Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

DevOps Engineer

OPSWAT
CompanyOPSWAT
CategoryEngineering
LocationHo Chi Minh City
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted8 Jun 2022
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
OPSWAT , a global leader in IT, OT , and ICS critical infrastructure cybersecurity, delivers an end-to-end platform that gives public and private sector organizations and enterprises the critical advantage needed to protect their complex networks, secure their devices, and ensure compliance. Over the last 20 years our commitment to innovative technology has earned the trust of more than 1,700 organizations, governments, and institutions globally, solidifying our role in protecting the world’s critical infrastructure and securing our way of life. The Position   Join the infrastructure team behind MDaaS, a real-time malware scanning platform handling 30M+ requests/day, built on AWS, Kubernetes, and event streaming. You'll work in an agile scrum team, owning infrastructure-as-code, CI/CD pipelines, and observability. Security and compliance are first-class requirements, not afterthoughts. What You Will be Doing   Deploy and maintain workloads on EKS via ArgoCD, review GitOps PRs, handle sync failures, approve image updates Write and update Helm charts / Kustomize overlays across dev / staging / prod Triage alerts from Prometheus / Grafana / Coralogix, root cause analysis, resolve or escalate Review and apply Terraform changes: plan, validate, and merge infra PRs ( EKS , MSK , ALB, IAM ) Maintain CI/CD pipelines on Bitbucket Pipelines and GitHub Actions: fix broken builds, integrate security scans Configure and tune KEDA ScaledObjects for Kafka / RabbitMQ consumers Triage CVEs from Blackduck / Trivy reports: prioritize CVSS ≥ 7.0, coordinate patches with dev team Rotate secrets, verify External Secrets Operator sync, enforce no-hardcoded-credentials policy Document infrastructure and application changes for engineers and QA Participate in on-call rotation: incident response, post-mortems, runbook updates Research new tools and technologies to address current pain points and improve system reliability, scalability, and security: evaluate, prototype, and propose adoption when appropriate   What We Need From You   Education & Background BA/ BS in Computer Science, Engineering, or equivalent hands-on experience Soft Skills Strong verbal and written communication in English Self-motivated; works well in a fast-paced, collaborative team Eager to learn new tools and apply them quickly Passionate about solving problems in a principled, elegant way Comfortable both teaching and learning from teammates Cloud & Infra AWS hands-on: EKS , ECR , IAM / IRSA , MSK , S3, ALB, VPC, Security Groups Terraform: write modules, manage remote state, integrate with CI Kubernetes: RBAC , ingress, network policies, HPA , resource tuning: cluster management via Rancher or K9s Helm + Ansible: author charts and playbooks, manage versioning Docker: multi-stage builds, image optimization Linux/Windows systems administration CI/CD & GitOps Bitbucket Pipelines, GitHub Actions, or TeamCity: write and maintain, not just use ArgoCD: sync policy, health checks, rollback PR-based deployments; no direct commits to main/prod Observability Prometheus, Grafana, CloudWatch, Elasticsearch: setup and maintain Structured logging, alert routing, dashboard authoring Security Least privilege: IAM , IRSA , K8s RBAC:  no wildcard permissions Secret management: External Secrets / AWS Secrets Manager, zero hardcoded credentials Supply chain: dependency scanning (Blackduck / Snyk / Trivy), CVE triage by CVSS score Network segmentation: private subnets, Security Groups, ingress/egress control Working knowledge of ISO/ IEC 27001 and SOC 2 Type II: access control, audit trail, change management
HOUSE AD991,236 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →