Search Jobs

Search by job, company or skills

DevSecOps Engineer -

DevSecOps Engineer -

jobster private ltd.
2-5 Years
SGD 5,000 - 9,000 per month
  • Posted an hour ago
  • Be among the first 10 applicants

Job Description

Key Responsibilities:

. Cloud Infrastructure & Kubernetes Ownership: Manage and scale our AWS cloud environments and take end-to-end ownership of production-grade Kubernetes on AWS EKS, including cluster architecture, workload deployment, security, upgrades, autoscaling, resilience, observability, and incident troubleshooting.

. AWS Ecosystem Administration: Provision, configure, and manage essential AWS services supporting our applications. This includes managed relational databases (RDS PostgreSQL), search/analytics (OpenSearch), AI services (Bedrock), and networking/load balancing (ELB).

. Network Architecture, Security & Connectivity: Design, operate, and troubleshoot secure AWS network architectures for regulated, multi-account environments. This includes VPC and subnet design, CIDR planning, Transit Gateway routing and route-table segmentation, centralized ingress and egress, AWS Network Firewall and WAF, security groups and network ACLs, private connectivity through VPC endpoints or AWS PrivateLink, DNS resolution, load balancing, and connectivity to shared services or on-premises networks through VPN or Direct Connect. Apply network segmentation and least-privilege principles across production, non-production, management, and shared-service environments.

. Production Reliability, Observability & Resilience: Establish service-level indicators and objectives, dashboards, alerts, logs, metrics, and distributed traces across infrastructure, Kubernetes, applications, and AI workloads. Lead incident response, root-cause analysis, corrective actions, capacity planning, backup and restore testing, and disaster-recovery exercises to meet agreed recovery objectives.

. Infrastructure as Code, CI/CD & Automation: Use Terraform as the primary Infrastructure as Code tool to provision and manage repeatable AWS and Kubernetes environments. Administer and optimise GitLab CI/CD pipelines with automated testing, SAST, DAST, dependency and container scanning, policy checks, approval controls, immutable artefacts, environment promotion, rollback mechanisms, and auditable release records.

. Compliance, Security Engineering & Vulnerability Management: Embed security controls throughout the platform lifecycle, including threat modelling, secure architecture reviews, vulnerability and patch management, penetration testing, hardening, remediation tracking, audit evidence, and technical risk assessments. Work with cybersecurity, governance, product, and project stakeholders to translate government security requirements and enterprise standards into automated, testable controls.

. Identity, Secrets & Software Supply Chain Security: Implement least-privilege IAM, workload identity, privileged-access controls, secrets and certificate management, container image signing and scanning, software bills of materials, dependency governance, and policy enforcement across infrastructure and deployment pipelines. Protect sensitive configuration and credentials, and maintain traceability of changes and releases.

. Vendor Transition: Work closely alongside existing external vendors to map the current architecture, reverse-engineer undocumented configurations, and safely transition infrastructure operations fully in-house.

Qualifications:

. Experience: Typically 2 to 5+ years of hands-on experience in DevOps, DevSecOps, Cloud Engineering, or a similar role. We welcome candidates with fewer years of experience who can demonstrate strong practical capability, sound engineering fundamentals, and ownership of production systems. Hands-on production experience with Kubernetes and Terraform is mandatory depth of capability and evidence of impact will be valued over years of service.

. Cloud & Kubernetes: Strong proficiency in AWS infrastructure, together with substantial hands-on experience designing, deploying, securing, operating, troubleshooting, and upgrading production Kubernetes clusters and workloads. Strong experience with AWS EKS and Kubernetes networking is required, including ingress controllers, load balancers, service discovery, network policies, pod and service CIDR planning, and diagnosis of cross-VPC or restricted-egress connectivity issues.

. AWS Networking: Strong knowledge of complex AWS networking in multi-account and regulated environments. Candidates should be able to design and troubleshoot VPCs, subnets, route tables, Transit Gateway attachments and segmentation, overlapping or constrained CIDR ranges, centralized firewalls and egress, VPC endpoints and PrivateLink, Route 53 private DNS, security groups, network ACLs, VPN or Direct Connect connectivity, and traffic flows across application, shared-service, security, and on-premises network zones.

. CI/CD Tools: Solid experience building and maintaining CI/CD pipelines (GitLab preferred).

. Operational Readiness: Proven experience defining service-level objectives, building actionable monitoring and alerting, responding to production incidents, conducting root-cause analysis, managing capacity, and designing and testing backup, restore, and disaster-recovery arrangements.

. Regulated Environments: Experience delivering or operating systems under Singapore Government Commercial Cloud and IM8 requirements, or under comparably stringent regulatory frameworks in sectors such as banking, finance, healthcare, or critical infrastructure. Candidates should understand audit evidence, risk acceptance, segregation of duties, change control, and secure handling of sensitive data.

. Communication & Documentation: Ability to explain complex infrastructure and security decisions to technical and non-technical stakeholders, produce clear architecture diagrams, runbooks, operational procedures, risk assessments, and audit evidence, and work effectively with developers, AI engineers, cybersecurity teams, vendors, and government governance stakeholders.

Bonus Points:

. AI Agent Platforms: Significant hands-on experience deploying and operating agentic AI workloads is a major advantage. Relevant experience includes agent observability and distributed tracing, agent harness engineering, prompt and configuration versioning, evaluation pipelines, secure tool and model connectivity, runtime isolation, rate limiting, failure handling, and platforms such as Amazon Bedrock AgentCore or equivalent technologies.

. Modern AI Workflows: Familiarity with production AI and machine-learning workloads, including model and agent deployment patterns, prompt and configuration management, observability of latency, errors, token usage and cost, protection against unintended data exposure, and operational controls for responsible AI use.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

Similar Jobs

1-3 yrs
Singapore
Skills:
Java, Devops, Docker, Terraform, Ansible, Python, AWS Cloud Formation, Redhat Openshift, MLOps tools
7-10 yrs
SGD 9,500 - 11,500 per month
Singapore, Raffles Link / Raffles Place
Skills:
.NET, Java, Jfrog Artifactory, Linux Administration, Javascript, Terraform, Shell scripting, Helm, Kubernetes, Python, cloud networking, AWS, App Mesh, GitOps, Istio, Terragrunt, CI CD pipeline, Zero Trust principles, Envoy, Linkerd, AWS CloudHSM
3-6 yrs
SGD 7,000 - 9,800 per month
Singapore, Toa Payoh
Skills:
DAST, RDS, PostgreSQL, Vpn, Terraform, Elb, Kubernetes, AWS, Bedrock AI services, Direct Connect, OpenSearch, SAST
7-9 yrs
Singapore
Skills:
Fortify, Jenkins, Octopus, Bitbucket, Terraform, Ansible, Unix Shell Scripting, Elasticsearch, Sonarqube, Jfrog, AWS CodePipeline, Kubernetes, Python, DevSecOps principles, Sonatype Nexus, AWS CloudCommit
5-8 yrs
SGD 6,000 - 8,000 per month
Singapore
Skills:
Java, PowerShell, Prometheus, Fortify, Bash, Javascript, Terraform, Docker, Ansible, Gitlab, Helm, Python, Kubernetes, AWS, Gatekeeper, HashiCorp Vault, Crossplane, Sonatype Nexus IQ, Istio, Tenable, ArgoCD