Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Cloudstaff Philippines Inc. is seeking a DevSecOps Engineer to lead cloud security and platform engineering for our AWS environment. The role emphasizes hardening security, IaC with Terraform, and supporting secure delivery of in-house applications.
You will define secure SDLC practices, stand up GitHub Enterprise with CI/CD pipelines, and collaborate across teams to ensure robust security posture in a hybrid work setup.
Looking for a role that fosters collaboration, creativity and career growth in a vibrant office environment? We got you covered! Join our team at Cloudstaff, the #1 workplace everywhere! Think you qualify for the role?
Role: DevSecOps Engineer
Work Arrangement: Hybrid
Location: Philippines - Makati/Ortigas/Pampanga (Angeles)
Schedule: Morning Shift
The DevSecOps Engineer runs the day-to-day security and platform engineering for the Nexgen Amazon Web Services (AWS) environment and the DevOps capability. The role hardens the cloud security posture, patches and configures workloads, maintains Infrastructure as Code (IaC), and supports the secure delivery of the in-house applications.
Harden the AWS platform against AWS Security Hub findings and the Centre for Internet Security (CIS) Benchmark, tightening security groups and rotating Identity and Access Management (IAM) keys.
Remediate AWS root account custody, move IAM keys into AWS Secrets Manager, and enable single sign-on through AWS Identity Center to the new Entra ID tenant.
Enable Amazon GuardDuty malware protection and AWS CloudTrail data events, forwarding events to the Security Information and Event Management (SIEM) platform for detection.
Define secure Software Development Lifecycle (SDLC) practices and coding standards for the in-house applications SOHO, Digital and Active Billing.
Stand up GitHub Enterprise with mandatory peer review and a Continuous Integration and Continuous Delivery (CI/CD) pipeline running Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA) and secrets detection.
Maintain Infrastructure as Code (IaC) with Terraform and manage workload patching and configuration through AWS Systems Manager, supporting deployments and the release cadence.
Support cloud security posture and vulnerability remediation alongside the Security Operations Engineer, using AWS Config and Microsoft Defender for Cloud.
Deploy and validate immutable backups of AWS workloads and workload configuration as IaC using AWS Backup, supporting disaster recovery.
Provide cloud detection support to the SOC Analyst by tuning and validating AWS log sources feeding the SIEM.
AWS platform, including AWS Config, AWS Security Hub, Amazon GuardDuty, AWS CloudTrail, AWS Identity Center, AWS Secrets Manager and AWS Backup.
AWS Systems Manager for workload patching and configuration management, with Terraform for Infrastructure as Code (IaC).
GitHub Enterprise, GitHub Actions, and GitHub Advanced Security for source control, peer review and the Continuous Integration and Continuous Delivery (CI/CD) pipeline.
In-house applications SOHO, Digital and Active Billing hosted on AWS, transitioning out from Infotrust, protected by Microsoft Defender for Cloud.
Demonstrated experience engineering and hardening production AWS environments against recognised security benchmarks.
Hands-on experience with Infrastructure as Code (IaC) using Terraform and with AWS Systems Manager for patching and configuration.
Working knowledge of AWS security services, including Security Hub, GuardDuty, CloudTrail, Identity Center and Secrets Manager.
Experience building and securing Continuous Integration and Continuous Delivery (CI/CD) pipelines with SAST, DAST, SCA and secrets detection.
Practical understanding of secure Software Development Lifecycle (SDLC) practices, source control with GitHub, and clear written English for engineering documentation.
An AWS certification such as AWS Certified Security Specialty, and experience integrating AWS logsources into a Security Information and Event Management (SIEM) platform such as Rapid7 or Microsoft Sentinel.
Experience with immutable backup and disaster recovery for cloud workloads using AWS Backup and Microsoft Defender for Cloud.
A relevant tertiary qualification in software engineering, cloud computing, cyber security or a related field, or equivalent experience.
Comprehensive health and life insurance on your 16th day of employment, covering 1 free dependent on the 16th day of employment
Up to 24 leave credits per year
Flexible leave credits which may be used for vacation, emergency and sick leaves
Endless opportunities for career advancement
Exclusive ATM inside the office for employee's convenience
Annual Performance Review with Salary Increase
We set you up for success with a company-provided PC/Laptop and fiber internet connection
Look forward to weekly office perks for work from office staff - Free Coffee, Meals and Beer Fridays!
Top notch workplace with first class VIP lounge and game rooms
Child friendly spaces to cater to the needs of employees with children, enhancing work-life balance
Participate and join our CS Social Clubs and Special Interest Groups to connect with colleagues
Mental Wellness Employee Assistance program through Lifeworks
In-house psychiatrist available to support employees' well-being
Become part of the Employee Share Units program
Cloudstaff Dream Points - To be used for bidding useful items like appliances, kitchenettes etc.
Established in 2005, Cloudstaff is a leading outsourcing company that empowers businesses to thrive through smarter talent solutions. We're passionate about creating a work environment that fosters your professional growth and overall well-being.