Cloud DevSecOps Engineer (AI Products)

Meinhardt Singapore · Singapore

Sector
AI
Function
Product & Engineering
Level
Mid-Level
Employment type
Full Time
Posted
2026-09-01
Source
mycareersfuture

About the RoleWe are seeking a Cloud DevSecOps Engineer (AI Products) to join our growing AI Product Engineering team. This role is ideal for someone passionate about cloud security, identity engineering, DevOps automation, and secure AI product delivery. You will be responsible for designing, securing, and automating the cloud infrastructure that powers our Retrieval-Augmented Generation (RAG) platform, ensuring that our deployments are scalable, resilient, and enterprise-ready.Identity is central to this role. Microsoft Entra ID is the security backbone of our Azure estate, and you will own how workloads, pipelines, and users authenticate and authorize across the platform.As part of a cross-functional team, you will collaborate with product managers, data scientists, and software engineers to ensure our AI products meet the highest standards of security, compliance, and performance.Key ResponsibilitiesIdentity & Access Management (Microsoft Entra ID)Operate and extend identity for AI workloads in Microsoft Entra ID, including app registrations, service principals, enterprise applications, and workload identity federation.Implement Conditional Access policies, MFA enforcement, and Privileged Identity Management (PIM) for just-in-time elevation of privileged roles.Define and maintain custom Azure RBAC roles and scope assignments across management groups, subscriptions, and resource groups following least-privilege principles.Run periodic access reviews and entitlement management to remove standing access and clean up orphaned identities.Integrate Entra ID authentication into RAG application layers (OAuth 2.0 / OIDC, App Roles, group claims, token validation) and secure API access through Entra-protected endpoints.Monitor identity risk and audit trails using Entra ID sign-in and audit logs, Identity Protection, and Microsoft Defender for Cloud, feeding signals into Log Analytics or Microsoft Sentinel.Credential-Free OperationsConfigure system-assigned and user-assigned managed identities for access to Key Vault, Azure OpenAI, Storage, AI Search, and databases, eliminating secrets from code and pipelines.Use workload identity federation for Azure DevOps and GitHub Actions in place of long-lived service principal secrets.Manage Key Vault policies, RBAC-based vault access, and secret and certificate rotation.Cloud Architecture & InfrastructureDesign and maintain secure, scalable Azure cloud environments for AI product deployments.Build and manage hub-and-spoke network topologies with appropriate segmentation, firewalls, and private endpoints.DevSecOps & AutomationDevelop and maintain Terraform scripts for Infrastructure-as-Code (IaC) to ensure consistent and repeatable deployments, including identity resources through the azuread and azurerm providers.Implement CI/CD pipelines in Azure DevOps to automate testing, integration, and deployment of RAG workloads.Embed security practices into DevOps pipelines, including IaC scanning, secret detection, dependency checks, and policy-as-code gates.Cloud Security & ComplianceStrengthen security posture through encryption at rest and in transit, TLS enforcement, firewall rules, private endpoints, and least-privilege access.Apply Azure Policy and landing zone guardrails to keep environments compliant as they scale.Support audit and compliance activities with evidence drawn from platform and identity logging.AI Product EnablementDeploy and monitor containerized RAG workloads on Azure Container Apps and Kubernetes.Support product teams in running secure and efficient large language model (LLM) workloads.Contribute to best practices for secure and scalable AI infrastructure.QualificationsRequiredMaster's degree in Computer Science, Cybersecurity, or a related field.2 to 4 years of relevant professional experience in cloud security, DevOps, or infrastructure engineering.Strong hands-on experience with Microsoft Entra ID as the identity backbone for Azure workloads: app registrations, service principals, managed identities, Conditional Access, PIM, and Azure RBAC design.Strong hands-on experience with Azure cloud services, Terraform, and CI/CD pipelines.Knowledge of containerization (Docker, Kubernetes) and cloud networking.Understanding of security best practices, encryption, zero-trust identity models, and compliance frameworks.PreferredExperience implementing OAuth 2.0 / OIDC authentication flows in applications using Entra ID, including on-behalf-of flows for multi-tier RAG services.Familiarity with Entra ID governance features (access reviews, entitlement management, administrative units) in a regulated or enterprise environment.Experience automating identity configuration through Terraform (azuread provider), Microsoft Graph API, or Microsoft Graph PowerShell.Exposure to Entra ID Protection, Defender for Identity, or Microsoft Sentinel for identity threat detection.Experience with AI/ML product infrastructure (RAG, Azure OpenAI, Databricks, or similar).Exposure to multi-cloud environments (AWS or GCP).Familiarity with MLOps practices and monitoring AI workloads.What We OfferOpportunity to work on cutting-edge AI products that shape the future of infrastructure and urban planning.Exposure to end-to-end product delivery, from architecture to deployment.A collaborative environment where security, AI, and engineering meet.Professional growth with mentorship and career progression in cloud security, DevSecOps, and AI infrastructure.

Apply on mycareersfuture →
AI Git Microsoft Azure Terraform Kubernetes Requirement Specification Azure DevOps Enforcement