Sr DevOps Engineer
Credit Union of Texas Allen, Texas, United States
Financial Services · 201-500 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Senior DevOps Engineer will design and maintain end-to-end CI/CD pipelines and standardize the software development lifecycle on Azure DevOps. They will also implement security, observability, and infrastructure automation practices while contributing to Node.js application development.
What they look for
Requirements
Candidates must have at least five years of DevOps experience with strong proficiency in Azure DevOps and Node.js development. Experience with security scanning tools, containerization, and infrastructure as code is essential for this role.
Full description
Position Summary
The Senior DevOps Engineer supports Credit Union of Texas's vision to be the trusted financial partner for our members and our community by building and owning the end-to-end software development lifecycle (SDLC) on Azure DevOps. The role modernizes and standardizes the SDLC for existing applications, implements CI/CD and multi-environment (Dev, UAT, Prod) strategies, and makes the Node.js application code changes needed to support them. The role establishes secure secrets management, artifact management, static and dynamic application security testing (SAST with JFrog and DAST with Invicti), code quality and test coverage gates (SonarQube), Infrastructure as Code, automated testing, and observability practices (Datadog APM and Logs) that make releases repeatable, traceable, and audit-ready. Once the foundation is in place, the Senior DevOps Engineer contributes to Node.js development and onboards new applications onto the standardized SDLC. The role uses CUTX-approved AI tools under defined governance, with mandatory human review of any AI-assisted code or configuration before it reaches production.
Key Responsibilities
CI/CD, Source Control & Release Management
- Design and implement CI/CD pipelines (YAML) in Azure DevOps for existing and new applications.
- Manage Azure Repos, including branching strategy, branch policies, pull request workflows, and code review gates.
- Design and implement multi-environment strategies (Dev, UAT, Prod) with automated promotion, including the infrastructure and application changes required to support them.
- Set up release strategies such as approvals, environment promotion, and rollback.
- Implement feature flags using Azure App Configuration to reduce release risk.
Security, Secrets & Code Quality
- Implement and standardize secrets management using Azure Key Vault and Managed Identity across applications, including the Node.js code changes needed to load secrets and configuration securely at runtime.
- Establish secure secret lifecycle practices, including rotation and access controls.
- Implement static application security testing (SAST) using JFrog Advanced Security, with critical and high findings blocking merges and releases.
- Integrate SonarQube for code quality and unit test coverage analysis (coverage thresholds, bugs, code smells, duplication, and maintainability), with quality gates enforced on every pull request and pipeline run.
- Integrate Invicti for dynamic application security testing (DAST) against deployed applications in Dev and UAT, with critical and high findings blocking promotion to Production.
- Coordinate triage and remediation of SAST, DAST, dependency, and secret scanning findings with development teams and Information Security, and track them to closure in Azure Boards.
- Implement dependency, vulnerability, and secret scanning (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks) with results enforced in pipelines.
- Enforce code consistency standards with ESLint and Prettier in pull request checks.
Infrastructure, Artifacts & Containers
- Implement Infrastructure as Code (Terraform, Bicep, or ARM) for repeatable environment provisioning.
- Set up and manage JFrog Artifactory for package and artifact management, including npm and Docker registries.
- Containerize applications with Docker where appropriate, and support a future move to Azure Kubernetes Service (AKS).
Testing, Monitoring & Observability
- Build automated testing into pipelines, including unit tests (Jest) and end-to-end tests (Playwright or Cypress).
- Set up monitoring and observability with Datadog APM and Datadog Log Management across all environments, alongside Azure Monitor and Application Insights for Azure platform metrics.
- Instrument Node.js applications with the Datadog APM tracer and structured logging, correlate traces with logs, and build dashboards, monitors, and alerts for service health, performance, and release impact.
Node.js Development & Application Onboarding
- Make code changes in Node.js applications to support DevOps practices such as configuration management, health checks, logging, and automated tests.
- Contribute to Node.js feature development and bug fixes as DevOps priorities allow.
- Onboard new applications onto the standardized SDLC process.
Governance, Documentation & Collaboration
- Set up Azure Boards for work tracking, with work items linked to commits, pull requests, and releases for end-to-end traceability and audit readiness.
- Document pipelines, environments, runbooks, and processes in the Azure DevOps Wiki, and train team members on them.
