Skills
CI/CD security automation
AWS
Azure
GCP
Docker
Kubernetes
SAST
DAST
SCA
Infrastructure as Code security
Terraform
CloudFormation
IAM
RBAC
SAML
OAuth
security frameworks
threat modeling
risk assessment
vulnerability management
Zero Trust
Jenkins
GitLab
CircleCI
GitHub Actions
Snyk
SonarQube
Checkmarx
Fortify
Cognito
JFrog
Nexus
Summary
✨ AI‑Generated
A DevSecOps Engineer role focused on embedding security throughout modern software delivery and cloud infrastructure. You will automate security controls across CI/CD pipelines, secure containerized environments, implement Infrastructure as Code security, strengthen identity and access controls, and support compliance, vulnerability management, threat modeling, and Zero Trust initiatives across major cloud platforms.
Highlights
Opportunity to work across cloud security, secure software delivery, infrastructure security, identity, compliance, threat modeling, and Zero Trust practices.
Description
About SM Investments
At SM Investments, we shape sustainable growth stories that move industries and uplift communities.
As one of the Philippines’ leading conglomerates, we build opportunities across retail, banking, and property guided by excellence, integrity, and innovation.
Key Responsibilitie
Automate security controls within CI/CD pipelines (Jenkins, GitLab, CircleCI, GitHub ActionsSecure cloud environments (AWS, Azure, GCP) and container platforms (Docker, Kubernetes)Integrate security testing tools (SAST, DAST, SCA) such as Snyk, SonarQube, Checkmarx, or FortifyImplement Infrastructure as Code (IaC) security using Terraform and CloudFormationEnforce IAM best practices, RBAC, and federated identity (SAML, OAuth, Cognito)Apply security frameworks (ISO 27001, NIST, CIS) and compliance automationPerform threat modeling, risk assessments, and vulnerability managementSecure DevOps toolchains, artifact repositories (JFrog, Nexus), and source control systemImplement Zero Trust principles and cloud-native security controlsMaintain audit trails, enforce policies (OPA, AWS Config), and ensure governance compliance
Technical Competencies
Strong expertise in DevSecOps practices and secure SDLCDeep knowledge of cloud and container securityHands-on experience with IaC security and automationFamiliarity with Kubernetes security (RBAC, network policies, secrets management)Proficiency in security tools and automation frameworksExperience with compliance-as-code tools (Chef InSpec, OpenSCAP)
Preferred Experience
Proven experience in DevSecOps within platform engineering environments, building secure and scalable developer platformsHands-on expertise with Terraform, including securing Terraform modules, state management, and IaC pipelinesExperience designing and securing internal developer platforms (IDPs) or platform-as-a-service (PaaS) environmentsStrong background in automating security controls at scale across cloud-native architecturesExperience with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud or Dome9Exposure to enterprise-grade security architecture and governance frameworks