Skip to content

Open nowPosted 30 days ago

Cloud DevSecOps Engineer (AI Products)

MyCareersFuture94,028 open roles

Pay
SGD 5,000 – SGD 6,800 a month
Where
Central, Singapore
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowCloud DevSecOps Engineer (AI Products)MyCareersFuture · Central, Singapore
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on MyCareersFuture's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.7% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.3%3 days
  3. 7.7%7 days
  4. 14.0%14 days
  5. 33.7%30 days
This job: posted 30 days ago

The posting

About the Role

We are seeking a Cloud DevSecOps Engineer (AI Products) to join our growing AI Product Engineering team. This role is ideal for someone passionate about cloud security, identity engineering, DevOps automation, and secure AI product delivery. You will be responsible for designing, securing, and automating the cloud infrastructure that powers our Retrieval-Augmented Generation (RAG) platform, ensuring that our deployments are scalable, resilient, and enterprise-ready.

Identity is central to this role. Microsoft Entra ID is the security backbone of our Azure estate, and you will own how workloads, pipelines, and users authenticate and authorize across the platform.

As part of a cross-functional team, you will collaborate with product managers, data scientists, and software engineers to ensure our AI products meet the highest standards of security, compliance, and performance.

Key Responsibilities

Identity & Access Management (Microsoft Entra ID)

  • Operate and extend identity for AI workloads in Microsoft Entra ID, including app registrations, service principals, enterprise applications, and workload identity federation.
  • Implement Conditional Access policies, MFA enforcement, and Privileged Identity Management (PIM) for just-in-time elevation of privileged roles.
  • Define and maintain custom Azure RBAC roles and scope assignments across management groups, subscriptions, and resource groups following least-privilege principles.
  • Run periodic access reviews and entitlement management to remove standing access and clean up orphaned identities.
  • Integrate Entra ID authentication into RAG application layers (OAuth 2.0 / OIDC, App Roles, group claims, token validation) and secure API access through Entra-protected endpoints.
  • Monitor identity risk and audit trails using Entra ID sign-in and audit logs, Identity Protection, and Microsoft Defender for Cloud, feeding signals into Log Analytics or Microsoft Sentinel.

Credential-Free Operations

  • Configure system-assigned and user-assigned managed identities for access to Key Vault, Azure OpenAI, Storage, AI Search, and databases, eliminating secrets from code and pipelines.
  • Use workload identity federation for Azure DevOps and GitHub Actions in place of long-lived service principal secrets.
  • Manage Key Vault policies, RBAC-based vault access, and secret and certificate rotation.

Cloud Architecture & Infrastructure

  • Design and maintain secure, scalable Azure cloud environments for AI product deployments.
  • Build and manage hub-and-spoke network topologies with appropriate segmentation, firewalls, and private endpoints.

DevSecOps & Automation

  • Develop and maintain Terraform scripts for Infrastructure-as-Code (IaC) to ensure consistent and repeatable deployments, including identity resources through the azuread and azurerm providers.
  • Implement CI/CD pipelines in Azure DevOps to automate testing, integration, and deployment of RAG workloads.
  • Embed security practices into DevOps pipelines, including IaC scanning, secret detection, dependency checks, and policy-as-code gates.

Cloud Security & Compliance

  • Strengthen security posture through encryption at rest and in transit, TLS enforcement, firewall rules, private endpoints, and least-privilege access.
  • Apply Azure Policy and landing zone guardrails to keep environments compliant as they scale.
  • Support audit and compliance activities with evidence drawn from platform and identity logging.

AI Product Enablement

  • Deploy and monitor containerized RAG workloads on Azure Container Apps and Kubernetes.
  • Support product teams in running secure and efficient large language model (LLM) workloads.
  • Contribute to best practices for secure and scalable AI infrastructure.

Qualifications

Required

  • Master's degree in Computer Science, Cybersecurity, or a related field.
  • 2 to 4 years of relevant professional experience in cloud security, DevOps, or infrastructure engineering.
  • Strong hands-on experience with Microsoft Entra ID as the identity backbone for Azure workloads: app registrations, service principals, managed identities, Conditional Access, PIM, and Azure RBAC design.
  • Strong hands-on experience with Azure cloud services, Terraform, and CI/CD pipelines.
  • Knowledge of containerization (Docker, Kubernetes) and cloud networking.
  • Understanding of security best practices, encryption, zero-trust identity models, and compliance frameworks.

Preferred

  • Experience implementing OAuth 2.0 / OIDC authentication flows in applications using Entra ID, including on-behalf-of flows for multi-tier RAG services.
  • Familiarity with Entra ID governance features (access reviews, entitlement management, administrative units) in a regulated or enterprise environment.
  • Experience automating identity configuration through Terraform (azuread provider), Microsoft Graph API, or Microsoft Graph PowerShell.
  • Exposure to Entra ID Protection, Defender for Identity, or Microsoft Sentinel for identity threat detection.
  • Experience with AI/ML product infrastructure (RAG, Azure OpenAI, Databricks, or similar).
  • Exposure to multi-cloud environments (AWS or GCP).
  • Familiarity with MLOps practices and monitoring AI workloads.

What We Offer

  • Opportunity to work on cutting-edge AI products that shape the future of infrastructure and urban planning.
  • Exposure to end-to-end product delivery, from architecture to deployment.
  • A collaborative environment where security, AI, and engineering meet.
  • Professional growth with mentorship and career progression in cloud security, DevSecOps, and AI infrastructure.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against MyCareersFuture's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on MyCareersFuture's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    MyCareersFuture's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.