- Coordinate with Application Development, IT Operations, Information Security, and Compliance to align SDLC standards with enterprise priorities and control requirements.
Performance Outcomes & KPIs
Outcome
Primary KPI
Reporting Cadence
Target / Direction
Applications run on a standardized, automated SDLC.
SDLC Adoption Rate — percent of in-scope applications deployed through standardized Azure DevOps YAML pipelines with automated environment promotion.
Quarterly
▲ 100% of in-scope applications [Timeline — confirm with Hiring Manager]
Releases are reliable and low-risk.
Change Failure Rate — percent of production deployments that require rollback, hotfix, or incident remediation.
Monthly
▼ ≤ 15%
Issues are recovered from quickly.
Mean Time to Restore (MTTR) — average time to restore service after a failed production change.
Monthly
▼ [Target — confirm with Hiring Manager]
Secrets and credentials are managed securely.
Secrets Management Compliance — percent of in-scope applications loading secrets from Azure Key Vault via Managed Identity, with zero secrets in source control.
Quarterly
▲ 100%
Code meets quality and security standards before release.
Security Gate Enforcement — percent of production releases that passed JFrog SAST and Xray dependency scans, Invicti DAST scans, SonarQube code quality and test coverage gates, and secret scans with no unresolved critical or high findings.
Monthly
▲ 100%
Code changes are covered by automated tests.
Test Coverage — percent of in-scope applications meeting the SonarQube unit test coverage threshold on new code.
Monthly
▲ ≥ 80% coverage on new code [confirm threshold with Hiring Manager]
Production applications are fully observable.
Observability Coverage — percent of production applications instrumented with Datadog APM and centralized Datadog logs, with active monitors and alerts.
Quarterly
▲ 100%
Changes are traceable and audit-ready.
Change Traceability Rate — percent of production releases linked to Azure Boards work items, pull requests, and approvals.
Quarterly
▲ 100%
AI-assisted code and configuration are reviewed before use.
Human Review Rate on AI-Assisted Changes — percent of AI-assisted code, pipeline, or IaC changes that went through documented pull request review before merge.
Monthly
▲ 100%
Qualifications
Education
- Bachelor's degree in Computer Science, Software Engineering, Information Systems, or a related field, or equivalent practical experience. [Confirm with Hiring Manager — not specified in source posting]
Experience
- Five (5) or more years of experience in DevOps, with a strong background in software development.
- Strong hands-on experience with Azure DevOps (Repos, Pipelines, YAML, Releases, Environments).
- Solid Node.js development experience, enough to independently read, modify, and ship production code.
- Hands-on experience refactoring application code to use a secrets manager (Azure Key Vault preferred) with Managed Identity.
- Experience with the JFrog Platform (Artifactory, Xray, and Advanced Security SAST) in CI/CD workflows.
- Experience with SonarQube for code quality and test coverage quality gates in CI/CD workflows.
- Experience with dynamic application security testing (DAST) integrated into CI/CD pipelines; Invicti preferred.
- Experience building automated testing into CI/CD pipelines, including unit testing (Jest) and end-to-end testing (Playwright or Cypress).
- Experience with application security scanning tools for dependencies, vulnerabilities, and secrets (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks).
- Experience with Datadog APM and Log Management, including tracer instrumentation, log pipelines, dashboards, and monitors; experience with Azure Monitor and Application Insights.
- Experience with feature flags (Azure App Configuration or similar).
- Experience with Docker and containerized application deployment.
- Experience with Azure Boards or similar work tracking tools, including linking work items to code and releases.
- Proven experience introducing CI/CD and environment standardization to existing applications.
- Kubernetes (AKS) experience preferred.
- Experience with container image scanning and broader DevSecOps practices preferred.
- Prior experience in financial services or another regulated industry preferred.
Licenses, Registrations, and Certifications
- No specific license or registration required for this role.
- Microsoft Azure certifications (AZ-400 DevOps Engineer Expert, AZ-104 Azure Administrator) preferred.
Knowledge & Skills
- Working knowledge of Azure services such as App Service, Functions, AKS, virtual machines, and networking.
- Experience with Infrastructure as Code (Terraform or Bicep preferred).
- Git expertise, including branching strategies such as GitFlow or trunk-based development.
- