Vice President, GT-TSS, Infrastructure Innovation, DevSecOps (Senior DevOps Engineer)
CIMB, Kuala Lumpur, Federal Territory of Kuala Lumpur, Malaysia
Job Purpose
The DevSecOps Engineer is responsible for embedding and maintaining strong security practices within the organization’s DevOps processes to ensure the security, compliance, and operational efficiency of financial applications. This role plays a critical part in strengthening the company’s security posture, with a primary focus on supporting on‑premises environments.
Key Responsibilities
- Deployment and automation activities
- Security integration throughout the CI / CD pipeline
- Project delivery
- Operational support
- Additional tasks as assigned
Detailed Responsibilities
Security IntegrationEmbed security controls and practices within CI / CD pipelines, tools, and processes.
Ensure all deployments and system changes adhere to security and compliance requirements, particularly for financial applications.Deployment & AutomationDevelop, maintain, and improve deployment pipelines with automation and security best practices.
Support and manage deployment activities across on‑premises environments.Vulnerability ManagementPerform vulnerability scanning, remediation tracking, and security patch management.
Work closely with application, infrastructure, and security teams to address security gaps.Operational SupportProvide day‑to‑day support for DevSecOps tools and infrastructure.
Troubleshoot deployment, security, and operational issues promptly.Collaboration & Stakeholder EngagementWork closely with development, infrastructure, security, and audit teams to ensure alignment on security and operational requirements.
Engage with vendors as needed to resolve technical and support issues.Continuous ImprovementContinuously evaluate and recommend improvements to existing DevSecOps processes, tools, and security controls.
Stay current with emerging security trends, tools, and best practices.Compliance & DocumentationEnsure DevSecOps practices comply with internal policies, industry standards, and regulatory requirements.
Maintain clear and comprehensive documentation of configurations, processes, and incident resolutions.Qualifications
Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field.Master’s Degree in a related discipline will be an added advantage.DevOps Tools Certification : Jenkins, GitLab CI / CD, Kubernetes, Docker, or equivalent.Security Certifications : CompTIA Security+, CISSP, or equivalent. Certified DevSecOps Professional or related certification is an advantage.Cloud / Container Certifications : CKA, Docker Certified Associate, or equivalent. ITIL Foundation certification is an advantage.Minimum 5‑8 years of hands‑on experience in a DevOps or DevSecOps role, preferably in financial services or regulated industries.Proven experience building and maintaining CI / CD pipelines with integrated security tools.Experience managing on‑premises infrastructure and deployments.Experience implementing security controls, vulnerability management, and automated security testing.Strong knowledge of configuration management tools (Ansible, Helm, Terraform), containerization platforms (Kubernetes, Docker), security scanning tools (Trivy, SonarQube, Snyk).Experience supporting security audits and ensuring compliance with security policies and regulatory requirements.Core Competencies
Strong problem‑solving skills with the ability to assess security risks and recommend appropriate solutions.Effective cross‑functional team player.Strong verbal and written communication skills.Thorough and precise in managing security configurations, deployments, and compliance documentation.Ability to work in a fast‑paced environment.Proactive in staying updated with the latest DevSecOps trends and emerging tools.About CIMB
With operations that span 15 different markets across the region, CIMB offers a dynamic workplace where you can broaden your experience, hone your capabilities, and prove your resilience. Join us to make a meaningful impact for yourself and the bank.
Employment Details
Seniority Level : Mid‑Senior level
Employment type : Full‑time
Job function : Information Technology
#J-18808-Ljbffr