The thirteen months of build-year output that sit in this repo —
pdpa-sg-clj, daglog, careerbot,
security-tools, identity-policy-as-code — were
never just artefacts. They were rehearsal for a single seat:
GovTech Platform Operations Engineer (WOG IAM),
twelve-month contract, Whole-of-Government scope. That seat is the
anchor. Everything after it is mobility.
This post locks the plan, the proof, and the proof-matrix that maps
what I have already shipped to what the requisition actually asks
for.
Base target and lifestyle
vision
| Anchor |
Detail |
| Hub |
Singapore (SG) — financial, tax, and execution hub |
| Spokes |
Java (Jakarta / Surabaya) and Bali (Denpasar) |
| Flight-time budget |
1.5 h SIN → JKT/SUB · 2.5 h SIN → DPS |
| Lifestyle vision |
High-value enterprise and sovereign security infrastructure work
executed out of Singapore to build capital and credentials, enabling
seamless mobility across SG, Java, and Bali |
Why a phased plan, not a
single leap
Regional mobility without a financial anchor is travel, not a life. A
plan that swings directly into Bali-based remote contracting skips the
part where banks and tax authorities decide you are real. The phases are
sequenced so that credentials and capital precede
optionality.
| Phase |
Outcome that closes the phase |
Risk that limits optionality if missed |
| 1 — Anchor |
Tax-resident, payroll-verified IAM/WOG execution |
Cold application queue without portfolio proof |
| 2 — Hybrid |
Same contract or an equivalent converted to remote-permitted |
Pure remote without a financial home reverts to travel |
| 3 — Sovereign |
International-rate remote contracts from a Bali or Java base |
Speculative contracting without a banking hub |
Phase 1 —
Anchor: capital + credential building (months 1–12)
| Field |
Detail |
| Action |
Land and execute the GovTech Platform Operations Engineer
(WOG IAM) role |
| Indicative target band |
SGD 7,500 – 8,000 / month (within the approved 7–9K target band;
floor SGD 6,000, ceiling SGD 12,000+ for niche PAM/IAM seats) |
| Objective |
Maximise SGD cashflow, fulfil Singapore tax residency, and build
direct enterprise IAM / WOG execution credentials |
| Stack in scope |
Entra ID, Active Directory, AD FS, SAML / OAuth / OIDC, Microsoft
Graph API, security governance |
| Lifestyle reality |
Rent-free base at the parents’ home in SG; 1.5 h hops to Java on
weekends; 2.5 h hops to Bali during approved annual-leave blocks |
Phase
2 — Hybrid regional enterprise operations (months 12–24)
| Field |
Detail |
| Action |
Transition internally inside the government/enterprise ecosystem, or
pivot to a regional tech / security consultancy that operates across SG
and ID |
| Objective |
Convert the employment contract to a hybrid model that permits
remote work from secondary locations in the same time zone (UTC+7 /
UTC+8) |
| Lifestyle reality |
2–3 weeks per month in Java or Bali with my partner while the
primary Singapore financial infrastructure (banking, tax status, capital
accumulation) stays intact |
Phase
3 — Independent specialist and sovereign mobility (months 24+)
| Field |
Detail |
| Action |
Position as a specialised Non-Human Identity (NHI) and Cloud
Security Infrastructure Specialist |
| Objective |
Secure high-yield remote contracts with international firms or
regional consultancies paying SG-level / global remote rates while
operating from Java or Bali |
| Lifestyle reality |
Full regional mobility — primary residence in Indonesia, Singapore
retained as banking and execution hub |
This is the proof matrix that maps shipped artefacts to the
requisition’s stated scope. Every row is verifiable in this
repository.
