DevSecOps Engineer/Lead
LeadOn-site (Jakarta)Salary undisclosed
Required Skills
PythonNode.jsJavaKubernetesDockerTerraformCI/CD
Job Description
As a DevSecOps Engineer, you will bridge the gap between development, operations, and information security. Reporting to the Application Security Lead, you will architect, maintain, and scale security automation across our software development lifecycles (SDLC). Your primary mandate is to shift security left by embedding SAST, DAST, and SCA tools directly into modern CI/CD pipelines, eliminating security bottlenecks and ensuring continuous code compliance.
Key Responsibilities
- Pipeline Security Automation: Integrate and manage static, dynamic, and software composition analysis tools into continuous integration and continuous deployment (CI/CD) pipelines.
- Tooling Optimization: Own, configure, and fine-tune AppSec platforms including Checkmarx, Semgrep, Snyk, and SonarQube to minimize false positives and maximize actionable alerts.
- Automated & Manual DAST: Configure automated dynamic scanners and leverage Burp Suite Professional for targeted security testing on APIs and web services.
- Vulnerability Remediation & Triage: Act as the primary technical point of contact to triage code vulnerabilities, providing clear remediation guidance and proof-of-concept fixes directly to engineering teams.
- Open Source Security (SCA): Utilize Snyk and similar tools to monitor open-source dependencies, license compliance, and third-party software supply chain vulnerabilities.
- Policy Enforcement: Define au
Ready to apply? Optimize your CV for this specific jobAI customizes your experience bullets and increases chances to get hired.