Senior DevSecOps Engineer
SM Investments
Pasay, National Capital Region, PhilippinesPosted 4 days agoLinkedIn
Setup
On-site
Type
Full-time
Level
Senior
Salary
Not listed
Closes
Open
Skills mentioned
AWSAzureGoogle CloudDockerKubernetesCI/CDGitTerraformFinanceRetail OperationsLegalBanking
Sign up free to tailor my resume for this job Apply on LinkedIn
Members see a match score against their own skills and get a resume + cover letter written for this posting.
About the role
About SM Investments
At SM Investments, we shape sustainable growth stories that move industries and uplift communities. As one of the Philippines’ leading conglomerates, we build opportunities across retail, banking, and property guided by excellence, integrity, and innovation.
Key Responsibilitie
- Automate security controls within CI/CD pipelines (Jenkins, GitLab, Circle
CI, GitHub Actions
- Secure cloud environments (AWS, Azure, GCP) and container platforms (Docker, Kubernetes)
- Integrate security testing tools (SAST, DAST, SCA) such as Snyk, Sonar
Qube, Checkmarx, or Fortify
- Implement Infrastructure as Code (IaC) security using Terraform and Cloud
Formation
- Enforce IAM best practices, RBAC, and federated identity (SAML, OAuth, Cognito)
- Apply security frameworks (ISO 27001, NIST, CIS) and compliance automation
- Perform threat modeling, risk assessments, and vulnerability management
- Secure DevOps toolchains, artifact repositories (JFrog, Nexus), and source control system
- Implement Zero Trust principles and cloud-native security controls
- Maintain audit trails, enforce policies (OPA, AWS Config), and ensure governance compliance
Technical Competencies
- Strong expertise in DevSecOps practices and secure SDLC
- Deep knowledge of cloud and container security
- Hands-on experience with IaC security and automation
- Familiarity with Kubernetes security (RBAC, network policies, secrets management)
- Proficiency in security tools and automation frameworks
- Experience with compliance-as-code tools (Chef In
Spec, Open
SCAP)
Preferred Experience
- Proven experience in DevSecOps within platform engineering environments, building secure and scalable developer platforms
- Hands-on expertise with Terraform, including securing Terraform modules, state management, and IaC pipelines
- Experience designing and securing internal developer platforms (IDPs) or platform-as-a-service (PaaS) environments
- Strong background in automating security controls at scale across cloud-native architectures
- Experience with Cloud Security Posture Management (CSPM) tools such as Prisma Cloud or Dome9
- Exposure to enterprise-grade security architecture and governance frameworks
Sourced from LinkedIn · posted 4 days ago · you apply on the original site