Company Logo

DevSecOps Engineer | IIOT

Rp37,000,000 - 44,000,000/Month
Full-Time · Hybrid
Minimum Bachelor’s Degree
5 - 10 years of experience

Job Requirements

Hybrid
5 - 10 years of experience
Minimum Bachelor’s Degree

Skills

Ansible

Docker

Microsoft Azure

Jenkins

CI/CD

Microsoft Office

Kubernetes

Teamwork

Amazon Web Services (AWS)

DevOps

Job Benefits

Career Path

Perform Bonus

hybrid working

This job post is managed by

JN
John Nguyen

Job description for DevSecOps Engineer | IIOT at REC Talents Co.Ltd

SUMMARY

🌍 Client: Singapore company

📍 Open to candidates: Vietnam & Indonesia

💼 Salary: SGD $2,700 - $3,200 (sign contractor, no SHUI)

🗣 English: Good at 4 skills (must)

🚀 Working type:

- Fulltime Remote at Singapore official time, then become Hybrid when we open office.

- Employees are not permitted to take other part-time jobs or other consulting jobs while they work for us.

- Expect to travel for occasional short business trips (APAC)

THE ROLE

We're looking for an engineer who wants to own security and developer platforms end-to-end, not just maintain them. You'll report directly to the CTO and be the first person accountable for how we build, ship, and secure our platform, from cloud infrastructure to IoT devices deployed at client sites.

Who You Are

• You tinker for fun. You run a homelab, self-host your own services, or have a Raspberry Pi doing something in a drawer. You break things at home so you know how to fix them at work.

• You sweat the details. An open port, an over-permissioned service account, or an unpinned dependency bothers you until it's fixed.

• You're pragmatic about security. You understand that a startup needs to ship to survive. You know the difference between a risk that blocks a release and one that goes on the backlog with a deadline, and you can explain that choice to the people making it.

• You see compliance as a way to win deals. ISO 27001 and SOC 2 help us close enterprise clients. You want to meet them with as little friction for developers as possible, not by piling on process.

• You own outcomes, not tickets. When something is yours, you see it through: shipped, documented, and handed over cleanly. You don't wait to be told what's next.

• You have something to prove. You're early in your career but ready for more responsibility than your current role gives you, and you want a place where your work is visible.

• You make developers' lives easier. You'd rather build a guardrail that makes the secure path the easy path than a gate that says no.

• You communicate clearly. You can explain a vulnerability to a developer, a risk to the CTO, and our security posture to a client's IT team, and adjust how you say it for each.

• You're comfortable working remotely. You write things down, keep people updated without being asked, and get unblocked on your own.

• You're curious about the physical world. Sensors on industrial machines, gateways on factory floors, and data flowing from a motor bearing to the cloud sound interesting to you, not intimidating.

KEY RESPONSIBILITIES

Platform & Developer Tooling

• Own and improve CI/CD pipelines (GitHub Actions) so developers can ship quickly and safely.

• Manage and evolve cloud infrastructure on GCP and Azure using Terraform, Docker, and Kubernetes.

• Build internal tooling and self-service workflows that reduce operational load on the development team.

• Improve build speed, environment reliability, and deployment consistency across products.

• Maintain infrastructure documentation, runbooks, and deployment standards

Security & Compliance Ownership

• Own the technical side of our ISO 27001, SOC 2, and CSA Cyber Trust compliance programs.

• Implement and maintain security controls: identity and access management, secrets management, logging, network security, and data protection.

• Embed security into the development lifecycle through SAST, dependency, secret, and container scanning in CI.

• Prepare the organisation for external VAPT engagements and make sure systems meet the consultants' standards.

• Triage, prioritise, and drive remediation of VAPT and scanner findings with the development team.

• Automate compliance evidence collection so audits don't disrupt feature work

• Maintain security policies, risk registers, and procedures together with management.

IoT & Edge Device Security

• Make sure IoT sensors, gateways, and edge devices meet our security and compliance standards.

• Define and implement secure practices for device identity, certificate management, firmware and OTA updates, and device-to-cloud communication.

• Review the security of edge deployments at client sites together with IoT Engineers and Solution Architects.

Test Automation & Quality Engineering

• Build and maintain automated test pipelines, test environments, and quality gates in CI.

• Work with QA to increase automated test coverage and reduce manual testing bottlenecks.

