Point your AI agent at freehire and let it find you a job.

Get the CLI →

Helius Technologies

DevSecOps Engineer

Posted Updated
Discussion

About the role

The DevSecOps Engineer will be responsible for integrating security practices directly into the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipelines. This mid-level role focuses on automating security controls, managing vulnerabilities, securing cloud infrastructure, and ensuring application security without sacrificing development speed.

Key responsibilities

  • Embed automated security testing tools into CI/CD pipelines (SAST, DAST, SCA, and secret scanning)

  • Harden cloud environments (AWS/Azure/GCP) and audit Infrastructure as Code (IaC) scripts (Terraform/CloudFormation) for compliance and misconfigurations

  • Analyze scan results, prioritize vulnerabilities, and work directly with software developers to remediate security issues

  • Secure containerized applications and orchestrators (Docker, Kubernetes) by performing image scanning and enforcing runtime policies

  • Ensure deployments align with security standards (e.g., OWASP Top 10, CIS Benchmarks, NIST)

About you

  • Experience in DevOps, Application Security, or Systems Engineering with a focus on DevSecOps practices

  • Proficiency with CI/CD platforms (GitLab CI, GitHub Actions, Jenkins, or Azure DevOps)

  • Experience with security tools such as SonarQube, Snyk, Checkmarx, OWASP ZAP, Trivy, or Aqua Security

  • Strong scripting skills in Python, Bash, or Go for building automation wrappers

  • Hands-on experience with cloud security models (AWS, Azure, or GCP)


Top 3 Most Important Skills

  1. CI/CD Security Integration & Security Testing: Hands-on experience embedding automated security scanning tools—SAST (e.g., SonarQube, Checkmarx), DAST, and SCA (e.g., Snyk, Dependency-Check)—into pipelines (Jenkins, GitLab CI, GitHub Actions).

  2. Cloud Security & Infrastructure as Code (IaC): Solid understanding of securing cloud environments (AWS, Azure, or GCP) and scanning IaC configurations (Terraform, CloudFormation) for security flaws using tools like Checkov or Trivy.

  3. Container & Kubernetes Security: Expertise in containerization (Docker) security, image scanning, container registry security, and Kubernetes RBAC/policy enforcement (e.g., Aqua Security, Sysdig, Trivy).

Interested candidate can share below details

Candidate Name (as per Passport)

Current Location

Total Experience

Relevant Experience

Current Company

Notice Period

Current Salary

Expected Salary

Reason for Change

Important Note:

Please share your resume in Word format with arti@helius-tech.com

If this requirement is not a match for you, please feel free to refer your friends.

Interested professionals can reach out to me for a confidential discussion at +65 68177759.

Best Regards,

Arti C

Sr. Talent Acquisition


Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available