DevSecOps
About the Role
WOXA GROUP is looking for an experienced DevSecOps professional to design and govern a secure software supply chain across the organization.
In this role, you will oversee source-code governance, CI/CD architecture, application security, Kubernetes workloads, cloud services, and external network protection. You will help embed security and compliance throughout the software-development lifecycle, from development and testing to production delivery.
You will also serve as a key technical contributor to the company’s ISO 27001 compliance program and act as a bridge between Development, IT Operations, Security, SRE, and other business units.
Responsibilities
Design and maintain a secure software supply chain.
Govern source-code management, repository standards, and GitLab CI/CD architecture.
Manage application security across Kubernetes platforms, cloud services, and edge networks.
Serve as a technical foundation for the organization’s ISO 27001 compliance program.
Embed security and compliance into the way applications are developed, tested, and delivered.
Drive Shift-Left Security practices across Development, IT Operations, and Security teams.
Secure microservices deployed to Kubernetes clusters.
Manage the organization’s external perimeter through Cloudflare.
Coordinate security-related operations across technical and business units.
Qualifications
At least 5 years of proven experience in Application Security, DevSecOps, Software Engineering, or a related field, including experience leading technical teams.
Expert-level experience with GitLab or similar source-code management platforms and governance of large codebases.
Advanced experience building complex, automated, and secure CI/CD pipelines.
Deep expertise in deploying and securing applications on Kubernetes and using Helm in high-traffic production environments.
Hands-on experience with enterprise edge-security solutions, particularly Cloudflare, including WAF, DNS, DDoS protection, CDN configuration, and API security.
Strong knowledge of integrating security-testing tools such as Snyk, SonarQube, and Trivy into development workflows.
Strong understanding of the OWASP Top 10 and secure software-design principles.
Experience securing application workloads and managed services across Hybrid or Multi-Cloud environments, including AWS, GCP, and DigitalOcean.
Strong understanding of the CIA Triad: Confidentiality, Integrity, and Availability.
Ability to balance priorities among product development, system reliability, and regulatory compliance, including determining when a deployment should be delayed for security reasons.
Work Information
Location: Khon Kaen, Thailand
Work Arrangement: On-site
Employment Type: Full-time
Experience: 5–10 years
Education: Bachelor’s degree or higher
Salary: Negotiable
Interested in this role?
Send your CV and tell us why you're a fit — we review every application.
Apply now