DevSecOps Engineer
Summary
Build and secure CI/CD pipelines, automate security testing (SAST/DAST/SCA), and manage cloud infrastructure with IaC to embed DevSecOps across the SDLC.
Responsibilities
- Integrate security controls into CI/CD pipelines, including vulnerability scanning, dependency checks, secrets management, code quality validation and compliance checks.
- Design, implement, and maintain secure CI/CD pipelines to support automated application build, testing, deployment, and release processes.
- Monitor application, infrastructure and pipeline health using enterprise monitoring tools, dashboards, alerts, and log analysis to ensure availability, performance, and security.
- Implement automated security testing such as SAST, DAST, Software Composition Analysis (SCA), container scanning and Infrastructure-as-Code (IaC) security checks.
- Identify, assess and remediate security vulnerabilities across applications, cloud infrastructure, containers, and deployment environments in collaboration with development and infrastructure teams.
- Manage secrets, credentials, certificates, and access controls securely across development, testing and production environments.
- Develop and maintain Infrastructure-as-Code (IaC) and automation scripts to improve deployment consistency, scalability, security and operational efficiency.
- Establish monitoring, logging, and alerting mechanisms to proactively detect system issues, security threats, performance degradation, and deployment failures.
- Collaborate with Development, Security, Infrastructure, and Operations teams to embed DevSecOps practices throughout the Software Development Life Cycle (SDLC).
- Support security governance and compliance requirements by maintaining documentation, audit trails, security policies, remediation records, and evidence required for internal and external audits.
Requirements
- Degree or Diploma in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline, with relevant experience in DevOps, DevSecOps, Cloud Engineering, or Infrastructure Engineering.
- Hands-on experience with CI/CD platforms and automation tools such as Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps, or equivalent technologies.
- Good knowledge of application and infrastructure security, including vulnerability management, secrets management, SAST/DAST, dependency scanning, container security, and secure coding principles.
- Experience with cloud platforms, containers, and Infrastructure-as-Code, such as AWS/Azure/GCP, Docker, Kubernetes, Terraform, Ansible, or equivalent technologies.
- Strong troubleshooting and analytical skills, with experience using enterprise monitoring, logging, and observability tools; able to work effectively with cross-functional Development, Security, Infrastructure and Operations teams.
Clarence Khoh
R1552376