Job Overview
Senior DevSecOps Engineer
Vexere is a technology company aiming to revolutionize the travel and transportation industry in Vietnam. We are pioneering a comprehensive digital transformation of the transport industry with diverse web applications and latest technology apps. We are available on all super apps such as Grab, Momo, and Zalopay. Covering diverse vehicles from low-priced to luxury buses, with 1,000 bus operators on all over 3,000 routes, Vexere is the largest online inter-city bus booking platform that empowers millions of travelers to make their life journeys happier.
Want to secure a large-scale cloud-native platform with 100+ production services?
Want to turn DevSecOps strategy into practical controls across Kubernetes, CI/CD, cloud infrastructure, secrets management, observability, and public-facing systems?
Come to us to build and improve security for a modern microservices ecosystem using GitLab CI, Flux CD, Kubernetes, Vault, Cloudflare, OpenTelemetry, SigNoz, ELK, VictoriaMetrics, and other production-grade technologies. This is a hands-on engineering role, not a pure compliance or advisory role. You will work directly with a small DevOps team that owns both platform operations and security improvements, with autonomy to build scripts, CI templates, dashboards, runbooks, policies-as-code, and practical controls that reduce real production risks.
OUR PLATFORM & TECH STACK:
Infrastructure & Delivery:
- Multi-cloud Kubernetes environment
- GitLab CI and Flux CD as primary delivery paths
- 100+ production services
- Cloud infrastructure, databases, public websites, and WordPress deployments
Security & Access:
- Vault for secrets management
- IAM, RBAC, service accounts, internal users, database accounts, and privileged access paths
- Cloudflare for public perimeter controls
- Security controls for APIs, cloud storage, BigQuery, databases, and public-facing resources
Observability & Detection:
- OpenTelemetry, SigNoz, ELK, and VictoriaMetrics
- Logs, metrics, traces, dashboards, alerting, and incident investigation workflows
RESPONSIBILITIES:
- Own the DevOps security roadmap, risk register, control priorities, and quarterly maturity checkpoints.
- Lead continuous risk assessment across databases, backend APIs, frontend web and mobile surfaces, CI/CD, Kubernetes, cloud services, observability systems, and privileged access paths.
- Build and maintain security maps for system components, IAM roles, service accounts, internal users, database accounts, website administrators, and other sensitive access points.
- Facilitate lightweight threat modeling for public services, deployment paths, database access paths, and privileged internal tools.
- Implement and tune CI/CD security checks for secrets, dependencies, containers, IaC, manifests, and other supply-chain risks.
- Define and roll out Kubernetes security hardening baselines for workload policy, RBAC, network controls, runtime posture, and cluster access.
- Drive practical hardening for public websites, APIs, cloud storage, BigQuery, databases, and cloud services using proven frameworks such as DSOMM, OWASP SAMM, OWASP ASVS, and OWASP Top 10 where useful.
- Build dashboards and metrics to measure control effectiveness, detection coverage, remediation speed, privileged access reduction, and DevSecOps program health.
- Build and optimize alerts for suspicious access, secret exposure, public endpoint attacks, abnormal database activity, Kubernetes abuse, and other potential security threats.
- Create disaster recovery plans and lab scenarios for leaked credentials, critical vulnerabilities, compromised systems, and other high-impact incidents.
- Run quarterly disaster recovery exercises, review recovery effectiveness, and update response and restoration procedures.
- Lead security incident investigations and write concise incident reports, timelines, remediation items, and detection improvements.
- Write clear runbooks, short policies, exception rules, developer-facing remediation guidance, and post-mortem follow-up actions.
REQUIREMENTS:
Must-Have:
- Hands-on production Kubernetes security experience, including workload hardening, RBAC, admission policy, namespace controls, runtime detection, or network policy.
- CI/CD and supply-chain security experience with GitLab CI or similar systems.
- Hands-on secrets management experience, preferably with Vault.
- Solid cloud security fundamentals across IAM, networking, logging, storage exposure, and posture scanning.
- Experience in incident response using logs, timelines, containment, blast-radius analysis, root cause analysis, and remediation.
- Ability to automate security work using APIs, scripts, dashboards, or evidence generation.
