Vice President, GT-TSS, Infrastructure Innovation, DevSecOps
2 days ago
Job Purpose *
The DevSecOps Engineer is responsible for embedding and maintaining strong security practices within the organization's DevOps processes to ensure the security, compliance, and operational efficiency of financial applications. This role plays a critical part in strengthening the company's security posture, with a primary focus on supporting on-premises environments.
The engineer will be actively involved in:
- Deployment and automation activities
- Security integration throughout the CI/CD pipeline
- Project delivery
- Operational support
- Additional tasks as assigned
This position bridges development, security, and operations, providing hands-on support to deliver secure, reliable, and scalable solutions.
Key Responsibilities *
- Security Integration
- Embed security controls and practices within CI/CD pipelines, tools, and processes.
- Ensure all deployments and system changes adhere to security and compliance requirements, particularly for financial applications.
- Deployment & Automation
- Develop, maintain, and improve deployment pipelines with automation and security best practices.
- Support and manage deployment activities across on-premises environments.
- Vulnerability Management
- Perform vulnerability scanning, remediation tracking, and security patch management.
- Work closely with application, infrastructure, and security teams to address security gaps.
- Operational Support
- Provide day-to-day support for DevSecOps tools and infrastructure.
- Troubleshoot deployment, security, and operational issues promptly.
- Collaboration & Stakeholder Engagement
- Work closely with development, infrastructure, security, and audit teams to ensure alignment on security and operational requirements.
- Engage with vendors as needed to resolve technical and support issues.
- Continuous Improvement
- Continuously evaluate and recommend improvements to existing DevSecOps processes, tools, and security controls.
- Stay current with emerging security trends, tools, and best practices.
- Compliance & Documentation
- Ensure DevSecOps practices comply with internal policies, industry standards, and regulatory requirements.
- Maintain clear and comprehensive documentation of configurations, processes, and incident resolutions
Job Specification *
Qualifications (Basic Degree/Diploma etc)
- Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Software Engineering, or a related field.
- A Master's Degree in a related discipline will be an added advantage.
Professional Qualification and/or Regulatory, Licensing requirements
- DevOps Tools Certification: Jenkins, GitLab CI/CD, Kubernetes, Docker, or equivalent.
- Security Certifications:
- CompTIA Security+, Certified Information Systems Security Professional (CISSP), or equivalent.
- Certified DevSecOps Professional, or related security-focused DevOps certifications will be an advantage.
- Cloud/Container Certifications:
- Kubernetes Administrator (CKA), Docker Certified Associate, or equivalent.
- ITIL Foundation certification is an advantage.
Relevant Work Experience
- Minimum 5-8 years of hands-on experience in a DevOps or DevSecOps role, preferably in the financial services or regulated industries.
- Proven experience in:
- Building and maintaining CI/CD pipelines with integrated security tools.
- Managing on-premises infrastructure and deployments.
- Implementing security controls, vulnerability management, and automated security testing.
- Strong working knowledge of:
- Configuration management tools (e.g., Ansible, Helm, Terraform)
- Containerization platforms (e.g., Kubernetes, Docker)
- Security scanning tools (e.g., Trivy, SonarQube, Snyk)
- Experience in supporting security audits and ensuring compliance with security policies and regulatory requirements.
Required Competencies and Skills *
Competencies/Skills
(Essential to succeed in this job)
Technical Competencies
- Strong understanding of DevSecOps principles, methodologies, and best practices.
- Hands-on experience with CI/CD tools (e.g., GitLab CI/CD, Jenkins).
- Proficient in containerization and orchestration using Docker and Kubernetes.
- Solid knowledge of security integration within the software development lifecycle (SDLC), including vulnerability scanning, static and dynamic code analysis, and security automation.
- Familiar with configuration management tools such as Ansible, Helm, or Terraform.
- Competent in managing on-premises infrastructure, with exposure to cloud environments being an added advantage.
- Proficient in using security tools (e.g., Trivy, SonarQube, Snyk, Fortify) for application and infrastructure security assessments.
- Strong scripting skills (e.g., Bash, Python, Groovy) for automation and integration.
- Good understanding of network security, firewalls, and access control principles
Core Competencies
- Strong problem-solving skills with the ability to assess security risks and recommend appropriate solutions.
