DevSecOps Engineer

Helius Technologies Pte Ltd

Singapore

On-site

SGD 90,000 - 150,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Helius Technologies Pte Ltd is seeking a DevSecOps Engineer to integrate security into the SDLC and CI/CD pipelines, automating controls and managing vulnerabilities. The role emphasizes securing cloud infrastructure and application security without slowing development.

You will automate security testing (SAST/DAST/SCA), harden AWS/Azure/GCP environments, and enforce runtimes and policies for containers and Kubernetes, aligning with OWASP Top 10, CIS, and NIST.

Qualifications

  • Experience in DevSecOps or security-focused DevOps within SDLC/CI-CD.
  • Proficient with CI/CD platforms and security tooling as listed.
  • Hands-on scripting in Python/Bash/Go for automation.
  • Cloud security knowledge across AWS/Azure/GCP and IaC review.

Responsibilities

  • Integrate automated security testing into CI/CD pipelines (SAST/DAST/SCA/secret scanning).
  • Harden cloud environments and audit IaC for compliance and misconfigurations.
  • Analyze vulnerability findings and work with developers to remediate.
  • Secure containerized apps and enforce runtime policies in Kubernetes.
  • Ensure deployments align with OWASP Top 10, CIS, and NIST.

Skills

CI/CD Security
Cloud Security
Vulnerability Management
Container Security
Python
Bash
Go
AWS
Azure
GCP

Tools

SonarQube
Snyk
Checkmarx
OWASP ZAP
Trivy
Aqua Security
Checkov
Kubernetes

Job description

DevSecOps Engineer
Domain

Cloud Security, DevOps, Application Security (AppSec)

Position Overview

The DevSecOps Engineer will be responsible for integrating security practices directly into the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipelines. This mid-level role focuses on automating security controls, managing vulnerabilities, securing cloud infrastructure, and ensuring application security without sacrificing development speed.

Key Responsibilities
  • CI/CD Security Automation: Embed automated security testing tools into CI/CD pipelines (SAST, DAST, SCA, and secret scanning).
  • Cloud & Infrastructure Security: Hardening cloud environments (AWS/Azure/GCP) and auditing Infrastructure as Code (IaC) s (Terraform/CloudFormation) for compliance and misconfigurations.
  • Vulnerability Management: Analyze scan results, prioritize vulnerabilities, and work directly with software developers to remediate security issues.
  • Container Security: Secure containerized applications and orchestrators (Docker, Kubernetes) by performing image scanning and enforcing runtime policies.
  • Compliance & Policy Enforcement: Ensure deployments align with security standards (e.g., OWASP Top 10, CIS Benchmarks, NIST).
Requirements
  • Experience: In DevOps, Application Security, or Systems Engineering with a focus on DevSecOps practices.
  • Pipeline Tools: Proficiency with CI/CD platforms (GitLab CI, GitHub Actions, Jenkins, or Azure DevOps).
  • Security Tooling: Experience with security tools such as SonarQube, Snyk, Checkmarx, OWASP ZAP, Trivy, or Aqua Security.
  • ing/Coding: Strong ing skills in Python, Bash, or Go for building automation wrappers.
  • Cloud Platforms: Hands-on experience with cloud security models (AWS, Azure, or GCP).
Top 3 Most Important Skills
  1. CI/CD Security Integration & Security Testing: Hands-on experience embedding automated security scanning tools—SAST (e.g., SonarQube, Checkmarx), DAST, and SCA (e.g., Snyk, Dependency-Check)—into pipelines (Jenkins, GitLab CI, GitHub Actions).
  2. Cloud Security & Infrastructure as Code (IaC): Solid understanding of securing cloud environments (AWS, Azure, or GCP) and scanning IaC configurations (Terraform, CloudFormation) for security flaws using tools like Checkov or Trivy.
  3. Container & Kubernetes Security: Expertise in containerization (Docker) security, image scanning, container registry security, and Kubernetes RBAC/policy enforcement (e.g., Aqua Security, Sysdig, Trivy).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

LINKTRIX Consultants, Asia Pacific • Singapore

On-site
SGD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

Kerry Consulting • Singapore

On-site
SGD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

Aryan-Solutions-Pte.-Ltd. • Singapore

On-site
SGD 90,000 - 130,000
DevSecOps Engineer
DevSecOps Engineer

TOPPAN ECQUARIA PTE. LTD. • Singapore

On-site
SGD 70,000 - 110,000
DevSecOps Engineer - 1548
DevSecOps Engineer - 1548

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 90,000 - 150,000
DevOps Engineer
DevOps Engineer

infinite Computer Solution • Singapore

On-site
SGD 120,000 - 180,000
Senior DevOps Engineer
Senior DevOps Engineer

Unison Group • Singapore

On-site
SGD 120,000 - 180,000
DevSecOps Engineer (Contract)
DevSecOps Engineer (Contract)

TOPPAN ECQUARIA PTE. LTD. • Singapore

On-site
SGD 60,000 - 90,000
DevOps Engineer
DevOps Engineer

INNOVATIQ TECHNOLOGIES PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
DevSecOps Engineer
DevSecOps Engineer

ITCAN PTE. LIMITED • Singapore

On-site
SGD 90,000 - 130,000