Deskripsi Pekerjaan
Informasi lengkap tentang posisi dan persyaratan
Ringkasan Yukerja
Lowongan DevSecOps Engineer di Lembaga Pengkajian Pangan, Obat-Obatan Dan Kosmetika Mui kami kurasi dari JobStreet (kategori Kesehatan). Perhatikan lokasi kerja (Bogor, West Java) sebelum melamar. Yukerja.com bukan pemberi kerja — lamaran diproses di situs sumber resmi.
About the role
We are looking for a DevSecOps professional with a background in DevOps or Cloud Security Engineering to join our team. This role focuses on building and maintaining secure, automated infrastructure on Google Cloud Platform (GCP), combining infrastructure management, security implementation, and operational excellence to enable fast, secure application deployments while ensuring compliance with ISO 27001 standards.
Key responsibilities
Build and maintain CI/CD pipelines to ensure automated, fast, and secure application deployments
Install, configure, and maintain physical and virtual servers
Manage cloud architecture and infrastructure, with a strong focus on Google Cloud Platform (GCP)
Manage networking, routing, SSH, and tunneling/VPN protocols to ensure secure and high-performance infrastructure connectivity
Design and implement network security policies, including the configuration of Hardware and Cloud-based Firewalls
Deploy, configure, and monitor centralized security using SIEM Wazuh for threat detection, log analysis, and incident response
Ensure all IT infrastructure, deployments, and server operations are fully compliant with ISO 27001 security standards
Setup and maintain monitoring and logging systems (Prometheus, Grafana, ELK Stack) to track server health and detect security anomalies
Design and execute comprehensive Backup procedures and Disaster Recovery Plans (DRP)
Qualifications
Minimum of 3 years of proven experience as a DevSecOps, DevOps, or Cloud Security Engineer
In-depth knowledge of Linux operating systems (Ubuntu, CentOS, Debian) and fundamental network troubleshooting
Hands-on experience in virtualization management (Proxmox VE) and Cloud Computing, specifically GCP (familiarity with GKE is a strong plus)
Solid experience building and managing CI/CD pipelines (e.g., GitLab CI, GitHub Actions, Jenkins) and working with Containerization technologies (Docker, Kubernetes)
Proficient with Infrastructure as Code (IaC) tools such as Terraform or Ansible
Practical experience configuring Firewalls, SSH, and secure Tunneling/VPN architectures
Experience in managing and configuring SIEM solutions, with mandatory hands-on experience using Wazuh for security posture analysis and threat monitoring
Familiarity with monitoring and logging stacks (Prometheus, Grafana, or ELK Stack)
Strong technical understanding of, or direct involvement in, ISO 27001 security implementations
Proactive, able to work independently, and equipped with excellent problem-solving skills