DevSecOps Engineer/Lead

Ajaib


Tanggal: 1 hari yang lalu
Kota: Jakarta, Jakarta
Jenis kontrak: Penuh waktu

As a DevSecOps Engineer, you will bridge the gap between development, operations, and information security. Reporting to the Application Security Lead, you will architect, maintain, and scale security automation across our software development lifecycles (SDLC). Your primary mandate is to shift security left by embedding SAST, DAST, and SCA tools directly into modern CI/CD pipelines, eliminating security bottlenecks and ensuring continuous code compliance.

Key Responsibilities

  • Pipeline Security Automation: Integrate and manage static, dynamic, and software composition analysis tools into continuous integration and continuous deployment (CI/CD) pipelines.
  • Tooling Optimization: Own, configure, and fine-tune AppSec platforms including Checkmarx, Semgrep, Snyk, and SonarQube to minimize false positives and maximize actionable alerts.
  • Automated & Manual DAST: Configure automated dynamic scanners and leverage Burp Suite Professional for targeted security testing on APIs and web services.
  • Vulnerability Remediation & Triage: Act as the primary technical point of contact to triage code vulnerabilities, providing clear remediation guidance and proof-of-concept fixes directly to engineering teams.
  • Open Source Security (SCA): Utilize Snyk and similar tools to monitor open-source dependencies, license compliance, and third-party software supply chain vulnerabilities.
  • Policy Enforcement: Define automated gatekeeping thresholds (e.g., failing builds for critical/high vulnerabilities) within the deployment pipeline based on internal security policies.

Requirements

  • Experience: 4+ years of experience in DevOps, software engineering, or application security, with at least 2+ years dedicated exclusively to DevSecOps practices.
  • Tooling Command: Proven, deep technical proficiency with the following tools:
    • SAST: Checkmarx, Semgrep, SonarQube
    • SCA & Container Security: Snyk
    • DAST / Pen-testing: Burp Suite Professional
  • CI/CD Ecosystems: Extensive experience building automation plugins and pipelines in GitHub Actions, GitLab CI, Jenkins, or Bitbucket Pipelines.
  • Infrastructure as Code (IaC): Solid understanding of cloud-native infrastructure, containerization (Docker, Kubernetes), and secure IaC deployment (Terraform).
  • Development Background: Ability to read and understand code snippets across multiple languages (e.g., Python, Java, Go, Node.js).
  • Certifications: Certifications such as Certified DevSecOps Professional (CDP), Practical DevSecOps (CDEP), or CSSLP are highly preferred

Benefits

Join us as we make magic happen to increase Indonesia’s financial inclusion!

Cara melamar

Untuk melamar pekerjaan ini, Anda perlu otorisasi di situs web kami. Jika Anda belum memiliki akun, silakan daftar.

Posting CV

Pekerjaan serupa

Fund Accountant

Standard Chartered, Jakarta, Jakarta
1 hari yang lalu
Requisition Number: 54269 Job Location: Jakarta, IDN Global Grade: Band 8 Work Type: Office Working Employment Type: Permanent Posting Start Date: 12/06/2026 Posting End Date: 10/07/2026 : Job Summary We are seeking a highly analytical and precise Fund Accountant to join our dynamic team. You will manage the post-trade lifecycle, ensuring the accurate valuation, reconciliation and accounting of investment funds...

General Cashier and Pay Master

Marriott International, Inc, Jakarta, Jakarta
4 hari yang lalu
Additional Information Job Number26072010 Job CategoryFinance & Accounting LocationJalan Jenderal Sudirman, Jakarta, Jakarta, Indonesia, 10220 ScheduleFull Time Located Remotely?N Position Type Non-Management POSITION SUMMARY Check figures, postings, and documents for correct entry, mathematical accuracy, and proper codes. Organize, secure, and maintain all files, records, cash and cash equivalents in accordance with policies and procedures. Record, store, access, and/or analyze computerized...

Technical Support Engineer (PST Shift / Remote Indonesia)

IBMC, Jakarta, Jakarta
4 hari yang lalu
IBMC stands as a prominent Business Management Consulting Company in Indonesia, dedicated to propelling business achievements. We offer a comprehensive range of services tailored to meet the diverse needs of both local and international businesses. This role will be managed directly under IBMC to support our client based in Bali within the high-growth SaaS and IT Services sector.We are looking...