- Posted 8 hours ago
- Be among the first 10 applicants
Job Description
Role: CLOUD DEVOPS ENGINEER
Mode of hiring: 4 months extendable contract with IDC Technologies
Work Location kl location malaysia
CLOUD DEVOPS ENGINEER
Requirements :
- Tenure : Contractual for 4 months (project starts immediately till end of December 2026)
- Total headcount : 1 headcount (to support both Malaysia Region)
- Only Local Malaysians
- Working hours – Office Hours (Monday to Friday) ; able to stand by if required by the business
- Min 4 years of proven experience in a Cloud Operations , DevOps and well verse with AWS / Azure
- Hands-on experience designing, building, and maintaining CI/CD pipelines in both Jenkins and GitHub Actions (include migration, workflow authoring and etc).
- Must have strong understanding of Agile and Scrum methodologies
- Must have Bachelor's Degree in Computer Science, Information Technology, or a related field.
Job Summary
Job Title: Cloud DevOps Engineer
Position Summary
In line with aim to be a truly customer- and product-centric organization, the functional area Applications ensures end-to-end responsibility for all applications in its scope. These applications are clustered in Verticals owning the build, roll-out, and maintenance/run.
Cloud DevOps Engineers are role-models for changing the culture and provide cloud operations capabilities, self-service tools, and easy configuration to other IT specialists. They are responsible for operating, monitoring, and maintaining cloud infrastructure and the CI/CD toolchain that supports application build, roll-out, and maintenance/run.
They see their work as building a development and cloud platform used by other engineers, not providing a manual and repetitive service.
The ideal candidate will prefer the excitement of shaping the technology evolution over following the beaten path, and regards highly qualified colleagues not as competition, but as a learning opportunity. The candidate must have hands-on experience designing, building, and operating CI/CD pipelines — with particular depth in Jenkins and GitHub Actions — and managing fully automated, zero-downtime deployment of applications, including integrating artifact and quality-gate tooling such as Nexus, Harbor, and SonarQube into the pipeline. Given the organization's ongoing shift of build/release tooling, direct, hands-on experience migrating pipelines from Jenkins to GitHub Actions is a core requirement, as is configuring and operating GitHub Advanced Security (GHAS) and implementing the standard pipeline to embed security and quality checks natively into the SDLC.
Beyond building the toolchain, the role is expected to handhold application teams and DevOps tribes through adoption of the modernized, standardized toolset (GitHub, GitHub Actions, GHAS, and related tools), and to produce documentation and reusable artifacts (templates, reusable workflows/actions, runbooks, guides) that let teams self-serve and adopt these standards independently. Experience applying automation and AI-augmentation to streamline pipeline engineering, security triage, and documentation work is a desirable differentiator.
Job Responsibilities
- Implement the standard pipeline, ensuring consistent, compliant build/release patterns are adopted across teams.
- Design, build, and maintain CI/CD pipelines in Jenkins and GitHub Actions, ensuring security and quality checks are embedded at each stage.
- Integrate Nexus (artifact/package repository), Harbor (container/image registry), and SonarQube (static code analysis/quality gates) into CI/CD pipelines, and manage their configuration, policies, and pipeline gating rules.
- Lead or execute the migration of existing Jenkins pipelines to GitHub Actions workflows, preserving build integrity, secrets handling, approval gates, and deployment logic while modernizing the toolchain.
- Configure, roll out, and operate GitHub Advanced Security — including code scanning (CodeQL), secret scanning (with push protection), and dependency review/Dependabot — across repositories, and tune policies to reduce noise while maintaining coverage.
- Establish and maintain infrastructure-as-code practices for cloud resources and pipeline/workflow definitions (pipeline-as-code).
- Collaborate with development, security, and operations teams to integrate automated security and quality testing tools (SAST/DAST/SCA, SonarQube quality gates) within CI/CD pipelines, including GitHub Actions and Jenkins.
- Continuously assess and optimize cloud resources and CI/CD processes based on feedback and evolving best practices, including retiring legacy Jenkins jobs post-migration.
- Define reusable GitHub Actions workflows, composite actions, and self-hosted runner strategy to standardize pipelines across teams.
- Handhold application teams and DevOps tribes through the adoption of the modernized, standardized toolset (GitHub, GitHub Actions, GHAS, and related tools), providing direct enablement, pairing, and onboarding support.
- Create and maintain documentation and reusable artifacts — templates, reusable workflows/composite actions, onboarding guides, and runbooks — so teams can self-serve adoption of standardized pipelines and tooling.
