Verified current Job

DevSecOps Engineer/Lead

As a DevSecOps Engineer, you will bridge the gap between development, operations, and information security. Reporting to the Application Security Lead, you will architect, maintain, and scale security automation across our softwar...

Job Full source details
Ajaib Jakarta, Indonesia Source published Jun 15, 2026 Verified 1 week ago
✓ 80% verification score · Source: Ajaib Group (workable) · Always confirm final requirements on the original source.
Complete source information imported The available role or programme description, requirements, benefits and source facts were imported from the public official endpoint and formatted for reading.
EmploymentFull Time
CountryIndonesia
DepartmentEngineering
Job functionEngineering
IndustryFinancial Services

Overview

As a DevSecOps Engineer, you will bridge the gap between development, operations, and information security. Reporting to the Application Security Lead, you will architect, maintain, and scale security automation across our software development lifecycles (SDLC). Your primary mandate is to shift security left by embedding SAST, DAST, and SCA tools directly into modern CI/CD pipelines, eliminating security bottlenecks and ensuring continuous code compliance. Key Responsibilities Pipeline Security Automation: Integrate and manage static, dynamic, and software composition analysis tools into continuous integration and continuous deployment (CI/CD) pipelines. Tooling Optimization: Own, configure, and fine-tune AppSec platforms including Checkmarx, Semgrep, Snyk, and SonarQube to minimize false positives and maximize actionable alerts. Automated & Manual DAST: Configure automated dynamic scann

Full job description

Full Job Description

As a DevSecOps Engineer, you will bridge the gap between development, operations, and information security. Reporting to the Application Security Lead, you will architect, maintain, and scale security automation across our software development lifecycles (SDLC). Your primary mandate is to shift security left by embedding SAST, DAST, and SCA tools directly into modern CI/CD pipelines, eliminating security bottlenecks and ensuring continuous code compliance.

Key Responsibilities

  • Pipeline Security Automation: Integrate and manage static, dynamic, and software composition analysis tools into continuous integration and continuous deployment (CI/CD) pipelines.
  • Tooling Optimization: Own, configure, and fine-tune AppSec platforms including Checkmarx, Semgrep, Snyk, and SonarQube to minimize false positives and maximize actionable alerts.
  • Automated & Manual DAST: Configure automated dynamic scanners and leverage Burp Suite Professional for targeted security testing on APIs and web services.
  • Vulnerability Remediation & Triage: Act as the primary technical point of contact to triage code vulnerabilities, providing clear remediation guidance and proof-of-concept fixes directly to engineering teams.
  • Open Source Security (SCA): Utilize Snyk and similar tools to monitor open-source dependencies, license compliance, and third-party software supply chain vulnerabilities.
  • Policy Enforcement: Define automated gatekeeping thresholds (e.g., failing builds for critical/high vulnerabilities) within the deployment pipeline based on internal security policies.

Requirements

  • Experience: 4+ years of experience in DevOps, software engineering, or application security, with at least 2+ years dedicated exclusively to DevSecOps practices.

  • Tooling Command: Proven, deep technical proficiency with the following tools:

  • SAST: Checkmarx, Semgrep, SonarQube

  • SCA & Container Security: Snyk

  • DAST / Pen-testing: Burp Suite Professional

  • CI/CD Ecosystems: Extensive experience building automation plugins and pipelines in GitHub Actions, GitLab CI, Jenkins, or Bitbucket Pipelines.

  • Infrastructure as Code (IaC): Solid understanding of cloud-native infrastructure, containerization (Docker, Kubernetes), and secure IaC deployment (Terraform).

  • Development Background: Ability to read and understand code snippets across multiple languages (e.g., Python, Java, Go, Node.js).

  • Certifications: Certifications such as Certified DevSecOps Professional (CDP), Practical DevSecOps (CDEP), or CSSLP are highly preferred

Benefits

Join us as we make magic happen to increase Indonesia’s financial inclusion!

Qualifications And Requirements

Mid-Senior level

Requirements & qualifications

Mid-Senior level

Tips for this job

Practical Job and Scholarship guidance. These tips do not replace official rules or create new eligibility requirements.

  1. Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
  2. Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
  3. Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
  4. Apply through the original employer or official recruitment destination shown on this page.

Verification notes

Discovered directly from the employer’s public Workable account endpoint with details=true where supported. Public description, responsibilities, requirements and benefits were normalized into complete candidate-facing sections.

Original authoritative source

Job and Scholarship is the discovery and verification layer. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.

Ajaib Group (workable) ↗

Browse current Job and Scholarship listings from Ajaib Group (workable) →

More ways to save

Discover deals, coupons and free courses on our sister site.

Explore DealVorio
Save more with DealVorio: deals, coupons, free courses, apps and books