DevSecOps Engineer
Role: DevSecOps Engineer JD: What You Will Be Working On
- Design, maintain, and optimize of CI/CD pipelines using GitLab CI/CD and SHIP-
HATS across development, UAT, staging, and production environments.
- Implement secure and reliable deployment automation, including approval
workflows, quality gates, audit trails, rollback procedures, and release controls.
- Support cloud operations across AWS and GCC environments, including
infrastructure configuration, environment management, operational monitoring, and production support.
- Develop and maintain automation scripts, reusable pipeline templates, operational
runbooks, and deployment standards to improve consistency and reduce manual effort.
- Integrate security controls into CI/CD pipelines, including vulnerability scanning,
dependency checks, secrets management, code quality validation, and compliance checks.
- Monitor application, infrastructure, and pipeline health through enterprise
monitoring tools, dashboards, alerts, and log analysis.
- Support release management activities and coordinate deployment planning with
development, infrastructure, security, and operations teams.
- Conduct root cause analysis for deployment, pipeline, application, infrastructure,
and cloud-related incidents, and drive corrective and preventive actions.
- Execute configuration and infrastructure changes through established change
management processes with proper documentation and risk controls.
- Maintain access controls and conduct regular access reviews across DevOps
platforms, repositories, cloud environments, and deployment tools.
- Support vulnerability management, audit requests, security compliance reviews,
and remediation tracking in accordance with government requirements.
What We Are Looking For
- Degree in Computer Science, Software Engineering, or a relevant IT field with 3+
years of relevant experience in DevOps, platform engineering, systems engineering, or cloud operations.
- Hands-on experience designing, managing, and troubleshooting GitLab CI/CD
pipelines in enterprise or government environments.
- Experience with SHIP-HATS or similar DevSecOps delivery platforms, including
secure pipeline configuration and release governance.
- Experience with monitoring tools, log analytics platforms, alerting frameworks, and
incident investigation techniques.
- Strong working knowledge of AWS cloud services and experience supporting cloud-
hosted workloads.
- Strong knowledge of Infrastructure-as-Code tools such as Terraform, Bicep, or
CloudFormation.
- Ability to work independently, manage multiple priorities, and provide technical
guidance to project and operations teams.
- Strong communication and documentation skills for engaging both technical and
non-technical stakeholders.
Preferred Skills:
- Prior experience working on Singapore Government projects or within a public
sector agency, including familiarity with government development standards, tools (e.g., SHIP/HATS), and compliance requirements, will be a strong advantage.
- Knowledge of zero-trust architectures and secure cloud landing zones.
- Exposure to data platforms, analytics workloads, or AI/ML pipelines.
- Relevant certifications (e.g. AWS/Azure DevOps, Kubernetes, Terraform).
- Experience with cloud security frameworks, automated testing frameworks and
quality assurance processes.
- Strong analytical thinking and systematic problem-solving approach.
- Excellent documentation and communication skills for technical and non-technical
stakeholders.
- Detail-oriented focus on system reliability, security, and performance optimisation.
- Collaborative mindset for working effectively with development and operations
teams.