WOG and enterprise IAM
alignment
| Requisition scope |
What I have shipped |
Evidence path |
| CyberArk PAM operations |
Operational vaulting, session recording, account onboarding at
HTX/ICA (via NCS) and DCS-adjacent environments |
careerbot/Background/, careerbot/cv.md,
canonical resume SOT |
| Active Directory / M365 / Entra ID
administration |
DCS enterprise directory administration; Entra ID / Graph API
scripting in this repo |
careerbot/Background/,
identity-control-plane/ |
| Clearance lineage |
Passed G50 / ICA Category-2 twice (NEC, NCS/HTX);
currently lapsed, eligible for immediate employer project
re-sponsorship |
careerbot/Background/ SOT; trust signal only, never
active |
| CSA Cyber Trust Mark evidence |
SPOC for certification (Cert No. 797101, Promoter Tier) at DCS, with
operational gap remediation across seven Annex A control domains |
docs/CAREER-TRAJECTORY-2026-08-31.md |
Protocols, Graph API,
and policy-as-code
| Requisition scope |
What I have shipped |
Evidence path |
| OAuth / OpenID Connect / SAML fluency |
OIDC and OAuth flow analysis in published posts;
identity-policy-as-code expresses delegation rules declaratively |
posts/collapsing-auth-entropy-to-zero.md,
identity-policy-as-code/ |
| Microsoft Graph API automation |
Entra ID automation written in Babashka / Clojure against Graph
endpoints |
identity-control-plane/,
security-tools/ |
| OPA / Rego policy enforcement |
identity-policy-as-code denies wildcard permissions
over Terraform plans; Rego is the enforcement layer |
identity-policy-as-code/ |
| CI/CD pipeline auditing |
pdpa-sg-clj, aur-audit, and
security-tools ship as pipeline-callable scanners with
ripgrep and Babashka |
pdpa-sg-clj/, aur-audit/,
security-tools/ |
| Requisition scope |
What I have shipped |
Evidence path |
| Zero-dependency security tooling |
All four flagship tools run on Babashka + native CLIs — no npm, no
Python wheels, no cloud dependency |
pdpa-sg-clj/, aur-audit/,
security-tools/ |
| Compliance-as-code |
PDPA-SG CLI encodes Singapore PDPA controls, NRIC Mod-11 detection,
and ripgrep-backed scanning |
pdpa-sg-clj/ |
| Supply-chain static analysis |
AUR-audit scans Arch package builds for IoCs and BPF / systemd host
integrity |
aur-audit/ |
| Linux system administration |
Daily-driver Arch / CachyOS, systemd unit authoring, kernel
diagnostics (amdgpu, limine) |
posts/cachyos-*, posts/aur-audit-* |
| Provenance and audit trail |
daglog is an append-only flight recorder for delegated
agent work |
daglog/ |
Phase-by-phase deliverable
check
| Phase |
Concrete deliverable that proves the phase closed |
| 1 |
Signed twelve-month contract + first payroll credit + at least one
published WOG IAM artefact (post or repo) tagged
govtech |
| 2 |
Hybrid contract clause verified in writing + one quarter of remote
weeks logged in careerbot/data/applications.tsv (or
equivalent) |
| 3 |
Two international remote contracts executed end-to-end with NHI /
cloud-security scope + Bali or Java operating base registered with the
SG bank |
What this post is not
| It is not |
Why |
| A claim that I have already worked at GovTech |
No employer record exists yet; the plan is forward-looking |
| A claim that a specific GovTech requisition is open |
Job postings rotate; the scope is what I align to |
| A salary floor written into the public site |
The 7.5–8K band is the indicative target for the
requisition’s scope; the canonical band lives in
careerbot/profile.json |
| A replacement for the canonical resume |
careerbot/Report/Nur_Azhar_Resume.docx (sha256-locked,
read-only) is the source of truth for facts |
Operating rules
carried into every phase
| Rule |
What it means in practice |
| Outbound approval gate |
No recruiter email, application submission, or DM goes out without
explicit operator approval for that specific message |
| Canonical sources win |
Resume docx beats this post beats cv.md beats recruiter
chat; if any disagreement surfaces, the docx wins |
| Identity discipline |
No NRIC, DOB, former legal name, or clearance dates in any published
material; clearance cited as a trust signal only |
| TSV hygiene |
Every application lands in
careerbot/data/applications.tsv after header-width
inspection and URL / source normalisation |
| Receipts over vibes |
After every job — logical commit + git push origin main
+ GitLab PM sync per AGENTS.md |
The seat is the anchor. The phases convert the anchor into mobility.
The matrix proves the seat fits.