Sr DevOps Engineer
Jobleads-US
1 Bethany
900 W Bethany Dr
Suite 500
Allen, TX 75013, USA
Description
Position Summary
The Senior DevOps Engineer supports Credit Union of Texas's vision to be the trusted financial partner for our members and our community by building and owning the end-to-end software development lifecycle (SDLC) on Azure DevOps. The role modernizes and standardizes the SDLC for existing applications, implements CI/CD and multi-environment (Dev, UAT, Prod) strategies, and makes the Node.js application code changes needed to support them. The role establishes secure secrets management, artifact management, static and dynamic application security testing (SAST with JFrog and DAST with Invicti), code quality and test coverage gates (SonarQube), Infrastructure as Code, automated testing, and observability practices (Datadog APM and Logs) that make releases repeatable, traceable, and audit-ready. Once the foundation is in place, the Senior DevOps Engineer contributes to Node.js development and onboards new applications onto the standardized SDLC. The role uses CUTX-approved AI tools under defined governance, with mandatory human review of any AI-assisted code or configuration before it reaches production.
Key Responsibilities
CI/CD, Source Control & Release Management
- Design and implement CI/CD pipelines (YAML) in Azure DevOps for existing and new applications.
- Manage Azure Repos, including branching strategy, branch policies, pull request workflows, and code review gates.
- Design and implement multi-environment strategies (Dev, UAT, Prod) with automated promotion, including the infrastructure and application changes required to support them.
- Set up release strategies such as approvals, environment promotion, and rollback.
- Implement feature flags using Azure App Configuration to reduce release risk.
Security, Secrets & Code Quality
- Implement and standardize secrets management using Azure Key Vault and Managed Identity across applications, including the Node.js code changes needed to load secrets and configuration securely at runtime.
- Establish secure secret lifecycle practices, including rotation and access controls.
- Implement static application security testing (SAST) using JFrog Advanced Security, with critical and high findings blocking merges and releases.
- Integrate SonarQube for code quality and unit test coverage analysis (coverage thresholds, bugs, code smells, duplication, and maintainability), with quality gates enforced on every pull request and pipeline run.
- Integrate Invicti for dynamic application security testing (DAST) against deployed applications in Dev and UAT, with critical and high findings blocking promotion to Production.
- Coordinate triage and remediation of SAST, DAST, dependency, and secret scanning findings with development teams and Information Security, and track them to closure in Azure Boards.
- Implement dependency, vulnerability, and secret scanning (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks) with results enforced in pipelines.
- Enforce code consistency standards with ESLint and Prettier in pull request checks.
Infrastructure, Artifacts & Containers
- Implement Infrastructure as Code (Terraform, Bicep, or ARM) for repeatable environment provisioning.
- Set up and manage JFrog Artifactory for package and artifact management, including npm and Docker registries.
- Containerize applications with Docker where appropriate, and support a future move to Azure Kubernetes Service (AKS).
Testing, Monitoring & Observability
- Build automated testing into pipelines, including unit tests (Jest) and end-to-end tests (Playwright or Cypress).
- Set up monitoring and observability with Datadog APM and Datadog Log Management across all environments, alongside Azure Monitor and Application Insights for Azure platform metrics.
- Instrument Node.js applications with the Datadog APM tracer and structured logging, correlate traces with logs, and build dashboards, monitors, and alerts for service health, performance, and release impact.
Node.js Development & Application Onboarding
- Make code changes in Node.js applications to support DevOps practices such as configuration management, health checks, logging, and automated tests.
- Contribute to Node.js feature development and bug fixes as DevOps priorities allow.
- Onboard new applications onto the standardized SDLC process.
- Set up Azure Boards for work tracking, with work items linked to commits, pull requests, and releases for end-to-end traceability and audit readiness.
- Document pipelines, environments, runbooks, and processes in the Azure DevOps Wiki, and train team members on them.
- Coordinate with Application Development, IT Operations, Information Security, and Compliance to align SDLC standards with enterprise priorities and control requirements.