- Explore and apply automation and AI-augmentation (e.g., AI-assisted pipeline authoring, automated triage of security findings, generative documentation) to improve the efficiency and productivity of DevOps activities.
- Participate in and lead training sessions and workshops to enhance understanding of cloud technologies, the standard pipeline, GitHub Actions/Advanced Security, and DevSecOps principles.
- Ensure all cloud, DevOps, and CI/CD practices comply with organizational policies, industry standards, and regulatory requirements.
- Assist in conducting audits to review SDLC processes, pipeline configurations, and deployed systems for compliance with production efficiency and security protocols.
- Maintain clear and effective communication with stakeholders to ensure alignment with business objectives, including reporting migration progress and security posture improvements.
Job Requirements
- Bachelor's degree in Computer Science, Information Technology, or a related field.
- 3–5 years of experience in Cloud Operations, DevOps, or related roles.
- Demonstrated proficiency with at least one major cloud platform (AWS, Azure).
- Must-have: Hands-on experience designing, building, and maintaining CI/CD pipelines in both Jenkins and GitHub Actions.
- Must-have: Demonstrable, hands-on experience migrating pipelines from Jenkins to GitHub Actions (e.g., translating Jenkinsfiles/Groovy pipelines into YAML workflows, re-platforming credentials/secrets, replicating multi-stage/approval logic, and validating parity post-migration).
- Must-have: Experience configuring and administering GitHub Advanced Security features (code scanning/CodeQL, secret scanning with push protection, dependency review/Dependabot alerts) at repository and organization level.
- Must-have: Experience integrating Nexus, Harbor, and SonarQube into CI/CD pipelines (artifact publishing/retrieval, image registry push/pull, and automated quality-gate enforcement).
- Experience implementing standardized/organization-wide pipeline templates (e.g., an standard pipeline-style approach) across multiple teams.
- Experience enabling/handholding application teams through tooling migrations or adoptions, including producing documentation and reusable artifacts (templates, guides, runbooks) that support self-service adoption.
- Experience working in cross-functional teams, including developers, operations, and security professionals.
Functional Skills
- Strong understanding of Agile and Scrum methodologies.
- Ability to collaborate effectively with diverse teams to foster a DevSecOps culture.
- Experience in project management and supporting Agile development processes (Scrum, Kanban, etc.).
- Strong problem-solving skills and adaptability in a fast-paced environment.
- Ability to plan and execute a toolchain migration (Jenkins → GitHub Actions) with minimal disruption to delivery teams, including stakeholder communication and rollback planning.
- Strong enablement/coaching mindset — able to handhold application teams and DevOps tribes through toolset adoption and translate standards into practical, self-service guidance.
- Strong technical writing skills for producing clear, reusable documentation and templates.
Technical Skills — Must Have
- Jenkins: pipeline (declarative/scripted) authoring, plugin management, shared libraries, agent/node administration.
- GitHub Actions: workflow authoring (YAML), reusable/composite actions, self-hosted runners, environments, secrets/OIDC-based cloud auth.
- Hands-on Jenkins-to-GitHub Actions migration experience — not just familiarity with both tools independently, but demonstrated execution of a migration project.
- GitHub Advanced Security configuration and operation: CodeQL code scanning, secret scanning with push protection, dependency review, Dependabot security updates, and org-level security policy enforcement.
- Nexus: repository/artifact management, integration with build tools and pipelines for publishing and consuming artifacts.
- Harbor: container image registry configuration, image scanning policies, and pipeline integration for image push/pull.
- SonarQube: quality gate configuration, pipeline integration, and enforcement of code quality/security standards as part of CI/CD.
- Ability to implement and roll out a standardized (standard) pipeline template across teams.
- Experience with cloud infrastructure management and automation.
- Knowledge of Infrastructure as Code (IaC) tools (e.g., Terraform, Ansible).
Technical Skills — Nice to Have
- Experience with additional security scanning tools (e.g., third-party SAST/DAST) beyond native GitHub Advanced Security.
- Proficiency in scripting languages (e.g., Python, Bash) and build tools (e.g., Maven, Gradle).
- Familiarity with GitHub Enterprise administration (organization/repo policy management, branch protection, rulesets).
- Desired: Experience applying automation and AI-augmentation (e.g., AI coding/pipeline assistants, LLM-based documentation or triage automation, GitHub Copilot) to improve the efficiency and productivity of DevOps and pipeline-engineering activities.
More Info
Key Skills
About Company
IDC Technologies (Singapore) Pte Ltd
