- Jalan Tun Sambanthan Bandar Kuala Lumpur WP Kuala Lumpur Malaysia 50470

工作地点
职位描述
任职资格
Bachelor's degree in Computer Science, Information Technology, or a related field.
3–5 years of experience in Cloud Operations, DevOps, or related roles.
Demonstrated proficiency with at least one major cloud platform (AWS, Azure).
Must-have: Hands-on experience designing, building, and maintaining CI/CD pipelines in both Jenkins and GitHub Actions.
Must-have: Demonstrable, hands-on experience migrating pipelines from Jenkins to GitHub Actions (e.g., translating Jenkins files/Groovy pipelines into YAML workflows, re-platforming credentials/secrets, replicating multi-stage/approval logic, and validating parity post-migration).
Must-have: Experience configuring and administering GitHub Advanced Security features (code scanning/CodeQL, secret scanning with push protection, dependency review/Dependabot alerts) at repository and organization level.
Must-have: Experience integrating Nexus, Harbor, and SonarQube into CI/CD pipelines (artifact publishing/retrieval, image registry push/pull, and automated quality-gate enforcement).
Experience implementing standardized/organization-wide pipeline templates across multiple teams.
Experience enabling/handholding application teams through tooling migrations or adoptions, including producing documentation and reusable artifacts (templates, guides, runbooks) that support self-service adoption.
Experience working in cross-functional teams, including developers, operations, and security professionals.
Additional Details:
Location: Jalan Tun Sambathan, Kuala Lumpur
Type: Contract
Contract Duration: Until December 2026
Salary: Up to RM12,500.00
Working hours: Office Hours (Monday to Friday) ; able to stand by if required by the business
岗位职责
Implement the company standard pipeline, ensuring consistent, compliant build/release patterns are adopted across teams.
Design, build, and maintain CI/CD pipelines in Jenkins and GitHub Actions, ensuring security and quality checks are embedded at each stage.
Integrate Nexus (artifact/package repository), Harbor (container/image registry), and SonarQube (static code analysis/quality gates) into CI/CD pipelines, and manage their configuration, policies, and pipeline gating rules.
Lead or execute the migration of existing Jenkins pipelines to GitHub Actions workflows, preserving build integrity, secrets handling, approval gates, and deployment logic while modernizing the toolchain.
Configure, roll out, and operate GitHub Advanced Security — including code scanning (CodeQL), secret scanning (with push protection), and dependency review/Dependabot — across repositories, and tune policies to reduce noise while maintaining coverage.
Establish and maintain infrastructure-as-code practices for cloud resources and pipeline/workflow definitions (pipeline-as-code).
Collaborate with development, security, and operations teams to integrate automated security and quality testing tools (SAST/DAST/SCA, SonarQube quality gates) within CI/CD pipelines, including GitHub Actions and Jenkins.
Continuously assess and optimize cloud resources and CI/CD processes based on feedback and evolving best practices, including retiring legacy Jenkins jobs post-migration.
Define reusable GitHub Actions workflows, composite actions, and self-hosted runner strategy to standardize pipelines across teams.
Handhold application teams and DevOps tribes through the adoption of the modernized, standardized toolset (GitHub, GitHub Actions, GHAS, and related tools), providing direct enablement, pairing, and onboarding support.
Create and maintain documentation and reusable artifacts — templates, reusable workflows/composite actions, onboarding guides, and runbooks — so teams can self-serve adoption of standardized pipelines and tooling.
Explore and apply automation and AI-augmentation (e.g., AI-assisted pipeline authoring, automated triage of security findings, generative documentation) to improve the efficiency and productivity of DevOps activities.
Participate in and lead training sessions and workshops to enhance understanding of cloud technologies, the Allianz standard pipeline, GitHub Actions/Advanced Security, and DevSecOps principles.
Ensure all cloud, DevOps, and CI/CD practices comply with organizational policies, industry standards, and regulatory requirements.
Assist in conducting audits to review SDLC processes, pipeline configurations, and deployed systems for compliance with production efficiency and security protocols.
Maintain clear and effective communication with stakeholders to ensure alignment with business objectives, including reporting migration progress and security posture improvements.
好处
LRT - MASJID JAMEK
0.5 km
LRT - PLAZA RAKYAT
0.7 km
LRT - DANG WANGI
0.8 km
MRL - BUKIT NANAS
0.8 km
MRT - MERDEKA
0.9 km
LRT - BANDARAYA
0.9 km
KTM - BANK NEGARA
1.0 km
MRL - MEDAN TUANKU
1.0 km
MRT - PASAR SENI
1.1 km
LRT - PASAR SENI
1.1 km
MRL - RAJA CHULAN
1.1 km
MRT - BUKIT BINTANG
1.2 km
MRL - BUKIT BINTANG
1.2 km
MRL - HANG TUAH
1.2 km
MRL - IMBI
1.3 km
重要安全守则
申请工作时,切勿提供您的银行或信用卡详细资料。不要转账或完成无关的在线调查问卷。如果您发现可疑内容,请举报此招聘广告。