Performance Outcomes & KPIs
Outcome
Primary KPI
Target / Direction
Applications run on a standardized, automated SDLC.
SDLC Adoption Rate - percent of in-scope applications deployed through standardized Azure DevOps YAML pipelines with automated environment promotion.
100% of in-scope applications [Timeline - confirm with Hiring Manager]
Releases are reliable and low-risk.
Change Failure Rate - percent of production deployments that require rollback, hotfix, or incident remediation.
Monthly
Issues are recovered from quickly.
Mean Time to Restore (MTTR) - average time to restore service after a failed production change.
Monthly
[Target - confirm with Hiring Manager]
Secrets and credentials are managed securely.
Secrets Management Compliance - percent of in-scope applications loading secrets from Azure Key Vault via Managed Identity, with zero secrets in source control.
Code meets quality and security standards before release.
Security Gate Enforcement - percent of production releases that passed JFrog SAST and Xray dependency scans, Invicti DAST scans, SonarQube code quality and test coverage gates, and secret scans with no unresolved critical or high findings.
Monthly
Code changes are covered by automated tests.
Test Coverage - percent of in-scope applications meeting the SonarQube unit test coverage threshold on new code.
Monthly
≥ 80% coverage on new code [confirm threshold with Hiring Manager]
Production applications are fully observable.
Observability Coverage - percent of production applications instrumented with Datadog APM and centralized Datadog logs, with active monitors and alerts.
Changes are traceable and audit-ready.
Change Traceability Rate - percent of production releases linked to Azure Boards work items, pull requests, and approvals.
AI-assisted code and configuration are reviewed before use.
Human Review Rate on AI-Assisted Changes - percent of AI-assisted code, pipeline, or IaC changes that went through documented pull request review before merge.
Monthly
Qualifications
Education
- Bachelor's degree in Computer Science, Software Engineering, Information Systems, or a related field, or equivalent practical experience. [Confirm with Hiring Manager — not specified in source posting]
Experience
- Five (5) or more years of experience in DevOps, with a strong background in software development.
- Strong hands-on experience with Azure DevOps (Repos, Pipelines, YAML, Releases, Environments).
- Solid Node.js development experience, enough to independently read, modify, and ship production code.
- Hands-on experience refactoring application code to use a secrets manager (Azure Key Vault preferred) with Managed Identity.
- Experience with the JFrog Platform (Artifactory, Xray, and Advanced Security SAST) in CI/CD workflows.
- Experience with SonarQube for code quality and test coverage quality gates in CI/CD workflows.
- Experience with dynamic application security testing (DAST) integrated into CI/CD pipelines; Invicti preferred.
- Experience building automated testing into CI/CD pipelines, including unit testing (Jest) and end-to-end testing (Playwright or Cypress).
- Experience with application security scanning tools for dependencies, vulnerabilities, and secrets (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks).
- Experience with Datadog APM and Log Management, including tracer instrumentation, log pipelines, dashboards, and monitors; experience with Azure Monitor and Application Insights.
- Experience with feature flags (Azure App Configuration or similar).
- Experience with Docker and containerized application deployment.
- Experience with Azure Boards or similar work tracking tools, including linking work items to code and releases.
- Proven experience introducing CI/CD and environment standardization to existing applications.
- Kubernetes (AKS) experience preferred.
- Experience with container image scanning and broader DevSecOps practices preferred.
- Prior experience in financial services or another regulated industry preferred.
Licenses, Registrations, and Certifications
- No specific license or registration required for this role.
Knowledge & Skills
- Working knowledge of Azure services such as App Service, Functions, AKS, virtual machines, and networking.
- Experience with Infrastructure as Code (Terraform or Bicep preferred).
- Git expertise, including branching strategies such as GitFlow or trunk-based development.
- Scripting skills in PowerShell and/or Bash.
- Experience enforcing code quality standards with ESLint and Prettier.
- Strong documentation habits, including runbooks and process documentation.
