freehire launches on Product Hunt on 26 August.

Follow →

DevSecOps Engineer

Summary

Build and secure CI/CD pipelines, automate security testing (SAST/DAST/SCA), and manage cloud infrastructure with IaC to embed DevSecOps across the SDLC.

Responsibilities

  1. Integrate security controls into CI/CD pipelines, including vulnerability scanning, dependency checks, secrets management, code quality validation and compliance checks.
  2. Design, implement, and maintain secure CI/CD pipelines to support automated application build, testing, deployment, and release processes.
  3. Monitor application, infrastructure and pipeline health using enterprise monitoring tools, dashboards, alerts, and log analysis to ensure availability, performance, and security.
  4. Implement automated security testing such as SAST, DAST, Software Composition Analysis (SCA), container scanning and Infrastructure-as-Code (IaC) security checks.
  5. Identify, assess and remediate security vulnerabilities across applications, cloud infrastructure, containers, and deployment environments in collaboration with development and infrastructure teams.
  6. Manage secrets, credentials, certificates, and access controls securely across development, testing and production environments.
  7. Develop and maintain Infrastructure-as-Code (IaC) and automation scripts to improve deployment consistency, scalability, security and operational efficiency.
  8. Establish monitoring, logging, and alerting mechanisms to proactively detect system issues, security threats, performance degradation, and deployment failures.
  9. Collaborate with Development, Security, Infrastructure, and Operations teams to embed DevSecOps practices throughout the Software Development Life Cycle (SDLC).
  10. Support security governance and compliance requirements by maintaining documentation, audit trails, security policies, remediation records, and evidence required for internal and external audits.

Requirements

  1. Degree or Diploma in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline, with relevant experience in DevOps, DevSecOps, Cloud Engineering, or Infrastructure Engineering.
  2. Hands-on experience with CI/CD platforms and automation tools such as Jenkins, GitLab CI/CD, GitHub Actions, Azure DevOps, or equivalent technologies.
  3. Good knowledge of application and infrastructure security, including vulnerability management, secrets management, SAST/DAST, dependency scanning, container security, and secure coding principles.
  4. Experience with cloud platforms, containers, and Infrastructure-as-Code, such as AWS/Azure/GCP, Docker, Kubernetes, Terraform, Ansible, or equivalent technologies.
  5. Strong troubleshooting and analytical skills, with experience using enterprise monitoring, logging, and observability tools; able to work effectively with cross-functional Development, Security, Infrastructure and Operations teams.


Clarence Khoh
R1552376

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available