DevSecOps Engineer (Application & Endpoint)

 Posted 14 hours ago
     
2-5 years experience
Apply Now

Please mention DailyRemote when applying

AI Summary

Own the technical security layer for code, delivery pipelines, and developer endpoints by automating security controls within CI/CD workflows. Responsibilities include managing software supply-chain security, tuning AI-assisted SAST pipelines, and acting as the primary technical responder for security incidents.

Location: Kuala Lumpur, Malaysia

Role: DevSecOps Engineer (Application & Endpoint)

Department: Backend

About Respond.io

Founded in Hong Kong in early 2017, respond.io is an AI-powered business messaging platform that helps companies manage customer conversations across chat, calls and email — all in one place.

Trusted by businesses in over 127 countries and recognized by G2 and SME100, respond.io enables fast-growing companies around the world to capture, convert, and retain customers at scale.

We operate as a globally distributed team with employees based around the world, contributing to a diverse and inclusive culture. Join us, and be part of a team that is shaping the future of customer conversation management!

Our Culture

At respond.io, we move fast, work smart, and always keep our customers at the heart of what we do. Here’s what we stand for:

  • Solve Customer Problems: Every effort must solve real customer pain points. No guesswork—just real feedback and clear value!
  • The 80/20 Rule: We focus on 20% of actions that create 80% of the value. Simple is powerful—it gets us moving fast.
  • 100% Alignment, 80% Accuracy: We aim 100% team alignment and 80% accuracy. Perfect plans can wait—clear goals come first.
  • Be Direct: We give honest feedback, and tackle problems head-on. Clarity moves us forward!
  • Own It and Support Each Other: We step up, help out, and drive outcomes—together.
  • Build Human Connections: Work is better when we trust, care, and celebrate wins together. We’re a team!

Role Description

At respond.io, security is a platform engineering discipline, not a gate. Our security team builds Secure SDLC capabilities (software supply-chain security, SAST, and DevSecOps automation) so developers can ship secure software fast. We apply AI and agent technologies to code review, vulnerability analysis, and false-positive reduction, and we embed security controls directly into CI/CD and developer workflows.

We are hiring a DevSecOps Engineer (Application & Endpoint Security) to own the technical security layer around our code, delivery pipelines, cloud telemetry, and developer endpoints. You will turn security policy into enforced, automated configuration without slowing developer velocity.

This is a hands-on engineering role. You will write code, tune tooling, build detections, and respond to incidents. A separate DevSecOps (GRC) role owns compliance audits (SOC 2, ISO 27001, GDPR), vendor risk, and policy governance. You will partner with them, not duplicate them.

Key Responsibilities

Software Supply-Chain Security

  • Own dependency and container security across our Node.js ecosystems (npm, pnpm, yarn) using Socket.dev, Dependabot, and AWS ECR image scanning.
  • Enforce dependency vulnerability, OSS license, and container image policies directly in CI/CD, using reachability analysis to prioritize what is actually exploitable.

Application Security Testing (SAST, Penetration)

  • Own and tune our AI-assisted SAST pipeline: automated code review, vulnerability analysis, and reachability-based false-positive reduction.
  • Run the annual third-party pentest end to end: scoping, vendor selection, access provisioning, findings triage, severity calibration, remediation tracking, and retest sign-off.

GitHub Organization Security

  • Operate secret scanning with push protection; own remediation of leaked credentials.
  • Harden GitHub Actions workflows: OIDC for cloud authentication, actions pinned to commit SHAs, and minimally scoped workflow permissions.

Detection Engineering & SIEM

  • Build and operate our centralized SIEM: ingest and correlate logs from MDM, EDR, GuardDuty, CloudTrail, the EC2 fleet, and GitHub events/audit logs.
  • Author and maintain detection rules that turn raw telemetry into high-signal, actionable alerts, and measure and reduce false-positive rates.

Endpoint Security

  • MDM security configuration and EDR tuning, exclusions and alert investigation.
  • Triage and resolve MDM/EDR security signals across all developer machines.

Incident Response

  • Act as the primary technical responder for live security incidents: containment, isolation, forensic evidence capture, and hotfix coordination with engineering teams.
  • Coordinate disclosure and reporting with the GRC function.

Continuous Improvement

  • Track developments in application security, supply-chain security, and AI-assisted security engineering, and fold proven improvements back into our tooling and workflows.

What We’re Looking For

  • 3+ years in Application Security, DevSecOps or Security Engineering with strong AppSec fundamentals (OWASP Top 10, secure code review, threat modeling).
  • Working proficiency in Node.js/JavaScript: able to read production code, trace a vulnerability to its root cause, and validate that a fix is correct.
  • Hands-on SCA and SAST experience: deploying and tuning tools such as Socket.dev, Semgrep, Trivy, or TruffleHog including reachability-based prioritization and validating AI-generated findings before acting on them.
  • CI/CD and GitHub hardening experience: branch protection, secret scanning, Actions security (OIDC, pinned actions, scoped permissions), and SSO/token governance at the organization level.
  • AWS security telemetry experience: CloudTrail, GuardDuty, and audit logs, including standing up a SIEM (or equivalent log pipeline) and writing detection rules.
  • Security automation experience: you have built security tools, scanners, CI plugins, or internal engineering tooling; scripting in Python, TypeScript, or Bash.
  • MDM/EDR experience: investigating and triaging endpoint security signals from tools such as CrowdStrike and Jamf.
  • Pentest coordination experience: managing external testers, triaging findings, and driving remediation.
  • Clear written and spoken English: able to explain risk and remediation directly to backend engineers.

What's in it for you

  • You will become part of an amazing culture with smart, collaborative teammates who actually care about each other's growth and success.
  • You will grow more here than you would anywhere else, that is a promise.
  • Virtual events like talent shows, Among Us nights, and online game sessions to keep the fun going, no matter where you are!
  • We offer a highly competitive compensation package.
  • You'll receive a mental health allowance to support your health and wellness needs.
  • Flexible working environment and working hours that fit your lifestyle, wherever you're based.

Similar Jobs

See all Remote Software Development jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified