Zorky CRMZorky CRM
EN|RU
@termdocs
← All jobs

DevSecOps / Cloud Security Engineer (Salary up to 80K)

leadofficeBangkok, Thailand, THScore 65/100today
Market insights
📊 Security: salaries and demand on the market
Stack
clouddevsecopsawsdevopsgcpgluepythonterraform
Apply
Upload your CV — we will connect you with the employer directly through our pool.
Send your CV →
Description
Role Overview This is a builder-operator position requiring a combination of technical engineering and operational excellence. Success in this role is defined by a fully managed and secured endpoint environment, the implementation of short-lived credentialing for engineering workflows, and the establishment of robust monitoring and alerting systems. You will ensure that ISO 27001 controls are integrated into daily operations, facilitating efficient evidence collection for audits. Working alongside external security partners and our internal DevOps team, you will serve as the primary technical lead for security implementation. Key Responsibilities Endpoint Security Management — Direct the deployment and optimization of the security stack across the Mac and Windows fleet. Manage MDM baselines, EDR configuration, and the triage of escalations from managed detection services. Cloud Security Operations — Maintain least-privilege IAM principles across AWS and GCP environments. Implement SSO, hardware-based MFA, and manage service account hygiene, secrets, and cloud governance guardrails. Detection Engineering — Centralize telemetry from cloud audit logs, endpoints, and networks. Develop and maintain high-fidelity alerting for critical security events, including unauthorized IAM changes and anomalous data egress. Incident Response — Serve as the primary responder for security incidents. Conduct investigations, execute containment strategies, and produce comprehensive post-incident reviews while maintaining updated runbooks. ISMS Operations — Operationalize ISO 27001 controls through automation. Facilitate evidence collection, conduct periodic access reviews, and manage corrective actions to support internal and external audits. Security SDLC Integration — Collaborate with engineering teams to integrate security into the development lifecycle. Implement secret scanning, dependency analysis, and conduct security reviews for high-risk architectural changes. Security Culture & Advocacy — Lead security awareness initiatives and phishing simulations. Act as a subject matter expert and accessible resource for security-related inquiries across the organization. What We're Looking For Required: 3+ years hands-on security or DevOps/infrastructure experience with meaningful security ownership — title matters less than what you've operated Working proficiency with at least one major cloud (AWS or GCP): IAM, audit logging, and security tooling (GuardDuty, Security Command Center, or equivalents) Experience deploying or administering endpoint management/EDR tooling across a fleet (any of: Intune, Jamf, Kandji, CrowdStrike, SentinelOne, Defender) Scripting ability for automation (Python, Bash, or PowerShell) — enough to glue systems together and automate evidence collection You can investigate an incident: read logs, build a timeline, distinguish evidence from assumption, and write it up clearly Thai and English working proficiency Nice to have ISO 27001 exposure from the inside — you've lived through an audit, owned controls, or closed nonconformities PDPA familiarity, or GDPR experience that translates Experience at a SaaS or fintech company Infrastructure-as-code experience (Terraform) for codifying security baselines Certifications like AWS Security Specialty, ISO 27001 LA/LI, GIAC, or CISSP — valued, never required Benefits Competitive salary and benefits package Relocation support and flexible work hours. 45 days a year work from anywhere policy Collaborative and friendly work environment Comprehensive training and mentorship program to help you grow your skills and advance your career Opportunities to work on cutting-edge technologies and have an impact on the future of the industry Opportunity for professional growth in a dynamic environment. Location: BKK BangRak Office (MRT Samyan or BTS Saladaeng)
Employer contacts (email/phone/telegram) are hidden from the public preview — send your CV, and we will connect you directly.
Urgent question? Message @termdocs