormation
- Containerization
- DAST
- DevOps
- DevSecOps
- DNS
- Docker
- EC2
- ELK
- Firewall
- Flux
- GitHub
- GitHub Actions
- GitLab
- GitOps
- Grafana
- IAM
- Infrastructure as Code
- ISO 27001
- Jenkins
- Kubernetes
- Lambda
- Networking
- OpenShift
- OWASP
- Pci Dss
- Prometheus
- Puppet
- Python
- RBAC
- RDS
- SAST
- Scrum
- SDLC
- Secrets Management
- SonarQube
- Terraform
- Vault
- VPC
- Vulnerability Scanning