Skip to main content

Bjak

DevSecOps Engineer

Global (Remote)fulltimemidAdded today

About this role

BJAK seeks a DevSecOps Engineer to embed security throughout its software delivery pipelines across AWS and GCP. You'll automate security controls, manage compliance frameworks (SC TRM and BNM RMiT), and collaborate with engineering teams to enable secure, rapid delivery of financial applications.

What you'll do

  • Integrate code, dependency, container, and infrastructure scanning into CI/CD pipelines
  • Maintain security guardrails for builds, releases, artifacts, and deployment identities
  • Secure containerized workloads and orchestration platforms across AWS and GCP
  • Implement and own SC TRM and BNM RMiT compliance controls with evidence and audit support
  • Partner with engineers on TypeScript, Python, Swift, and Kotlin projects to embed security checks
  • Enhance vulnerability monitoring, incident readiness, and secure delivery practices

What they're looking for

  • CI/CD tools (GitHub Actions, GitLab CI, Jenkins)
  • AWS and GCP cloud platforms
  • Docker and Kubernetes
  • Infrastructure as code
  • Security scanning and software supply chain security
  • Secrets management and IAM
  • Python, TypeScript/Node.js, Bash, or Go scripting
  • Regulatory compliance (SC TRM, BNM RMiT)
Apply with Autofill

Opens the application — the Jobs AI extension fills it for you. Set up autofill

Opens the official application on the employer’s site. No login required.

Bjak

Bjak is a Southeast Asian fintech super app offering insurance, payments, savings, wallets, and investment products through a unified platform. The company is hiring full stack engineers, backend engineers, iOS developers, and Android engineers to build scalable features and reliable systems across mobile and web products.

Website
bjak.com
View all jobs at Bjak

Likely interview questions

  • Describe your experience implementing SC TRM or BNM RMiT controls—what was your approach to evidence gathering and audit preparation?
  • Walk us through how you've embedded security scanning into a CI/CD pipeline; what tools did you use and what challenges did you overcome?