Diagram

The thirteen months of build-year output that sit in this repo — pdpa-sg-clj, daglog, careerbot, security-tools, identity-policy-as-code — were never just artefacts. They were rehearsal for a single seat: GovTech Platform Operations Engineer (WOG IAM), twelve-month contract, Whole-of-Government scope. That seat is the anchor. Everything after it is mobility.

This post locks the plan, the proof, and the proof-matrix that maps what I have already shipped to what the requisition actually asks for.

Base target and lifestyle vision

Anchor Detail
Hub Singapore (SG) — financial, tax, and execution hub
Spokes Java (Jakarta / Surabaya) and Bali (Denpasar)
Flight-time budget 1.5 h SIN → JKT/SUB · 2.5 h SIN → DPS
Lifestyle vision High-value enterprise and sovereign security infrastructure work executed out of Singapore to build capital and credentials, enabling seamless mobility across SG, Java, and Bali

Why a phased plan, not a single leap

Regional mobility without a financial anchor is travel, not a life. A plan that swings directly into Bali-based remote contracting skips the part where banks and tax authorities decide you are real. The phases are sequenced so that credentials and capital precede optionality.

Phase Outcome that closes the phase Risk that limits optionality if missed
1 — Anchor Tax-resident, payroll-verified IAM/WOG execution Cold application queue without portfolio proof
2 — Hybrid Same contract or an equivalent converted to remote-permitted Pure remote without a financial home reverts to travel
3 — Sovereign International-rate remote contracts from a Bali or Java base Speculative contracting without a banking hub

Phase 1 — Anchor: capital + credential building (months 1–12)

Field Detail
Action Land and execute the GovTech Platform Operations Engineer (WOG IAM) role
Indicative target band SGD 7,500 – 8,000 / month (within the approved 7–9K target band; floor SGD 6,000, ceiling SGD 12,000+ for niche PAM/IAM seats)
Objective Maximise SGD cashflow, fulfil Singapore tax residency, and build direct enterprise IAM / WOG execution credentials
Stack in scope Entra ID, Active Directory, AD FS, SAML / OAuth / OIDC, Microsoft Graph API, security governance
Lifestyle reality Rent-free base at the parents’ home in SG; 1.5 h hops to Java on weekends; 2.5 h hops to Bali during approved annual-leave blocks

Phase 2 — Hybrid regional enterprise operations (months 12–24)

Field Detail
Action Transition internally inside the government/enterprise ecosystem, or pivot to a regional tech / security consultancy that operates across SG and ID
Objective Convert the employment contract to a hybrid model that permits remote work from secondary locations in the same time zone (UTC+7 / UTC+8)
Lifestyle reality 2–3 weeks per month in Java or Bali with my partner while the primary Singapore financial infrastructure (banking, tax status, capital accumulation) stays intact

Phase 3 — Independent specialist and sovereign mobility (months 24+)

Field Detail
Action Position as a specialised Non-Human Identity (NHI) and Cloud Security Infrastructure Specialist
Objective Secure high-yield remote contracts with international firms or regional consultancies paying SG-level / global remote rates while operating from Java or Bali
Lifestyle reality Full regional mobility — primary residence in Indonesia, Singapore retained as banking and execution hub

Target-job alignment: GovTech Platform Operations Engineer (WOG IAM)

This is the proof matrix that maps shipped artefacts to the requisition’s stated scope. Every row is verifiable in this repository.

WOG and enterprise IAM alignment

Requisition scope What I have shipped Evidence path
CyberArk PAM operations Operational vaulting, session recording, account onboarding at HTX/ICA (via NCS) and DCS-adjacent environments careerbot/Background/, careerbot/cv.md, canonical resume SOT
Active Directory / M365 / Entra ID administration DCS enterprise directory administration; Entra ID / Graph API scripting in this repo careerbot/Background/, identity-control-plane/
Clearance lineage Passed G50 / ICA Category-2 twice (NEC, NCS/HTX); currently lapsed, eligible for immediate employer project re-sponsorship careerbot/Background/ SOT; trust signal only, never active
CSA Cyber Trust Mark evidence SPOC for certification (Cert No. 797101, Promoter Tier) at DCS, with operational gap remediation across seven Annex A control domains docs/CAREER-TRAJECTORY-2026-08-31.md

Protocols, Graph API, and policy-as-code

Requisition scope What I have shipped Evidence path
OAuth / OpenID Connect / SAML fluency OIDC and OAuth flow analysis in published posts; identity-policy-as-code expresses delegation rules declaratively posts/collapsing-auth-entropy-to-zero.md, identity-policy-as-code/
Microsoft Graph API automation Entra ID automation written in Babashka / Clojure against Graph endpoints identity-control-plane/, security-tools/
OPA / Rego policy enforcement identity-policy-as-code denies wildcard permissions over Terraform plans; Rego is the enforcement layer identity-policy-as-code/
CI/CD pipeline auditing pdpa-sg-clj, aur-audit, and security-tools ship as pipeline-callable scanners with ripgrep and Babashka pdpa-sg-clj/, aur-audit/, security-tools/

DevSecOps and platform automation

Requisition scope What I have shipped Evidence path
Zero-dependency security tooling All four flagship tools run on Babashka + native CLIs — no npm, no Python wheels, no cloud dependency pdpa-sg-clj/, aur-audit/, security-tools/
Compliance-as-code PDPA-SG CLI encodes Singapore PDPA controls, NRIC Mod-11 detection, and ripgrep-backed scanning pdpa-sg-clj/
Supply-chain static analysis AUR-audit scans Arch package builds for IoCs and BPF / systemd host integrity aur-audit/
Linux system administration Daily-driver Arch / CachyOS, systemd unit authoring, kernel diagnostics (amdgpu, limine) posts/cachyos-*, posts/aur-audit-*
Provenance and audit trail daglog is an append-only flight recorder for delegated agent work daglog/

Phase-by-phase deliverable check

Phase Concrete deliverable that proves the phase closed
1 Signed twelve-month contract + first payroll credit + at least one published WOG IAM artefact (post or repo) tagged govtech
2 Hybrid contract clause verified in writing + one quarter of remote weeks logged in careerbot/data/applications.tsv (or equivalent)
3 Two international remote contracts executed end-to-end with NHI / cloud-security scope + Bali or Java operating base registered with the SG bank

What this post is not

It is not Why
A claim that I have already worked at GovTech No employer record exists yet; the plan is forward-looking
A claim that a specific GovTech requisition is open Job postings rotate; the scope is what I align to
A salary floor written into the public site The 7.5–8K band is the indicative target for the requisition’s scope; the canonical band lives in careerbot/profile.json
A replacement for the canonical resume careerbot/Report/Nur_Azhar_Resume.docx (sha256-locked, read-only) is the source of truth for facts

Operating rules carried into every phase

Rule What it means in practice
Outbound approval gate No recruiter email, application submission, or DM goes out without explicit operator approval for that specific message
Canonical sources win Resume docx beats this post beats cv.md beats recruiter chat; if any disagreement surfaces, the docx wins
Identity discipline No NRIC, DOB, former legal name, or clearance dates in any published material; clearance cited as a trust signal only
TSV hygiene Every application lands in careerbot/data/applications.tsv after header-width inspection and URL / source normalisation
Receipts over vibes After every job — logical commit + git push origin main + GitLab PM sync per AGENTS.md

The seat is the anchor. The phases convert the anchor into mobility. The matrix proves the seat fits.