Role Purpose :
Embed security, compliance, and automation into build and release processes so teams can ship fast and safely across all K3 brands and divisions.
Key Responsibilities :
- Implement CI / CD templates with SAST / DAST / SCA and container scanning
- Enforce secrets management (OIDC to Key Vault, no long-lived credentials)
- Define and monitor policy gates for secure code
- Build SBOM generation, image signing, and provenance
- Automate compliance evidence and deployment checklists
Profile :
3+ years in DevOps / DevSecOps with GitHub Actions or Azure DevOpsHands-on with CodeQL / OWASP ZAP / Snyk / Trivy / CheckovDocker / Kubernetes fundamentals and scripting skillsTrack record of reducing vulnerability backlog and failed deploymentsExperience with supply chain security (Sigstore / cosign)You will be a Malay National to be consideredSuccess Measures :
90%+ repos covered by automated security gatesCritical MTTRWhat we offer :
Competitive benefits package included