Deskripsi pekerjaan DevSecOps Engineer – Container Security (Project-Based) PT. Citra Multi Services
Role Objective
Responsible for ensuring end-to-end security in containerized environments (Docker, Kubernetes) by integrating security practices into the DevOps (CI/CD) process, while maintaining compliance and continuous risk mitigation.
Key Responsibilities
- Implement security across the container lifecycle (build, ship, run)
- Perform image hardening and vulnerability scanning
- Integrate security tools (SAST, DAST, container scanning) into CI/CD pipelines
- Establish automated security gates in deployment pipelines
- Secure Kubernetes environments (RBAC, network policies, pod security)
- Manage secrets (Vault/KMS) and container registries securely
- Conduct vulnerability assessments and ensure compliance (CIS, OWASP, NIST)
- Monitor security events, analyze logs, and handle incident response
- Collaborate with DevOps/Engineering teams and promote security best practices
Qualifications
- Bachelor’s degree in Computer Science, Engineering, or related field
- 2–3 years of experience in DevOps/DevSecOps
- Hands-on experience with Docker/Podman and Kubernetes/OpenShift
- Familiar with CI/CD tools (GitLab CI, Jenkins, GitHub Actions)
- Experience with security tools (Trivy, Clair, Anchore, SAST/DAST)
- Strong understanding of Linux systems and networking
- Nice to Have
- Experience with Kubernetes security tools (Falco, Kyverno, OPA Gatekeeper)
- Knowledge of secrets management (HashiCorp Vault)
- Familiarity with SIEM/logging tools (ELK, Splunk)
