The posting
Responsibilities
- Design, implement and maintain secure CI/CD pipelines using GitLab and SHIP-HATS, including runners, branching/merge controls and access management.
- Integrate Fortify, Nexus IQ and SonarQube into CI/CD pipelines and implement appropriate security and quality gates.
- Apply shift-left security practices across the SDLC, covering code, dependencies, containers and application deployments.
- Automate application build, testing, security scanning and deployment across development and production environments.
- Support containerised application deployment using Docker and Kubernetes/EKS.
- Manage pipeline credentials, secrets and service accounts securely.
- Develop reusable pipeline templates and standardise DevSecOps practices across AE applications.
- Troubleshoot pipeline, security scanning and deployment issues and support developers in resolving identified findings.
Experience and Skills Needed
- Degree or Diploma in Computer Science, Information Technology, Software/Computer Engineering or related discipline.
- Hands-on experience with GitLab CI/CD, including pipeline configuration and GitLab Runners.
- Good understanding of SDLC, DevSecOps and shift-left security, including SAST, DAST, Software Composition Analysis (SCA) and security gates.
- Experience integrating application security and code-quality tools, preferably Fortify, Nexus IQ and SonarQube, into CI/CD pipelines.
- Experience with Git, Docker and Kubernetes, with working knowledge of AWS/EKS environments.
- Scripting experience using Python, Bash, PowerShell or equivalent.
- Working knowledge of Linux, networking, access control and secrets management.
- Strong troubleshooting skills across CI/CD, security tooling and application deployment.
Added Advantage
- Hands-on experience with SHIP-HATS, particularly CI/CD and DevSecOps implementation.
- Experience with Infrastructure as Code using Terraform, Ansible or AWS CloudFormation.
- Experience with Helm, Argo CD or similar Kubernetes deployment/GitOps tools.
- Knowledge of SBOM and software supply-chain security.
- Experience with DevSecOps implementation in Singapore Government or regulated environments.



