Platform & DevSecOps Delivery Architect
Posted 9hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Platform & DevSecOps Architect building automated CI/CD, security, and AI infrastructure for STChealth’s public-health software. Enabling compliant delivery across Kubernetes and legacy systems.
Responsibilities:
- Architect, implement, and maintain centralized reusable CI/CD pipeline templates using GitHub Actions or GitLab CI
- Build modular release architecture with universal scanning and sanitization upstream and downstream delivery branching
- Implement GitOps promotion with ArgoCD/Kargo, progressive canary rollouts with Argo Rollouts, and Amazon EKS delivery
- Build machine-image pipelines using HashiCorp Packer and AWS Launch Templates, plus blue/green agent updates for EC2/ClearData Docker systems
- Provide compliant project scaffolding and Helm/IaC modules for engineering self-service
- Embed SAST, SCA, container image, snapshot CVE, and secret-detection gates into build processes
- Generate software artifacts and deployment logs for SOC 2 Type II, HIPAA, and federal public-health audits
- Design and operate secrets distribution through External Secrets Operator with AWS Secrets Manager/Parameter Store and least-privilege IAM
- Partner with Engineering leads to enforce automated operational readiness standards before staging or production
- Integrate OpenTelemetry instrumentation for logging, distributed tracing, and metrics feeding Grafana LGTM and Datadog
- Embed PHI and PII sanitization checks into build and logging pipelines
- Architect and operate secure private AI infrastructure, gateways, traffic routing, rate limiting, and private cloud-hosted LLM endpoints
- Design, deploy, and support scalable environments for autonomous agentic workflows, multi-agent pipelines, vector storage, and operational context retrieval
Requirements:
- 5+ years of hands-on experience in Platform Engineering, DevOps, or Site Reliability Engineering (SRE)
- Demonstrated experience designing and standardizing enterprise CI/CD pipelines
- Deep hands-on proficiency with Amazon Web Services (AWS) and Kubernetes (Amazon EKS), including container networking, pod security, and Helm chart lifecycle management
- Practical experience with GitOps controllers (ArgoCD, Flux) and automated canary deployment strategies (Argo Rollouts, weighted ingress, or ALB traffic shifting)
- Practical software development experience with C# / .NET, Node.js, and Python
- Hands-on experience engineering self-hosted AI architecture, including AI model gateways, intelligent request routing, and orchestrating multi-step agentic workflows
- Working knowledge of VM-based delivery concepts (HashiCorp Packer, EC2 Launch Templates, Cloud-Init, or rolling agent deployments)
- Experience integrating security scanning tools (Trivy, Snyk, SonarQube, AWS Inspector, or similar) directly into deployment workflows as non-negotiable quality gates
- Solid experience authoring modular, maintainable Terraform or Pulumi definitions
- Practical capability with AI-assisted development tools and infrastructure for AI-driven workloads
- Experience working inside AWS GovCloud and navigating GovCloud IAM/IRSA partition boundaries is highly regarded
- Background in HIPAA-regulated, HITRUST, or public-sector SaaS data environments is highly regarded
- Experience building and deploying backend services or automated agent frameworks in C# (.NET Core), Python, or Node.js/TypeScript is highly regarded
- Experience deploying and managing vector databases such as Qdrant or pgvector and embedding inference pipelines in containerized environments is highly regarded
Benefits:
- 100% Remote Flexibility: Work from home anywhere within the United States
- Medical, Dental, and Vision coverage starting on your first day of employment
- 401(k) matching program
- Constellation Software employee stock ownership opportunities
- 3 weeks of vacation
- 5 personal days
- Company-recognized holidays


















