Loại hình
Toàn thời gian
Hình thức
Tại văn phòng
Cấp bậc
Nhân viên
Ngành nghề
Kỹ thuật / Cơ khí
Mức lương
Thương lượng
Địa điểm
Hồ Chí Minh
Tổng quan
- We are seeking an AppSec/DevSecOps Engineer to help
- establish and mature our application security and secure development practices.
- This role will initially focus on standardizing our DevOps pipelines and
- progressively integrate security into every stage of the software lifecycle. The
- engineer will support secure software design, application security testing, and
- developer enablement programs, with the long-term goal of leading our AppSec
- capability.
- DevOps Standardization: Streamline and standardize the
- company’s CI/CD pipelines for cybersecurity projects, preparing the foundation
- for DevSecOps integration.
- Secure SDLC Integration: Embed security controls and checks
- into software development workflows, from design to deployment.
- Application Security Testing: Implement and maintain SAST
- DAST, SCA, and other testing tools within pipelines; triage and coordinate
- fixes with developers.
- Developer Training & Security Champions: Deliver secure
- coding training, support Security Champions program, and promote security awareness among
- developers.
- Security by Design: Collaborate with architects and product
- teams to ensure applications are designed with security principles in mind
- (Threat Modeling, Secure Design Review, Security Requirement).
- Framework & Maturity Models: Contribute to the adoption
- of industry standards and frameworks such as OWASP SAMM for measuring and
- improving software assurance maturity.
- Continuous Improvement: Proactively recommend enhancements
- to DevSecOps tools, processes, and policies to improve resilience and
- efficiency.
Yêu cầu
- 2-3+ years of experience with DevOps practices (CI/CD
- containerization, cloud-native deployment).
- Experience with DevSecOps integration in modern pipelines
- (GitLab CI, Jenkins, GitHub Actions, etc.).
- Familiarity with application security testing tools (SAST
- DAST, SCA, dependency scanning).
- Knowledge of secure software development practices (threat
- modeling, secure design principles, OWASP Top 10).
- Strong scripting/automation skills (Python, Bash, or
- similar).
- Excellent collaboration and communication skills, with the
- ability to work closely with developers, architects, and operations teams.
- A proactive attitude & the ability to think outside of
- the box
- Works in an organised, structured manner
- Can do attitude, gets things done
- Excellent communication skills with diverse audiences
- Strong critical thinking and analytical skills
- Exposure to security frameworks such as OWASP SAMM, BSIMM
- or NIST SSDF.
- Experience delivering developer training or mentoring
- Security Champions.
- Familiarity with infrastructure as code security (Terraform
- Kubernetes, Helm).
- Cloud security knowledge (AWS, Azure, GCP).
- English communication.
- Benefit
- Annual bonus: 2 - 3 months under minimum
- KPI requirement
- Fast promotion opportunities based on
- personal ability
- Work in a dynamic, open, creative environment
- Regular training, company team building
- birthday bonus
- About Concung.com
- Working time: 8:30 - 17:30 Monday - Friday
- Working place: 5th Floor, Con Cưng Super
- Center, 09 Nguyen Trai Street, Ben Thanh Ward, Dist. 1, HCMC
- Chia sẻ:
Quyền lợi
Chế độ thưởngDu lịchĐào tạo
Tóm tắt thông tin từ tin tuyển dụng chính thức. Xem bản gốc ↗
Quan tâm đến vị trí này?
Bạn sẽ được chuyển đến trang ứng tuyển chính thức của nhà tuyển dụng.
Ứng tuyển tại trang chính thức ↗
Đây là doanh nghiệp của bạn?
Nhận quản lý trang, yêu cầu chỉnh sửa hoặc gỡ bỏ
→