LOG IN
SIGN UP
Canary Wharfian - Online Investment Banking & Finance Community.
Sign In
Forgot password?
Don't have an account?
or
Join Canary Wharfian
By signing up, you agree to our Terms & Conditions and Privacy Policy.
or

DevSecOps Engineer

ExperiencedNo visa sponsorship
Capgemini logo

at Capgemini

Consultancies

Posted 5 days ago

No clicks

**DevSecOps Engineer** Own security, reliability, and compliance of cloud & Kubernetes environments for AI platforms. **Key Responsibilities**: - Manage AWS & Kubernetes infrastructure, deployments, scaling, security, and incident troubleshooting. - Administer essential AWS services, including RDS PostgreSQL, OpenSearch, AWS Bedrock, and ELB. - Design, operate, and troubleshoot secure AWS network architectures, applying least-privilege principles. - Establish production observability, alerting, and disaster recovery processes. - Automate workflows using Terraform and GitLab CI/CD with automated testing, scanning, and approval controls. - Embed security controls throughout the platform lifecycle and manage vendor transitions. **Required Skills and Experience**: - 2 to 5+ years in DevOps, Cloud Engineering, or similar roles, with hands-on experience in Kubernetes and Terraform. - Strong proficiency in AWS, Kubernetes networking, and secure multi-account network design. - Experience with CI/CD tools (GitLab preferred) and operational readiness in regulated environments. - Excellent communication skills for explaining complex decisions to both technical and non-technical stakeholders. **BONUS**: Experience with AI agent platforms and modern AI workflows.

Compensation
Not specified

Currency: Not specified

City
Singapore
Country
Singapore

Full Job Description

About Capgemini

Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.

About the Role

We are a growing technology team within a government agency building and operating production Generative AI platforms and applications. We are looking for an experienced DevSecOps Engineer to own the security, reliability, scalability, and compliance of our cloud and Kubernetes environments, deployment pipelines, and AI workload infrastructure.

In this role, you will be the primary technical owner of our AWS and Kubernetes platform, bridging software development, AI engineering, cybersecurity, governance, and production operations. You will establish secure engineering guardrails, automate repeatable controls, and build resilient platform capabilities that enable teams to deploy and operate Generative AI workloads safely at scale.

Responsibilities

  • Cloud Infrastructure & Kubernetes Ownership: Manage and scale our AWS cloud environments and take end-to-end ownership of production-grade Kubernetes on AWS EKS, including cluster architecture, workload deployment, security, upgrades, autoscaling, resilience, observability, and incident troubleshooting.
  • AWS Ecosystem Administration: Provision, configure, and manage essential AWS services supporting our applications. This includes managed relational databases (RDS PostgreSQL), search/analytics (OpenSearch), AI services (Bedrock), and networking/load balancing (ELB).
  • Network Architecture, Security & Connectivity: Design, operate, and troubleshoot secure AWS network architectures for regulated, multi-account environments. This includes VPC and subnet design, CIDR planning, Transit Gateway routing and route-table segmentation, centralized ingress and egress, AWS Network Firewall and WAF, security groups and network ACLs, private connectivity through VPC endpoints or AWS PrivateLink, DNS resolution, load balancing, and connectivity to shared services or on-premises networks through VPN or Direct Connect. Apply network segmentation and least-privilege principles across production, non-production, management, and shared-service environments.
  • Production Reliability, Observability & Resilience: Establish service-level indicators and objectives, dashboards, alerts, logs, metrics, and distributed traces across infrastructure, Kubernetes, applications, and AI workloads. Lead incident response, root-cause analysis, corrective actions, capacity planning, backup and restore testing, and disaster-recovery exercises to meet agreed recovery objectives.
  • Infrastructure as Code, CI/CD & Automation: Use Terraform as the primary Infrastructure as Code tool to provision and manage repeatable AWS and Kubernetes environments. Administer and optimise GitLab CI/CD pipelines with automated testing, SAST, DAST, dependency and container scanning, policy checks, approval controls, immutable artefacts, environment promotion, rollback mechanisms, and auditable release records.
  • Compliance, Security Engineering & Vulnerability Management: Embed security controls throughout the platform lifecycle, including threat modelling, secure architecture reviews, vulnerability and patch management, penetration testing, hardening, remediation tracking, audit evidence, and technical risk assessments. Work with cybersecurity, governance, product, and project stakeholders to translate government security requirements and enterprise standards into automated, testable controls.
  • Identity, Secrets & Software Supply Chain Security: Implement least-privilege IAM, workload identity, privileged-access controls, secrets and certificate management, container image signing and scanning, software bills of materials, dependency governance, and policy enforcement across infrastructure and deployment pipelines. Protect sensitive configuration and credentials, and maintain traceability of changes and releases.
  • Vendor Transition: Work closely alongside existing external vendors to map the current architecture, reverse-engineer undocumented configurations, and safely transition infrastructure operations fully in-house.