- Effective cross-functional team player, working closely with development, security, infrastructure, and audit teams.
- Strong verbal and written communication skills to present technical concepts clearly to both technical and non-technical stakeholders.
- Thorough and precise in managing security configurations, deployments, and compliance documentation.
- Ability to work in a fast-paced environment, managing multiple priorities and shifting project demands.
- Proactive in staying updated with the latest DevSecOps trends, security threats, and emerging tools.
- #LI-AZ1
-
Vice President Fund Accounting
2 days ago
Malaysia Ascent Full time**Vice President Fund Accounting** **JOB DESCRIPTION** Headquartered in Singapore, ASCENT Group is an Independent Global Fund Administrator that provides a full range of fund administration services for Alternative funds such as Hedge Funds, Private Equity Funds, Venture Capital, Crypto Funds, VCC, Retail Estate Funds, etc., which include reviewing fund...
-
Assistant Vice President, GT-TSS, Consumer
2 days ago
Malaysia CIMB Group Full time 80,000 - 200,000 per yearDescriptionJob Purpose *The ITIL Lead for Incident & Problem Management is responsible for providing strategic leadership, governance, and continual improvement of IT Service Management (ITSM) processes in alignment with CIMB's Service Management Model and ITIL best practices.This role oversees and drives the effectiveness of Incident and Problem...
-
Assistant Vice President, Gcad
4 days ago
Malaysia CIMB Group Full time**Advisory Assignment** - Responsible to ensure the accuracy and completeness of the information obtained for audit planning purposes via Audit Planning Memorandum. - Analyze data from the data sources / data points as information feeds to micro-risk assessment for all risk factors on annual audit plan - Lead and execute advisory assignments including...
-
Malaysia CIMB Group Full time 900,000 - 1,200,000 per yearDescriptionJob Purpose *Lead and direct the team's daily operations of application system support for eComm systems, CAF system and related ecosystems and ensure that all incidents and problems are managed accordingly within the established standard operating procedures (SOP), stipulated service level agreements (SLAs), CIMB Group's established IT...
-
Assistant Vice President, Risk
2 days ago
Malaysia CIMB Group Full time 80,000 - 200,000 per yearDescription#LI-DA1Key Responsibilities Support risk assessments related to IT resilience, including disaster recovery, high availability and failover mechanismsDefine and monitor key IT resilience risk indicators and controls across critical systems and applicationsEvaluate the effectiveness of business continuity and disaster recovery testing...
-
Malaysia CIMB Group Full time 150,000 - 250,000 per yearDescriptionKey Responsibilities Strategy and Planning Understand the new data needs of different teams in Group Risk and propose solution enhancements that will benefit majority of the data users.Lead and/or participate in key strategic initiatives and focus projects and ensure the implementation is delivered with quality within the stipulated...
-
First Avenue, Petaling Jaya, Malaysia Grab Full time 120,000 - 180,000 per yearCompany Description About Grab and Our WorkplaceGrab is Southeast Asia's leading superapp. From getting your favourite meals delivered to helping you manage your finances and getting around town hassle-free, we've got your back with everything. In Grab, purpose gives us joy and habits build excellence, while harnessing the power of Technology and AI to...
-
Vice President, CCPF
2 days ago
Malaysia CIMB Group Full time 900,000 - 1,200,000 per yearDescriptionJob DescriptionStrategize and develop new or variation of Personal Financing sales and marketing campaigns which is relevant in the personal loan market/industry and work with various stakeholders in CIMB especially the respective sales channelsChampions the sales acquisitions strategies by working with var...
-
Assistant Vice President
2 days ago
Malaysia CIMB Group Full time**Job Scope**: - Ensure coordination and integration across the organisation as well as managing his / her preparations for key meetings. - Work with relevant parties on communications with all stakeholders eg craft key messaging and presentation for annual strategic meetings, town halls, quarterly financial results, drafting of speeches, etc. - Manage...
-
Infrastructure Engineer
2 days ago
Malaysia decube Full time 60,000 per yearAt Decube, we're not just developing a platform; we're redefining how enterprises approach data health and quality. Our cutting-edge data observability platform empowers data teams to proactively manage and maintain the integrity of their systems, ensuring optimal performance and reliability. By preventing data quality incidents, we enable our clients to...