OCI Cloud Security Engineer | GitOps Ready, Hybrid

Avaloq

Makati

Hybrid

PHP 1,200,000 - 1,800,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Flexible working
Inclusive culture

Job summary

Avaloq, a Switzerland-based wealth management technology provider, seeks a proactive Cloud Security Engineer to design and automate security controls on OCI. You will implement secure-by-default templates, deploy Cloud Guard and WAF, manage TLS and secrets, and drive CI/CD integration with GitHub Actions.

Experience with OCI, Terraform, and GitOps is essential; you will collaborate across teams to improve security while enabling fast delivery in a hybrid work environment.

Qualifications

  • 3–6+ years’ experience in Security Engineering, SecOps, or Infrastructure Security, focusing on building and operating security controls.
  • Experience deploying and managing endpoint security agents at scale, tuning detection rules
  • Ability to manage certificate lifecycles from end to end, configure encryption services, set up secrets management, and troubleshoot certificate and TLS issues.
  • Hands‑on skill in securing cloud infrastructure, with strong preference for Oracle Cloud Infrastructure (OCI); experience with AWS and/or Azure is advantageous.
  • Ability to configure and operate OCI Cloud Guard, Security Zones, Vault, WAF, Bastion, Identity Domains, and NSGs.
  • Hands‑on experience with GitOps workflows using GitHub, including branch protections, code reviews, and CI/CD pipelines.
  • Competence in writing, maintaining, and troubleshooting Terraform configurations using the OCI Terraform Provider, managing remote state, and building reusable modules.
  • Experience in building and maintaining security pipelines with GitHub Actions or similar tools.
  • Ability to write functional automation scripts in Python and/or Bash for operational security needs.
  • Someone who builds solutions, not just advises on controls. You implement security measures, not just recommend them.
  • An automation‑first mindset: if you have performed a task manually more than once, you automate it with a script or Terraform module.
  • Comfortable working in the terminal, including SSH sessions, coding, log reading, and configuration debugging.
  • Iterative and pragmatic, able to deploy secure defaults rapidly and improve them over time rather than waiting for the ideal solution.
  • Collaborative and communicative, able to work alongside developers and platform engineers, explaining how to fix issues, not just reporting them.
  • Curious and self‑motivated, continuously learning, experimenting, and enhancing infrastructure security and automation.

Responsibilities

  • Data Security: Deploy and manage DLP policies across endpoints, cloud, and network to prevent unauthorized data movement. Continuously refine DLP rules to reduce false positives.
  • Endpoint Security: Deploy and manage endpoint security agents at scale across servers, VMs, and containers. Operate host-based intrusion detection, and log collection with tuned alerting. Configure antivirus/antimalware schedules, exclusions. Build automated response playbooks.
  • Network Security: Tune IDS/IPS, WAF policies, and rate-limiting rules. Conduct firewall rule audits to eliminate overly permissive access and enforce least privilege.
  • Cryptography & Certificate Management: Automate the full certificate lifecycle (generate, deploy, rotate, revoke) across all services. Configure encryption in transit and at rest using cloud-native and third‑party KMS. Manage secrets management solutions with rotation, access policies, and CI/CD integration.
  • Cloud Security & Secure-by-Default Configuration (OCI Preferred): Create secure-by-default templates (Terraform modules, cloud policies, guardrails) so all new resources meet security baselines. Operationalise OCI-native security services: Cloud Guard, Security Zones, Vulnerability Scanning, Bastion, WAF, and IAM compartment policies. Harden cloud resources (compute, storage, databases) and enforce tagging compliance. Remediate misconfigurations through code and automation, not just detection.
  • GitOps Practices & Automation: Use GitHub as the single source of truth for all security configurations and infrastructure changes (version-controlled). Write and maintain Terraform modules (OCI provider) for security infrastructure provisioning. Enforce GitHub repository governance (branch protection, code owners, merge policies). Build CI/CD pipelines via GitHub Actions for terraform plan/apply, static analysis, policy-as-code enforcement, and automated security scans. Manage Terraform state securely (remote backends, state locking, encryption, RBAC). Script automation (Python/Bash) for log parsing, bulk changes, compliance reporting, and alert enrichment.

Skills

Security engineering
SecOps
Infrastructure security
GitOps
Terraform
Python
Bash
OCI
Cloud security

Education

Bachelor's degree in Computer Science or related field

Tools

OCI Terraform Provider
GitHub Actions
Terraform
Cloud Guard
WAF
Bastion
Security Zones

Job description

Avaloq, a Switzerland-based wealth management technology provider, seeks a proactive Cloud Security Engineer to design and automate security controls on OCI. You will implement secure-by-default templates, deploy Cloud Guard and WAF, manage TLS and secrets, and drive CI/CD integration with GitHub Actions.

Experience with OCI, Terraform, and GitOps is essential; you will collaborate across teams to improve security while enabling fast delivery in a hybrid work environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

OCI Cloud Security Engineer – GitOps & Automation
OCI Cloud Security Engineer – GitOps & Automation

Avaloq • Philippines

Hybrid
PHP 900,000 - 1,500,000
Cloud Security Engineer — OCI & GitOps Maestro
Cloud Security Engineer — OCI & GitOps Maestro

Avaloq • Metro Manila

Hybrid
PHP 900,000 - 1,500,000
Hybrid work arrangement
Flexible working hours
Inclusive culture
+1
Cloud Security Engineer
Cloud Security Engineer

Avaloq • Philippines

Hybrid
PHP 900,000 - 1,500,000
Cloud Security Engineer
Cloud Security Engineer

Avaloq • Metro Manila

Hybrid
PHP 900,000 - 1,500,000
Hybrid work arrangement
Flexible working hours
Inclusive culture
+1
Cloud Security Engineer
Cloud Security Engineer

Avaloq • Makati

Hybrid
PHP 1,200,000 - 1,800,000
Hybrid work model
Flexible working
Inclusive culture
CI/CD Automation Engineer: GitHub Actions & Cloud
CI/CD Automation Engineer: GitHub Actions & Cloud

Avaloq • Metro Manila

Hybrid
PHP 1,000,000 - 1,800,000
Hybrid work model
Diversity & Inclusion
OCI Cloud Security Engineer: Compliance & SecOps Lead
OCI Cloud Security Engineer: Compliance & SecOps Lead

Workstreet • Philippines

On-site
PHP 1,200,000 - 1,800,000
Career development
Technical training
Remote-first culture
DevOps Engineer: CI/CD Automation Specialist (Hybrid)
DevOps Engineer: CI/CD Automation Specialist (Hybrid)

Cari • Philippines

Hybrid
PHP 1,100,000 - 1,500,000
Hybrid work model
CI/CD Automation Engineer - GitHub Actions & Cloud
CI/CD Automation Engineer - GitHub Actions & Cloud

Avaloq AG • Makati

On-site
PHP 600,000 - 1,200,000
DevOps Engineer — CI/CD & Cloud Automation
DevOps Engineer — CI/CD & Cloud Automation

Avaloq Group • Philippines

Hybrid
PHP 900,000 - 1,500,000
Hybrid work model
Flexible working hours