Requirements

  • Experience: Typically 2 to 5+ years of hands-on experience in DevOps, DevSecOps, Cloud Engineering, or a similar role. We welcome candidates with fewer years of experience who can demonstrate strong practical capability, sound engineering fundamentals, and ownership of production systems. Hands-on production experience with Kubernetes and Terraform is mandatory; depth of capability and evidence of impact will be valued over years of service.
  • Cloud & Kubernetes: Strong proficiency in AWS infrastructure, together with substantial hands-on experience designing, deploying, securing, operating, troubleshooting, and upgrading production Kubernetes clusters and workloads. Strong experience with AWS EKS and Kubernetes networking is required, including ingress controllers, load balancers, service discovery, network policies, pod and service CIDR planning, and diagnosis of cross-VPC or restricted-egress connectivity issues.
  • AWS Networking: Strong knowledge of complex AWS networking in multi-account and regulated environments. Candidates should be able to design and troubleshoot VPCs, subnets, route tables, Transit Gateway attachments and segmentation, overlapping or constrained CIDR ranges, centralized firewalls and egress, VPC endpoints and PrivateLink, Route 53 private DNS, security groups, network ACLs, VPN or Direct Connect connectivity, and traffic flows across application, shared-service, security, and on-premises network zones.
  • CI/CD Tools: Solid experience building and maintaining CI/CD pipelines (GitLab preferred).
  • Operational Readiness: Proven experience defining service-level objectives, building actionable monitoring and alerting, responding to production incidents, conducting root-cause analysis, managing capacity, and designing and testing backup, restore, and disaster-recovery arrangements.
  • Regulated Environments: Experience delivering or operating systems under Singapore Government Commercial Cloud and IM8 requirements, or under comparably stringent regulatory frameworks in sectors such as banking, finance, healthcare, or critical infrastructure. Candidates should understand audit evidence, risk acceptance, segregation of duties, change control, and secure handling of sensitive data.
  • Communication & Documentation: Ability to explain complex infrastructure and security decisions to technical and non-technical stakeholders, produce clear architecture diagrams, runbooks, operational procedures, risk assessments, and audit evidence, and work effectively with developers, AI engineers, cybersecurity teams, vendors, and government governance stakeholders.

Bonus Points:

  • AI Agent Platforms: Significant hands-on experience deploying and operating agentic AI workloads is a major advantage. Relevant experience includes agent observability and distributed tracing, agent harness engineering, prompt and configuration versioning, evaluation pipelines, secure tool and model connectivity, runtime isolation, rate limiting, failure handling, and platforms such as Amazon Bedrock AgentCore or equivalent technologies.
  • Modern AI Workflows: Familiarity with production AI and machine-learning workloads, including model and agent deployment patterns, prompt and configuration management, observability of latency, errors, token usage and cost, protection against unintended data exposure, and operational controls for responsible AI use.

Let's talk about what's in it for you!

