Senior DevOps Engineer - Cloud Security

1 openings in Jakarta, Indonesia


About the Role


At Vidio, we deliver high-quality content to millions of users at streaming scale — managing massive live broadcasts, sharp traffic spikes, and infrastructure that must remain resilient, performant, and secure under peak load.

This role owns the security posture of that infrastructure. Rather than auditing after the fact or creating passive tickets, you will build automated guardrails directly into the platform so that misconfigurations are hard or impossible to commit in the first place.

What You'll Own

 
  • Cloud Security Posture: Maintain continuous configuration assessment across our environment against CIS benchmarks, implement real-time drift detection, and drive findings to active remediation.

 
  • Guardrails as Code: Architect Cloud Organization Policy, policy-as-code (OPA/Rego, Kyverno), and secure-by-default Terraform modules to prevent misconfigurations upstream in development.

 
  • IAM & Least-Privilege at Scale: Design structured access reviews, central secrets lifecycle, automated key rotation, and eliminate standing over-permissive privileges.

 
  • Host & Compute Hardening: Build and maintain golden base images, enforce CIS-benchmarked OS baselines, maintain predictable patching cycles, and establish robust bastion/IAP SSH controls.

 
  • Endpoint Hardening (~30% of role): Enforce MDM, EDR, full disk encryption, and baseline OS controls across the engineering laptop fleet.

 
  • CI/CD & Automation Security: Shift security controls left into CI/CD pipelines and infrastructure tooling with an "everything-as-code" discipline.

 
  • Engineering Enablement: Build secure, frictionless "paved roads" so security is the easiest default path.

 
  • Streaming-Scale Performance: Scale all security systems to handle high volume of concurrent requests without degrading system throughput or developer velocity.




Requirements


1. Cloud Security (Required)

 
  • IAM Architecture: Deep understanding of least-privilege identity architecture, federated identity, and role boundaries.

 
  • OS & Host Hardening: Practical implementation of CIS benchmarks, audit logging, and minimized attack surfaces.

 
  • Secrets & Cryptography: Hands-on secrets lifecycle management and modern encryption standards (at-rest and in-transit).

 
  • Preventive Mindset: A strong architectural preference for automated guardrails over manual ticketing workflows.

 


2. DevOps Foundation

 
  • Linux Administration: Strong operational and debugging experience in production Linux environments.

 
  • Infrastructure as Code: Production proficiency with Terraform (or Ansible/Chef/Puppet).

 
  • Container Orchestration: Hands-on experience with Docker and Kubernetes in production environments.

 
  • Scripting & Software Engineering: Comfort with at least one high-level language (Python, Go, or Ruby) along with shell scripting.

 
  • Networking & Protocols: Solid understanding of DNS, TCP/IP, HTTP/HTTPS, TLS termination, and CDN edge architectures.

 
  • Cloud Platforms: Hands-on operational experience with at least one major cloud provider (GCP, AWS, or Azure).




3. Bonus Points

 
  • CSPM Tooling: Real-world experience deploying or operationalizing CSPM platforms (Wiz, Prowler, Scout Suite, AWS Security Hub, or GCP Security Command Center).

 
  • Endpoint Fleet Management: Hands-on experience with enterprise MDM solutions (Jamf, Microsoft Intune, Kandji).

 
  • Certifications: Industry-recognized credentials such as AWS Certified Security – Specialty, CKS (Certified Kubernetes Security Specialist), or equivalent GCP certifications.

 
  • Observability: Telemetry and alerting experience using Datadog, Prometheus, Grafana, or OpenTelemetry.

 
  • High-Throughput Workloads: Prior experience with high-concurrency streaming or real-time media platforms.

 
  • Compliance Exposure: Working knowledge of standards such as PCI-DSS, SOC 2, or ISO 27001.

 
  • Modern Developer Tooling: Pragmatic experience using AI/LLM tooling to safely accelerate IaC authoring, runbook creation, and incident triage.



What are we about?

We are building services for everyone in Indonesia — defining the digital landscape of our 13k island archipelago.

We embrace change, but it doesn't mean we work crazy hours.

We maintain a sustainable pace (8 hour days, no overtime, no nights or weekends) because everyone needs a life.

Some of your future coworkers:

Yohan Ardiansyah
Yohan
Rahmat Sanjaya
Rahmat
Daniel Fablius
Daniel
Bobby
Bobby
Abdulmunaf Abdulaziz Chhatra
Abdulmunaf
Muhammad Muis Muhidin
Muhammad
Apply Now

Follow Us On