Location: Onsite, Philippines
About the Hiring Company
The DevSecOps Engineer embeds security into every stage of the software delivery lifecycle, integrating automated security controls into CI/CD pipelines and infrastructure, and working closely with development, operations, and security teams to enable the fast, secure delivery of the gaming platform.
Job Responsibilities
- Integrate automated security testing (SAST, DAST, SCA, container and image scanning) into CI/CD pipelines, enforcing security gates before deployment.
- Define and maintain security-as-code and policy-as-code controls, including infrastructure as code (IaC) scanning for cloud and on-premises environments.
- Harden container and orchestration platforms such as Docker and Kubernetes, enforcing least-privilege access, image signing, and runtime security controls.
- Manage secrets, credentials, and certificates through centralized secrets management, eliminating hard-coded credentials across pipelines and services.
- Monitor, triage, and prioritize vulnerabilities across code, dependencies, images, and infrastructure, driving remediation with development teams against defined SLAs.
- Automate security baseline enforcement and compliance evidence collection across cloud and on-premises environments.
- Collaborate with development teams to embed secure coding practices, threat modeling, and security requirements early in the development cycle.
- Support incident response and post-incident reviews for security events affecting pipelines, infrastructure, and workloads, driving root-cause remediation.
- Continuously improve security tooling coverage and accuracy, reducing false positives and mean time to remediate.
- Participate in the on-call rotation to support production systems.
Key Performance Indicators/Key Success Factors
- Percentage of CI/CD pipelines with enforced security gates (SAST/DAST/SCA coverage).
- Mean time to remediate (MTTR) critical and high-severity vulnerabilities.
- Reduction in vulnerabilities reaching production.
- Compliance with security baselines across cloud and on-premises environments.
- Secrets management coverage, with zero hard-coded credentials in code and pipelines.
The Successful Candidate
- Education: Bachelor’s degree in computer science, Engineering, or a related field, or equivalent practical experience.
- Experience: 3+ years in a DevSecOps, DevOps, or security engineering role, ideally supporting high-availability, real-time platforms such as online gaming.
- Skills & Knowledge: Proficiency with CI/CD tools (Jenkins, GitLab CI, GitHub Actions), security scanning tools (SonarQube, Snyk, Trivy, OWASP ZAP), containerization/orchestration (Docker, Kubernetes), infrastructure as code (Terraform), cloud platforms (AWS/Azure/GCP), secrets management (HashiCorp Vault), and scripting (Python, Bash).
- Certifications (good to have): Certified Kubernetes Security Specialist (CKS), AWS Certified Security – Specialty, GIAC Cloud Security Automation (GCSA), or CISSP preferred.