We are looking for a DevSecOps Engineer with strong experience in CI/CD pipeline automation and a strong preference for candidates with SHIP-HATS (Secure Hybrid Integration Pipeline / Hive Agile Testing Solutions) exposure. In this role, you will design, build, and maintain robust deployment pipelines, drive DevOps best practices across software projects, and integrate automated security and compliance controls into the software development lifecycle (SDLC).
Responsibilities:
1. CI/CD & Pipeline Management
- Design, build, and maintain scalable CI/CD pipelines using SHIP-HATS (GitLab CI / Bitbucket / Bamboo / Jenkins stack) or mainstream CI/CD tooling to enable automated testing, scanning, and deployment across both Windows and Linux environments.
- Standardize build and release processes across microservices, cloud applications, and legacy workloads.
- Manage infrastructure-as-code (IaC) deployments (e.g. Terraform, Ansible) to ensure consistency between development, staging, and production environments.
2. Security & Compliance Integration (DevSecOps)
- Embed automated security tools into CI/CD workflows, including SAST (Static Application Security Testing), DAST, SCA (Software Composition Analysis), and container image scanning (e.g. SonarQube, Fortify, Nexus IQ, Prisma Cloud).
- Ensure systems and pipeline configurations conform to Singapore Government policies (IM8 / Security Directives) and industry compliance standards.
- Track, remediate, and report security vulnerabilities identified during pipeline execution in collaboration with development and cyber security teams.
3. Platform & Pipeline Operations
- Assist in pipeline monitoring, logging, and automated workflow enhancements to ensure build reliability and efficiency.
- Drive operational efficiency through script automation (Bash, Python, PowerShell) and container orchestration (Kubernetes / Docker).
Requirements:
- DevOps / CI/CD: Hands-on experience designing and operating CI/CD pipelines; experience within the SHIP-HATS ecosystem (GitLab CI, Confluence, Jira, Nexus Repository, SonarQube) is strongly preferred but not mandatory.
- Operating Systems : Comfortable working in and supporting both Windows and Linux operating environments.
- Security Integration: Direct experience integrating security scanning tools (e.g. SonarQube, Fortify, Dependency-Check, Trivy) into developer workflows and CI/CD pipelines.
- Web Application Security: Deep understanding of web application security principles, common vulnerabilities (e.g. OWASP Top 10), and secure coding practices.
- Cloud & Security Knowledge: Solid familiarity with cloud infrastructure (AWS, Azure, or GCC) and cloud security concepts. Direct administration or maintenance of cloud infrastructure is preferred but not strictly required.