GovTech is the lead agency driving Singapore's Smart Nation initiatives and public sector digital transformation. As the Centre of Excellence for Infocomm Technology and Smart Systems (ICT & SS), GovTech develops the Singapore Government's capabilities in Data Science & Artificial Intelligence, Application Development, Smart City Technology, Digital Infrastructure, and Cybersecurity. At GovTech, we offer you a purposeful career to make lives better, and we help our people master their craft through learning and development opportunities all year round.
Singpass is Singapore's national digital identity system. It provides high-assurance authentication, digital signatures, corporate identity (Corppass) and government-verified data sharing (Myinfo) to millions of residents and thousands of government and private-sector services. Because it is critical national infrastructure, Singpass is audited continuously against strict security and regulatory controls. Today, most of that audit evidence is collected by hand, point in time, in screenshots and spreadsheets. We want to replace that with continuous, machine-verified compliance: every control measured live, every piece of evidence produced automatically, and every drift detected within minutes instead of at the next audit cycle.
This is a hands-on software engineering role. You will design, write and operate production code and data pipelines. It is not a GRC analyst, audit management or policy-writing role. We are looking for engineers who treat compliance as a software problem: controls as code, evidence as data, audits as queries.
[What you will be working on]
You will join the Singpass GRC engineering effort, working with the Core Platform team, which runs the shared foundations that every Singpass product team builds on: multi-cluster OpenShift on AWS, Istio Ambient service mesh, GitLab CI, ArgoCD GitOps, OpenBao secrets management and YugabyteDB distributed SQL. Your job is to instrument these systems so that their compliance posture can be observed, measured and proven continuously, and to bring the results together in a single pane of glass that auditors, security and engineering leadership can query 24/7.
Continuous Controls Monitoring & Evidence Automation
- Integrate with the delivery pipeline: Build integrations into GitLab CI and ArgoCD to capture change-management evidence automatically: who changed what, who reviewed and approved it, which tests and security scans ran, and what was deployed where. Target outcomes include signed artefacts, SBOMs, provenance attestations and separation of duties.
- Instrument the container platform: Collect and normalise control signals from OpenShift clusters, such as Compliance Operator / CIS benchmark results, admission and policy-engine decisions, RBAC and privileged-access state, network and authorization policies, image provenance and Kubernetes audit logs.
- Instrument the data tier: Build collectors for YugabyteDB clusters that cover database audit logs, role and privilege inventories, encryption and backup posture, and access reviews, while keeping overhead low on production workloads.
- Extend to the wider estate: Bring in signals from OpenBao (secret lifecycle, lease and rotation compliance), AWS (CloudTrail, Config, Security Hub, IAM), identity providers and SIEM, as the platform grows.
Compliance Data Platform & Single Pane of Glass
- Design the evidence data model: Build a normalised, tamper-evident, time-series evidence store that maps raw technical signals to control objectives across frameworks (e.g. IM8, ISO/IEC 27001, NIST SP 800-53, CIS). Wherever possible, a single signal should satisfy many controls.
- Build the pipelines: Write reliable, idempotent ingestion and transformation pipelines with clear lineage, so that every metric on the dashboard can be traced back to its raw evidence.
- Deliver live audit views: Build dashboards and APIs that show real-time control status, drift, exceptions and remediation SLAs. Auditors should be able to self-serve point-in-time and period-of-time evidence without filing a ticket.
- Close the loop: Turn failing controls into actionable alerts, tickets or pipeline gates for the owning team, and push fixes upstream into golden paths so that the compliant path is also the default path.
Engineering Leadership
- Write secure, production-ready code in Go. All GRC services, collectors, pipelines and tooling are written in Go. TypeScript is used only for frontend applications such as the audit dashboard. You will also work with SQL and infrastructure-as-code (Terraform/OpenTofu, Helm, Kustomize).
- Author Architecture Decision Records (ADRs) and RFCs, and turn ambiguous regulatory requirements into precise, testable technical controls together with Security, GRC and product teams.
