TipsLoker

← Kembali ke Daftar Lowongan

FULL_TIME

DevSecOps Engineer/Lead

Ajaib • Jakarta • Gaji tidak dicantumkan

Lamar di Sumber Asli →


Deskripsi Pekerjaan

As a DevSecOps Engineer, you will act as a link between development, operations, and information security. Reporting to the Application Security Lead, you will design, maintain, and scale security automation across software development lifecycles (SDLC). The main objective is to shift security left by integrating SAST, DAST, and SCA tools directly into modern CI/CD pipelines, removing security bottlenecks and maintaining continuous code compliance. Key Responsibilities: - Pipeline Security Automation: Integrate and manage static, dynamic, and software composition analysis tools into continuous integration and continuous deployment (CI/CD) pipelines. - Tooling Optimization: Own, configure, and fine-tune AppSec platforms including Checkmarx, Semgrep, Snyk, and SonarQube to minimize false positives and maximize actionable alerts. - Automated & Manual DAST: Configure automated dynamic scanners and leverage Burp Suite Professional for targeted security testing on APIs and web services. - Vulnerability Remediation & Triage: Serve as the primary technical point of contact to triage code vulnerabilities, delivering clear remediation guidance and proof-of-concept fixes directly to engineering teams. - Open Source Security (SCA): Use Snyk and similar tools to monitor open-source dependencies, license compliance, and third-party software supply chain vulnerabilities. - Policy Enforcement: Define automated gatekeeping thresholds (e.g., failing builds for critical/high vulnerabilities) within the deployment pipeline based on internal security policies. Requirements: - Experience: 4+ years of experience in DevOps, software engineering, or application security, with at least 2+ years focused exclusively on DevSecOps practices. - Tooling Command: Proven, deep technical proficiency with the following tools: SAST: Checkmarx, Semgrep, SonarQube; SCA & Container Security: Snyk; DAST / Pen-testing: Burp Suite Professional; CI/CD Ecosystems: Extensive experience building automation plugins and pipelines in GitHub Actions, GitLab CI, Jenkins, or Bitbucket Pipelines. - Infrastructure as Code (IaC): Solid understanding of cloud-native infrastructure, containerization (Docker, Kubernetes), and secure IaC deployment (Terraform). - Development Background: Ability to read and understand code snippets across multiple languages (e.g., Python, Java, Go, Node.js). - Certifications: Certifications such as Certified DevSecOps Professional (CDP), Practical DevSecOps (CDEP), or CSSLP are highly preferred. Benefits: Join us as we make magic happen to increase Indonesia's financial inclusion

Ringkasan

Perusahaan
Ajaib
Lokasi
Jakarta
Tipe kerja
FULL_TIME
Gaji
Gaji tidak dicantumkan
Tanggal tayang
15 Jun 2026
Terlihat sejak
30 Sep 2026

Sumber & keterlacakan data

Workable ATS (first-party) — https://apply.workable.com/j/55564DFDFA

Siap melamar? Langsung di sumber asli.Buka Halaman Lamaran
Lamar di Sumber Asli →

Lowongan Terkait Lainnya

FULL_TIME3bln

Offensive Security Engineer/Lead

Ajaib • Jakarta

Gaji tidak dicantumkanLihat Detail →
FULL_TIME4bln

IT Support & Project Manager

Ajaib • Jakarta

Gaji tidak dicantumkanLihat Detail →
FULL_TIME4bln

Application Security Engineer/Lead

Ajaib • Jakarta

Gaji tidak dicantumkanLihat Detail →
FULL_TIME5bln

Security Platform Engineer

Ajaib • Jakarta

Gaji tidak dicantumkanLihat Detail →