DevSecOps Engineer

ABOUT CLIENT

Our client is one of the world's leading technology companies specializing in cybersecurity and digital identity solutions

JOB DESCRIPTION

Establish and oversee DevOps procedures for integrating CI/CD pipelines with various tools such as Jenkins, Bitbucket, Artifactory, and Phabricator.
Develop and execute modifications to current systems and new products to comply with business needs.
Automate DevSecOps operations through the creation of scripts for automated deployments, pipeline integration with SAST/DAST, and environment monitoring.
Supervise Jenkins master, slave nodes, and other relevant DevSecOps systems/resources, as well as manage artefacts and improve customer artifact generation and release processes.
Provide support for troubleshooting pipeline issues and work on enhancing the DevSecOps process across teams.
Head the DevSecOps team within the Security and Operations department.

JOB REQUIREMENT

A degree in Computer Science or a related field.
At least 6 years of experience in DevOps and 2 years in a team management role.
Experience in creating DevSecOps processes is necessary.
Proficiency in Jenkins, Groovy, shell scripting, and Python is a must.
Previous experience in developing DevSecOps functions is preferred.
Familiarity with Linux systems (RHEL or equivalent, Ubuntu, etc.) and container technologies is necessary.
Willingness to travel as needed.
Knowledge of DevOps infrastructure and exposure to Information Security fields is an advantage.
Must be self-motivated and able to work independently.
Capable of guiding and mentoring team members.
Comfortable working in a fast-paced environment.
Strong problem-solving abilities and critical thinking skills.
Excellent interpersonal and communication skills.
Willingness to provide standby support when required.
Keeping up-to-date with new technologies in DevSecOps related fields.
Actively seeking deeper understanding of DevSecOps relevant topics.
Proficient in English communication skills.
Soft skills
Demonstrates honesty, integrity, and commitment.
Displays a positive attitude and self-motivation.
Shows respect to everyone.
Self-organized and open to implementing new ideas.
Committed to delivering high-quality work and focused on customer satisfaction.

WHAT'S ON OFFER

Energetic and collegial work atmosphere with engaging team events
Provided Macbook Pro for work
Competitive salary
14 days of annual leave and insurance in accordance with labor regulations
Flexible benefits and leave options, including birthday leave, personal leave, medical leave, and monthly work from home
Performance-based incentives and acknowledgment
Healthcare coverage, company-sponsored trips, and quarterly team-building activities
Gifts on public holidays
Work hours: 8:30am – 5:30pm, Monday to Friday

CONTACT

PEGASI – IT Recruitment Consultancy | Email: recruit@pegasi.com.vn | Tel: +84 28 3622 8666
We are PEGASI – IT Recruitment Consultancy in Vietnam. If you are looking for new opportunity for your career path, kindly visit our website www.pegasi.com.vn for your reference. Thank you!

Job Summary

Company Type:

Product, mobile cyber-security

Technical Skills:

Devops, Security

Location:

Ho Chi Minh - Viet Nam

Working Policy:

Hybrid

Job ID:

J01491

Status:

Close

Related Job:

Engineering Manager – Shop 6.0

Ho Chi Minh - Viet Nam


Outsource

  • Management
  • Backend
  • Frontend
  • Devops
  • Azure

Take on overall technical and organizational responsibility for delivering Shop 6.0 across frontend, backend, and infrastructure Plan delivery scope, milestones, and releases, and coordinate the work of parallel workstreams (frontend, backend, DevOps, QA) Make and facilitate key architectural decisions together with the senior engineers, particularly around microservices, APIs, and cloud-native implementation on Azure Identify and manage risks related to integration (especially the ERP Cloud connection), scalability, and technical dependencies Serve as the central point of contact for stakeholders on scope, prioritization, and timelines Ensure code quality through reviews, mentoring, and clear standards, including a pull request process with mandatory checks and senior/lead review Ensure transparency on progress, risks, and decisions towards the team and management Hire, lead, develop and retain a team of 6 engineers (4 backend and 2 frontend)

