Logo for Harris Computer

Platform & DevSecOps Delivery Architect

Role overview

Qualifications

  • 5+ years of hands-on experience in Platform Engineering, DevOps, or Site Reliability Engineering (SRE)
  • Deep hands-on proficiency with Amazon Web Services (AWS) and Kubernetes (Amazon EKS)
  • Practical experience with GitOps controllers (ArgoCD, Flux) and automated canary deployment strategies
  • Experience integrating security scanning tools directly into deployment workflows

Responsibilities

  • Architect, implement, and maintain centralized, reusable pipeline templates for CI/CD
  • Provide engineering teams with pre-configured project scaffolding and IaC modules
  • Embed automated vulnerability scanning directly into the build process
  • Design and operate programmatic secrets distribution for least-privilege IAM roles

Key facts

Hard skills

Other skills

  • Problem Solving
  • Teamwork
  • Communication

About the company

Harris Computer logo

Harris Computer

Computer Software / SaaS

Harris provides mission-critical software solutions for the Public Sector, Healthcare, Utilities, and Private Sector verticals throughout North America, Europe, Asia, and Australia. Harris is a wholly-owned subsidiary of Constellation Software, Inc (CSI), a publicly-traded company on the Toronto Stock Exchange. Trading symbol CSU.

Company details

Company typeLarge
IndustryComputer Software / SaaS
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

About the Opportunity & The Mission 

STChealth has nearly 40 years safeguarding communities by building the systems that report and verify more than a quarter of all childhood and adult vaccinations nationwide. As part of the Harris family of software companies, we deliver mission-critical public sector technology where platform stability directly protects public health. 


We are seeking a Platform & DevSecOps Delivery Architect to act as the primary owner and builder of our modern "Golden Path" deployment platform. 

This role is not about babysitting infrastructure or handling one-off developer support tickets. It is about building an automated, secure, self-service software delivery platform that makes shipping safe, compliant code effortless for development teams. You will bridge our high-throughput modern platform and our existing production systems, ensuring every build meets rigorous DevSecOps and Operational Readiness standards—regardless of where the code ultimately lands. 


If you love clean pipeline architecture, automated security rails, and solving complex distributed systems puzzles with a high degree of autonomy, this role is built for you.


What You Will Build and Own

1. The Paved Road / "Golden Path" Delivery Engine

  • Universal CI/CD Pipelines: Architect, implement, and maintain centralized, reusable pipeline templates (GitHub Actions / GitLab CI) that abstract underlying infrastructure away from software developers.
  • Dual-Target Dispatching: Build a modular release architecture that runs universal scanning and sanitization upstream, while intelligently branching to specific downstream delivery targets:
  • Modern Engine: GitOps promotion (ArgoCD / Kargo) with progressive canary rollouts (Argo Rollouts) to Amazon EKS.
  • Core VM Engine: Automated machine-image pipelines (HashiCorp Packer, AWS Launch Templates) and blue/green agent updates (EC2 / ClearData Docker) for state production systems.
  • Shift-Down Self-Service: Provide engineering teams with pre-configured project scaffolding and Helm/IaC modules so they can stand up new services independently within compliant guardrails.

2. DevSecOps & Security Gate Automation

  • Automated Pipeline Gates: Embed automated vulnerability scanning directly into the build process:
  • Static Application Security Testing (SAST) and Software Composition Analysis (SCA) dependency checks.
  • Container image hygiene and snapshot CVE detection prior to promotion.
  • Pre-commit and pipeline secret-detection to eliminate static credential leaks.
  • Automated Compliance & Audit Trails: Build automated generation of software artifacts and deployment logs to satisfy strict SOC 2 Type II, HIPAA, and federal public-health security audits without manual spreadsheets. 
  • Runtime Identity & Secrets Governance: Design and operate programmatic secrets distribution via External Secrets Operator (ESO) syncing from AWS Secrets Manager / Parameter Store backed by least-privilege IAM roles.

3. Operational Readiness Reviews (ORRs) as Code

  • Enforcing Quality Guardrails: Partner with Engineering leads to ensure no service reaches staging or production without meeting automated operational standards.
  • Telemetry Scaffolding: Ensure all platform templates integrate standardized OpenTelemetry (OTel) instrumentation for logging, distributed tracing, and metrics (feeding the Grafana LGTM stack and Datadog).
  • Data Privacy at the Edge: Embed client-side sanitization checks into build and logging pipelines to verify Protected Health Information (PHI) and PII are redacted before data reaches centralized collectors.

