DevSecOps Engineer
On-siteSingapore, Singapore
Job Summary
Build the cloud foundation in Terraform and OpenTofu, designing Azure infrastructure as configurable, composable modules that assemble into a coherent foundation with versioning, review, and testing. Operate platform-as-a-service on Kubernetes, managing observability, multi-tenancy, RBAC, governance, and FinOps alongside zero-trust posture controls including workload-to-workload mTLS and supply-chain integrity. Work across teams to build golden paths for developers, integrating testing, security scanning, and SBOM generation into pipelines while enabling AI workloads like model serving. Develop self-service interfaces for provisioning resources such as namespaces and clusters, documenting runbooks and guides to scale capabilities without manual requests. Own platform reliability at runtime by defining SLIs and SLOs, writing recovery runbooks, leading incident response, and executing safe cluster upgrades with minimal disruption.
Required Qualifications
- Bachelor's degree in computer science, Information Technology or related field
- Master's degree in Computer Science or Information Technology if applicable
- Several years building platform or DevOps capabilities end to end, from a developer problem to a production-grade, self-service solution (three to five years is a useful guide)
- Strong, hands-on Kubernetes experience in production, including RBAC, admission control, and diagnosing and resolving platform issues under pressure
- Solid infrastructure-as-code practice (Terraform or OpenTofu) and a GitOps approach to delivery (FluxCD or Argo CD)
- A working command of CI/CD pipelines and release strategy (GitLab pipelines, or equivalent)
- A sound grasp of cloud-native security: least privilege, network segmentation, secrets management, identity, and supply-chain integrity
- Operational maturity: defining SLOs, responding to incidents, and running upgrades safely in production
- Proficiency in at least one of Go, Python, or Bash, and comfort operating Linux
- The conviction that infrastructure is code: version-controlled, reviewed, tested, and secured
- You see systems end to end and resist thinking in silos
- You translate technology into developer experience and hold several stakeholders' perspectives at once
- You treat the platform as a product: you measure adoption and developer experience, and let that evidence, not assumption, guide what to build, harden, or retire next
- You have learning agility, flexibility, and initiative
- You are comfortable in an agile team and engaging directly with the developers you serve
- You hold your convictions with humility, welcome constructive feedback, and stay resilient
Desired Qualifications
- Depth in Azure and its native services (AKS, AI Foundry, Network Manager, Key Vault, Entra ID, Application Gateway, Firewall, Private Endpoints)
- Experience building or operating an internal developer platform or developer portal
- Familiarity with supply chain tooling (Sigstore/cosign, Trivy, DefectDojo, or equivalent) and policy engines (Kyverno, OPA/Gatekeeper)
- Exposure to data-platform components such as a lakehouse, event streaming, or workflow orchestration
- Exposure to safety-critical or regulated environments and the assurance discipline they require
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.