DevSecOps
About the Role
WOXA GROUP is looking for an experienced DevSecOps professional to design and govern a secure software supply chain across the organization.
In this role, you will oversee source-code governance, CI/CD architecture, application security, Kubernetes workloads, cloud services, and external network protection. You will help embed security and compliance throughout the software-development lifecycle, from development and testing to production delivery.
You will also serve as a key technical contributor to the company’s ISO 27001 compliance program and act as a bridge between Development, IT Operations, Security, SRE, and other business units.
Responsibilities
Design and maintain a secure software supply chain.
Govern source-code management, repository standards, and GitLab CI/CD architecture.
Manage application security across Kubernetes platforms, cloud services, and edge networks.
Serve as a technical foundation for the organization’s ISO 27001 compliance program.
Embed security and compliance into the way applications are developed, tested, and delivered.
Drive Shift-Left Security practices across Development, IT Operations, and Security teams.
Secure microservices deployed to Kubernetes clusters.
Manage the organization’s external perimeter through Cloudflare.
Coordinate security-related operations across technical and business units.
Qualifications
At least 5 years of proven experience in Application Security, DevSecOps, Software Engineering, or a related field, including experience leading technical teams.
Expert-level experience with GitLab or similar source-code management platforms and governance of large codebases.
Advanced experience building complex, automated, and secure CI/CD pipelines.
Deep expertise in deploying and securing applications on Kubernetes and using Helm in high-traffic production environments.
Hands-on experience with enterprise edge-security solutions, particularly Cloudflare, including WAF, DNS, DDoS protection, CDN configuration, and API security.
Strong knowledge of integrating security-testing tools such as Snyk, SonarQube, and Trivy into development workflows.
Strong understanding of the OWASP Top 10 and secure software-design principles.
Experience securing application workloads and managed services across Hybrid or Multi-Cloud environments, including AWS, GCP, and DigitalOcean.
Strong understanding of the CIA Triad: Confidentiality, Integrity, and Availability.
Ability to balance priorities among product development, system reliability, and regulatory compliance, including determining when a deployment should be delayed for security reasons.
Work Information
Location: Khon Kaen, Thailand
Work Arrangement: On-site
Employment Type: Full-time
Experience: 5–10 years
Education: Bachelor’s degree or higher
Salary: Negotiable
Apply for this role
DevSecOps – วิศวกรความปลอดภัยในการพัฒนาระบบ
Prepare your CV and relevant portfolio. The button opens your email app with the role and job link filled in. Attach your files, review your message, and send it from your email app.
Open application emailOr compose an email to: career@woxacorp.com
Use the role title as your subject. Only send information relevant to your application.