- Ability to explain technical standards clearly and train team members on new processes.
- Drive to learn and adopt new technologies, techniques, and CUTX-approved AI tools.
Core Competencies
Competency
Proficiency Level
Why This Matters in This Role
AI Literacy
Intermediate
The role uses AI-assisted code and configuration tools (Tier 2) and must recognize when AI output is wrong or insecure, apply required controls, and ensure human review before changes are merged.
Technical Excellence
Advanced
The role owns the design of pipelines, environments, and release processes that every CUTX application team will depend on.
Advanced
Pipeline, secrets, or access-control weaknesses can expose member data or disrupt services; the role must identify, remediate, and elevate security and change risk.
Operational Discipline
Advanced
Pipelines, infrastructure, and documentation must be repeatable, version-controlled, and audit-ready to meet change management and examination expectations.
Communication
Intermediate
The role must document standards clearly, train teams, and explain trade-offs to technical and non-technical partners.
Intermediate
Standardizing the SDLC requires working across development, operations, security, and compliance teams to drive adoption.
Compliance Orientation
Intermediate
SDLC controls must support GLBA data protection, NCUA information security requirements, and TRAIGA-aligned AI governance.
AI & Technology Expectations
AI-Augmented Workflows
The following workflows are AI-augmented in this role. The Senior DevOps Engineer is expected to work fluently within these workflows, exercise sound judgment over AI outputs, and follow all applicable controls.
- AI-assisted code generation and refactoring for Node.js applications.
- AI-assisted authoring of pipeline YAML, Infrastructure as Code templates, and scripts.
- AI-assisted triage and remediation of SAST (JFrog), DAST (Invicti), dependency (JFrog Xray), code quality (SonarQube), and secret scan findings.
- AI-assisted log, trace, alert, and incident analysis using Datadog APM, Datadog Logs, and Azure Monitor data.
- AI-assisted drafting of runbooks, wiki documentation, and training materials.
AI Tier and Human-in-the-Loop Responsibility
This role operates in AI Tier 2 for its principal AI-augmented workflows (see Appendix A). The Senior DevOps Engineer retains accountability for any decision, communication, or member/employee-impacting action influenced by AI output, consistent with the CUTX Generative AI Usage Policy §3.4.
The Senior DevOps Engineer is required to:
- Review, test, and validate all AI-generated code, pipeline definitions, IaC templates, and scripts before they are merged or run against any environment.
- Route every AI-assisted change through the standard pull request, code review, and pipeline quality gates; AI output never bypasses these controls.
- Verify AI-suggested remediations for security findings against authoritative sources before applying them.
- Escalate to the Hiring Manager, IT Security, and the AI Council any use case that would let AI make changes to production systems without human approval, which is treated as Tier 3 and requires additional controls.
- Stop reliance on AI output and escalate immediately if the output appears inaccurate, insecure, non-compliant, or outside the role's documented scope (Generative AI Usage Policy §3.5).
- Refrain from entering secrets, credentials, connection strings, member non-public personal information (NPI), or confidential CUTX source code into any AI tool not explicitly approved for that data classification.
- Complete all required AI training within thirty (30) days of hire and maintain annual currency.
Approved AI Tools
The role is approved to use the following AI tools in performing essential functions (subject to the Generative AI Usage Policy and any tool-specific guidance issued by the AI Council):
- CUTX-approved internal AI assistants (e.g., Sam) for general productivity and approved knowledge tasks.
- Microsoft Copilot for office productivity (drafting, summarization, spreadsheet support).
- CUTX-approved code-assistance tools used within sanctioned development environments and CUTX repositories.
- AI features built into CUTX-approved DevOps, security scanning, and monitoring platforms (e.g., Azure DevOps, JFrog, SonarQube, Invicti, Datadog, and Azure Monitor).
Use of AI tools outside this list requires prior approval from the role's department leader and the AI Council, per the Generative AI Usage Policy §4.
