DevOps 工程師 | DevOps Engineer
Technology
十論科技股份有限公司
台北市, 台灣4週前截至 2026/9/13
全職現場辦公
職缺描述
工作內容
- 地端架構設計與自動化部署: 負責企業客戶地端 (On-premise) 基礎架構的評估與建置規劃,涵蓋裸機 (Bare Metal)、企業級虛擬化環境 (如 VMware) 及地端 Kubernetes 叢集 的自動化配置與生命週期管理。
- DevSecOps 與企業級安全合規: 將極致的資安標準無縫整合至軟體開發生命週期 (SDLC)。實施源碼掃描 (SAST/DAST)、軟體物料清單 (SBOM) 管理與容器弱點掃描,並積極配合企業客戶進行滲透測試、漏洞修補與資安合規稽核 (如 ISO 27001, 零信任架構)。
- 封閉網路 (Air-gapped) CI/CD 管線建置: 設計並維護適用於無網際網路連線或高資安限制環境的持續整合與持續交付流程。自建並管理內網專用的程式碼代管與軟體資源庫 (如 ,確保交付過程的高效與絕對安全。
- 系統網路安全與存取控制: 嚴格設計系統邊界與內部網路的防護機制。設定防火牆規則、網路隔離 (Network Segmentation)、反向代理 (Reverse Proxy),並落實基於角色的存取控制 (RBAC) 與最小權限原則 (PoLP),防止未授權的橫向移動與資料外洩。
- 地端系統可觀測性與日誌稽核: 建置可完全獨立運作的地端監控、日誌收集與分析平台 (如 Prometheus, Grafana, ELK/EFK Stack)。確保所有系統行為、API 呼叫與管理員操作皆具備完整的軌跡紀錄 (Audit Trails),並設計符合企業資安規範的即時告警機制。
- 軟體交付與升級機制封裝: 針對地端環境的特殊性,將複雜的微服務架構封裝為易於交付、安裝與驗證的格式 (如 Helm Charts, 離線安裝包、OVA 映像檔)。建立標準化的部署手冊,確保產品能在客戶端環境中平滑升級、降版與災難復原。
- On-premise architecture design and automated deployment: Own assessment and build planning for enterprise customers' on-premise infrastructure—covering automated provisioning and lifecycle management across bare metal, enterprise virtualization (e.g., VMware), and on-premise Kubernetes clusters (e.g., Rancher, OpenShift, Kubespray).
- DevSecOps and enterprise-grade security compliance: Integrate uncompromising security into the SDLC. Implement source code scanning (SAST/DAST), SBOM management, and container vulnerability scanning, while supporting customers through penetration testing, vulnerability remediation, and compliance audits (e.g., ISO 27001, Zero Trust).
- Air-gapped CI/CD pipeline development: Design and maintain CI/CD pipelines for environments with no internet connectivity or stringent security constraints. Build and operate self-hosted, intranet-only code hosting and repositories to keep delivery both efficient and absolutely secure.
- System network security and access control: Rigorously design protections for system boundaries and internal networks. Configure firewall rules, network segmentation, and reverse proxies, and enforce RBAC and the principle of least privilege (PoLP) to prevent unauthorized lateral movement and data exfiltration.
- On-premise system observability and log auditing: Build fully self-contained on-premise monitoring, log collection, and analytics platforms. Ensure all system behaviors, API calls, and admin actions are captured in audit trails, and design real-time alerting that meets enterprise security requirements.
- Software delivery and upgrade packaging: Package complex microservice architectures into formats easy to deliver, install, and validate for on-premise environments. Establish standardized deployment runbooks for smooth upgrades, rollbacks, and disaster recovery in customer environments.
條件要求
- 資訊工程、資訊管理或相關領域學士以上學位,具備 1 年以上 DevOps、SRE 或大型系統維運實務經驗,且具備明確的地端 (On-premise) 系統建置實績。
- 精通 Linux 作業系統核心原理、系統維運與效能調優,能運用底層工具進行複雜問題的除錯與排障。
- 具備紮實的企業網路基礎知識,深入理解 TCP/IP、DNS、VPN、VLAN、防火牆策略、負載平衡機制以及 PKI (公鑰基礎建設) 與憑證管理。
- 具備豐富的 Kubernetes 地端建置與維護經驗 (包含但不限於使用 Kubeadm 或 Kubespray 進行裸機安裝),而不僅限於操作公有雲代管服務 (如 EKS/GKE)。
- 熟練掌握自動化組態管理與 IaC (基礎架構即程式碼) 工具 (如 Ansible, Terraform),能將手動的地端維運作業轉化為具備版控的自動化腳本。
- 具備強烈的資安意識,熟悉作業系統層級的安全防護與存取控制機制 (如 SELinux, AppArmor, Iptables/nftables)。
- 熟練掌握至少一種程式語言或系統腳本語言 (如 Python, Go, Bash),能夠針對地端維運的特殊需求開發客製化工具。
- Bachelor's in CS, IT, or related field; 1+ years in DevOps/SRE/large-scale ops, with a demonstrable on-premise build track record.