Passionate people are Capgemini's Ace of Spades - join us to discover a career that will challenge, support and inspire you. Working at Capgemini you'll find the rewards are more than just financial. You will work alongside some very smart and inspiring people on exciting projects and you will also enjoy incredible benefits. We offer flexible work practices and 40 hours of self-development every year with a huge selection of learning opportunities to choose from.

As 'Architects of Positive Futures', Capgemini actively supports the community in 3 ways:

Diversity and Inclusion - we believe diversity of thought fuels excellence and innovation, which is why we positively encourage applications from suitably qualified candidates regardless of their gender identity, ethnicity, sexual orientation, religion, ability, intersex status or age. To support our commitment to diversity and inclusion, we celebrate special events and days of significance that are important to our employees such as Diwali, Bastille Day, Pride, IDAHOBIT, IWD and International day of people with Disabilities. Our Employee Resource Groups Women@Capgemini and OutFront support the grassroots passion of employees to drive our diversity agenda and effect change.

Digital inclusion - at Capgemini we are using our skills to drive social impact initiatives focusing on helping society address the impact of the digital and automation revolution. We also provide employees with opportunities to give back to the community through charity projects and volunteer days.

Environmental Sustainability - Capgemini joined the CDP's (Carbon Disclosure Project) prestigious 'A list' for its commitment to the Net-Zero economy. We are focusing on helping our clients transform towards more sustainable business models and committing to reduce our own carbon emissions (GHG) by 20% per employee by 2020.

Recognized by Ethisphere as one of the World's Most Ethical Companies for the last 8 years in a row, ethics and values are at the heart of Capgemini's corporate culture and business. Embedded in our DNA, our seven values - Honesty, Boldness, Trust, Team Spirit, Freedom, Fun and Modesty - have remained the same since company inception in 1967. To see how we bring these values to life, click here to listen to some of our employees stories.

Come join us, bring your whole self to work, create new possibilities for you, your customers and your community and help us to be Architects of Positive Futures.

DevSecOps Engineer

Compensation

Not specified

City: Singapore

Country: Singapore

Capgemini logo
Consultancies

5 days ago

No clicks

at Capgemini

ExperiencedNo visa sponsorship

**DevSecOps Engineer** Own security, reliability, and compliance of cloud & Kubernetes environments for AI platforms. **Key Responsibilities**: - Manage AWS & Kubernetes infrastructure, deployments, scaling, security, and incident troubleshooting. - Administer essential AWS services, including RDS PostgreSQL, OpenSearch, AWS Bedrock, and ELB. - Design, operate, and troubleshoot secure AWS network architectures, applying least-privilege principles. - Establish production observability, alerting, and disaster recovery processes. - Automate workflows using Terraform and GitLab CI/CD with automated testing, scanning, and approval controls. - Embed security controls throughout the platform lifecycle and manage vendor transitions. **Required Skills and Experience**: - 2 to 5+ years in DevOps, Cloud Engineering, or similar roles, with hands-on experience in Kubernetes and Terraform. - Strong proficiency in AWS, Kubernetes networking, and secure multi-account network design. - Experience with CI/CD tools (GitLab preferred) and operational readiness in regulated environments. - Excellent communication skills for explaining complex decisions to both technical and non-technical stakeholders. **BONUS**: Experience with AI agent platforms and modern AI workflows.

Full Job Description

About Capgemini

Capgemini is an AI-powered global business and technology transformation partner, delivering tangible business value. We imagine the future of organizations and make it real with AI, technology and people. With our strong heritage of nearly 60 years, we are a responsible and diverse group of over 420,000 team members in more than 50 countries. We deliver end-to-end services and solutions with our deep industry expertise and strong partner ecosystem, leveraging our capabilities across strategy, technology, design, engineering and business operations. The Group reported 2025 global revenues of €22.5 billion.

About the Role

We are a growing technology team within a government agency building and operating production Generative AI platforms and applications. We are looking for an experienced DevSecOps Engineer to own the security, reliability, scalability, and compliance of our cloud and Kubernetes environments, deployment pipelines, and AI workload infrastructure.

