Loại hình
Toàn thời gian
Hình thức
Tại văn phòng
Cấp bậc
Nhân viên
Ngành nghề
Kỹ thuật / Cơ khí
Mức lương
Thương lượng
Địa điểm
Quận 1, Hồ Chí Minh, Hồ Chí Minh
Tổng quan
- The company is seeking a SecOps Engineer to design, implement, and operate its core security infrastructure and network security, with particular emphasis on securing and hardening the Kubernetes/container platform. This role is both hands-on and strategic: building secure-by-design infrastructure from the ground up before expanding into SOC/DFIR capability as the security baseline matures. The…
- Security Architecture & Infrastructure
- Design and implement Identity & Access Management (IAM/SSO) architecture and Single Sign-On integration across internal applications.
- Design and implement Privileged Access Management (PAM) and Zero Trust Network Access (ZTNA) / identity-aware proxy solutions.
- Design and implement network security architecture, including segmentation, firewalls, VPN, and secure remote access.
- Build infrastructure using Infrastructure-as-Code (Terraform, Ansible) and version-controlled configuration where applicable.
- Platform & Container Security
- Support the hardening of the company's Kubernetes platform: RBAC design, network policy, workload security baseline, secrets management.
- Contribute to the rollout of Policy-as-Code (e.g., Kyverno, OPA) for cluster governance.
- Collaborate with the current Cluster Admin to reduce single-point-of-failure risk and support knowledge transfer / documentation.
- SOC Development & Operations
- Support the design, implementation, and day-to-day operation of the company's SOC capabilities (SIEM, EDR, log management, monitoring pipelines).
- Contribute to detection rule and alert logic development as SOC capability is built out.
- Threat Detection, Response & DFIR
- Participate in security event investigation, containment, and remediation activities.
- Contribute to DFIR playbooks, escalation paths, and evidence-handling procedures.
- Continuous Improvement & Collaboration
- Assist in tabletop exercises and simulations to validate incident response readiness.
- Collaborate with IT, InfraOps, AppSec, and Red Team functions to close security gaps.
- Document architecture decisions, runbooks, and lessons learned.
- Contribute to security policies, standards, and compliance initiatives (ISO 27001, etc.) incollaboration with the GRC team.
- Your Skills and Experience
- We are looking for a highly motivated person with:
- 2-3+ years of experience in security engineering, infrastructure/platform engineering, SRE, or DevSecOps.
- Hands-on production experience operating Kubernetes — RBAC design and troubleshooting, network policy, workload/container security fundamentals.
- Practical experience designing or implementing at least one of: IAM/SSO (e.g., Keycloak, Okta, Azure AD), PAM, ZTNA / identity-aware proxy, or network security architecture (firewall, segmentation, VPN).
- Strong Linux system administration and scripting/automation skills (Python, Bash, PowerShell, or similar).
- Familiarity with Infrastructure-as-Code and/or GitOps concepts (Terraform, Ansible, ArgoCD/Flux, or equivalent).
- A proactive attitude & the ability to think outside of the box.
- Works in an organized, structured manner; can-do attitude, gets things done.
- Excellent communication skills with diverse audiences.
- Strong critical thinking and analytical skills.
- Nice-to-have:
- Experience with SIEM platforms (ELK Stack, Wazuh, Splunk, Graylog) or EDR tools.
- Foundation skills in log analysis, network traffic analysis, or malware analysis.
- Solid understanding of security frameworks (MITRE ATT&CK, NIST CSF, CIS Benchmarks).
- Foundation knowledge in AI integration for security operations.
- English communication.
- Relevant certifications: CKA/CKS, Security+, GCIA, GCIH, or equivalent.
- Why You'll Love Working Here
Quyền lợi
Chế độ thưởngDu lịchĐào tạo
Tóm tắt thông tin từ tin tuyển dụng chính thức. Xem bản gốc ↗
Quan tâm đến vị trí này?
Bạn sẽ được chuyển đến trang ứng tuyển chính thức của nhà tuyển dụng.
Ứng tuyển tại trang chính thức ↗
Đây là doanh nghiệp của bạn?
Nhận quản lý trang, yêu cầu chỉnh sửa hoặc gỡ bỏ
→