Kulalampur, Malaysia | Posted on 04/24/2026
Job Description: Cloud Automationand DevSecOps Engineer
Experience : 5-7 years (Core Terraform and DevOps Experience)
1. Role Overview
As a Cloud Automation and DevSecOps Engineer,you will drive the architecture and orchestration of a centralized Terraformmodule management system and implement secure DevSecOps release pipelineswithin our non-production AWS environment. Your mission is to establish awell-architected, "security-first" infrastructure-as-code (IaC)foundation that serves as the building block for our regional landing zone.This is a leadership-heavy technical role where you will facilitate workshopswith stakeholders to gather requirements, bridge the gap between systemoperations and application teams, and deliver a governed platform that balancesdeveloper agility with enterprise-grade security.
2. Key Responsibilities
2.1 Terraform Module Development& Management
- Architect ReusableInfrastructure: Design and implement five core, centralized Terraform modules for AmazonEKS, EC2, S3, RDS, and Auto Scaling Groups, ensuring they are shared across theorganization.
- Drive Standardization: Develop comprehensive samplecode for each module to demonstrate usage and ensure consistent implementationby application teams.
- Establish Security Baselines: Integrate initialMinimum-Security Baselines (MSB) and security standards directly into the IaCmodules to ensure compliance by default.
- Lifecycle Management: Orchestrate the full modulelifecycle through a centralized version control system, managing versioning,maintenance, and collaborative updates.
- Pipeline Architecture: Define target architectures forDevSecOps pipelines specifically tailored to the lifecycle management (testing,deployment, and maintenance) of reusable modules.
- GitOps Implementation: Configure and manage Gitbranching strategies to ensure effective GitOps workflows and maintain codeintegrity across environments.
- Automated Validation: Implement CI/CD pipelinesdedicated to module testing to ensure every update adheres to security policiesbefore distribution.
- Secure Access Management: Establish granular accesscontrols and security measures for the end-to-end module management process,defining clear boundaries between platform and application teams.
2.3 Landing Zone &Infrastructure Security
- Orchestrate Governance: Lead the setup of AWS ControlTower and organizational unit (OU) structures, including the implementation ofa "break-glass" solution for emergency access.
- Account Vending &Automation: Deploy automated account provisioning for an initial five (5) corenon-production accounts using Terraform-based account vending processes.
- Advanced Policy Implementation: Define and create sophisticatedsecurity controls, including five (5) Service Control Policies (SCPs), ResourceControl Policies, Declarative policies, and Tag policies.
- Identity & ThreatProtection: Implement SAML federation with IAM Identity Center (configuring up to 15permission sets) and deploy centralized security services including AmazonInspector, AWS Security Hub, and Amazon GuardDuty with auto-enrollment for allnew accounts.
Requirements
3. Technical Expertise & Requirements
3.1Technical Competency Requirements
Technology / Domain,Specific Application
Terraform,"Centralized moduledevelopment, account vending machine implementation, and IaC lifecyclemanagement."
AWS Networking,"AWS Network Orchestrationfor AWS Transit Gateway , VPC IP Address Manager (IPAM), and Centralized VPCEndpoints."
Containerization,Design and management ofAmazon EKS modules and underlying infrastructure.
Database &Storage,"Automation ofAmazon RDS and Amazon S3 within a reusable, hardened module framework."
3.2 Security & Governance
- Declarative Security: Proficiency in implementingSCPs, Declarative policies, Tag policies, and Resource Control Policies withinAWS Organizations.
- Identity Management: Expert knowledge of IAMIdentity Center, SAML federation, and permission set orchestration.
- Security Automation: Experience configuring AWSSecurity Hub, GuardDuty, and Amazon Inspector at scale with automatedenrollment.
- Baseline Development: Ability to document andimplement Minimum-Security Baselines (MSB) and recommended guardrails.
3.3 Networking & Infrastructure
- Hybrid Connectivity: Implementation of Route 53hybrid DNS using outbound resolver rules for on-premises connectivity.
- Traffic Inspection: Designing centralized egress,ingress, and North-South/East-West traffic inspection patterns utilizingAWS Network Firewalland AWS Firewall Manager.
- Network Orchestration: Automated management of TransitGateway architectures usingAWSNetwork Orchestration for AWS Transit Gateway .
4. Preferred Qualifications &Standards
- Adherence to Frameworks: Deep familiarity with AWSGeneral Best Practices, the AWS Shared Responsibility Model, and EnterpriseSecurity Principles.
- Multi-IaC Proficiency: While Terraform is the primarytool, experience using AWS CloudFormation for specific operational tasks,suchas automated AWS Budget alerts, is required.
- Architectural Documentation: Proven ability to producetechnical decision registers, detailed architectural diagrams, and high-qualityepics/user stories.
- Collaborative Leadership: Experience leading technicalworkshops and advising customers on access controls between system operationsand application teams.