In this role, you will be the primary technical owner of our AWS and Kubernetes platform, bridging software development, AI engineering, cybersecurity, governance, and production operations. You will establish secure engineering guardrails, automate repeatable controls, and build resilient platform capabilities that enable teams to deploy and operate Generative AI workloads safely at scale.

Responsibilities

  • Cloud Infrastructure & Kubernetes Ownership: Manage and scale our AWS cloud environments and take end-to-end ownership of production-grade Kubernetes on AWS EKS, including cluster architecture, workload deployment, security, upgrades, autoscaling, resilience, observability, and incident troubleshooting.
  • AWS Ecosystem Administration: Provision, configure, and manage essential AWS services supporting our applications. This includes managed relational databases (RDS PostgreSQL), search/analytics (OpenSearch), AI services (Bedrock), and networking/load balancing (ELB).
  • Network Architecture, Security & Connectivity: Design, operate, and troubleshoot secure AWS network architectures for regulated, multi-account environments. This includes VPC and subnet design, CIDR planning, Transit Gateway routing and route-table segmentation, centralized ingress and egress, AWS Network Firewall and WAF, security groups and network ACLs, private connectivity through VPC endpoints or AWS PrivateLink, DNS resolution, load balancing, and connectivity to shared services or on-premises networks through VPN or Direct Connect. Apply network segmentation and least-privilege principles across production, non-production, management, and shared-service environments.
  • Production Reliability, Observability & Resilience: Establish service-level indicators and objectives, dashboards, alerts, logs, metrics, and distributed traces across infrastructure, Kubernetes, applications, and AI workloads. Lead incident response, root-cause analysis, corrective actions, capacity planning, backup and restore testing, and disaster-recovery exercises to meet agreed recovery objectives.
  • Infrastructure as Code, CI/CD & Automation: Use Terraform as the primary Infrastructure as Code tool to provision and manage repeatable AWS and Kubernetes environments. Administer and optimise GitLab CI/CD pipelines with automated testing, SAST, DAST, dependency and container scanning, policy checks, approval controls, immutable artefacts, environment promotion, rollback mechanisms, and auditable release records.
  • Compliance, Security Engineering & Vulnerability Management: Embed security controls throughout the platform lifecycle, including threat modelling, secure architecture reviews, vulnerability and patch management, penetration testing, hardening, remediation tracking, audit evidence, and technical risk assessments. Work with cybersecurity, governance, product, and project stakeholders to translate government security requirements and enterprise standards into automated, testable controls.
  • Identity, Secrets & Software Supply Chain Security: Implement least-privilege IAM, workload identity, privileged-access controls, secrets and certificate management, container image signing and scanning, software bills of materials, dependency governance, and policy enforcement across infrastructure and deployment pipelines. Protect sensitive configuration and credentials, and maintain traceability of changes and releases.
  • Vendor Transition: Work closely alongside existing external vendors to map the current architecture, reverse-engineer undocumented configurations, and safely transition infrastructure operations fully in-house.

