Senior DevOps Engineer
- Gaji
- Gaji tidak dicantumkan
- Jenis pekerjaan
- Penuh waktu
- Diposting
- Sumber
- Dealls Indonesia (sitemap + page JSON)
Kami akan mengarahkan Anda ke situs tempat lowongan diposting untuk menyelesaikan lamaran.
Deskripsi pekerjaan
Tanggung jawab
- Cloud security posture across our environment — continuous configuration assessment against CIS benchmarks, drift detection, and driving remediation to done rather than to a backlog
- Guardrails as code — SCPs, policy-as-code (OPA/Kyverno), and secure-by-default
- Terraform modules so misconfigurations are prevented, not just reported
- IAM and least-privilege at scale — access reviews, secrets management, key rotation, and killing standing over-permissive access
- Hardening of cloud hosts and servers — golden images, CIS-benchmarked baselines, patch cadence, and bastion/SSH controls
- Employee endpoint hardening (~30% of the role) — MDM, EDR, disk encryption, and OS baselines across the laptop fleet
- Security built into CI/CD and infrastructure automation — everything as code
- Partnering with and leveling up other engineers, making the secure path the easy default instead of a blocker
- Scaling all of the above to millions of users without slowing delivery down
Persyaratan
- Strong Linux system administration
- Infrastructure as code — Terraform (or Ansible/Chef/Puppet)
- Containers and Kubernetes in production
- At least one high-level language: Python, Ruby, or Go, plus comfort writing
shell scripts
- Solid understanding of DNS, TCP/IP, HTTP, TLS, and CDN
- Hands-on with at least one major cloud: AWS, GCP, or Azure
Requirements — Cloud security (required):
- IAM and least-privilege design, not just usage
- CIS benchmarks and host/OS hardening baselines
- Secrets management and encryption at rest and in transit
- Hands-on experience with a Cloud Security Posture Management (CSPM) tool —
Wiz, Prowler, Scout Suite, AWS Security Hub, or GCP Security Command Center
- A preventive, guardrails-as-code mindset over scan-and-ticket
Bonus points:
- Endpoint management experience — Jamf, Intune, or Kandji
- A cloud security certification such as AWS Security Specialty or CKS
- Monitoring/alerting experience — Datadog, Prometheus
- Experience with high-traffic or streaming platforms
- Exposure to compliance frameworks (PCI-DSS, ISO 27001)
- Comfortable using AI/LLM tooling to accelerate IaC, runbooks, and triage —
with sound judgment about handling sensitive data
Referensi: 34407 · Berlaku sampai 10 Oktober 2026