DevSecOps Engineer - #1634

JOBSTER PRIVATE LTD.

Singapore

On-site

SGD 140,000 - 210,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

JOBSTER PRIVATE LTD. seeks a hands-on Cloud Engineer to own AWS/Kubernetes production environments, including EKS-based clusters, networking, and observability.

You will design secure multi-account architectures, implement Terraform pipelines, and drive SRE practices, incident response, and audit readiness. The role requires 2–5+ years in DevOps/Cloud, strong AWS/Kubernetes experience, and familiarity with regulated environments.

Qualifications

  • 2–5+ years in DevOps/Cloud Eng with hands-on Kubernetes and Terraform.
  • Strong AWS/Kubernetes production experience, especially EKS and networking.
  • Experience in regulated environments or Gov/IM8-style standards.

Responsibilities

  • Own cloud infrastructure and Kubernetes on AWS for production workloads.
  • Administer AWS services including RDS, OpenSearch, Bedrock, ELB.
  • Design secure multi-account networks, VPCs, subnets and Transit Gateways.
  • Lead SRE practices: SLOs, dashboards, alerts, logs, traces and DR testing.
  • Automate with Terraform; manage GitLab CI/CD pipelines and scans.
  • Embed security controls across lifecycle; risk assessments and audits.
  • Manage IAM, secrets, and software supply chain security.
  • Collaborate with vendors and transition operations in-house.

