DevSecOps Engineer | IIOT

REC Talents Co.LtdQuận Một, Thành phố Hồ Chí Minhglintsoffentliggjort 22.09.2026
Skal:TypeScriptPythonGitAWSAzureGoogle CloudDockerKubernetesCloudDevOpsQA/TestCI/CDSecurityLeadRemoteHybrid

SUMMARY

  • 🌍 Client: Singapore company
  • 📍 Open to candidates: Vietnam & Indonesia
  • 💼 Salary: SGD $2,700 - $3,200 (sign contractor, no SHUI)
  • 🗣 English: Good at 4 skills (must)
  • 🚀 Working type:
  • Fulltime Remote at Singapore official time, then become Hybrid when we open office.
  • Employees are not permitted to take other part-time jobs or other consulting jobs while they work for us.
  • Expect to travel for occasional short business trips (APAC)

THE ROLE

We're looking for an engineer who wants to own security and developer platforms end-to-end, not just maintain them. You'll report directly to the CTO and be the first person accountable for how we build, ship, and secure our platform, from cloud infrastructure to IoT devices deployed at client sites.

Who You Are

  • You tinker for fun. You run a homelab, self-host your own services, or have a Raspberry Pi doing something in a drawer. You break things at home so you know how to fix them at work.
  • You sweat the details. An open port, an over-permissioned service account, or an unpinned dependency bothers you until it's fixed.
  • You're pragmatic about security. You understand that a startup needs to ship to survive. You know the difference between a risk that blocks a release and one that goes on the backlog with a deadline, and you can explain that choice to the people making it.
  • You see compliance as a way to win deals. ISO 27001 and SOC 2 help us close enterprise clients. You want to meet them with as little friction for developers as possible, not by piling on process.
  • You own outcomes, not tickets. When something is yours, you see it through: shipped, documented, and handed over cleanly. You don't wait to be told what's next.
  • You have something to prove. You're early in your career but ready for more responsibility than your current role gives you, and you want a place where your work is visible.
  • You make developers' lives easier. You'd rather build a guardrail that makes the secure path the easy path than a gate that says no.
  • You communicate clearly. You can explain a vulnerability to a developer, a risk to the CTO, and our security posture to a client's IT team, and adjust how you say it for each.
  • You're comfortable working remotely. You write things down, keep people updated without being asked, and get unblocked on your own.
  • You're curious about the physical world. Sensors on industrial machines, gateways on factory floors, and data flowing from a motor bearing to the cloud sound interesting to you, not intimidating.

KEY RESPONSIBILITIES

Platform & Developer Tooling

  • Own and improve CI/CD pipelines (GitHub Actions) so developers can ship quickly and safely.
  • Manage and evolve cloud infrastructure on GCP and Azure using Terraform, Docker, and Kubernetes.
  • Build internal tooling and self-service workflows that reduce operational load on the development team.
  • Improve build speed, environment reliability, and deployment consistency across products.
  • Maintain infrastructure documentation, runbooks, and deployment standards

Security & Compliance Ownership

  • Own the technical side of our ISO 27001, SOC 2, and CSA Cyber Trust compliance programs.
  • Implement and maintain security controls: identity and access management, secrets management, logging, network security, and data protection.
  • Embed security into the development lifecycle through SAST, dependency, secret, and container scanning in CI.
  • Prepare the organisation for external VAPT engagements and make sure systems meet the consultants' standards.
  • Triage, prioritise, and drive remediation of VAPT and scanner findings with the development team.
  • Automate compliance evidence collection so audits don't disrupt feature work
  • Maintain security policies, risk registers, and procedures together with management.

IoT & Edge Device Security

  • Make sure IoT sensors, gateways, and edge devices meet our security and compliance standards.
  • Define and implement secure practices for device identity, certificate management, firmware and OTA updates, and device-to-cloud communication.
  • Review the security of edge deployments at client sites together with IoT Engineers and Solution Architects.

Test Automation & Quality Engineering

  • Build and maintain automated test pipelines, test environments, and quality gates in CI.
  • Work with QA to increase automated test coverage and reduce manual testing bottlenecks.
  • Improve test reliability and speed, including managing flaky tests and ephemeral test environments.

Enterprise Security Advisory

  • Complete enterprise security questionnaires and vendor assessments from clients
  • Represent the company in client security reviews and technical due diligence.
  • Support Solution Architects and Sales with security content for tenders and proposals

Cross-Functional Enablement

  • Serve as the go-to person for security and infrastructure questions across the team
  • Coach developers on secure coding practices and infrastructure best practices
  • Explain technical risks and trade-offs clearly to non-technical stakeholders and management

KEY REQUIREMENTS

  • 4+ years of experience in a DevOps, DevSecOps, Platform, or SRE role
  • Familiarity with both GCP and Azure, with hands-on production experience in at least one
  • Production experience with Terraform, Docker, and Kubernetes
  • Experience with GitHub Actions and at least one other open-source CI/CD tool (e.g., GitLab CI, Jenkins, Argo CD, Tekton)
  • Proficiency in Python and TypeScript
  • Hands-on experience integrating security tooling into CI/CD pipelines (SAST, SCA, secret scanning, container scanning)
  • Direct involvement in at least one security compliance audit (ISO 27001, SOC 2, or equivalent) or in remediating VAPT findings
  • Solid understanding of IAM, secrets management, network security, and cloud security fundamentals
  • Clear written and verbal communication, including the ability to explain security risks to non-technical stakeholders
  • A track record of ownership: you have built, taken over, or fixed something end-to-end
  • Able to work independently and asynchronously in a remote setup
  • Bachelor's degree in Computer Science, Engineering, or a related field, or equivalent practical experience

Bonus Requirements

IoT & Edge Security

  • Experience securing IoT devices, gateways, or edge deployments
  • Familiarity with device identity (X.509 certificates), secure boot, and OTA update mechanisms
  • Experience with MQTT over TLS or other secure device-to-cloud protocols
  • Knowledge of IEC 62443, ETSI EN 303 645, or Singapore's Cybersecurity Labelling Scheme (CLS)
  • Experience with lightweight Kubernetes (e.g., k3s) or other edge orchestration

Compliance & Governance

  • Experience leading or heavily supporting an ISO 27001 or SOC 2 certification
  • Familiarity with compliance automation platforms (e.g., Vanta, Drata)
  • Experience writing security policies and procedures
  • Experience answering enterprise security questionnaires

Security Engineering

  • Threat modelling for cloud and IoT systems
  • Experience with cloud security posture tools (Microsoft Defender for Cloud, Google Security Command Center)
  • Experience with SIEM, log monitoring, and incident response

Test Automation

  • Experience with test frameworks such as pytest, Playwright, or Cypress
  • Experience building test environments and quality gates in CI

Observability

  • Experience with Prometheus, Grafana, OpenTelemetry, or similar tools

Additional Skills

  • Go or Bash scripting
  • Experience in industrial, OT, or manufacturing environments
  • Experience working in B2B SaaS serving enterprise clients

Certifications

  • CKA or CKS (Certified Kubernetes Administrator / Security Specialist)
  • Google Professional Cloud Security Engineer or Microsoft Azure Security Engineer (AZ-500)
  • HashiCorp Terraform Associate
  • CompTIA Security+
  • ISO 27001 Lead Implementer
  • OSCP (useful for understanding VAPT findings, not required)

Skills: Teamwork, Docker, Amazon Web Services (AWS), Jenkins, Ansible, DevOps, CI/CD, Microsoft Office, Kubernetes, Microsoft Azure