- Deep Linux internals, ops, and performance tuning; able to debug complex issues with low-level tools.
- Solid enterprise networking: TCP/IP, DNS, VPN, VLAN, firewalls, load balancing, and PKI/certificate management.
- Hands-on on-premise Kubernetes (bare-metal via Kubeadm/Kubespray) — not just managed cloud (EKS/GKE).
- Strong IaC/config management (Ansible, Terraform) to turn manual ops into version-controlled automation.
- Security mindset: OS-level hardening and access control (SELinux, AppArmor, iptables/nftables).
- Proficient in at least one language for custom tooling (Python, Go, Bash).
遠端型態
部分遠端面試 第一次面試可以遠端進行, 第一次面試需要 Onsite進行。加分條件
- 具備於半導體產業、金融機構、政府機關、國防或醫療等高監管產業進行系統建置、維運與合規稽核的實戰經驗。
- 擁有封閉網路 (Air-gapped environments) 的軟體架構設計、離線部署與日常維運經驗。
- 熟悉企業級虛擬化解決方案的管理與自動化操作 (如 VMware vSphere/ESXi, KVM, Nutanix)。
- 持有具公信力的資安專業認證 (如 CISSP, CEH, CompTIA Security+) 或 Kubernetes 安全管理認證 (CKS)。
- 具備各類靜態與動態應用程式安全測試工具 (如 SonarQube, Checkmarx, Trivy, DefectDojo) 的導入與整合經驗。
- 熟悉資料庫在地端環境的高可用性架構設計、備援機制與資料加密 (Data at Rest / Data in Transit) 規範。
- 具備半導體、材料科學、物理模擬或科學計算等相關領域背景或產業知識者佳(歡迎但非必要)。
- Experience building/operating/auditing systems in regulated industries (semiconductors, finance, government, defense, healthcare).
- Air-gapped environment design, offline deployment, and operations.
- Enterprise virtualization (VMware vSphere/ESXi, KVM, Nutanix).
- Security certs (CISSP, CEH, Security+) or Kubernetes CKS.
- SAST/DAST tooling (SonarQube, Checkmarx, Trivy, DefectDojo).
- On-prem database HA, redundancy, and encryption (data at rest / in transit).
- Background in semiconductors, materials science, physics simulation, or scientific computing (a plus).
員工福利
法定項目
週休二日、家庭照顧假、勞保、健保、陪產假、產假、特別休假、育嬰留停、女性生理假、勞退、安胎假、產檢假、就業保險、防疫照顧假、員工體檢、職災保險、婚假其他福利
- 休假制度:年假
- 獎金福利制度:年終獎金、績效獎金、專利與創新獎勵
- 專業發展與學習支持:
a. 提供線上或實體課程補助、證照考試費用補貼。
b. 定期舉辦相關講座、工作坊以及讀書會。
c. 支持員工進行創新專案,提供額外的經費與資源。
- 成長空間:加入充滿活力的團隊,參與核心產品開發,實現個人技術成長與價值。
- 其他:免費飲料、咖啡、餅乾;員工聚餐;員工健康檢查。
- Leave Policy: Annual Leave
- Bonus and Welfare System: Year-End Bonus, Performance Bonuses, and Patent & Innovation Rewards
- Professional Development and Learning Support a. Subsidies for online or in-person courses and certification exam fees.
b. Regularly organized lectures, workshops, and book clubs.
c. Support for innovative projects with additional funding and resources.
- Growth Opportunities Join a dynamic team and contribute to core product development, fostering personal technical growth and value realization.
- Additional Perks a. Complimentary beverages, coffee, and snacks.
b. Team meals and gatherings.
c. Employee health check-ups.
薪資範圍
面議(經常性薪資達4萬元) 已收藏Keywords
development-operations-devopskubernetesdevsecopssoftware-development-lifecyclesystems-development-life-cycle-sdlcstatic-application-security-testing-sastdynamic-application-security-testing-dastsoftware-bill-of-materials-sbomsi-o-memory-peripheral-connectorsinternational-organization-for-standardization-isoincentive-stock-options-isoiso-iec-27001-2013customer-intelligence-cicontinuous-integrationcd-certificate-of-depositci-cdreverse-proxyrole-based-access-control-rbacprometheusgrafana
對這個職缺感興趣嗎?