Skills

Kubernetes
AWS
EKS
Terraform
CI/CD
Observability
Incident management

Tools

GitLab
Terraform
AWS EKS

Job description

Key Responsibilities:
  • Cloud Infrastructure & Kubernetes Ownership: Manage and scale our AWS cloud environments and take end-to-end ownership of production-grade Kubernetes on AWS EKS, including cluster architecture, workload deployment, security, upgrades, autoscaling, resilience, observability, and incident troubleshooting.
  • AWS Ecosystem Administration: Provision, configure, and manage essential AWS services supporting our applications. This includes managed relational databases (RDS PostgreSQL), search/analytics (OpenSearch), AI services (Bedrock), and networking/load balancing (ELB).
  • Network Architecture, Security & Connectivity: Design, operate, and troubleshoot secure AWS network architectures for regulated, multi-account environments. This includes VPC and subnet design, CIDR planning, Transit Gateway routing and route-table segmentation, centralized ingress and egress, AWS Network Firewall and WAF, security groups and network ACLs, private connectivity through VPC endpoints or AWS PrivateLink, DNS resolution, load balancing, and connectivity to shared services or on-premises networks through VPN or Direct Connect. Apply network segmentation and least-privilege principles across production, non-production, management, and shared-service environments.
  • Production Reliability, Observability & Resilience: Establish service-level indicators and objectives, dashboards, alerts, logs, metrics, and distributed traces across infrastructure, Kubernetes, applications, and AI workloads. Lead incident response, root-cause analysis, corrective actions, capacity planning, backup and restore testing, and disaster-recovery exercises to meet agreed recovery objectives.
  • Infrastructure as Code, CI/CD & Automation: Use Terraform as the primary Infrastructure as Code tool to provision and manage repeatable AWS and Kubernetes environments. Administer and optimise GitLab CI/CD pipelines with automated testing, SAST, DAST, dependency and container scanning, policy checks, approval controls, immutable artefacts, environment promotion, rollback mechanisms, and auditable release records.
  • Compliance, Security Engineering & Vulnerability Management: Embed security controls throughout the platform lifecycle, including threat modelling, secure architecture reviews, vulnerability and patch management, penetration testing, hardening, remediation tracking, audit evidence, and technical risk assessments. Work with cybersecurity, governance, product, and project stakeholders to translate government security requirements and enterprise standards into automated, testable controls.
  • Identity, Secrets & Software Supply Chain Security: Implement least-privilege IAM, workload identity, privileged-access controls, secrets and certificate management, container image signing and scanning, software bills of materials, dependency governance, and policy enforcement across infrastructure and deployment pipelines. Protect sensitive configuration and credentials, and maintain traceability of changes and releases.
  • Vendor Transition: Work closely alongside existing external vendors to map the current architecture, reverse-engineer undocumented configurations, and safely transition infrastructure operations fully in-house.
Qualifications:
  • Experience: Typically 2 to 5+ years of hands-on experience in DevOps, DevSecOps, Cloud Engineering, or a similar role. We welcome candidates with fewer years of experience who can demonstrate strong practical capability, sound engineering fundamentals, and ownership of production systems. Hands-on production experience with Kubernetes and Terraform is mandatory; depth of capability and evidence of impact will be valued over years of service.
  • Cloud & Kubernetes: Strong proficiency in AWS infrastructure, together with substantial hands-on experience designing, deploying, securing, operating, troubleshooting, and upgrading production Kubernetes clusters and workloads. Strong experience with AWS EKS and Kubernetes networking is required, including ingress controllers, load balancers, service discovery, network policies, pod and service CIDR planning, and diagnosis of cross-VPC or restricted-egress connectivity issues.
  • AWS Networking: Strong knowledge of complex AWS networking in multi-account and regulated environments. Candidates should be able to design and troubleshoot VPCs, subnets, route tables, Transit Gateway attachments and segmentation, overlapping or constrained CIDR ranges, centralized firewalls and egress, VPC endpoints and PrivateLink, Route 53 private DNS, security groups, network ACLs, VPN or Direct Connect connectivity, and traffic flows across application, shared-service, security, and on-premises network zones.
  • CI/CD Tools: Solid experience building and maintaining CI/CD pipelines (GitLab preferred).
  • Operational Readiness: Proven experience defining service-level objectives, building actionable monitoring and alerting, responding to production incidents, conducting root-cause analysis, managing capacity, and designing and testing backup, restore, and disaster-recovery arrangements.
  • Regulated Environments: Experience delivering or operating systems under Singapore Government Commercial Cloud and IM8 requirements, or under comparably stringent regulatory frameworks in sectors such as banking, finance, healthcare, or critical infrastructure. Candidates should understand audit evidence, risk acceptance, segregation of duties, change control, and secure handling of sensitive data.
  • Communication & Documentation: Ability to explain complex infrastructure and security decisions to technical and non-technical stakeholders, produce clear architecture diagrams, runbooks, operational procedures, risk assessments, and audit evidence, and work effectively with developers, AI engineers, cybersecurity teams, vendors, and government governance stakeholders.
Bonus Points:
  • AI Agent Platforms: Significant hands-on experience deploying and operating agentic AI workloads is a major advantage. Relevant experience includes agent observability and distributed tracing, agent harness engineering, prompt and configuration versioning, evaluation pipelines, secure tool and model connectivity, runtime isolation, rate limiting, failure handling, and platforms such as Amazon Bedrock AgentCore or equivalent technologies.
  • Modern AI Workflows: Familiarity with production AI and machine-learning workloads, including model and agent deployment patterns, prompt and configuration management, observability of latency, errors, token usage and cost, protection against unintended data exposure, and operational controls for responsible AI use.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

CAPGEMINI SINGAPORE PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Site Reliability Engineer
Site Reliability Engineer

U3 PROJECTS PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
DevOps SRE
DevOps SRE

Wipro • Singapore

On-site
SGD 120,000 - 150,000
DevOps Engineer | Singapore or Hong Kong
DevOps Engineer | Singapore or Hong Kong

Io Tech Solutions Limited • Singapore

On-site
SGD 90,000 - 180,000
ART 1486 - Application Engineer (Site Reliability)
ART 1486 - Application Engineer (Site Reliability)

FPT Asia Pacific Pte Ltd • Singapore

On-site
SGD 120,000 - 180,000
ART 1486 - Application Engineer (Site Reliability)
ART 1486 - Application Engineer (Site Reliability)

FPT Asia Pacific • Singapore

On-site
SGD 140,000 - 190,000
Site Reliability Engineer
Site Reliability Engineer

U3 INFOTECH PTE. LTD. • Singapore

On-site
SGD 120,000 - 180,000
Cloud Operations Engineer – Infrastructure
Cloud Operations Engineer – Infrastructure

TP-LINK CORPORATION PTE. LTD. • Singapore

On-site
SGD 110,000 - 170,000
DevOps Engineer - #1625
DevOps Engineer - #1625

JOBSTER PRIVATE LTD. • Singapore

On-site
SGD 90,000 - 150,000
CLOUD ENGINEER
CLOUD ENGINEER

RFNET TECHNOLOGIES PTE LTD • Singapore

On-site
SGD 120,000 - 170,000