Ascensus is the leading independent technology and service platform powering savings plans across America, providing products and expertise that help nearly 16 million people save for a better today and tomorrow.
Section 1: Position Summary
We are seeking a Senior DevOps Engineer with 10+ years of handson experience designing, building, and operating enterprisegrade CI/CD platforms across hybrid environments (AWS and onpremises). This role will lead platform standardization, progressive delivery, reliability engineering, and securitybydesign to enable highquality, lowrisk software delivery at scale.
Key Responsibilities
CI/CD Platform & Environment Strategy
- Design, implement, and operate a standardized CI/CD framework supporting Dev, QA, PartnerLab, Staging, and Production
- Define promotion workflows with enforced quality gates and artifact immutability
- Establish PartnerLab as a dedicated integration and validation environment with no direct path to Production
- Ensure environment parity across AWS and onprem systems
Progressive Delivery & Release Engineering
- Implement feature flags, canary deployments, bluegreen deployments, and phased rollouts
- Enable automated rollback based on health checks, error rates, and SLO breaches
- Maintain full release traceability from commit through production
Test Automation & Quality Engineering
- Integrate unit, integration, regression, security, and performance testing into CI/CD pipelines
- Enforce automated quality gates before environment promotion
- Support manual validation workflows with controlled access, observability, and test artifacts
Database & Data Automation
- Automate database schema versioning, migrations, rollbacks, and validation
- Build lowerenvironment refresh pipelines sourced from production data
- Enforce data masking and PII anonymization for nonproduction environments
- Validate data integrity and consistency postrefresh
Observability, Reliability & Operations
- Define and enforce observability standards across logs, metrics, and traces
- Implement service health dashboards, alerts, and incident signals
- Integrate deployment health into automated release decisions
- Support oncall readiness, incident response, and postincident reviews
Security, Governance & Compliance
- Embed security scanning, secrets management, and access controls into pipelines
- Enforce leastprivilege IAM, credential rotation, and artifact integrity checks
- Align CI/CD workflows with enterprise change management and audit requirements
Required Technical Skills
Cloud & Infrastructure
- AWS (mandatory): ECS, EKS, Lambda, RDS, IAM, CloudFormation, CloudWatch
- Hybrid infrastructure experience across onprem VMs, bare metal, and internal networks
- Terraform for modular, reusable, policycompliant infrastructure
CI/CD & Platform Engineering
- GitHub Enterprise & GitHub Actions (reusable workflows, templates, runners, environments)
- CI/CD orchestration across hybrid AWS and onprem topologies
- Artifact versioning, promotion, and immutability strategies
Containers & Orchestration
- Docker image design, optimization, and security hardening
- Kubernetes (EKS and onprem) deployment patterns, scaling, and lifecycle management
- Helm for deployment standardization
Testing, Release Safety & Analysis
- Automated testing frameworks (unit, integration, regression, performance)
- Static and dynamic analysis tools (code quality, security, dependency scanning)
- Feature flag platforms or equivalent internal capabilities
Database & Data Management
- Oracle and Microsoft SQL Server (mandatory)
- Schema migration tooling with automated rollback
- Data masking, anonymization, and controlled refresh automation
Observability & Reliability Engineering
- Metrics, logging, and tracing with Prometheus, Grafana, Splunk, New Relic, CloudWatch, OpenTelemetry, ELK
- SLOdriven alerting and deployment health evaluation (e.g., Uptrends, PagerDuty)
- Automated failure containment and rollback strategies
Security & Secrets Management
- HashiCorp Vault, AWS Secrets Manager, or equivalent
- Secure pipeline design with controlled credential access
- Complianceready logging, approvals, and traceability
Soft Skills & Delivery Expectations- Experience in regulated or financial services environments
- Strong documentation, runbooks, and architectural communication
- Proven collaboration with application, infrastructure, security, and QA teams
- Comfortable operating in enterprise, onshore delivery models
We are proud to be an Equal Opportunity Employer
The national average salary range for this role is 120-165k in base pay, exclusive of any bonuses and benefits.This base salary range represents the low and high end of the salary range for this position. Actual salary offered will vary and may be above or below the range based on various factors including but not limited to location, experience, performance, and internal pay alignment. We do not anticipate that candidates hired will begin at the top of the range however, from time to time, it may occur on a case-by-case basis. Other rewards and benefits may include: 401(k) match, Medical, Dental, Vision, Paid-Time-Off, etc. For more information, please visit careers.ascensus.com/#Benefits.
Be aware of employment fraud. All email communications from Ascensus or its hiring managers originate from @ascensus.com or @futureplan.com email addresses. We will never ask you for payment or require you to purchase any equipment. If you are suspicious or unsure about validity of a job posting, we strongly encourage you to apply directly through our website.