DevSecOps Engineer
Summary
Build and secure CI/CD pipelines for government cloud workloads using GitLab CI/CD, SHIP-HATS, and AWS, integrating vulnerability scanning and compliance checks.
Role: DevSecOps Engineer
JD:
What You Will Be Working On
• Design, maintain, and optimize of CI/CD pipelines using GitLab CI/CD and SHIP-
HATS across development, UAT, staging, and production environments.
• Implement secure and reliable deployment automation, including approval
workflows, quality gates, audit trails, rollback procedures, and release controls.
• Support cloud operations across AWS and GCC environments, including
infrastructure configuration, environment management, operational monitoring,
and production support.
• Develop and maintain automation scripts, reusable pipeline templates, operational
runbooks, and deployment standards to improve consistency and reduce manual
effort.
• Integrate security controls into CI/CD pipelines, including vulnerability scanning,
dependency checks, secrets management, code quality validation, and compliance
checks.
• Monitor application, infrastructure, and pipeline health through enterprise
monitoring tools, dashboards, alerts, and log analysis.
• Support release management activities and coordinate deployment planning with
development, infrastructure, security, and operations teams.
• Conduct root cause analysis for deployment, pipeline, application, infrastructure,
and cloud-related incidents, and drive corrective and preventive actions.
• Execute configuration and infrastructure changes through established change
management processes with proper documentation and risk controls.
• Maintain access controls and conduct regular access reviews across DevOps
platforms, repositories, cloud environments, and deployment tools.
• Support vulnerability management, audit requests, security compliance reviews,
and remediation tracking in accordance with government requirements.
What We Are Looking For
• Degree in Computer Science, Software Engineering, or a relevant IT field with 3+
years of relevant experience in DevOps, platform engineering, systems engineering,
or cloud operations.
• Hands-on experience designing, managing, and troubleshooting GitLab CI/CD
pipelines in enterprise or government environments.
• Experience with SHIP-HATS or similar DevSecOps delivery platforms, including
secure pipeline configuration and release governance.
• Experience with monitoring tools, log analytics platforms, alerting frameworks, and
incident investigation techniques.
• Strong working knowledge of AWS cloud services and experience supporting cloud-
hosted workloads.
• Strong knowledge of Infrastructure-as-Code tools such as Terraform, Bicep, or
CloudFormation.
• Ability to work independently, manage multiple priorities, and provide technical
guidance to project and operations teams.
• Strong communication and documentation skills for engaging both technical and
non-technical stakeholders.
Preferred Skills:
• Prior experience working on Singapore Government projects or within a public
sector agency, including familiarity with government development standards, tools
(e.g., SHIP/HATS), and compliance requirements, will be a strong advantage.
• Knowledge of zero-trust architectures and secure cloud landing zones.
• Exposure to data platforms, analytics workloads, or AI/ML pipelines.
• Relevant certifications (e.g. AWS/Azure DevOps, Kubernetes, Terraform).
• Experience with cloud security frameworks, automated testing frameworks and
quality assurance processes.
• Strong analytical thinking and systematic problem-solving approach.
• Excellent documentation and communication skills for technical and non-technical
stakeholders.
• Detail-oriented focus on system reliability, security, and performance optimisation.
• Collaborative mindset for working effectively with development and operations
teams.