
DevSecOps Lead
Posted Jul 29

Posted Jul 29
This is a fully remote position, open to applicants in Indonesia.
• Define and spearhead Ajaib’s DevSecOps strategy, roadmap, standards, and operational model.
• Integrate security controls throughout the software development lifecycle.
• Incorporate security testing into CI/CD pipelines across applications, services, and infrastructure.
• Implement and enhance SAST, DAST, software composition analysis, secrets detection, container scanning, and infrastructure-as-code scanning.
• Develop automated security guardrails that assist teams in identifying and resolving issues early.
• Collaborate with engineering and platform teams to enhance the security of build, deployment, and release processes.
• Strengthen security across cloud environments, containers, Kubernetes, APIs, backend services, and internal platforms.
• Establish secure infrastructure-as-code practices and reusable security patterns.
• Enhance identity, access, secrets, keys, and privileged-access controls across engineering environments.
• Define secure configuration baselines for cloud services, containers, workloads, and deployment platforms.
• Automate the identification, prioritization, assignment, remediation tracking, and verification of vulnerabilities.
• Collaborate with application security and engineering teams to minimize false positives and make security findings actionable.
• Support threat modeling, architecture reviews, and security assessments for new systems and platforms.
• Improve logging, monitoring, alerting, and detection across development and production environments.
• Partner with incident response teams to enhance readiness, containment, recovery, and post-incident improvements.
• Evaluate and enhance software supply chain security, including dependencies, artifacts, build systems, and third-party components.
• Define DevSecOps metrics and provide transparent reporting on security coverage, risk, and remediation progress.
• Cultivate security knowledge across engineering teams through documentation, training, tooling, and practical guidance.
• Mentor DevSecOps and security engineers and contribute to the growth of the function as Ajaib scales.
• Extensive experience in DevSecOps, cloud security, platform security, security engineering, or infrastructure security.
• Proven experience leading DevSecOps programs, technical initiatives, or security engineering teams.
• Practical experience in building and securing CI/CD pipelines.
• Strong expertise in cloud security, containers, Kubernetes, infrastructure as code, and modern software delivery practices.
• Experience with security tools such as SAST, DAST, software composition analysis, secrets scanning, container scanning, and infrastructure-as-code scanning.
• Profound understanding of software supply chain security and secure build practices.
• Familiarity with cloud platforms such as AWS, Google Cloud, or Azure.
• Experience with tools such as Terraform, Kubernetes, Docker, GitHub Actions, GitLab CI, Jenkins, or similar technologies.
• Capability to write automation and integrations using languages such as Python, Go, Bash, or JavaScript.
• Strong grasp of identity and access management, secrets management, encryption, key management, and privileged access.
• Experience managing vulnerabilities across applications, cloud environments, infrastructure, and third-party components.
• Knowledge of secure software development practices, threat modeling, and application security principles.
• Ability to translate security requirements into actionable engineering controls and automated workflows.
• Excellent communication and stakeholder management skills.
• Proficient written and spoken English.
• High-impact ownership: influence how security is integrated across Ajaib’s engineering and delivery methods.
• Meaningful technical challenges: secure cloud platforms, CI/CD pipelines, containers, applications, and financial systems.
• Real influence: collaborate directly with engineering and platform teams to enhance how technology is built and operated.
• Security at scale: develop automation and guardrails that safeguard the business as it expands.
• Leadership opportunity: establish DevSecOps standards, mentor engineers, and contribute to building a robust security engineering culture.
• Meaningful mission: assist in protecting customers, investments, personal data, and financial transactions.
DATAGROUP
Ambush
DuoKey
TEKsystems
Get handpicked remote jobs straight to your inbox weekly.