Start Your Search Here

Job Search

vinova pte. ltd.

Toa Payoh, Singapore / Global

DevSecOps Engineer

  • $7000-$9800

Job Description

Company Overview

Vinova is an award-winning development company specializing in mobile, web, and enterprise applications worldwide. We deliver quality, flexible, and fast solutions in IoT, blockchain, fintech, networking, and ecommerce, fostering a collaborative and innovative work environment.

Job Summary

Design, implement, and maintain secure CI/CD pipelines integrating security and quality tools to automate application build, testing, and deployment. Support containerized deployments and standardize DevSecOps practices across applications.

Responsibilities

Design and maintain secure CI/CD pipelines using GitLab and SHIP-HATS, managing runners, branching, merge controls, and access rights to ensure robust deployment workflows

Integrate Fortify, Nexus IQ, and SonarQube tools into CI/CD pipelines to enforce security and code quality gates effectively

Apply shift-left security practices throughout the software development lifecycle to identify and mitigate vulnerabilities early in code, dependencies, containers, and deployments

Automate application build, testing, security scanning, and deployment processes across development and production environments to enhance efficiency and reliability

Support containerized application deployment using Docker and Kubernetes/EKS to ensure scalable and consistent environments

Manage pipeline credentials, secrets, and service accounts securely to protect sensitive information and maintain compliance

Develop reusable pipeline templates and standardize DevSecOps practices across AE applications to promote consistency and best practices

Troubleshoot pipeline, security scanning, and deployment issues, collaborating with developers to resolve findings and improve pipeline stability

Required competencies and certifications

Hands-on experience with GitLab CI/CD

Good understanding of SDLC, DevSecOps, and shift-left security principles

Experience integrating application security and code-quality tools, preferably Fortify, Nexus IQ, and SonarQube

Experience with Git, Docker, and Kubernetes

Scripting skills using Python, Bash, PowerShell, or equivalent

Working knowledge of Linux, networking, access control, and secrets management

Preferred competencies and qualifications

Hands-on experience with SHIP-HATS

Experience with Infrastructure as Code tools such as Terraform, Ansible, or AWS CloudFormation

Experience with Helm and Argo CD

Apply Now

Similar Opportunities

View all jobs