The DevSecOps Engineer (Middle) role is responsible for building and operating YODY's cloud-native infrastructure on AWS, with security and reliability as first-class concerns. You will own the CI/CD pipeline, Kubernetes platform, Infrastructure as Code, and security posture for a high-traffic e-commerce environment serving thousands of concurrent users continuously.
This is a hands-on, build-and-operate position — not a support or monitoring role. You will work directly with the Solution Architect to implement system architecture and report to the Head of Technology & Digital Transformation (HOD). The role is on a fast-track path toward Senior Cloud Platform / Security Engineering.
Responsibilities
1. Platform & Reliability: Operate production EKS workloads, lead incident response, drive SLO/SLI ownership, and perform root cause analysis using observability tools. Use AI-augmented ops (e.g., Datadog Watchdog, AWS DevOps Guru) where they earn their place.
2. CI/CD & Progressive Delivery: Own GitLab CI / GitHub Actions pipelines with embedded security scanning (SAST, SCA, container scan, IaC scan). Manage progressive delivery via ArgoCD using GitOps patterns.
3. Infrastructure as Code: Author and review Terraform modules across environments. Enforce drift detection, multi-environment promotion workflow, and cost governance.
4. Security Posture (DevSecOps Core): Implement and operate AWS-native security controls: IAM least-privilege design, Secrets Manager, GuardDuty, Security Hub, AWS Config. Manage secrets, certificate lifecycle, and vulnerability remediation. Drive PCI-DSS readiness aligned with our e-commerce compliance roadmap.
5. Developer Experience: Maintain dev/staging environments and build self-service platform capabilities so developers can ship safely without ops bottleneck. Support developers in debugging infrastructure-related issues.
6. Data Protection: Own backup, disaster recovery (DR), and data integrity for AWS workloads and the GCP data warehouse (BigQuery, Cloud Storage). Ensure business continuity targets are met.
7. Innovation & Automation: Evaluate and adopt cloud-native tooling. Deliver at least one platform improvement initiative per quarter (security tooling, automation, cost reduction, or developer productivity).
Must-have
- Bachelor's or Associate degree in IT, Computer Science, Software Engineering, or related fields. Self-taught candidates with strong portfolios of cloud-native projects are encouraged to apply.
- 2–3 years of production experience in DevOps or Cloud Engineering roles (not pure System Administration backgrounds).
- Hands-on AWS production experience across: EKS, RDS, S3, IAM, VPC, ALB, CloudWatch, Secrets Manager.
- Production Kubernetes experience on managed clusters (EKS preferred): Helm/Kustomize, ingress controllers, RBAC, network policies, troubleshooting beyond reading pod logs.
- CI/CD ownership using GitLab CI, GitHub Actions, or equivalent. Familiarity with GitOps patterns (ArgoCD or Flux).
- Terraform: comfortable authoring modules, managing remote state, and multi-environment workflows.
- Linux administration on Ubuntu / Amazon Linux 2 or 2023 / Rocky or AlmaLinux.
- Hands-on experience with at least 2 of the following security domains: container/image scanning (Trivy, Snyk, ECR scan); IaC scanning (Checkov, tfsec, terrascan); secrets management (AWS Secrets Manager, HashiCorp Vault); AWS-native security services (GuardDuty, Security Hub, AWS Config).
- Scripting in Bash and Python for automation.
- Observability with Prometheus + Grafana, plus AWS CloudWatch.
- Ability to read and understand technical documentation in English.
Nice-to-have
- Bachelor's or Associate degree in IT, Computer Science, Software Engineering, or related fields. Self-taught candidates with strong portfolios of cloud-native projects are encouraged to apply.
- Familiarity with GCP data platform (BigQuery, Cloud Storage, Cloud IAM) for our data warehouse layer — deep GCP ops expertise is not required.
- Exposure to compliance frameworks relevant to e-commerce: PCI-DSS, ISO 27001, or SOC 2.
- Certifications (any of): AWS Certified Solutions Architect – Associate, CKA (Certified Kubernetes Administrator), Google Cloud Associate Cloud Engineer.
- Service mesh exposure (Istio, Linkerd), policy-as-code (OPA/Gatekeeper).
- Hands-on with AI coding/ops assistants (Claude, Gemini/Antigravity, Codex)
- Comfortable owning incidents end-to-end and working closely with the Solution Architect to realize system architecture.
- A dynamic, open, and inclusive work environment that promotes a culture of learning.
- Trust and empowerment for you to engage with and address real-world challenges from the market.
- A fast-track career development path with competitive compensation.
- Year-end bonuses based on business performance.
- Special policies from YODY (Tet gifts, internal purchase discounts, etc.).
- Full participation in social insurance, health insurance, and unemployment insurance.
- Hồ Chí Minh: VP HCM: Số 495 Nguyễn Thị Thập, Phường Tân Hưng (Quận 7 cũ)
Thứ 2 - Thứ 6 (từ 08:00 đến 17:00)