4. Self-Hosted AI Infrastructure & Agentic Orchestration

  • AI Routing & Gateways: Architect and operate secure, compliant private AI infrastructure—including self-hosted AI gateways, traffic routing, rate limiting, and private cloud-hosted LLM endpoints.
  • Agentic Workflows & Orchestration: Design, deploy, and support scalable execution environments for autonomous agentic workflows, orchestrating multi-agent pipelines, vector storage integration, and operational context retrieval.

What We Are Looking For

  • Architecture Experience: 5+ years of hands-on experience in Platform Engineering, DevOps, or Site Reliability Engineering (SRE), with demonstrated experience designing and standardizing enterprise CI/CD pipelines. 
  • Cloud & Containers: Deep hands-on proficiency with Amazon Web Services (AWS) and Kubernetes (Amazon EKS), including container networking, pod security, and Helm chart lifecycle management. 
  • GitOps & Delivery Mechanics: Practical experience with GitOps controllers (ArgoCD, Flux) and automated canary deployment strategies (Argo Rollouts, weighted ingress, or ALB traffic shifting).
  • Coding & Systems Development: Practical software development experience with C# / .NET, Node.js, and Python to build internal tooling, automate platform interfaces, and understand service-level application code.
  • AI Infrastructure & Agentic Systems: Hands-on experience engineering self-hosted AI architecture, including AI model gateways, intelligent request routing, and orchestrating multi-step agentic workflows.
  • Traditional Infrastructure Chops: Working knowledge of VM-based delivery concepts (HashiCorp Packer, EC2 Launch Templates, Cloud-Init, or rolling agent deployments). 
  • DevSecOps Integration: Experience integrating security scanning tools (Trivy, Snyk, SonarQube, AWS Inspector, or similar) directly into deployment workflows as non-negotiable quality gates. 
  • Infrastructure as Code (IaC): Solid experience authoring modular, maintainable Terraform or Pulumi definitions.
  • AI & Innovation Mindset: Deep curiosity and practical capability with emerging technologies—both in leveraging AI-assisted development tools (copilots, chat assistants) to accelerate operational toil, and in architecting scalable infrastructure for AI-driven workloads. 

Highly Regarded Nice-to-Haves

  • Experience working inside AWS GovCloud (aws-us-gov partition) and navigating GovCloud IAM/IRSA partition boundaries.
  • Background in HIPAA-regulated, HITRUST, or public-sector SaaS data environments.
  • Experience building and deploying backend services or automated agent frameworks in C# (.NET Core), Python, or Node.js/TypeScript. 
  • Experience deploying and managing vector databases (e.g., Qdrant, pgvector) and embedding inference pipelines in containerized environments.

What We Offer

  • 100% Remote Flexibility: Work from home anywhere within the United States. 
  • Comprehensive Day-One Benefits: Medical, Dental, and Vision coverage starting on your first day of employment.  
  • Retirement & Equity Programs: 401(k) matching program and Constellation Software employee stock ownership opportunities.  
  • Work-Life Balance: 3 weeks of vacation, 5 personal days, and company-recognized holidays.  
  • Mission Impact: The platform you build directly supports the delivery of systems tracking vaccines and protecting public health across the nation.  

About Us:
STChealth, founded in 1988, is dedicated to eradicating vaccine-preventable diseases through innovative technology and service solutions. With over 36 years of experience, the company has developed the first Immunization Information System (IIS) and now supports more than a quarter of all vaccinations reported nationwide. STChealth’s platform securely connects consumers, providers, and public health entities, facilitating real-time data exchange to enhance immunization rates and public health responses.


Recognized for its commitment to employee well-being, STChealth has received the 2024 Top Workplaces Industry Award and the American Heart Association’s Gold Recognition for promoting a healthy work culture. The company values innovation, work-life flexibility, and a collaborative environment, making it an attractive workplace for professionals passionate about public health and technology. Learn more at: stchealth.com


About Harris:

Harris is a leading provider of mission critical software to the public sector in North America. As a wholly owned subsidiary of Constellation Software Inc. (“CSI”, symbol CSU on the TSX), Harris has become the cornerstone for CSI’s investment in utility, local government, school districts, public safety, and healthcare software verticals.


Our success has been realized through investments in our proprietary software and market expertise. This focus, combined with acquiring businesses that build upon or complement our offerings, has helped drive our success. Harris will continue to growth through reinvestment – both in the people and products that we offer and making investments in acquiring new businesses.


#LI-remote

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Harris Computer

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.