Negotiation

View details

Senior AI DevSecOps Engineer

Ho Chi Minh - Viet Nam


Product

  • Devops
  • AWS
  • Azure
  • Security

Management of CI/CD Pipeline: Ensure automation, security, and scalability across all stages of the development lifecycle. Infrastructure & Security: Design and implement secure multi-cloud infrastructure solutions leveraging cloud services, containerization, and orchestration tools. Policy as Code: Define and enforce security and compliance policies across Kubernetes clusters using OPA or Kyverno, ensuring guardrails are automated and auditable. AI & Platform Automation: Drive the adoption of AI-powered tools and workflows to automate infrastructure operations, optimize CI/CD pipelines, accelerate root cause analysis, improve security posture, and enhance engineering productivity. Observability & Alerting: Build and maintain a comprehensive observability stack with proactive alerting, dashboards, and runbooks for critical business flows and security events. Secret & Credential Management: Design and enforce secrets management practices across all environments ensuring zero hardcoded credentials in codebases and pipelines. Incident Response & On-Call: Own and continuously improve incident response processes, define runbooks, lead post-mortems, track MTTR, and participate in on-call rotation to maintain platform reliability and SLO adherence. Threat Modelling & Penetration Testing: Conduct regular threat modelling sessions with engineering teams and coordinate or perform penetration testing activities to proactively identify attack surfaces before they reach production. Code Security: Conduct regular code reviews and static/dynamic analysis to identify and remediate security vulnerabilities. Compliance and Best Practices: Ensure compliance with industry standards and best practices. Collaboration: Collaborate with development, operations, and security teams to foster a culture of automation and security-first thinking. Mentorship: Mentor junior engineers and other team members on security best practices. Documentation: Maintain thorough and up-to-date documentation of security policies, procedures, and incident reports. Trend Scouting: Stay updated with the latest trends in technology and AI to integrate innovative solutions into our processes.

Negotiation

View details

Lead Penetration Tester

Ho Chi Minh, Ha Noi - Viet Nam


Outsource

  • Security

Conduct authorized penetration testing for various digital platforms, including web applications, mobile applications, APIs, infrastructure, and cloud environments. Identify and document security vulnerabilities, validate and exploit when necessary, covering areas such as authentication, authorization, session management, input validation, encryption, access control, and business logic issues. Perform security assessments according to industry standards (e.g. OWASP Top 10, OWASP API Security Top 10, OWASP Mobile Security Testing Guide) and relevant security practices. Analyze application flows, user journeys, transaction processes, access controls, and data handling mechanisms to uncover potential security risks. Conduct vulnerability assessment and manual verification to reduce false positives, confirming actual exploitability in authorized environments. Retest to validate remediation effectiveness and ensure vulnerabilities are properly resolved. Support security testing activities within the software development life cycle (SDLC), including security requirement review, threat analysis, test planning, and release security validation. Stay updated with emerging cyber threats, attack techniques, security risks, and security testing best practices. Lead the planning, scoping, and execution of penetration testing activities across assigned projects. Define the penetration testing approach, test strategy, testing scope, priorities, timelines, and required evidence based on project and client requirements. Guide and mentor penetration testers or security engineers in testing methodology, vulnerability validation, reporting quality, and remediation discussions. Review vulnerability findings, risk ratings, evidence, and remediation recommendations to ensure accuracy, consistency, and practical value. Serve as the main technical point of contact for penetration testing activities, working with client stakeholders, security teams, development teams, DevOps, infrastructure teams, and compliance teams. Facilitate vulnerability walkthroughs, risk clarification sessions, remediation discussions, and retesting alignment with relevant stakeholders. Support estimation, planning, status tracking, issue escalation, and delivery reporting for security testing activities. Contribute to improving security testing processes, reporting templates, testing checklists, knowledge sharing, and reusable testing practices. Support regulatory, audit, and compliance requirements by providing security testing evidence, reports, remediation status, and technical clarification when needed.

Negotiation

View details