Capgemini Engineering
DevSecOps Engineer
Singapore, SG
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.
Tailor my resume for this job →hirly's read of this role
- Seniority
- Mid level
- Country
- SG
- Work mode
- On-site / unstated
- First seen by hirly
- 27 Sept 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
About Capgemini
Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.
About the Role
We are looking for an experienced DevSecOps Engineer to own the security, reliability, scalability, and compliance of our cloud and Kubernetes environments, deployment pipelines, and AI workload infrastructure.
In this role, you will be the primary technical owner of our AWS and Kubernetes platform, bridging software development, AI engineering, cybersecurity, governance, and production operations. You will establish secure engineering guardrails, automate repeatable controls, and build resilient platform capabilities that enable teams to deploy and operate Generative AI workloads safely at scale.
Responsibilities
- Cloud Infrastructure & Kubernetes Ownership: Manage and scale our AWS cloud environments and take end-to-end ownership of production-grade Kubernetes on AWS EKS, including cluster architecture, workload deployment, security, upgrades, autoscaling, resilience, observability, and incident troubleshooting.
- AWS Ecosystem Administration: Provision, configure, and manage essential AWS services supporting our applications. This includes managed relational databases (RDS PostgreSQL), search/analytics (OpenSearch), AI services (Bedrock), and networking/load balancing (ELB).
- Network Architecture, Security & Connectivity: Design, operate, and troubleshoot secure AWS network architectures for regulated, multi-account environments. This includes VPC and subnet design, CIDR planning, Transit Gateway routing and route-table segmentation, centralized ingress and egress, AWS Network Firewall and WAF, security groups and network ACLs, private connectivity through VPC endpoints or AWS PrivateLink, DNS resolution, load balancing, and connectivity to shared services or on-premises networks through VPN or Direct Connect. Apply network segmentation and least-privilege principles across production, non-production, management, and shared-service environments.
- Production Reliability, Observability & Resilience: Establish service-level indicators and objectives, dashboards, alerts, logs, metrics, and distributed traces across infrastructure, Kubernetes, applications, and AI workloads. Lead incident response, root-cause analysis, corrective actions, capacity planning, backup and restore testing, and disaster-recovery exercises to meet agreed recovery objectives.
- Infrastructure as Code, CI/CD & Automation: Use Terraform as the primary Infrastructure as Code tool to provision and manage repeatable AWS and Kubernetes environments. Administer and optimise GitLab CI/CD pipelines with automated testing, SAST, DAST, dependency and container scanning, policy checks, approval controls, immutable artefacts, environment promotion, rollback mechanisms, and auditable release records.
- Compliance, Security Engineering & Vulnerability Management: Embed security controls throughout the platform lifecycle, including threat modelling, secure architecture reviews, vulnerability and patch management, penetration testing, hardening, remediation tracking, audit evidence, and technical risk assessments. Work with cybersecurity, governance, product, and project stakeholders to translate government security requirements and enterprise standards into automated, testable controls.
- Identity, Secrets & Software Supply Chain Security: Implement least-privilege IAM, workload identity, privileged-access controls, secrets and certificate management, container image signing and scanning, software bills of materials, dependency governance, and policy enforcement across infrastructure and deployment pipelines. Protect sensitive configuration and credentials, and maintain traceability of changes and releases.
- Vendor Transition: Work closely alongside existing external vendors to map the current architecture, reverse-engineer undocumented configurations, and safely transition infrastructure operations fully in-house.
Requirements
- Experience: Typically 2 to 5+ years of hands-on experience in DevOps, DevSecOps, Cloud Engineering, or a similar role. We welcome candidates with fewer years of experience who can demonstrate strong practical capability, sound engineering fundamentals, and ownership of production systems. Hands-on production experience with Kubernetes and Terraform is mandatory; depth of capability and evidence of impact will be valued over years of service.
- Cloud & Kubernetes: Strong proficiency in AWS infrastructure, together with substantial hands-on experience designing, deploying, securing, operating, troubleshooting, and upgrading production Kubernetes clusters and workloads. Strong experience with AWS EKS and Kubernetes networking is required, including ingress controllers, load balancers, service discovery, network policies, pod and service CIDR planning, and diagnosis of cross-VPC or restricted-egress connectivity issues.
- AWS Networking: Strong knowledge of complex AWS networking in multi-account and regulated environments. Candidates should be able to design and troubleshoot VPCs, subnets, route tables, Transit Gateway attachments and segmentation, overlapping or constrained CIDR ranges, centralized firewalls and egress, VPC endpoints and PrivateLink, Route 53 private DNS, security groups, network ACLs, VPN or Direct Connect connectivity, and traffic flows across application, shared-service, security, and on-premises network zones.
- CI/CD Tools: Solid experience building and maintaining CI/CD pipelines (GitLab preferred).
- Operational Readiness: Proven experience defining service-level objectives, building actionable monitoring and alerting, responding to production incidents, conducting root-cause analysis, managing capacity, and designing and testing backup, restore, and disaster-recovery arrangements.
- Regulated Environments: Experience delivering or operating systems under Singapore Government Commercial Cloud and IM8 requirements, or under comparably stringent regulatory frameworks in sectors such as banking, finance, healthcare, or critical infrastructure. Candidates should understand audit evidence, risk acceptance, segregation of duties, change control, and secure handling of sensitive data.
- Communication & Documentation: Ability to explain complex infrastructure and security decisions to technical and non-technical stakeholders, produce clear architecture diagrams, runbooks, operational procedures, risk assessments, and audit evidence, and work effectively with developers, AI engineers, cybersecurity teams, vendors, and government governance stakeholders.
Bonus Points:
- AI Agent Platforms: Significant hands-on experience deploying and operating agentic AI workloads is a major advantage. Relevant experience includes agent observability and distributed tracing, agent harness engineering, prompt and configuration versioning, evaluation pipelines, secure tool and model connectivity, runtime isolation, rate limiting, failure handling, and platforms such as Amazon Bedrock AgentCore or equivalent technologies.
- Modern AI Workflows: Familiarity with production AI and machine-learning workloads, including model and agent deployment patterns, prompt and configuration management, observability of latency, errors, token usage and cost, protection against unintended data exposure, and operational controls for responsible AI use.
Let's talk about what's in it for you!
Passionate people are Capgemini's Ace of Spad
Similar jobs
- DevSecOps EngineerIBM · Singapore, SingaporeFirst seen 3d ago
- DevSecOps Engineer – Client Identity and Access Management 100% (f/m/d)Juliusbaer · SingaporeFirst seen 3d ago
- DevSecOps EngineerThales · SingaporeFirst seen 6d ago
- DevSecOps Engineer, Senior Associate, Technology ConsultingEY · SGFirst seen 3d ago
- DevSecOps EngineerTruist · Atlanta, GAFirst seen today
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job