Prohibited AI Use
In addition to the prohibited uses defined in the Generative AI Usage Policy §3.6, the following are specifically prohibited in this role:
- Merging or deploying AI-generated code, configuration, or infrastructure changes without documented human review and passing pipeline quality gates.
- Entering secrets, credentials, keys, connection strings, member NPI, or confidential CUTX source code into any AI tool not explicitly approved for that data classification.
- Granting AI agents or tools autonomous write access to production environments, pipelines, or secrets stores without governance review and required approvals.
- Using unsanctioned third-party AI services for CUTX code generation, infrastructure changes, or log and data analysis.
Compliance & Regulatory Responsibilities
Enterprise Compliance Obligations
The Senior DevOps Engineer is responsible for all enterprise compliance obligations applicable to a CUTX team member, including BSA/AML, OFAC, USA PATRIOT Act/CIP/CDD, GLBA and the Safeguards Rule, Fair Lending laws (ECOA/Reg B, Fair Housing Act), UDAAP, Information Security and Acceptable Use, and the CUTX Code of Conduct.
AI-Specific Compliance Obligations
The Senior DevOps Engineer is responsible for the CUTX Generative AI Usage Policy (TRAIGA / HB 149-aligned), the CUTX AI Playbook (including Tier 2 obligations applicable to this role), and Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149) requirements applicable to the role.
Role-Specific Compliance Obligations
- CUTX Change Management, Release Management, and Secure SDLC standards covering approvals, segregation of duties, testing, and rollback.
- Gramm-Leach-Bliley Act (GLBA) and the Safeguards Rule, and NCUA Part 748 information security program requirements, as applied to systems, pipelines, and environments that handle member data.
- FFIEC IT Examination Handbook expectations for development, acquisition, and operations, including change traceability and audit evidence.
- CUTX Information Security, Access Management, and Secrets Management policies, including least-privilege access and credential rotation.
- CUTX Vendor and Third-Party Risk Management requirements for DevOps, cloud, artifact and security testing (JFrog, Invicti), code quality (SonarQube), and observability (Datadog) tools.
- CUTX Data Governance and Data Classification policies as applied to non-production environments, code repositories, and logs, including masking of member NPI and secrets before logs and trace are sent to Datadog.
Working Conditions & Physical Requirements
This role is performed primarily on-site at the CUTX Corporate Office in the Dallas-Fort Worth, TX area, with hybrid eligibility subject to manager approval and CUTX policy. The work environment is office-based with no significant hazardous or unpleasant conditions. Occasional after-hours or weekend work may be required to support production releases, maintenance windows, or incident response. Essential physical activities include the ability to remain stationary at a workstation for extended periods; operate a computer, telephone, and standard office equipment; perform frequent repetitive motions of the hands, wrists, and fingers (keyboard and mouse use); communicate clearly by phone, email, video, and in person with technical and business partners; and read, analyze, and interpret detailed written and on-screen information. The role requires the ability to apply reasoning to problems involving many variables and to communicate complex technical concepts in plain language. Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions of this role, consistent with the Americans with Disabilities Act and CUTX policy.
Acknowledgement & Disclaimer
This job description is intended to describe the general nature and level of work being performed by individuals assigned to this position. It is not intended to be an exhaustive list of all responsibilities, duties, and skills required, and CUTX reserves the right to modify, add to, or remove duties at any time as business needs require.
