DevSecOps Engineer

Helius Technologies Pte Ltd

Santo Niño 1st

On-site

PHP 800,000 - 1,200,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Helius Technologies Pte Ltd is seeking a mid-level DevSecOps Engineer to embed security into the SDLC and CI/CD pipelines. You will automate security controls, manage vulnerabilities, and secure cloud infrastructure without sacrificing velocity.

The role requires collaboration with software developers to remediate issues, audit IaC, and enforce container security and runtime policies across Docker and Kubernetes environments.

Qualifications

  • Experience in DevOps, Application Security, or Systems Engineering with a focus on DevSecOps practices.
  • Proficiency with CI/CD platforms (GitLab CI, GitHub Actions, Jenkins, or Azure DevOps).
  • Experience with security tools such as SonarQube, Snyk, Checkmarx, OWASP ZAP, Trivy, or Aqua Security.
  • Strong scripting skills in Python, Bash, or Go for building automation wrappers.
  • Hands‑on experience with cloud security models (AWS, Azure, or GCP).

Responsibilities

  • Embed automated security testing tools into CI/CD pipelines (SAST, DAST, SCA, and secret scanning).
  • Harden cloud environments (AWS/Azure/GCP) and audit IaC scripts (Terraform/CloudFormation) for compliance and misconfigurations.
  • Analyze scan results, prioritize vulnerabilities, and remediate security issues with developers.
  • Secure containerized applications and orchestrators (Docker, Kubernetes) by image scanning and runtime policy enforcement.
  • Ensure deployments align with security standards (OWASP Top 10, CIS Benchmarks, NIST).

Skills

CI/CD Security
Cloud Security
Container & Kubernetes Security

Tools

SonarQube
Snyk
Checkmarx
OWASP ZAP
Trivy
Aqua Security
GitHub Actions
GitLab CI
Jenkins
Azure DevOps
Terraform

Job description

About the role

The DevSecOps Engineer will be responsible for integrating security practices directly into the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipelines. This mid-level role focuses on automating security controls, managing vulnerabilities, securing cloud infrastructure, and ensuring application security without sacrificing development speed.

Key responsibilities
  • Embed automated security testing tools into CI/CD pipelines (SAST, DAST, SCA, and secret scanning)

  • Harden cloud environments (AWS/Azure/GCP) and audit Infrastructure as Code (IaC) scripts (Terraform/CloudFormation) for compliance and misconfigurations

  • Analyze scan results, prioritize vulnerabilities, and work directly with software developers to remediate security issues

  • Secure containerized applications and orchestrators (Docker, Kubernetes) by performing image scanning and enforcing runtime policies

  • Ensure deployments align with security standards (e.g., OWASP Top 10, CIS Benchmarks, NIST)

About you
  • Experience in DevOps, Application Security, or Systems Engineering with a focus on DevSecOps practices

  • Proficiency with CI/CD platforms (GitLab CI, GitHub Actions, Jenkins, or Azure DevOps)

  • Experience with security tools such as SonarQube, Snyk, Checkmarx, OWASP ZAP, Trivy, or Aqua Security

  • Strong scripting skills in Python, Bash, or Go for building automation wrappers

  • Hands‑on experience with cloud security models (AWS, Azure, or GCP)

Top 3 Most Important Skills
  1. CI/CD Security Integration & Security Testing: Hands-on experience embedding automated security scanning tools—SAST (e.g., SonarQube, Checkmarx), DAST, and SCA (e.g., Snyk, Dependency-Check)—into pipelines (Jenkins, GitLab CI, GitHub Actions).

  2. Cloud Security & Infrastructure as Code (IaC): Solid understanding of securing cloud environments (AWS, Azure, or GCP) and scanning IaC configurations (Terraform, CloudFormation) for security flaws using tools like Checkov or Trivy.

  3. Container & Kubernetes Security: Expertise in containerization (Docker) security, image scanning, container registry security, and Kubernetes RBAC/policy enforcement (e.g., Aqua Security, Sysdig, Trivy).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Manager
DevSecOps Manager

Socium - Teams Done Differently • Pasay

On-site
PHP 1,200,000 - 2,400,000
DevSecOps Lead
DevSecOps Lead

NCS Group • Taguig

On-site
PHP 1,500,000 - 2,300,000
DevSecOps Specialist
DevSecOps Specialist

Maya • Metro Manila

On-site
PHP 900,000 - 1,300,000
Sr. Devsecops Security Engineer
Sr. Devsecops Security Engineer

Atos SE • Hinoba-an

On-site
PHP 1,000,000 - 2,000,000
Senior DevSecOps Engineer (Hybrid)
Senior DevSecOps Engineer (Hybrid)

blaseek • Manila

On-site
PHP 1,800,000 - 2,400,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Certa • Hinoba-an

On-site
PHP 1,786,000 - 2,678,000
Application Security Engineer
Application Security Engineer

Comrise • Taguig

Hybrid
PHP 1,800,000 - 3,200,000
DevSecOps Engineer
DevSecOps Engineer

Dencom Consultancy & Manpower Services • Manila

On-site
Devops Engineer L1
Devops Engineer L1

SID Global Solutions • Pasig

On-site
PHP 600,000 - 1,200,000
DevOps Security Engineer
DevOps Security Engineer

UST • Philippines

On-site
PHP 2,158,000 - 4,316,000