Helius Technologies Pte Ltd
Singapore / Global
Singapore / Global
DevSecOps Engineer
Domain:
Cloud Security, DevOps, Application Security (AppSec)
Position Overview
The
DevSecOps Engineer
will be responsible for integrating security practices directly into the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipelines. This mid-level role focuses on automating security controls, managing vulnerabilities, securing cloud infrastructure, and ensuring application security without sacrificing development speed.
Key Responsibilities
CI/CD Security Automation:
Embed automated security testing tools into CI/CD pipelines (SAST, DAST, SCA, and secret scanning).
Cloud & Infrastructure Security:
Hardening cloud environments (AWS/Azure/GCP) and auditing Infrastructure as Code (IaC) scripts (Terraform/CloudFormation) for compliance and misconfigurations.
Vulnerability Management:
Analyze scan results, prioritize vulnerabilities, and work directly with software developers to remediate security issues.
Container Security:
Secure containerized applications and orchestrators (Docker, Kubernetes) by performing image scanning and enforcing runtime policies.
Compliance & Policy Enforcement:
Ensure deployments align with security standards (e.g., OWASP Top 10, CIS Benchmarks, NIST).
Requirements
Experience:
In DevOps, Application Security, or Systems Engineering with a focus on DevSecOps practices.
Pipeline Tools:
Proficiency with CI/CD platforms (GitLab CI, GitHub Actions, Jenkins, or Azure DevOps).
Security Tooling:
Experience with security tools such as SonarQube, Snyk, Checkmarx, OWASP ZAP, Trivy, or Aqua Security.
Scripting/Coding:
Strong scripting skills in
Python
,
Bash
, or
Go
for building automation wrappers.
Cloud Platforms:
Hands-on experience with cloud security models (AWS, Azure, or GCP).
Top 3 Most Important Skills
CI/CD Security Integration & Security Testing:
Hands-on experience embedding automated security scanning tools—SAST (e.g., SonarQube, Checkmarx), DAST, and SCA (e.g., Snyk, Dependency-Check)—into pipelines (Jenkins, GitLab CI, GitHub Actions).
Cloud Security & Infrastructure as Code (IaC):
Solid understanding of securing cloud environments (AWS, Azure, or GCP) and scanning IaC configurations (Terraform, CloudFormation) for security flaws using tools like Checkov or Trivy.
Container & Kubernetes Security:
Expertise in containerization (Docker) security, image scanning, container registry security, and Kubernetes RBAC/policy enforcement (e.g., Aqua Security, Sysdig, Trivy).
Interested candidate can share below details
Candidate Name (as per Passport)
Current Location
Total Experience
Relevant Experience
Current Company
Notice Period
Current Salary
Expected Salary
Reason for Change
Important Note:
Please share your resume in Word format with
[HIDDEN TEXT]
If this requirement is not a match for you, please feel free to refer your friends.
Interested professionals can reach out to me for a confidential discussion at
+65 68177759
.
Best Regards,
Arti C
Singapore / Global
Singapore / Global
Kallang / Global
Singapore / Global
Bugis, Singapore / Global
Singapore / Global