DevSecOps Engineer
Location: Singapore
Experience Level: Mid-Senior (8+ years)
Role Overview
We are seeking a highly motivated DevSecOps Engineer to drive the adoption of secure software delivery practices across our development and operations teams. The successful candidate will design, implement, and maintain CI/CD pipelines, cloud infrastructure, security controls, and automated compliance processes to enable secure, scalable, and reliable application delivery.
This role requires a strong blend of DevOps engineering, cloud infrastructure, cybersecurity, automation, and stakeholder collaboration. The ideal candidate will champion a "security-by-design" approach and embed security throughout the Software Development Lifecycle (SDLC).
DevSecOps & CI/CD
- Design, implement, and maintain secure CI/CD pipelines to support application development and deployment
- Integrate security controls and automated testing into software delivery pipelines
- Implement Infrastructure as Code (IaC) practices for managing cloud and on-premise environments
- Automate build, deployment, configuration, and release management processes
- Support containerization and orchestration platforms to improve scalability and operational efficiency
- Establish deployment strategies such as blue-green, canary, and rolling deployments
Security Engineering
- Implement and manage DevSecOps tools covering:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Container Security Scanning
- Infrastructure Security Scanning
Cloud & Infrastructure Management
- Build and maintain secure cloud-native infrastructure across AWS, Azure, or Google Cloud Platform
- Manage container platforms such as Kubernetes and OpenShift
- Implement cloud security controls, identity and access management, network segmentation, and encryption standards
- Monitor system performance, availability, and reliability across environments
- Support disaster recovery, backup, and business continuity initiatives
Monitoring & Incident Response
- Implement centralized logging, monitoring, and observability solutions
- Develop security monitoring dashboards and automated alerting mechanisms
- Support incident response activities, including root cause analysis and post-incident reviews
- Continuously improve operational resilience and security monitoring capabilities
Governance, Risk & Compliance
- Ensure compliance with enterprise security policies and regulatory requirements
- Support security audits, vulnerability assessments, penetration testing, and compliance reviews
Required Experience
- Minimum 8+ years of experience in DevOps, Cloud Engineering, Cybersecurity, or DevSecOps roles
- Proven experience implementing enterprise-grade CI/CD pipelines and DevSecOps practices
- Experience supporting mission-critical applications in enterprise or government environments
- Strong understanding of Secure Software Development Lifecycle (SSDLC) principles
- Experience managing cloud infrastructure and container platforms at scale