Requirements

  • Experience: Typically 2 to 5+ years of hands-on experience in DevOps, DevSecOps, Cloud Engineering, or a similar role. We welcome candidates with fewer years of experience who can demonstrate strong practical capability, sound engineering fundamentals, and ownership of production systems. Hands-on production experience with Kubernetes and Terraform is mandatory; depth of capability and evidence of impact will be valued over years of service.
  • Cloud & Kubernetes: Strong proficiency in AWS infrastructure, together with substantial hands-on experience designing, deploying, securing, operating, troubleshooting, and upgrading production Kubernetes clusters and workloads. Strong experience with AWS EKS and Kubernetes networking is required, including ingress controllers, load balancers, service discovery, network policies, pod and service CIDR planning, and diagnosis of cross-VPC or restricted-egress connectivity issues.
  • AWS Networking: Strong knowledge of complex AWS networking in multi-account and regulated environments. Candidates should be able to design and troubleshoot VPCs, subnets, route tables, Transit Gateway attachments and segmentation, overlapping or constrained CIDR ranges, centralized firewalls and egress, VPC endpoints and PrivateLink, Route 53 private DNS, security groups, network ACLs, VPN or Direct Connect connectivity, and traffic flows across application, shared-service, security, and on-premises network zones.
  • CI/CD Tools: Solid experience building and maintaining CI/CD pipelines (GitLab preferred).
  • Operational Readiness: Proven experience defining service-level objectives, building actionable monitoring and alerting, responding to production incidents, conducting root-cause analysis, managing capacity, and designing and testing backup, restore, and disaster-recovery arrangements.
  • Regulated Environments: Experience delivering or operating systems under Singapore Government Commercial Cloud and IM8 requirements, or under comparably stringent regulatory frameworks in sectors such as banking, finance, healthcare, or critical infrastructure. Candidates should understand audit evidence, risk acceptance, segregation of duties, change control, and secure handling of sensitive data.
  • Communication & Documentation: Ability to explain complex infrastructure and security decisions to technical and non-technical stakeholders, produce clear architecture diagrams, runbooks, operational procedures, risk assessments, and audit evidence, and work effectively with developers, AI engineers, cybersecurity teams, vendors, and government governance stakeholders.

Bonus Points:

  • AI Agent Platforms: Significant hands-on experience deploying and operating agentic AI workloads is a major advantage. Relevant experience includes agent observability and distributed tracing, agent harness engineering, prompt and configuration versioning, evaluation pipelines, secure tool and model connectivity, runtime isolation, rate limiting, failure handling, and platforms such as Amazon Bedrock AgentCore or equivalent technologies.
  • Modern AI Workflows: Familiarity with production AI and machine-learning workloads, including model and agent deployment patterns, prompt and configuration management, observability of latency, errors, token usage and cost, protection against unintended data exposure, and operational controls for responsible AI use.

Let's talk about what's in it for you!

Passionate people are Capgemini's Ace of Spades - join us to discover a career that will challenge, support and inspire you. Working at Capgemini you'll find the rewards are more than just financial. You will work alongside some very smart and inspiring people on exciting projects and you will also enjoy incredible benefits. We offer flexible work practices and 40 hours of self-development every year with a huge selection of learning opportunities to choose from.

As 'Architects of Positive Futures', Capgemini actively supports the community in 3 ways:

Diversity and Inclusion - we believe diversity of thought fuels excellence and innovation, which is why we positively encourage applications from suitably qualified candidates regardless of their gender identity, ethnicity, sexual orientation, religion, ability, intersex status or age. To support our commitment to diversity and inclusion, we celebrate special events and days of significance that are important to our employees such as Diwali, Bastille Day, Pride, IDAHOBIT, IWD and International day of people with Disabilities. Our Employee Resource Groups Women@Capgemini and OutFront support the grassroots passion of employees to drive our diversity agenda and effect change.

Digital inclusion - at Capgemini we are using our skills to drive social impact initiatives focusing on helping society address the impact of the digital and automation revolution. We also provide employees with opportunities to give back to the community through charity projects and volunteer days.

Environmental Sustainability - Capgemini joined the CDP's (Carbon Disclosure Project) prestigious 'A list' for its commitment to the Net-Zero economy. We are focusing on helping our clients transform towards more sustainable business models and committing to reduce our own carbon emissions (GHG) by 20% per employee by 2020.

Recognized by Ethisphere as one of the World's Most Ethical Companies for the last 8 years in a row, ethics and values are at the heart of Capgemini's corporate culture and business. Embedded in our DNA, our seven values - Honesty, Boldness, Trust, Team Spirit, Freedom, Fun and Modesty - have remained the same since company inception in 1967. To see how we bring these values to life, click here to listen to some of our employees stories.

Come join us, bring your whole self to work, create new possibilities for you, your customers and your community and help us to be Architects of Positive Futures.