Hiring.Camp

G34 - DevSecOps Engineer

Fpt Asia Pacific Pte Ltd

·

2 days ago

Type
Full-time
Department
Engineering
Closing date
Today
Source
CareersPage

Description

Responsibilities 

  • Responsible for designing, automating, and maintaining secure, scalable, and resilient infrastructure and deployment pipelines:
  • Develop automation capabilities to deploy, manage, monitor, and maintain applications and infrastructure.
  • Design and maintain CI/CD pipelines for application deployment and release management.
  • Implement infrastructure-as-code and environment automation practices.
  • Manage cloud resources and platform services.
  • Develop and maintain CI/CD tooling and automation to support software build, testing, integration and release processes
  • Monitor and optimise platform availability, performance, utilisation, reliability, and operational health
  • Implement security controls and ensure compliance with government security requirements.
  • Plan, implement, and monitor system security architecture, including threat and risk assessments.
  • Conduct vulnerability assessments, system hardening, security reviews, and remediation activities.
  • Implement disaster recovery, backup, and business continuity measures.
  • Investigate, troubleshoot, and resolve system, application, and infrastructure issues
  • Collaborate closely with developers to integrate security throughout the software development lifecycle
  • Coordinate and work together with other members of the team.

Requirements: 

  • Strong understanding of Software Development Lifecycle (SDLC), CI/CD, Test-Driven Development (TDD) and DevSecOps practices.
  • Experience designing, deploying, and supporting cloud-native applications and infrastructure on AWS. Experience with GCC environment is advantageous.
  • Proficiency in at least two programming/scripting languages (Bash, PowerShell, Python, Javascript, or Java).
  • Experience with infrastructure-as-code and automation tools such as Terraform, Ansible, or equivalent technologies.
  • Experience with containerisation and orchestration technologies including Docker and Kubernetes.
  • Experience with source code management, GitLab workflows, and CI/CD platforms.
  • Experience implementing monitoring, logging and observability solutions to support platform reliability and operational excellence.
  • Knowledge of application security and cloud security, secure coding practices, and DevSecOps principles.
  • Hands-on experience with vulnerability management, security assessments, system hardening and remediation activities.
  • Familiarity with cloud-native and Cloud Native Computing Foundation (CNCF) tools (Prometheus, Helm, ArgoCD, Istio, Gatekeeper, Crossplane).
  • Familiarity with enterprise security and secrets management solutions (HashiCorp Vault, Tenable, Fortify, Sonatype Nexus IQ, AWS security services).
  • Experience with AWS services related to identity and access management, networking, monitoring, container platforms, and security
  • Strong troubleshooting, incident response, and operational support skills.
  • Experience working in regulated or government environments is preferred.

Skills

PythonJavaScriptJavaAWSDockerKubernetesTerraformAnsibleCI/CDGitLabCompliance