Job Type
Full-time
Description
This government contract position requires:
- US Citizen
- Ability to obtain a DoW (formerly DoD) Active Secret clearance
Centex Technologies is seeking three (3) strong Senior DevOps Engineers to support our work with the Air Force. This is an incredible opportunity to transform how the Air Force handles data, moving away from the limitations of siloed, monolithic datasets. We're building a secure, scalable Data Mesh Environment (DME) that will unlock advanced data discovery, access, and interoperability across the Department of the Air Force (DAF). This isn't just a technical upgrade; it's a fundamental shift that will provide our warfighters with real-time, governed access to diverse and distributed data products. Imagine the possibilities: faster decision-making in dynamic operational environments, improved interoperability between domains, and a new foundation for distributed data operations.
By enabling a unified approach to identity access management, enterprise metadata tagging, and streaming data pipelines, we are creating a resilient platform that will accelerate data readiness and give our military a critical decision advantage. The DME will ensure secure, scalable integrations and automated Zero Trust policy enforcement. The work we're doing will directly support the Cloud One mission. We will be designing the architecture, prototyping core capabilities, and providing the long-term sustainment needed to ensure mission continuity. This project will empower our forces with the data they need, when they need it, to stay ahead of any adversary.
Position Description (what you will do):
- Own and evolve infrastructure-as-code, CI/CD, and cloud deployment patterns for the DME / ACDC platform application stacks (Node.js/React dashboard, API gateway, identity, and policy services).
- Design, implement, and maintain Terraform modules and environment pipelines that provision and operate AWS workloads (ECS, RDS, IAM, networking, and supporting services) across multiple non-prod and production-like environments.
- Build and harden GitLab CI/CD workflows for plan/apply, image build/push, and controlled deployments, including runner configuration, credentials/role assumption, and environment promotion practices.
- Partner with application engineers to make services operable in AWS: ECS task definitions, autoscaling, service lifecycle, secrets/config, logging/metrics, and safe restart/redeploy patterns.
- Drive platform reliability and cost efficiency through automation (for example, environment park/wake schedules, inventory-driven start/stop tooling, and guardrails that prevent unsafe operations on protected environments).
- Embed security into delivery: least-privilege IAM, permissions boundaries, secure defaults for containers and pipelines, secret handling, and compliance-minded patterns for GovCloud / elevated environments.
- Lead incident and change support for infrastructure and pipeline failures—diagnose Terraform/state, CI, and AWS runtime issues, and land durable fixes.
- Improve engineering maturity through reusable modules, documented runbooks, reviewable IaC standards, and mentorship of developers on DevOps/DevSecOps practices.
- Review merge requests for infrastructure, CI, and deployment changes; uphold quality, security, and operational readiness before merge.
Requirements
- US Citizen
- Ability to obtain a DoW (formerly DoD) Active Secret clearance
- Experience: 6+ years in DevOps, DevSecOps, SRE, or platform engineering roles supporting production cloud applications (or equivalent depth with clear ownership of CI/CD + cloud infrastructure).
- Cloud & IaC: Hands-on experience designing and operating AWS workloads with Terraform (multi-env var files, remote state, modules, and safe plan/apply workflows).
- Containers & compute: Experience deploying and operating containerized services on ECS (or EKS/Kubernetes with clear transferability), including task/service definitions, autoscaling, and rollout practices.
- CI/CD: Strong experience building and maintaining pipelines in GitLab CI (or similar) for infrastructure and application delivery, including secrets, OIDC/role assumption, and environment-based promotion.
- Security: Practical DevSecOps mindset—IAM least privilege, secure pipeline design, secret management, and hardening of build/deploy paths.
- Collaboration: Ability to work closely with application teams (Node.js/React and backend services), translate operational requirements into automation, and communicate clearly in design reviews and MR feedback.
- Troubleshooting: Proven ability to debug failed pipelines, Terraform drift/apply errors, and AWS runtime issues under time pressure.
Nice to Have:
- Experience with AWS GovCloud and/or DoD / Cloud One / IL4–IL6 style environments and controls.
- Experience with API gateways (e.g. Tyk or equivalents), ICAM / AuthN / AuthZ platforms (e.g. Keycloak), and policy engines (e.g. OPA).
- Experience with FinOps / cost-control automation (scheduled scale-to-zero, start/stop of RDS/ECS, environment inventories).
- Experience with Docker image build, lightening/hardening, and ECR (or equivalent registries).
- Experience with Systems Manager, EventBridge/scheduling patterns, and App Auto Scaling for ECS.
- Experience with SonarQube or other automated quality/security scanning in CI.
- Experience with environment factories/bootstrap modules that provision accounts or shared platform baselines.
- Ability to obtain U.S. Security Clearance.