DevOps Engineer
Salary: $5,500 – $7,000 per month
About the Role
We are looking for an experienced DevOps Engineer to join our infrastructure/platform team. You will design, build, and maintain scalable cloud infrastructure and CI/CD pipelines, with a strong focus on AWS and Red Hat OpenShift environments. This role has a strong DevSecOps component — you will be expected to embed security practices throughout the development and deployment lifecycle, not treat it as an afterthought.
Key Responsibilities
Infrastructure & Platform
Design, implement, and maintain infrastructure-as-code (IaC) for AWS cloud environments
Deploy, manage, and optimize containerized applications on Red Hat OpenShift (OKD/OCP)
Manage Kubernetes/OpenShift clusters, including scaling, upgrades, and patching
Troubleshoot and resolve infrastructure, networking, and deployment issues
CI/CD & Automation
Build and maintain CI/CD pipelines to support development and release cycles
Automate repetitive operational tasks to improve deployment speed and reliability
Implement pipeline security gates (e.g., automated approval blocks on failed scans)
DevSecOps / Security Integration
Embed security checks across the SDLC ("shift left") — including static application security testing (SAST), dynamic testing (DAST), and software composition analysis (SCA)
Perform container/image vulnerability scanning before deployment to OpenShift (e.g., Trivy, Clair, Red Hat ACS/StackRox)
Manage secrets securely using tools like HashiCorp Vault, AWS Secrets Manager, or OpenShift Secrets
Implement policy-as-code and compliance-as-code (e.g., Open Policy Agent, OPA Gatekeeper) to enforce security and governance guardrails
Apply IAM least-privilege principles across AWS and OpenShift RBAC configurations
Monitor for security vulnerabilities, misconfigurations, and compliance drift in infrastructure and pipelines
Support security audits, vulnerability remediation, and incident response processes
Collaborate with security teams to align with organizational compliance frameworks
Monitoring & Reliability
Implement and maintain monitoring, logging, and alerting solutions (e.g., Prometheus, Grafana, ELK/EFK)
Support disaster recovery, backup strategies, and incident response procedures
Document infrastructure architecture, security controls, runbooks, and operational procedures
Requirements
Singapore Citizen, based in Singapore
3–5 years of relevant DevOps/DevSecOps/Platform Engineering experience
Hands-on experience with AWS (EC2, S3, VPC, IAM, Lambda, RDS, CloudFormation/Terraform, etc.)
Practical experience with Red Hat OpenShift (deployment, cluster management, operators, RBAC)
Solid understanding of containerization technologies (Docker, Kubernetes)
Experience with CI/CD tools (e.g., Jenkins, GitLab CI, GitHub Actions, Tekton)
Working knowledge of security scanning tools (SAST/DAST/SCA — e.g., SonarQube, Snyk, Checkmarx, OWASP ZAP)
Experience with container/image scanning tools (Trivy, Clair, Aqua, or Red Hat ACS)
Familiarity with secrets management tools (Vault, AWS Secrets Manager)
Proficiency in scripting languages (Bash, Python, or Go)
Familiarity with configuration management tools (Ansible, Chef, or Puppet)
Understanding of networking fundamentals (DNS, load balancing, firewalls, VPNs)
Experience with monitoring/logging tools (Prometheus, Grafana, ELK/EFK stack)
Strong problem-solving skills and ability to work independently under pressure
Good communication skills and ability to collaborate across Dev, Ops, and Security teams
Good to Have
AWS Certification (Solutions Architect, DevOps Engineer, or SysOps Administrator)
Red Hat Certified Specialist in OpenShift Administration (or equivalent)
Security certifications (e.g., CompTIA Security+, Certified Kubernetes Security Specialist - CKS)
Experience with GitOps tools (ArgoCD, Flux)
Exposure to compliance frameworks relevant to your industry (e.g., MAS TRM, ISO 27001, PCI-DSS)
Experience working in Agile/Scrum environments
Skills
- Agile
- Ansible
- Argo CD
- Automation
- AWS
- Bash
- CI/CD
- Cloud
- CloudFormation
- Containerization
- DAST
- DevOps
- DevSecOps
- DNS
- Docker
- EC2
- ELK
- Firewall
- Flux
- GitHub
- GitHub Actions
- GitLab
- GitOps
- Grafana
- IAM
- Infrastructure as Code
- ISO 27001
- Jenkins
- Kubernetes
- Lambda
- Networking
- OpenShift
- OWASP
- Pci Dss
- Prometheus
- Puppet
- Python
- RBAC
- RDS
- S3
- SAST
- Scrum
- SDLC
- Secrets Management
- SonarQube
- Terraform
- Vault
- VPC
- Vulnerability Scanning