About this role
Job Summary: The Senior AWS DevSecOps Engineer is responsible for embedding security controls throughout the Software Development Lifecycle (SDLC) and ensuring secure deployment of workloads across AWS cloud environments. This role supports cloud migration and cloud-native deployments by implementing Shift-Left Security practices, conducting Infrastructure-as-Code (IaC) security reviews, automated security assessment by assessing security findings, validating compliance controls, and driving remediation efforts in collaboration with DevOps teams. In addition, the role acts as the primary security advisor for cloud engineering teams, ensuring that AWS workloads, CI/CD pipelines, and deployment processes comply with security standards, compliance requirements, cloud security compliance frameworks and organizational governance requirements. Key Responsibilities: Shift-Left Security · Embed security controls throughout the development and deployment lifecycle. · Govern security implementation within GitLab. · Review and assess CI/CD pipelines to ensure security gates are enforced. · Conducting Terraform Infrastructure-as-Code (IaC) security reviews · Integrate security validation activities into the deployment process. · Promote secure-by-design and secure-by-default principles. · Review software delivery processes and identify opportunities for security improvements. . Terraform IaC Security Review · Conduct secure code reviews for Terraform Infrastructure-as-Code deployments. · Review and analyse generated by IaC scanning tools (Checkov, Terrascan). · Identify excessive IAM permissions and privilege escalation risks. · Assess network exposure and segmentation controls. · Validate encryption-at-rest and encryption-in-transit configurations. · Review logging and monitoring configurations. · Identify security misconfigurations and hardening gaps. · Provide remediation recommendations and validate fixes. AWS Cloud Security Governance · Review AWS architecture and security configurations. · Assess AWS services including: IAM, AWS Config, Security Hub, GuardDuty, CloudTrail, KMS, Secrets Manager, VPC, Security Groups, EC2, S3 · Validate implementation of security best practices. · Review cloud resource configurations against approved security baselines. Vulnerability Management & Open Source Security · Review findings generated by IaC scanning tools (CheckOv, Terrascan). · Assess vulnerabilities identified in third-party libraries and dependencies. · Review CVE alerts and vulnerability exposure. · Perform risk prioritisation and remediation tracking. · Validate remediation effectiveness and closure evidence. · Assess residual risks and recommend compensating controls where required. Security Governance, Compliance & Operational Assurance · Lead cloud security governance across AWS environments by conducting compliance assessments against corporate compliance requirements (Cloudscape, Codescape, AWS Security Best Practices, and internal security standards). · Perform security baseline reviews, AWS Config compliance assessments, and configuration drift monitoring. · Review cloud workload and AMI hardening controls, identify compliance gaps, recommend corrective actions, and support audit and regulatory compliance activities. · Provide security advisory to DevOps teams by analysing security findings, providing remediation recommendations, assessing security deviations, evaluating compensating controls, and documenting risk-based justifications where remediation is not immediately feasible. · Support security operations through any form of significant security risks where necessary. · Ensure security activities are delivered in accordance with project timelines by supporting change management, tracking remediation activities, monitoring security deliverables, conducting go-live readiness reviews, and driving continuous improvement of cloud security governance processes. · Collaborate closely with DevOps Engineers, Cloud Engineers, Architects, Security Teams, Project Managers, and business stakeholders to provide technical guidance, facilitate knowledge transfer, document security standards and remediation outcomes, and strengthen overall cloud security capability within the project and operational teams. Required Skills & Qualifications · 5 years or more of experience in DevSecOps related work · Hands-on experience with: - GitLab and CI/CD pipeline administration - Infrastructure as a Code using Terraform - Familiar with AWS …
What they're looking for
Security ControlsGitCertificationsTerraform
About Ntt Singapore Pte. Ltd.
Industry: Information & communications
Frequently asked questions
What does a Senior Devsecops Engineer at Ntt Singapore Pte. Ltd. do?
Job Summary: The Senior AWS DevSecOps Engineer is responsible for embedding security controls throughout the Software Development Lifecycle (SDLC) and ensuring secure deployment of workloads across AWS cloud environments. This role supports cloud migration and cloud-native deployments by implementin…
What skills does this Senior Devsecops Engineer role need?
Key skills for this role include Security Controls, Git, Certifications, Terraform.
How much does a Senior Devsecops Engineer at Ntt Singapore Pte. Ltd. pay?
This role lists a salary of S$7,000 – S$10,000 per month.
Is this Senior Devsecops Engineer role remote, hybrid, or on-site?
The listing is based in D12 Toa Payoh, Balestier, Serangoon. Check the posting for remote or hybrid options.
How do I apply for this Senior Devsecops Engineer role?
You can apply directly on Ntt Singapore Pte. Ltd.'s careers page. ApplyLah can tailor your résumé and cover letter to this exact role in seconds first.