Turn this role into an interview — a resume and cover letter built around what this employer wants.
Helius Technologies Pte Ltd is seeking a mid-level DevSecOps Engineer to embed security into the SDLC and CI/CD pipelines. You will automate security controls, manage vulnerabilities, and secure cloud infrastructure without sacrificing velocity.
The role requires collaboration with software developers to remediate issues, audit IaC, and enforce container security and runtime policies across Docker and Kubernetes environments.
The DevSecOps Engineer will be responsible for integrating security practices directly into the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipelines. This mid-level role focuses on automating security controls, managing vulnerabilities, securing cloud infrastructure, and ensuring application security without sacrificing development speed.
Embed automated security testing tools into CI/CD pipelines (SAST, DAST, SCA, and secret scanning)
Harden cloud environments (AWS/Azure/GCP) and audit Infrastructure as Code (IaC) scripts (Terraform/CloudFormation) for compliance and misconfigurations
Analyze scan results, prioritize vulnerabilities, and work directly with software developers to remediate security issues
Secure containerized applications and orchestrators (Docker, Kubernetes) by performing image scanning and enforcing runtime policies
Ensure deployments align with security standards (e.g., OWASP Top 10, CIS Benchmarks, NIST)
Experience in DevOps, Application Security, or Systems Engineering with a focus on DevSecOps practices
Proficiency with CI/CD platforms (GitLab CI, GitHub Actions, Jenkins, or Azure DevOps)
Experience with security tools such as SonarQube, Snyk, Checkmarx, OWASP ZAP, Trivy, or Aqua Security
Strong scripting skills in Python, Bash, or Go for building automation wrappers
Hands‑on experience with cloud security models (AWS, Azure, or GCP)
CI/CD Security Integration & Security Testing: Hands-on experience embedding automated security scanning tools—SAST (e.g., SonarQube, Checkmarx), DAST, and SCA (e.g., Snyk, Dependency-Check)—into pipelines (Jenkins, GitLab CI, GitHub Actions).
Cloud Security & Infrastructure as Code (IaC): Solid understanding of securing cloud environments (AWS, Azure, or GCP) and scanning IaC configurations (Terraform, CloudFormation) for security flaws using tools like Checkov or Trivy.
Container & Kubernetes Security: Expertise in containerization (Docker) security, image scanning, container registry security, and Kubernetes RBAC/policy enforcement (e.g., Aqua Security, Sysdig, Trivy).