Start Your Search Here

Job Search

elliott moss consulting

Singapore / Global

DevSecOps Engineer

Job Description

Job Overview

The DevSecOps Engineer will be responsible for designing, automating, securing, and maintaining scalable and resilient infrastructure and deployment pipelines across hybrid and multi-cloud environments. The role requires strong expertise in cloud platforms, infrastructure automation, containerization, CI/CD, security engineering, and modern DevOps practices.

The successful candidate will work closely with development, infrastructure, and security teams to integrate security throughout the software development lifecycle and ensure reliable, secure, and highly available technology platforms.

Key Responsibilities

Design, develop, automate, and maintain infrastructure and deployment processes across data centers and cloud environments.

Develop automation solutions that enable teams to deploy, manage, scale, and monitor applications efficiently.

Design and maintain secure CI/CD pipelines, incorporating automated security controls and streamlined release processes.

Develop scripts and automation tools to support software build, integration, testing, and deployment across development, QA, and production environments.

Automate infrastructure provisioning and configuration management using tools such as Terraform and Ansible.

Provision and manage virtual machines, databases, containers, and other infrastructure resources.

Deploy and maintain containerized workloads using Docker and Kubernetes.

Implement infrastructure monitoring, observability, and alerting solutions to monitor system performance, utilization, availability, and health.

Troubleshoot and resolve complex infrastructure, application, and security issues, including participation in on-call support for critical incidents.

Design and implement high-availability, resilient, and scalable infrastructure across hybrid cloud and multi-data-center environments.

Implement configuration management, backup, disaster recovery, and business continuity processes.

Implement security controls across cloud infrastructure, CI/CD pipelines, applications, and containerized environments.

Perform vulnerability assessments, security checks, system hardening, threat assessments, and risk assessments.

Monitor and respond to infrastructure and security incidents.

Apply secure configuration standards and industry best practices to infrastructure and applications.

Implement and manage secrets management and access controls using appropriate security technologies.

Ensure infrastructure and security practices align with applicable industry standards and compliance frameworks.

Collaborate with development, infrastructure, operations, and security teams in an Agile environment.

Continuously identify opportunities to improve automation, security, reliability, performance, and operational efficiency.

Required Qualifications & Experience

Degree or Diploma in Computer Science, Computer/Electronics Engineering, Information Technology, or a related discipline.

Strong understanding of SDLC, Continuous Integration (CI), Continuous Delivery (CD), and modern DevOps practices.

Strong experience working with high-availability, high-performance, and high-security systems across multi-data-center and hybrid cloud environments.

Hands-on experience with

AWS, Microsoft Azure, and Google Cloud Platform (GCP)

.

Strong experience with

Terraform and Ansible

for infrastructure provisioning and configuration management.

Strong hands-on experience with

Docker and Kubernetes

.

Experience designing and managing

GitLab CI/CD pipelines

.

Strong understanding of Git and modern branching strategies.

Proficiency in at least three scripting/programming languages such as

Bash, PowerShell, Python, or Go

.

Experience with infrastructure monitoring and observability, particularly

Prometheus

.

Knowledge of CNCF technologies such as

Helm, ArgoCD, Istio, Gatekeeper, and Crossplane

.

Experience with virtualization technologies such as

KVM, VMware, or Hyper-V

.

Experience with disaster recovery, system backup, and restoration processes.

Knowledge of RPM-based software packaging and deployment.

Strong troubleshooting and problem-solving skills across infrastructure, operating systems, applications, and network layers.

Security & Compliance

Hands-on experience implementing security controls within CI/CD pipelines and cloud-native environments.

Experience with vulnerability scanning, security assessments, and system hardening.

Experience with

HashiCorp Vault

or other enterprise secrets-management solutions.

Familiarity with enterprise security tools such as

Tenable, HP Fortify, Sonatype Nexus IQ, ElasticSearch Enterprise, and AWS security services

.

Strong understanding of network security concepts including firewalls, subnets, routing, access controls, and network segmentation.

Experience conducting security assessments within government or highly regulated environments.

Understanding of secure cloud architecture, API security, secrets management, and zero-trust principles.

Preferred / Advantageous Skills

Security certifications such as

CISSP, CISM, CREST

, or relevant cloud-security certifications.

Experience supporting or contributing to a

DevSecOps transformation

.

Knowledge of

ISO 27001, NIST, and CIS Benchmarks

.

Experience with

Istio or Linkerd

and service-mesh security.

Experience with additional CI/CD and DevOps tools such as Jenkins, Bitbucket, and ArgoCD.

Experience with cloud security services and enterprise security platforms.

Core Technical Skills

Cloud:

AWS, Azure, Google Cloud

Infrastructure as Code:

Terraform, Ansible

Containers:

Docker, Kubernetes

CI/CD:

GitLab CI/CD

Monitoring:

Prometheus

Secrets Management:

HashiCorp Vault

Scripting:

Bash, PowerShell, Python, Go

CNCF:

Helm, ArgoCD, Istio, Gatekeeper, Crossplane

Virtualization:

KVM, VMware, Hyper-V

Security:

Vulnerability Assessment, Security Hardening, Threat & Risk Assessment, Zero Trust, API Security

Compliance:

NIST, ISO 27001, CIS Benchmarks

Security Tools:

Tenable, HP Fortify, Sonatype Nexus IQ, AWS Security Services

Apply Now

Similar Opportunities

View all jobs