Employment with CUTX is at-will. This job description does not constitute an employment contract.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
- ...Cloud Platform Security Command Center) would be plus; Proficiency in python or golang for security, automation or observability engineering; Hands-on experience with automation and development Ability to work independently and collaboratively Chabez Tech is...Senior
- ...or spouse/family member of a protected veteran; or disability.Technical/Domain Skill 1Technology|Cloud Platform|Amazon Webservices DevOps Technical/Domain Skill 2Technology|DevOps|Continuous delivery - Continuous deployment and release Technical/Domain Skill 3Technology...SeniorFull timeTemporary workRelocation
- ...innovation and continuous improvement. You will act as a technical authority and platform owner, driving architecture, standards, and engineering practices across a portfolio of modern data technologies including: MongoDB Redis Graph databases (e.g., GraphDB, Neo4j,...SeniorWork at officeShift workDay shift
- ...and those who are committed to doing what is best for our customers.Bridge Specialty Group is seeking a Senior Azure DevOps & Cloud Platform Engineer to join our growing team in Plano, TX. We are seeking a talented and experienced Senior Azure DevOps & Cloud Platform...SeniorFull time
- ...servant leadership.BenefitsMedical InsuranceVision InsuranceDental Insurance401(k)Paid Sick hoursJob DescriptionWe are seeking an AI DevOps Engineer to design, develop, deploy, and support enterprise AI agents and Generative AI solutions for clients, primarily in the consumer...Senior
- Join a team that keeps modern cloud data platforms reliable so engineers can deliver features confidently. You will shape secure environments... ...others, this role will be a strong fit.As a Data Platform DevOps Engineer - Senior Associate within the Enterprise Data Solutions...SeniorFull timeH1bWork at office
- ...TechDigital Group is seeking a Senior Software Engineer to lead DevOps, CI/CD improvements, and AI-enabled initiatives across mobile, cloud, and firmware boundaries. You will design automations, coordinate product launches, and investigate field issues with a focus on...Senior
- ...Chabez Tech is a data & AI products company, headquartered in Pennsylvania. We are seeking a security engineering professional to design and implement information security in cloud environments, with emphasis on IAM, zero-trust, and multi-layer protection across OS, network...Senior
- ...Credit Union of Texas is seeking a Senior DevOps Engineer to own and modernize the SDLC across Dev, UAT, and Prod on Azure DevOps. You will implement CI/CD, multi-environment promotions, secrets management, SAST/DAST, and code quality gates while enabling Node.js development...
- ...JPMorgan Chase & Co. is seeking a Data Platform DevOps Engineer - Senior Associate in Plano to design, build, and operate secure, scalable cloud environments for mission-critical data apps. You will own the container platform on AWS and drive reliable deployments across...Senior
- ...Title : Senior Azure Platform & DevOps Engineer Location: Plano, TX Hybrid work Job Type: Contract Project description We are seeking a Senior Azure Platform & DevOps Engineer to design, implement, automate, and support enterprise cloud infrastructure...SeniorContract work
- ...excellence then we’d love to meet you. This role is ideal for an engineer with strong Linux systems expertise who believes infrastructure... ..., troubleshoot difficult production issues, and help establish DevOps and Linux engineering standards.This is a remote position and...Permanent employmentH1bWork at officeLocal areaRemote work
- Capgemini is seeking a Senior Software Engineer to lead DevOps and Mobile Operations, driving CI/CD improvements, automation, and cross-functional product launches for Android and iOS. You will investigate complex field issues across connected systems and apply AI-enabled...Senior
- ob Description - Cloud Engineer (5-12 Years Experience)We are looking for an experienced Cloud Engineer to join our Cloud Engineering team. The ideal candidate will have strong hands-on expertise in cloud infrastructure, automation, and production support, with the ability...
- ...Principal DevOps Engineer Job Location (Short): Richardson, Texas-USA Workplace Type: Hybrid Req Id: 3304 Responsibilities As Octave continues to grow, we are looking for a Principal DevOps Engineer to work in Richardson, TX- Hybrid...Afternoon shift
- ...Octave seeks a Principal DevOps Engineer in Richardson, TX, offering a hybrid work setup. You will drive cloud infrastructure, automate deployments, and champion IaC and CI/CD across multiple products. The role blends architecture influence with hands-on engineering...
