DevOps Engineer
Taguig, Metro Manila, Philippines
DevOps Engineer
- 202603724
- Taguig, Metro Manila, Philippines
Description
The role will be responsible for provisioning and managing Azure resources using Infrastructure as Code (IaC) compliant with security standards and delivering releases by automating build and deployment processes and software configuration management related tasks, and will be responsible for supporting applications after release.
With a primary focus on Cyber Security and AI integration, this role leads security compliance efforts across cloud infrastructure and application code, including vulnerability management, Azure Guardrails enforcement, and the adoption of AI-driven tooling to improve security posture and operational efficiency.
This role works closely with both Software Development and IT Operations groups to ensure final releases meet organizational security standards and deploy successfully without negative impact on customers.
The Role
Provision and manage cloud resources to be compliant with organizational security standards.
Remediate non-compliances in security standards for new or existing cloud resources.
Design, develop, maintain, and support high-quality in-house software builds for enterprise class software and systems.
Design scripts to deploy software in an automated process.
Manage and create configurations for internal customers responsible for scheduling and/or deployment to QA, Staging, and Production environments.
Manage and create configuration items for non-Production environments to support Software Development Life Cycle for internal customers.
Design and implement source code control management best practices.
Develop and maintain internal release management processes.
Create and maintain automated build/release scripts and plans.
Work independently and within project teams to provide guidance and recommendations to business stakeholders and management for risk remediation.
Communicate effectively with members of software development and other project-related groups to ensure processes and project objectives are met.
Contribute to and review ongoing improvements in the implementation of standards, methods, and procedures for Software Configuration Management.
Provide guidance as necessary to other team members in best practices, tool use, and software configuration management principles.
Contribute to updating the product's knowledgebase and creating new documentation as needed.
Provide after-hours support or team virtual calls when required, so a flexible time schedule is necessary at times.
Own and drive Azure Guardrails compliance across all subscriptions, ensuring cloud resources meet defined security baselines at all times.
Implement and maintain security controls within CI/CD pipelines
Assist in implementing security policies and standards for Azure resources, including network security groups, role-based access control (RBAC), and identity governance.
Collaborate with the Security team on audit readiness, including SOC 2 compliance activities, evidence collection, and control validation.
Monitor and respond to security alerts from cloud-native and third-party tools, escalating critical findings in accordance with the incident response process.
Enforce secrets management best practices using Azure Key Vault, including certificate rotation and access policy governance.
Support infrastructure risk assessments and participate in security architecture reviews for new systems or major changes.
Maintain up-to-date documentation of security configurations, remediation activities, and compliance status for audit and reporting purposes.
Evaluate and integrate AI-powered tools to automate security scanning, vulnerability triage, and compliance reporting within DevOps workflows.
Support the deployment and operational management of AI and machine learning workloads on Azure, including Azure OpenAI Service, AI Search, and Azure Machine Learning environments.
Build and maintain infrastructure for AI/ML pipelines, ensuring secure data handling and environment parity across development, staging, and production, covering compute, networking, and storage configurations.
Collaborate with application and data teams to define infrastructure requirements for AI workloads, including compute, networking, and storage configurations.
Enforce access controls, audit logging, and data residency requirements for AI service deployments in compliance with organizational security standards.
Support and execute on AI and automation initiatives within DevOps and security processes to reduce manual effort and improve detection and response times.
Qualifications
The Requirement
2 to 5+ years working experience in Azure cloud technology, including (but not limited to) knowledge of:
Microsoft Azure cloud platform (Platform as a Service)
Web and app services
Storage accounts (Blobs and file storages)
Azure SQL Database management and operation
Azure Kubernetes Service (AKS) management and support (working experience and knowledge required)
Working knowledge in Azure Networks (e.g., Application Gateway / Azure Front Door, Azure Web Application Firewall, Virtual Networks, Network peering, Network Security Groups)
Azure Cloud resource provisioning through Infrastructure as Code (IaC) using Terraform for Azure
Azure DevOps CI/CD (Build, Deployment, and IaC) pipeline provisioning using Classic pipelines but preferably using YAML scripting
Experience with PowerShell or Azure CLI scripting
Experience with Git version control and branching strategies
Familiarity with principles of Continuous Integration and Continuous Delivery concepts (CI/CD)
Experience with monitoring and logging tools (e.g., Azure Monitor, Application Insights, Log Analytics)
Capability to support a software development team's timelines and targets
Experience establishing standards and procedures and advocating best practices for security compliance
Strong written and verbal communication skills
Analytical, creative, adaptable, resourceful, innovative, and imaginative
Strong problem-solving skills and ability to follow through to completion
Customer focused and committed to best-in-class processes and procedures
Strong team player and demonstrates the core values of the company
Hands-on experience with cloud security tooling such as Microsoft Defender for Cloud, Wiz, or equivalent vulnerability and posture management platforms
Working knowledge of Azure Policy and Guardrails enforcement for subscription-level compliance
Practical understanding of identity and access management in Azure, including Managed Identity, Service Principal, RBAC, and Privileged Identity Management (PIM)
Familiarity with security frameworks and compliance standards relevant to cloud environments (e.g. SOC 2)
Experience with Azure Key Vault for secrets management, certificate lifecycle management, and access policy configuration
Understanding of network security principles including firewall rules, private endpoints, and zero-trust architecture patterns in Azure
WTW is an Equal Opportunity Employer
其他人还看过
主动联系
任何未经请求主动通过我们的网站或韦莱韬悦员工的个人电子邮件帐户提交的简历/应聘者资料,均视为韦莱韬悦的财产,且无需支付代理费用。要成为韦莱韬悦的授权招聘机构/猎头公司,此类机构必须持有由韦莱韬悦授权招聘人员签署的正式书面协议,并与公司保持积极的工作关系。简历必须按照我们的应聘者提交流程进行提交,包括积极参与特定职位的搜索工作。同样,对于我们授权的招聘机构/猎头公司,如果未能遵守应聘者提交流程,韦莱韬悦将不支付任何代理费用。韦莱韬悦是提倡机会均等的雇主。如果您希望我们保存您的联系信息以便将来考虑,请发送电子邮件至:Agency.inquiries@willistowerswatson.com 。
我们的办事处
我们的员工为全球 140 多个国家和市场提供服务。这为我们所做的每一项工作注入了全球视野,同时也能够为您创造许多绝佳的合作机遇与成长空间。探索下面的地图,探索您的职业发展可能。