• Improve test reliability and speed, including managing flaky tests and ephemeral test environments.

Enterprise Security Advisory

• Complete enterprise security questionnaires and vendor assessments from clients

• Represent the company in client security reviews and technical due diligence.

• Support Solution Architects and Sales with security content for tenders and proposals

Cross-Functional Enablement

• Serve as the go-to person for security and infrastructure questions across the team

• Coach developers on secure coding practices and infrastructure best practices

• Explain technical risks and trade-offs clearly to non-technical stakeholders and management

KEY REQUIREMENTS

• 4+ years of experience in a DevOps, DevSecOps, Platform, or SRE role

• Familiarity with both GCP and Azure, with hands-on production experience in at least one

• Production experience with Terraform, Docker, and Kubernetes

• Experience with GitHub Actions and at least one other open-source CI/CD tool (e.g., GitLab CI, Jenkins, Argo CD, Tekton)

• Proficiency in Python and TypeScript

• Hands-on experience integrating security tooling into CI/CD pipelines (SAST, SCA, secret scanning, container scanning)

• Direct involvement in at least one security compliance audit (ISO 27001, SOC 2, or equivalent) or in remediating VAPT findings

• Solid understanding of IAM, secrets management, network security, and cloud security fundamentals

• Clear written and verbal communication, including the ability to explain security risks to non-technical stakeholders

• A track record of ownership: you have built, taken over, or fixed something end-to-end

• Able to work independently and asynchronously in a remote setup

• Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience

Bonus Requirements

IoT & Edge Security

• Experience securing IoT devices, gateways, or edge deployments

• Familiarity with device identity (X.509 certificates), secure boot, and OTA update mechanisms

• Experience with MQTT over TLS or other secure device-to-cloud protocols

• Knowledge of IEC 62443, ETSI EN 303 645, or Singapore's Cybersecurity Labelling Scheme (CLS)

• Experience with lightweight Kubernetes (e.g., k3s) or other edge orchestration

Compliance & Governance

• Experience leading or heavily supporting an ISO 27001 or SOC 2 certification

• Familiarity with compliance automation platforms (e.g., Vanta, Drata)

• Experience writing security policies and procedures

• Experience answering enterprise security questionnaires

Security Engineering

• Threat modelling for cloud and IoT systems

• Experience with cloud security posture tools (Microsoft Defender for Cloud, Google Security Command Center)

• Experience with SIEM, log monitoring, and incident response

Test Automation

• Experience with test frameworks such as pytest, Playwright, or Cypress

• Experience building test environments and quality gates in CI

Observability

• Experience with Prometheus, Grafana, OpenTelemetry, or similar tools

Additional Skills

• Go or Bash scripting

• Experience in industrial, OT, or manufacturing environments

• Experience working in B2B SaaS serving enterprise clients

Certifications

• CKA or CKS (Certified Kubernetes Administrator / Security Specialist)

• Google Professional Cloud Security Engineer or Microsoft Azure Security Engineer (AZ-500)

• HashiCorp Terraform Associate

• CompTIA Security+

• ISO 27001 Lead Implementer

• OSCP (useful for understanding VAPT findings, not required)

About the company
REC Talents Co.Ltd
Information Technology and Services
11 - 50 employees

Global Headhunt Service for APAC Market

Vision: To be the benchmark of trust and excellence in APAC’s executive search and recruitment industry.

Mission: Connecting exceptional talent with visionary companies to build thriving teams across the APAC market.

Office address

85 Tan Cang Street, Binh Thanh District, HCMC, Vietnam

Glints Safety Tips

Legitimate employers won’t ask for contact Telegram or any kind of top-ups or payment. Do not provide your messaging app contacts, bank details, or credit card information.

Learn More

Similar jobs for you
Contract
5–10 years
Minimum Bachelor’s Degree
PT Sigma Global Teknologi

DevOps Engineer

Rp 10-15Mio
Full-Time
3–5 years
Minimum Bachelor’s Degree
PT Mau Kerja Indonesia

Head of DevOps

Not Disclosed
Full-Time
10+ years
Minimum Bachelor’s Degree
PT Global Loket Sejahtera
Full-Time
5–10 years
Minimum Bachelor’s Degree
OneTrade
Full-Time
3–5 years
Minimum Bachelor’s Degree
PT. Tenaga Kanggo Indonesia

DevSecOps Engineer | IIOT