
DevSecOps Engineer
- Singapore
- Permanent
- Full-time
Impact: Your work will focus on the hardening, stability, and enhancement of our product build and delivery systems. You will be responsible for reviewing and securing configurations and code produced by other DevOps engineers, while also contributing to the overall security posture of our CI/CD pipelines.What You’ll Do:
- Harden and secure CI/CD pipelines.
- Review configurations and code produced by DevOps engineers, identifying and mitigating potential security risks.
- Collaborate with development, security, and operations teams to integrate security best practices into the CI/CD process.
- Enhance the stability and performance of build and delivery systems.
- Implement new capabilities and improvements to CI/CD systems with a focus on security and efficiency.
- Conduct regular security assessments and audits of the CI/CD pipeline.
- Ensure all processes and pipelines adhere to Secure Software Development Life Cycle (SDLC) practices.
- Develop and implement automated security testing to identify vulnerabilities early in CI/CD process.
- Train teams on security best practices in DevOps, increasing awareness for security.
- Create and document security standards and policies for CI/CD processes.
- Set up monitoring and feedback mechanisms to detect potential threats.
- Strong experience with CI/CD tools and platforms such as Jenkins, Artifactory, Jira, Bitbucket and Kubernetes.
- Proficient in scripting and automation for CI/CD pipelines.
- Knowledge of containerization and orchestration technologies (e.g., Docker, Kubernetes).
- Experience in performing security reviews and hardening of infrastructure and code.
- Familiarity with security tools and practices such as OWASP SDLC, static code analysis, and vulnerability scanning.
- Certification in Secure Software Development or security disciplines (e.g., SANS) is a plus.
- Certification of
- Experience with Infrastructure as Code (IaC) tools like Terraform or Ansible is a plus
- Ability to work collaboratively across teams and communicate effectively in English.
- Strong analytical and problem-solving skills, with an eye for detail.
- A passion for security and continuous improvement.