Vui lòng bật chia sẻ vị trí để Toppy Ai gợi ý những cơ hội việc làm phù hợp nhất dành riêng cho bạn
100% tin đăng tải trên TopCV được cung cấp bởi các Nhà tuyển dụng đã được xác thực thông tin.
Job Details
Job Description
Platform & DevOps — the core of the job
- Build, operate and troubleshoot CI/CD pipelines across multiple .NET services, Azure Functions and a React front end; keep daily pipeline health green and unblock failed builds fast.
- Provision and manage Azure resources — App Service, Functions, Storage, Azure SQL, Service Bus, Redis, AI Search / Azure OpenAI, VMSS and container workloads - preferably through Infrastructure as Code.
- Own environment configuration, service connections, agent pools, build/release branch policies and deployment approvals.
- Manage identity and access: Entra ID app registrations, service principals, managed identities, RBAC, JIT/PIM elevation; review and clean up stale permissions on a schedule.
- Rotate secrets and certificates on schedule; move credentials into Key Vault and eliminate local / shared-key auth.
- Monitor platform health, availability and cost: Application Insights, Log Analytics / KQL, alert rules, budgets; respond to and drive incidents to resolution.
- Support developers day to day — grant deployment permissions, provision resources, triage DevOps requests — and document runbooks, FAQs and technical guidance.
- Plan and execute infrastructure lifecycle work: decommissioning, platform and runtime upgrades, migrations.
Security & compliance engineering — what makes this role different
- Drive security action items to closure: CVE and dependency vulnerability remediation, OS and runtime patching, and cloud-security recommendations (target: secure score ≥ 95%).
- Remediate static-analysis findings with the dev team — e.g. SSRF, disabled certificate validation, credential leaks — not just file them as bugs.
- Harden cloud posture: disable public network access, enforce private endpoints and end-to-end TLS, disable local auth on PaaS resources, manage IP / service tags, apply least privilege.
- Prepare and shepherd security design reviews and threat models for each product; run reviewer feedback rounds through to approval and keep due dates from slipping.
- Run annual assessments — security, privacy, accessibility, business continuity / DR — and keep the service registry, asset inventory and subscription classification accurate.
- Support Responsible AI reviews for AI features: document AI use cases and changes, coordinate harm testing (harmful content, jailbreak / prompt injection, groundedness), and record risks and mitigations.
- Enforce supply-chain controls in release pipelines: SBOM generation, approved package feeds, production-branch change management, code signing and anti malware gates.
- Report compliance status weekly to engineering and program management; forecast due dates, negotiate extensions and escalate blockers early.
Ways of working
- Participate in sprint planning; break security and compliance findings into actionable stories and tasks in Azure DevOps.
- Automate repetitive ops and compliance work with scripts, pipelines and AI / agent tooling. The team is moving from DevOps toward AIOps — our stated goal is for recurring SFI / S360 compliance tickets to be triaged, remediated and closed by agents, with humans only at approval gates. You will help build that
Candidate Requirements
Must-Have Skills
- DevOps capability is required — and the years must be DevOps years. We are hiring an engineer who builds and automates, not an operator who only follows checklists. A mixed background is welcome (e.g. 3 years software development + 3 years DevOps), but time spent purely in software development does not substitute for the DevOps requirement.
- Azure, hands-on: App Service, Azure Functions, Storage, Key Vault, Service Bus, Azure SQL, networking (VNet, Private Endpoint, NSG, firewall), Entra ID / RBAC / managed identity.
- CI/CD: strong Azure DevOps Pipelines (YAML); plus any of GitHub Actions, Jenkins, GitLab CI.
- Infrastructure as Code: Bicep, ARM templates or Terraform (Ansible a plus).
- Containerization & orchestration: Docker; Kubernetes / Helm fundamentals.
- Scripting & automation: PowerShell and/or Python, plus Bash. You must be able to write automation, not only click through portals.
- Application security fundamentals: OWASP Top 10, threat modeling (e.g. STRIDE), SAST / DAST / SCA concepts, CVE triage and patching, secrets management, least privilege.
- Observability: Application Insights, Log Analytics / KQL, alerting, basic incident response.
- Git and branch / release governance.
- Working English — you will read Microsoft security standards, write status updates, and work directly with reviewers and program managers
Nice-to-Have — AI & automation engineering
- Optional — but this is where we are heading, and it is the biggest differentiator in this hire. Compliance work today is highly repetitive: the same classes of S360 / SFI action items arrive every week and are handled by hand. Our goal is for an agent to do that work, and for delivery itself to run as an automated pipeline with humans only at approval gates.
- Agentic / AI-assisted automation — Azure OpenAI or equivalent LLM APIs, prompt and context engineering, agent frameworks (Semantic Kernel, AutoGen, LangChain, MCP), retrieval-augmented generation.
- Ticket-driven auto-remediation — an agent that reads a security or compliance action item (S360 / SFI / IcM), classifies it, gathers the evidence, proposes or applies the fix, and closes the loop — instead of an engineer repeating it every day.
- End-to-end delivery automation — from ADO work item → requirement / design → implementation → pull request → automated gates (code-quality / SAST, unit + integration tests, QA and acceptance gate, security and compliance gate) → release notes and deployment, with human approval only where it genuinely matters.
