Senior DevOps Engineer

Vidio Dot Com — Indonesia · Posted ~1 day ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Responsibilities Cloud security posture across our environment — continuous configuration assessment against CIS benchmarks, drift detection, and driving remediation to done rather than to a backlogGuardrails as code — SCPs, policy-as-code (OPA/Kyverno), and secure-by-defaultTerraform modules so misconfigurations are prevented, not just reportedIAM and least-privilege at scale — access reviews, secrets management, key rotation, and killing standing over-permissive accessHardening of cloud hosts and servers — golden images, CIS-benchmarked baselines, patch cadence, and bastion/SSH controlsEmployee endpoint hardening (~30% of the role) — MDM, EDR, disk encryption, and OS baselines across the laptop fleetSecurity built into CI/CD and infrastructure automation — everything as codePartnering with and leveling up other engineers, making the secure path the easy default instead of a blockerScaling all of the above to millions of users without slowing delivery down Requirements Strong Linux system administration Infrastructure as code — Terraform (or Ansible/Chef/Puppet) Containers and Kubernetes in production At least one high-level language: Python, Ruby, or Go, plus comfort writing shell scripts Solid understanding of DNS, TCP/IP, HTTP, TLS, and CDN Hands-on with at least one major cloud: AWS, GCP, or Azure Requirements — Cloud Security (required) IAM and least-privilege design, not just usage CIS benchmarks and host/OS hardening baselines Secrets management and encryption at rest and in transit Hands-on experience with a Cloud Security Posture Management (CSPM) tool — Wiz, Prowler, Scout Suite, AWS Security Hub, or GCP Security Command Center A preventive, guardrails-as-code mindset over scan-and-ticket Bonus Points Endpoint management experience — Jamf, Intune, or Kandji A cloud security certification such as AWS Security Specialty or CKS Monitoring/alerting experience — Datadog, Prometheus Experience with high-traffic or streaming platforms Exposure to compliance frameworks (PCI-DSS, ISO 27001) Comfortable using AI/LLM tooling to accelerate IaC, runbooks, and triage — with sound judgment about handling sensitive data