$61k - $101k
...000 - 101,000 per year Requirements: We require formal training or certification in software engineering concepts, along with 5+ years of practical experience in DevOps, cloud support, or platform engineering. We need hands-on experience with AWS ECS and end-to-end...SeniorFull time- OverviewThe Infosys Engineering unit is dedicated to amplifying product-centric value delivery through innovative engineering solutions.... ...protected veteran; or disability.Technical/Domain Skill 1Technology|DevOps|Continuous integration - Java Technical/Domain Skill 2...Full timeTemporary workRelocation
- ...ArkhaTech is seeking a DevOps Engineer to strengthen our cloud infrastructure, deployment automation, reliability, observability, and security. You will collaborate with application and quality teams to build scalable platforms and make software delivery faster, safer,...
- ...us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a DevOps Engineer to join our team in Plano, Texas (US-TX), United States (US).Who We Are: At NTT DATA America's, we are committed to hiring innovative...Work at officeRemote workFlexible hours
$102.68k - $136.9k
...us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a DevOps Engineer - Plano, TX to join our team in Plano, Texas (US-TX), United States (US).Join a high-impact DevOps team within a global organization...Full timeTemporary workWork at officeRemote workFlexible hours- ...Mohammed , Jhansi Bugatha, Vamsi SattaruCompany: SRI Tech SolutionsJob Title: Lead DevOps with GCP Cloud Infrastructure Location: Plano, TXRole Overview:We are seeking a Lead DevOps Engineer to design, implement, and manage scalable cloud infrastructure on Google Cloud...Full time
- ...WiproContact: Meghana GorusuCompany: SRI Tech SolutionsRole: Devops LeadOnly Visa independent profiles.Location : Plano - TX (Hybrid... ...Skills:Proficiency in DevOps and Agile principlesApply engineering standard methodologies to analyze and develop software solutionsLeverages...Full timeWork at officeWork from home
- ...Job Description Insight Global is seeking a Release Train Engineer (RTE) for a top enterprise technology client. This candidate will... ...VersionOne) • Deep understanding of SAFe, Scrum, Kanban, Lean, XP, and DevOps methodologies • Bachelor's Degree or equivalent experience •...
- Duration: Long Term ContractPay Rate: $40/Hr. W2Experience: 3-5 YearsOverviewWe are seeking a remote Junior SRE/DevOps Engineer role. The ideal candidate has foundational knowledge of Site Reliability Engineering (SRE) and Kubernetes, and is enthusiastic about growing in...Remote work
$55 - $65 per hour
...Title: Devops Engineer Location: Remote Duration: Long-Term Contract with Potential to Convert to Full-Time Employment Compensation: $55-65/hour Work Authorization: US Citizen, GC Holders or Authorized to Work in the US without sponsorship, either now or...Long term contractFull timeRemote workFlexible hours$40 per hour
A technology solutions provider is seeking a remote Junior SRE/DevOps Engineer. The ideal candidate should have foundational knowledge of Site Reliability Engineering (SRE) and Kubernetes. Responsibilities include gaining experience in a DevOps-driven environment. Applicants...Long term contractInternshipRemote work- ...An AI DevOps Engineer is responsible for integrating artificial intelligence and machine learning models into operational environments, managing cloud infrastructure, and automating deployment pipelines. This role ensures AI solutions are reliable, scalable, and secure...
- DevOps Engineer Our Client, a multinational telecommunications technology company has an urgent and immediate need for DevOps Engineer to automate and manage cloud deployments using Terraform and Ansible, with expertise in designing scalable CI/CD pipelines in Azure...Temporary workImmediate start3 days per week
- ...renowned and influential company. Among top performers, you can make a direct and meaningful impact.As a Senior Lead Infrastructure Engineer at JPMorganChase within the Corporate Sector - Employee Platforms team, you exhibit both depth and breadth of knowledge regarding...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr DevOps Engineer. Be the first to apply!
- senior devops engineer remote Allen, TX
- senior level Allen, TX
- senior network engineer remote Allen, TX
- senior implementation engineer Allen, TX
- senior medical science liaison Allen, TX
- senior manager m&a tax Allen, TX
- senior accountant Allen, TX
- remote senior business analyst Allen, TX
- senior application security Allen, TX
- senior property accountant Allen, TX