- Test automation that feeds those gates — unit, integration and E2E automation (e.g. Playwright), coverage thresholds and quality gates wired directly into pipelines.
- Practical experience with GitHub Copilot / Copilot Studio / Power Automate, MCP servers, or custom agents that call Azure DevOps and Azure APIs.
- The instinct we look for: if you did it by hand twice, you automate it the third time.
Nice-to-Have — Microsoft internal tools
- Optional. Nothing in this section is required — we will train you. A strong DevOps engineer typically picks these up within the first 2–3 months
- S360 / Service Tree — service registration, subscription Production vs Non Production classification, action-item dashboards.
- SFI (Secure Future Initiative) — security wave action items and remediation tracking.
- SDL / OneTrIP — SDL review, Privacy review, Responsible AI release assessment, Accessibility (ACE), BCDR Manager.
- 1ES Pipeline Templates, CodeQL, CredScan, BinSkim, Component Governance, CFS package feeds.
- Microsoft Defender for Cloud, AzTS, MISE, IcM.
- Responsible AI evaluation practices; GDPR / ISO 27001 / SOC 2 awareness.
- Certifications: AZ-400, AZ-500, SC-100.
Qualifications
- Bachelor's degree in Computer Science, Information Technology, Information Security or equivalent practical experience.
- 3+ years of DevOps experience is required — in a DevOps / Cloud Engineering / SRE / DevSecOps role, including hands-on Azure. Time spent purely in software development does not count toward this.
- Ownership mindset — you chase items to closure across teams, vendors and time zones, and you raise risk before it becomes a missed deadline.
- Comfortable being a single point of contact: communicating clear status to managers and working with external security reviewers.
- Strong problem-solving, documentation and cross-team communication skills.
Benefits
- Competitive Salary (negotiable)
- Salary at 100% during the probationary period
- 90% contribution of the gross salary to social insurance
- 20 days leave (12 days of annual leave and 8 days of sick leave)
- Annual health check up
- Full working equipment will be provided
- Activities: Birthday party, Employee engagement activities
Address and Time work
Location
- Hồ Chí Minh: Vista Building, 19 Tan Cang St.,, Phường Thạnh Mỹ Tây (Phường Thạnh Mỹ Tây thuộc quận Bình Thạnh cũ)
Work Schedule
- Thứ 2 - Thứ 6 (từ 09:00 đến 18:00)
How to Apply
- Ứng viên nộp hồ sơ trực tuyến bằng cách bấm Ứng tuyển ngay dưới đây.
Hạn ứng tuyển: 30/11/2026
Việc làm liên quan
Thông tin chung
Dưới đây là những dấu hiệu của các tổ chức, cá nhân tuyển dụng không minh bạch:
- Kiểm tra thông tin về công ty, việc làm trước khi ứng tuyển
- Báo cáo tin tuyển dụng với TopCV thông qua nút "Báo cáo tin tuyển dụng" để được hỗ trợ và giúp các ứng viên khác tránh được rủi ro
-
Hoặc liên hệ với TopCV thông qua kênh hỗ trợ ứng viên của TopCV:
Email: hotro@topcv.vn
Hotline: 1900 068 889 | Nhánh 2
Tìm hiểu thêm kinh nghiệm phòng tránh lừa đảo tại đây
Cơ hội tiếp cận việc làm đa ngành nghề với chế độ đãi ngộ hấp dẫn
Trước sự phát triển vượt bậc của nền kinh tế, rất nhiều ngành nghề trở nên khan hiếm nhân lực hoặc thiếu nhân lực giỏi. Vì vậy, hầu hết các trường Đại học đều liên kết với các công ty, doanh nghiệp, cơ quan để tạo cơ hội cho các bạn sinh viên được học tập, rèn luyện bản thân và làm quen với môi trường làm việc từ sớm. Trong danh sách việc làm trên đây, TopCV mang đến cho bạn những cơ hội việc làm tại những môi trường làm việc năng động, chuyên nghiệp.
Vậy tại sao nên tìm việc làm tại TopCV?
Việc làm Chất lượng
- Hàng ngàn tin tuyển dụng chất lượng cao được cập nhật thường xuyên để đáp ứng nhu cầu tìm việc của ứng viên.
- Hệ thống thông minh tự động gợi ý các công việc phù hợp theo CV của bạn.
Công cụ viết CV đẹp Miễn phí
- Nhiều mẫu CV đẹp, phù hợp nhu cầu ứng tuyển các vị trí khác nhau.
- Tương tác trực quan, dễ dàng chỉnh sửa thông tin, tạo CV online nhanh chóng trong vòng 5 phút.
Hỗ trợ Người tìm việc
- Nhà tuyển dụng chủ động tìm kiếm và liên hệ với bạn qua hệ thống kết nối ứng viên thông minh.
- Báo cáo chi tiết Nhà tuyển dụng đã xem CV và gửi offer tới bạn.
Nhanh tay tạo CV và ứng tuyển việc làm Hà Nội, việc làm TP.HCM cùng nhiều cơ hội việc làm tại các tỉnh, thành khác trên TopCV. Hãy truy cập chuyên trang việc làm của TopV để khám phá các việc làm mới cập nhật trên nền tảng.