- Own what you build in production, including SLOs, monitoring, on-call and incident follow-up.
- Mentor engineers, contribute to technical hiring, and help raise the security and reliability culture across Singpass.
[What we are looking for]
We value strong engineering fundamentals over specific tools. Prior GRC experience is a bonus, not a requirement. If you have built serious platform or data systems and care about proving they are secure, we can teach you the frameworks.
Technical Capabilities
- Engineering depth: 5+ years of professional software engineering, building and operating production backend, platform or data systems. Strong proficiency in Go, including concurrency, testing and building production services and CLIs.
- Kubernetes / OpenShift: Hands-on experience running workloads on Kubernetes or OpenShift, including a working understanding of the API server, RBAC, admission control, operators/controllers and audit logging. Experience writing controllers or operators is a strong plus.
- CI/CD & GitOps: Practical experience extending CI/CD systems (GitLab CI preferred) and GitOps tooling (ArgoCD), including APIs, webhooks, runners, and pipeline-level policy or attestation.
- Data engineering: Experience designing data models and ingestion pipelines for event, log or time-series data, with strong SQL skills and good judgement on correctness, idempotency and lineage.
- Security fundamentals: Solid grasp of identity and access management, least privilege, encryption, secrets handling, logging integrity and secure software supply chains.
Ways of Working
- Translation: You can read a control statement and turn it into a precise, automatable check, and you can explain a technical result clearly to an auditor or policy officer.
- Ownership: You don't wait for a ticket. You find gaps, ask why, and ship improvements end to end.
- Documentation first: You write clear designs, runbooks and developer guides that scale knowledge beyond yourself.
- Integrity: You understand the responsibility of working on national identity infrastructure and handling sensitive audit data.
Preferred Qualifications
- Experience with policy-as-code (OPA/Rego, Gatekeeper, Kyverno) or compliance-as-code frameworks (OSCAL, OpenSCAP, Compliance Operator).
- Experience with software supply-chain security, such as Sigstore/cosign, SLSA, in-toto attestations, and SBOM generation and analysis.
- Exposure to distributed SQL databases (YugabyteDB, CockroachDB, PostgreSQL at scale), including database auditing and access governance.
- Experience with secrets management platforms (OpenBao or HashiCorp Vault) and AWS security services (CloudTrail, Config, Security Hub).
- Familiarity with control frameworks and audit regimes such as IM8, ISO/IEC 27001, SOC 2, NIST SP 800-53, PCI DSS or MAS TRM.
- Experience building observability or analytics products (Grafana, OpenSearch, ClickHouse, or similar) used by non-engineering audiences.
- Experience building frontend applications in TypeScript (React or similar), for the audit dashboard.
- Prior experience in highly regulated, high-availability environments (government, defence, fintech).
[What it is like working here]
- Security-first mindset: National identity infrastructure demands strong engineering discipline, attention to detail and a proactive approach to risk.
- Greenfield with real stakes: You will help define how Singpass proves its security posture, working on live production systems that the whole nation depends on.
- Ownership: Engineers shape product direction, argue for robust technical choices, and influence how national systems evolve.
- Go-first engineering: Go is the only language we use for services and tooling, and TypeScript is reserved for frontend applications. One toolchain means shared libraries, consistent security review and code that any engineer can pick up.
- Continuous learning: You will work across platform engineering, security, data and regulation alongside diverse teams across government.
[What we offer you]
GovTech is an equal opportunity employer committed to fostering an inclusive workplace that values diverse voices and perspectives, as we believe diversity is the foundation of innovation.
Our employee benefits follow a total rewards approach, offering a holistic and market-competitive suite of perks. These include leave benefits to meet your work-life needs and employee wellness programmes.
We champion flexible work arrangements (subject to your job role) and trust you to manage your own time to deliver your best, wherever you are and whatever works best for you.
Learn more about life inside GovTech at go.gov.sg/GovTechCareers. Stay connected with us on social media at go.gov.sg/ConnectWithGovTech.
Please note that this will be a 2-year fixed term contract.