- Application security fundamentals, including OWASP risks, SAST/SCA triage, threat modeling, secure deployment, and vulnerability prioritization.
- Observability experience with logs, metrics, traces, alerts, and production debugging.
- Strong written communication and async collaboration skills, especially in a remote or hybrid working environment.
- Ownership mindset and ability to work effectively in a small team where security priorities and daily platform operations both matter.
Nice-to-Have (Plus):
- Experience owning a DevSecOps roadmap, risk register, maturity plan, or recurring security review process for a production platform.
- Experience building platform security inventories or security maps for services, users, IAM, service accounts, databases, CI/CD paths, Kubernetes clusters, public endpoints, or cloud resources.
- Experience implementing CI/CD, IaC, Kubernetes, container, dependency, or secrets scanning controls and tuning them to reduce real production risk without creating excessive delivery friction.
- Familiarity with DSOMM, OWASP SAMM, OWASP ASVS, OWASP Top 10, or similar frameworks.
- Experience creating security dashboards, control metrics, detection alerts, access review evidence, incident timelines, or remediation tracking used operationally by engineering teams.
- Experience contributing to security incident response, credential leak handling, vulnerability response, disaster recovery exercises, or post-incident control improvements.
- CKS, cloud security, incident response, application security, or broad security certifications are helpful, but hands-on delivery matters more than certificates alone.
BENEFITS:
Competitive Compensation & Bonuses
- Attractive salary package with performance-based monthly bonuses.
- 100% salary during the probation period.
- 13th-month salary to ensure financial stability.
- Performance reviews twice a year with opportunities for salary adjustments.
Flexible Work & Growth Opportunities
- Hybrid working model with remote work and offline in-person meetings twice each week.
- Work directly with the DevOps Lead and collaborate with experienced CTOs, architects, and tech leaders at Vexere.
- Codex AI access to support research, analysis, automation, and documentation work.
- Opportunity to secure a cloud-native microservices platform with meaningful production scale.
- Startup environment with low bureaucracy, no micromanagement, and direct ownership.
- Freedom to research, test, and apply new technologies when they provide practical value.
- Build your public profile through publishing technical articles, contributing to open-source projects managed by Vexere, and joining tech talks or industry events.
- Attractive stock options for dedicated developers and team leads.
Exclusive Employee Perks
- Up to 30% discount on bus tickets for Vexere employees and their families.
- 12 days of annual leave, with 1 extra day off every 3 years, convertible into salary.
- Vibrant and dynamic work environment with a friendly, supportive team.
- Training sessions on negotiation, communication, work management, interpersonal skills, and software technology.
- Exciting company activities: annual trips, team-building events, year-end parties, and more.
What factors can help you trust Vexere?
Currently, Vexere is the largest online bus ticketing platform in Vietnam with more than 1000 inter-city bus companies, covering over 3,000 domestic and cross-border routes to help users find bus information and buy tickets online easily. At the same time, Vexere also provides reviews of passengers who have traveled these buses. Passengers can simply select their favorite seats, pay online, or pay in cash at convenience stores across the country.
Vexere Bus Management System (BMS) is used by more than 700 bus companies all over the country, helping bus companies to modernize management with effective management, optimized revenue, and costs. This is a revolution in the inter-city bus industry.
Over 5,000 agents are using Vexere Agent Management System to increase ticket sales and serve their customers better.
Vexere’s efforts have been recognized and accompanied by famous institutional investors such as Woowa Brothers, CyberAgent Ventures, BonAngels, Pix Vine Capital, Spiral Ventures, Access Ventures, and NCore Ventures. Two investors of Vexere are Decacorns with valuation above USD10B.
For more information, please contact us via:
- Send your Resume to email: careers@vexere.com, with title: Fullname – Applied Position
- Phone/ Zalo: 0966 197 741 ( Mr. Anh)
- Office Location: Vexere Trading Service Co., Ltd – 2nd floor – Building H3, 384 Hoang Dieu, Ward 6, District 4, HCMC
- Working Hours: Hybrid Working 8:30 am – 6:00 pm from Monday to Friday, and Saturday morning.
