DevSecOps Engineer

Sminvestments — Philippines · Posted ~1 day ago

Mid

Skills

CI/CD security automation AWS Azure GCP Docker Kubernetes SAST DAST SCA Infrastructure as Code security Terraform CloudFormation IAM RBAC SAML OAuth security frameworks threat modeling risk assessment vulnerability management Zero Trust Jenkins GitLab CircleCI GitHub Actions Snyk SonarQube Checkmarx Fortify Cognito JFrog Nexus

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A DevSecOps Engineer role focused on embedding security throughout modern software delivery and cloud infrastructure. You will automate security controls across CI/CD pipelines, secure containerized environments, implement Infrastructure as Code security, strengthen identity and access controls, and support compliance, vulnerability management, threat modeling, and Zero Trust initiatives across major cloud platforms.

Highlights

Opportunity to work across cloud security, secure software delivery, infrastructure security, identity, compliance, threat modeling, and Zero Trust practices.

Description

About SM Investments At SM Investments, we shape sustainable growth stories that move industries and uplift communities. As one of the Philippines’ leading conglomerates, we build opportunities across retail, banking, and property guided by excellence, integrity, and innovation. Key Responsibilitie Automate security controls within CI/CD pipelines (Jenkins, GitLab, CircleCI, GitHub ActionsSecure cloud environments (AWS, Azure, GCP) and container platforms (Docker, Kubernetes)Integrate security testing tools (SAST, DAST, SCA) such as Snyk, SonarQube, Checkmarx, or FortifyImplement Infrastructure as Code (IaC) security using Terraform and CloudFormationEnforce IAM best practices, RBAC, and federated identity (SAML, OAuth, Cognito)Apply security frameworks (ISO 27001, NIST, CIS) and compliance automationPerform threat modeling, risk assessments, and vulnerability managementSecure DevOps toolchains, artifact repositories (JFrog, Nexus), and source control systemImplement Zero Trust principles and cloud-native security controlsMaintain audit trails, enforce policies (OPA, AWS Config), and ensure governance compliance Technical Competencies Strong expertise in DevSecOps practices and secure SDLCDeep knowledge of cloud and container securityHands-on experience with IaC security and automationFamiliarity with Kubernetes security (RBAC, network policies, secrets management)Proficiency in security tools and automation frameworksExperience with compliance-as-code tools (Chef InSpec, OpenSCAP) Preferred Experience Proven experience in DevSecOps within platform engineering environments, building secure and scalable developer platformsHands-on expertise with Terraform, including securing Terraform modules, state management, and IaC pipelinesExperience designing and securing internal developer platforms (IDPs) or platform-as-a-service (PaaS) environmentsStrong background in automating security controls at scale across cloud-native architecturesExperience with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud or Dome9Exposure to enterprise-grade security architecture and governance frameworks