DevSecOps Specialist
Job Purpose
The DevSecOps Specialist will be responsible for integrating and maintaining robust security measures within our DevOps processes, ensuring the security, compliance, and efficiency of our financial applications. The role combines development, security, and operations to enhance our overall security posture, primarily supporting on-premises environments. The engineer will play a key role in deployment and automation, as well as be involved in project work, operational support, and various tasks as assigned.
Key Responsibilities
The DevSecOps Specialist will develop, implement, and maintain automated deployment pipelines and workflows to streamline the deployment process.
DevSecOps Specialist will integrate security tools and processes into the CI/CD pipeline for on-premises environments to ensure secure software delivery.
DevSecOps Specialist will identify, manage, and mitigate security vulnerabilities in code, infrastructure, and third-party dependencies
DevSecOps Specialist will implement monitoring tools and frameworks to detect and respond to security incidents promptly.
Collaboration with development, operations, and security teams is essential to ensure cohesive security practices and smooth project execution.
DevSecOps Specialist will ensure all systems and software comply with relevant security standards and financial regulations, such as PCI-055, GDPR, and 150 27001.
DevSecOps Specialist will create and maintain comprehensive documentation for deployment processes, security practices, and took
Providing ongoing operational support for deployed applications and systems, including troubleshooting and resolving issues, is a crucial part of this role
DevSecOps Specialist will participate in various projects, providing expertise in DevSecOps practices and supporting the project lifecycle from planning to deployment.
DevSecOps Specialist will undertake any other tasks as assigned to support the team and organization goals.
Job Specification
Qualifications
Minimum B.Sc in Computer Science, Computer Engineering, MIS, other similar qualification .
Professional Qualification and/or Regulatory, Licensing requirements
Certification such as Certified DevSecOps Professional, Certified Kubernetes Administration (CKA), Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or relevant financial industry certifications are preferred
Relevant Work Experience
A minimum of three years of experience in DevOps, cybersecurity or a relevant field is required.
Hands-on experience with CI/CD tools, such Jenkins, Gitlab CI if necessary
Proficiency in scripting languages, like Python or Bash expected.
Experience with containerization and orchestration tools, such as Docker or kubernetes is also required
Familiarity with cloud platforms like AWS, Azure, or GEP is optional
Knowledge of financial industry regulations and standards, such as PCS DSS and SOC is important
Required Competencies and Skills
Competencies/Skills
Technical/Functional skills
The ideal candidate will have a strong understanding of security best practices and frameworks, such as OWASP and NIST.
Proven expertise in designing and implementing CI/CD pipelines to support software development practices
Deep understanding of configuration management principles and infrastructure automation
Excellent problem-solving and analytical abilities are necessary, to perform root clause analysis.
Experience with infrastructure as code tools like Terraform is essential
Experience with a broad range of toolsets including rational type Veracode, SonarQube, FPM, ALM & reporting tools
DevSecOps Specialist should have knowledge of secure coding practices and threat modelling
Proven experience in automating deployment processes and workflows is crucial.
Strong communication and collaboration skills are required to convey complex security concepts to non-technical stakeholders.
DevSecOps Specialist should be proactive and self-motivated with a keen attention to detail.
DevSecOps Specialist should have the ability to work independently and as part of a team.
Self-motivated and proactive in learning new technologies and improving deployment strategies.
Ability to prioritize and manage multiple tasks in a dynamic, fast-paced environment.
Commitment to continuous improvement and delivering high-quality solutions that meet business requirements.
Personal skills
Effectively convey technical information to diverse audiences.
Flexibility to adjust to changing priorities and technologies.
Remain composed under pressure and resolved challenges effectively.
Efficiently prioritize tasks and meet deadlines.
Understand and meet internal or external customer needs.
Job Types: Full-time, Permanent
Pay: From RM10,000.00 per month
Benefits:
- Health insurance
- Professional development
Ability to commute/relocate:
- Petaling Jaya: Reliably commute or planning to relocate before starting work (Required)