SE
DevOps Engineer — Senang.io
- Hiring from
- Malaysia
- Work type
- Hybrid
- Posted
- Sep 27, 2026
Is this job info correct?
Reports to: CEO/ HEAD OF ENGINEERING
Location: Kuala Lumpur (or remote with regular on-site)
Works closely with: CISO (independent function — you'll support their evidence and control requests, not own them)
Role SummaryOwn and run Senang.io's cloud infrastructure and production operations end-to-end, including completing the in-progress monitoring stack consolidation. This is a hands-on execution role focused on infrastructure reliability and observability — not a security-policy or compliance-ownership role.
Key Responsibilities- Own Azure infrastructure day-to-day: AKS/Kubernetes, MySQL, Azure Firewall Premium, Application Gateway WAF V2, Microsoft Defender, Azure Monitor
- Finish consolidating the monitoring stack (Kibana/ELK, Prometheus, Grafana, Uptime Kuma, Wazuh, SonarQube) into a single Grafana dashboard with tiered alerting; clear the stalled integration tickets
- Take the SIEM from proof-of-concept to fully operational
- Manage FusionAuth, Power Automate flows, JIRA-tracked infra work, and PagerDuty on-call rotation
- Execute incident response (detect, contain, remediate, escalate per plan) — policy and post-incident reporting sit with the CISO
- Provide technical documentation and evidence (configs, logs, change records) when the CISO or an external auditor requests it — you're the source of truth on the systems, not the one interpreting regulatory requirements
- 4–6 years in a DevOps/infrastructure/SRE role, with real production ownership (not just project-based cloud work)
- Hands-on Azure experience is strongly preferred; solid AWS/GCP experience is acceptable if willing to convert
- Has taken at least one monitoring tool or SIEM from setup/POC through to production use
- Comfortable owning a live production environment with genuine on-call responsibility
- Kubernetes (AKS or equivalent) — deployments, scaling, troubleshooting at a working level
- Cloud networking and security groups/firewalls (Azure Firewall, WAF, or equivalent)
- At least one observability stack (ELK, Prometheus/Grafana, or similar) configured from scratch, not just dashboards inherited from someone else
- Infrastructure-as-code basics (Terraform, ARM/Bicep, or equivalent)
- Identity/auth systems (FusionAuth, Auth0, Keycloak, or similar)
- Exposure to a regulated industry (banking, insurance, fintech) — helpful context, not a filter
- Any BNM RMiT / MAS TRM / ISO 27001 familiarity — bonus, but the CISO covers this
- CKA or similar certification