DevSecOps Engineer/Lead

Ajaib Group

Jakarta Pusat

On-site

IDR 300,000,000 - 600,000,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ajaib Group in Indonesia is seeking a DevSecOps Engineer to bridge development, operations, and information security across our SDLC. You will embed SAST, DAST, and SCA into modern CI/CD pipelines, automating security gates and enabling rapid, secure software delivery.

You will work with Checkmarx, Semgrep, Snyk, and Burp Suite Pro, while advancing our cloud-native infrastructure with Docker, Kubernetes, and Terraform.

Qualifications

  • 4+ years in DevOps, software engineering, or application security with 2+ years in DevSecOps.
  • Proficient with SAST/DAST/SCA tools: Checkmarx, Semgrep, SonarQube, Snyk, Burp Suite Pro.
  • Extensive experience building automation in GitHub Actions, GitLab CI, Jenkins, or Bitbucket Pipelines.
  • IaC and cloud-native infra, containerization (Docker/Kubernetes), secure deployments with Terraform.
  • Able to read multiple languages (Python, Java, Go, Node.js).
  • Certifications like CDP, CDEP, CSSLP are highly preferred.

Responsibilities

  • Implement security automation across CI/CD pipelines to shift left in SDLC.
  • Configure and optimize AppSec platforms to minimize false positives and alert noise.
  • Set up automated and targeted DAST tests using Burp Suite Pro.
  • Triage vulnerabilities and provide remediation guidance to engineering teams.
  • Monitor open-source components for SCA risks and license compliance.
  • Establish automated gate-keeping thresholds based on security policies.

Skills

DevSecOps
CI/CD automation
Security testing
Cloud security
SRE practices

Education

CDP (Certified DevSecOps)
CDEP (Practical DevSecOps)
CSSLP

Tools

Checkmarx
Semgrep
SonarQube
Snyk
Burp Suite Pro
GitHub Actions
GitLab CI
Jenkins
Bitbucket Pipelines
Docker
Kubernetes
Terraform

Job description

As a DevSecOps Engineer, you will bridge the gap between development, operations, and information security. Reporting to the Application Security Lead, you will architect, maintain, and scale security automation across our software development lifecycles (SDLC). Your primary mandate is to shift security left by embedding SAST, DAST, and SCA tools directly into modern CI/CD pipelines, eliminating security bottlenecks and ensuring continuous code compliance.

Key Responsibilities
  • Pipeline Security Automation: Integrate and manage static, dynamic, and software composition analysis tools into continuous integration and continuous deployment (CI/CD) pipelines.
  • Tooling Optimization: Own, configure, and fine-tune AppSec platforms including Checkmarx, Semgrep, Snyk, and SonarQube to minimize false positives and maximize actionable alerts.
  • Automated & Manual DAST: Configure automated dynamic scanners and leverage Burp Suite Professional for targeted security testing on APIs and web services.
  • Vulnerability Remediation & Triage: Act as the primary technical point of contact to triage code vulnerabilities, providing clear remediation guidance and proof‑of‑concept fixes directly to engineering teams.
  • Open Source Security (SCA): Utilize Snyk and similar tools to monitor open‑source dependencies, license compliance, and third‑party software supply chain vulnerabilities.
  • Policy Enforcement: Define automated gate‑keeping thresholds (e.g., failing builds for critical/high vulnerabilities) within the deployment pipeline based on internal security policies.
Qualifications
  • Experience: 4+ years of experience in DevOps, software engineering, or application security, with at least 2+ years dedicated exclusively to DevSecOps practices.
  • Tooling Command: Proven, deep technical proficiency with the following tools:
    • SAST: Checkmarx, Semgrep, SonarQube
    • SCA & Container Security: Snyk
    • DAST / Pen‑testing: Burp Suite Professional
  • CI/CD Ecosystems: Extensive experience building automation plugins and pipelines in GitHub Actions, GitLab CI, Jenkins, or Bitbucket Pipelines.
  • Infrastructure as Code (IaC): Solid understanding of cloud‑native infrastructure, containerization (Docker, Kubernetes), and secure IaC deployment (Terraform).
  • Development Background: Ability to read and understand code snippets across multiple languages (e.g., Python, Java, Go, Node.js).
  • Certifications: Certifications such as Certified DevSecOps Professional (CDP), Practical DevSecOps (CDEP), or CSSLP are highly preferred

Join us as we make magic happen to increase Indonesia’s financial inclusion!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer/Lead
DevSecOps Engineer/Lead

Ajaib • Indonesia

On-site
DevSecOps Lead: Architect Secure CI/CD Pipelines
DevSecOps Lead: Architect Secure CI/CD Pipelines

Ajaib Group • Jakarta Pusat

On-site
IDR 300,000,000 - 600,000,000
Application Security Engineer/Lead
Application Security Engineer/Lead

Ajaib • Indonesia

On-site
IDR 1,078,748,000 - 1,438,332,000
Application Security Engineer/Lead
Application Security Engineer/Lead

Ajaib Group • Jakarta Pusat

On-site
IDR 750,000,000 - 1,350,000,000
Lead DevSecOps Engineer: Secure CI/CD & AppSec Automation
Lead DevSecOps Engineer: Secure CI/CD & AppSec Automation

Dormont Manufacturing Co • Indonesia

On-site
DevOps / Security Engineer
DevOps / Security Engineer

Global Inovasi Ventura • Kota Yogyakarta

On-site
IDR 10,000,000 - 15,000,000
DevSecOps Engineer - CI/CD, Security & Cloud Automation
DevSecOps Engineer - CI/CD, Security & Cloud Automation

White Glove Hiring • Jakarta Pusat

On-site
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Paper • Jakarta Barat

On-site
IDR 700,000,000 - 1,100,000,000
Azure DevSecOps Engineer - Secure SaaS CI/CD Automation
Azure DevSecOps Engineer - Secure SaaS CI/CD Automation

DVI Solutions Asia • Daerah Khusus Ibukota Jakarta

Hybrid
IDR 899,118,000 - 1,258,767,000
Opportunities to work on regional projects
Exposure to multinational clients
Team-oriented culture and continuous learning
Security Engineer
Security Engineer

Autobahn Security | Reduce Hackability • Indonesia

Hybrid
IDR 300,000,000 - 520,000,000
Hybrid work arrangement
Competitive salary & benefits
Ownership of product