Senior Security Engineer (Cloud Security focus)

Ho Chi Minh City Permanent Work from Home or Hybrid View Job Description
Join a fast-growing AI technology company building enterprise-grade automation products and take ownership of security execution across cloud infrastructure, applications, and software delivery pipelines. This is a high-impact individual contributor role where you'll drive vulnerability management, security automation, cloud security, and engineering security practices while working closely with product and engineering leadership.
  • Secure a Cutting-Edge AI Platform
  • Own Security Across Engineering

About Our Client

Our client is an innovative AI company based in developing advanced automation technology used by enterprise customers globally. As the business continues to scale and serve increasingly security-conscious customers, they are investing heavily in strengthening security practices, compliance readiness, and secure engineering operations.The company offers a highly technical, engineering-driven environment where security is viewed as a strategic advantage rather than a compliance exercise. Team members enjoy significant ownership, fast decision-making, and the opportunity to influence how security is embedded throughout the organization.

Job Description

As the Senior DevSecOps Engineer, you will play a critical role in driving security initiatives across infrastructure and product engineering environments.Key responsibilities include:

  • Own the end-to-end vulnerability management lifecycle across cloud infrastructure, applications, containers, CI/CD pipelines, and production systems.
  • Establish and continuously improve processes for vulnerability discovery, risk assessment, remediation tracking, reporting, and verification.
  • Implement and maintain security controls across AWS environments, including IAM, encryption, networking, secrets management, logging, and workload isolation.
  • Integrate security into software development practices through SAST, DAST, dependency scanning, secret detection, container security, and Infrastructure-as-Code security controls.
  • Conduct threat modelling, security design reviews, and provide practical security recommendations to engineering teams.
  • Improve security posture across authentication systems, APIs, sensitive data handling, and software supply chains.
  • Coordinate penetration testing activities and ensure findings are remediated according to risk priorities.
  • Support incident response readiness through playbooks, tabletop exercises, investigations, and corrective action tracking.
  • Partner with engineering and infrastructure teams to enhance monitoring, security logging, threat detection, and observability capabilities.
  • Translate compliance and policy requirements into technical controls and automated security mechanisms.
  • Support security frameworks and audits such as SOC 2, ISO 27001, and related regulatory initiatives.
  • Provide visibility into security posture, vulnerability trends, remediation performance, and risk metrics.



The Successful Applicant

To be successful in this role, you will ideally have:

  • 5+ years of experience in DevSecOps, Security Engineering, Cloud Security, Application Security, or related fields.
  • Strong hands-on experience operating vulnerability management and remediation programs.
  • Deep expertise in AWS security including IAM, VPC, KMS, monitoring, secrets management, and multi-account architectures.
  • Experience with Infrastructure-as-Code, ideally using Terraform.
  • Practical experience securing CI/CD environments and modern software delivery pipelines.
  • Hands-on knowledge of security technologies such as SAST, DAST, container security, dependency scanning, secret detection, CSPM, and IaC security scanning.
  • Strong understanding of application security best practices, secure development, authentication and authorization models, and OWASP Top 10 risks.
  • Experience in security incident response, root cause analysis, and remediation tracking.
  • Familiarity with security and compliance frameworks including SOC 2, ISO 27001, CIS Benchmarks, or equivalent.
  • Scripting or automation skills using Python, Bash, or similar languages.
  • Strong communication skills with the ability to influence technical and non-technical stakeholders.



Preferred qualifications:

  • Experience securing Kubernetes, EKS, ECS, or containerized environments.
  • Exposure to AWS Security Hub, GuardDuty, CloudTrail, Control Tower, or related AWS security services.
  • Experience with SIEM platforms, detection engineering, penetration testing coordination, or compliance automation tools.
  • Industry certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or OSCP.



What's on Offer

  • Opportunity to secure a rapidly scaling AI-powered platform serving enterprise customers.
  • Significant ownership and autonomy in shaping security practices and technical controls.
  • Direct collaboration with senior engineering, infrastructure, and product leaders.
  • Modern cloud-native technology environment and challenging security problems.
  • Flexible remote/hybrid working arrangement.
  • Competitive compensation and long-term career growth opportunities.
  • Join a high-performing, globally distributed team that values engineering excellence, pragmatism, and accountability.
Contact
Daniel Nguyen
Quote job ref
JN-082026-7091283

Job summary

Function
IT
Specialisation
Security
What is your area of specialisation?
Technology & Telecoms
Location
Ho Chi Minh City
Contract Type
Permanent
Consultant name
Daniel Nguyen
Job Reference
JN-082026-7091283
Work from Home
Work from Home or Hybrid

Diversity & Inclusion at Michael Page

We don't just accept difference - we celebrate it. We encourage applicants from all backgrounds to apply for this role and are committed to building inclusive, diverse workplaces where everyone can thrive. If you require any support or reasonable adjustments during the recruitment process, please let us know.