Senior DevSecOps Engineer

Skyict Pcl — Thailand · Posted ~1 day ago

Senior

Skills

DevSecOps CI/CD SDLC security governance GitLab Git Flow automation Git Jira

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior DevSecOps position responsible for establishing secure development standards, automating delivery pipelines, and improving engineering efficiency across multiple teams.

Highlights

Strategic engineering role focused on improving software delivery, security practices, automation, and enterprise development processes.

Description

Position Overview This role is designed to lead the technical transformation of our software development organization, transitioning from fragmented, multi-team "siloed" operations to a standardized, commercial-grade enterprise. You will be responsible for defining and executing enterprise-wide SDLC (Software Development Life Cycle) standards, driving DevSecOps automation and security governance into CI/CD pipelines, and establishing Jira process standards to elevate delivery speed, engineering quality, and information security across all development sub-teams. Key Responsibilities 1. SDLC & Engineering Process Standardization Process Standardization: Define and roll out a unified enterprise Software Development Life Cycle (SDLC) standard, covering requirement reviews, technical design docs, Git branching strategies (GitLab/Git Flow), Code Review mandates, and canary release standards.Multi-Team Governance: Form and lead the Engineering Efficiency & Security Board to align technology stacks, development conventions, and toolchains across multiple sub-teams, dismantling isolated "silo" practices. 2. Jira & Toolchain Governance Workflow & Template Standardization: Restructure and standardize Jira workflows, issue types, and templates (Features/Bugs). Enforce transition gates (Validators/Conditions) to prevent incomplete tickets from moving forward prematurely.Toolchain Integration & Automation: Establish deep integrations between Jira, Git repositories (GitLab/GitHub), and CI/CD pipelines (e.g., auto-updating Jira statuses via Git commit/PR triggers) to minimize manual admin overhead for developers while ensuring end-to-end traceability. 3. DevSecOps & Security Governance (Shift-Left Security) Security Guardrails: Embed automated security gates into CI/CD pipelines using static code analysis (SonarQube), secrets detection (TruffleHog, GitGuardian), and Software Composition Analysis (SCA) to block high-risk vulnerabilities prior to release.Data & Access (Consolidation): Drive environment isolation (Dev/QA/Prod), decouple secrets/configs from source code (via Vault/Nacos), and enforce automated data masking and Principle of Least Privilege (PoLP). 4. CI/CD Automation & Engineering Metrics Standard Pipeline Templates: Design and maintain standardized, reusable CI/CD pipeline templates to provide "one-click" automated building, testing, and deployment across teams.Efficiency Dashboards: Build engineering efficiency and quality dashboards leveraging Jira and CI/CD metrics (monitoring Cycle Time, Escaped Defect Rate, Code Review response latency, etc.) to drive data-informed continuous improvement. 5. Cross-Team Change Management Phased Rollout Strategy: Apply structured change management principles with empathy and clear communication, prioritizing security redlines, validating through pilot teams, and progressively rolling out standards across the entire organization while balancing delivery speed with risk control. Key Qualifications 1. Experience & Background Bachelor’s degree or above in Computer Science, Software Engineering, or related fields.8+ years of experience in software development, technical architecture, or DevOps.Enterprise Vision: Prior experience in mid-to-large technology companies or mature SaaS enterprises with established DevOps or DevSecOps frameworks.Hands-on Execution: Proven track record of building technical infrastructure from 0 to 1 and transforming unstructured development teams into disciplined engineering organizations. 2. Technical Skills & Toolchain Proficiency Jira Administration: Deep expertise in Jira architecture, custom workflows, Automation Rules, permission schemes, and REST API integrations.CI/CD & Automation: Proficiency in GitLab CI, GitHub Actions, or Jenkins, with the ability to write pipeline guardrail logic as code.DevSecOps Tooling: Hands-on integration experience with SonarQube, Snyk, GitGuardian, HashiCorp Vault, or similar tools.Technical Foundation: Proficient in at least one core backend language (Java, Go, Python, etc.) and well-versed in Docker, Kubernetes, and microservice configuration/access management. 3. Soft Skills & Mindset "Governance via Tooling" Mindset: Firm belief in enforcing standards through automated tooling and hard guardrails rather than manual enforcement or personal discretion.Cross-Functional Influence: Excellent communication skills, diplomacy, and the ability to win buy-in from sub-team leads using data and pragmatic solutions.Business-Centric Focus: Pragmatic and anti-bureaucratic; ensures all standards directly serve commercial delivery speed, operational stability, and product quality. Preferred Qualifications Successful experience leading an engineering organization of 100+ developers from fragmented operations to a standardized DevSecOps framework.Familiarity with open-source license compliance and enterprise security/compliance certifications (e.g., SOC 2, ISO 27001) within the R&D lifecycle.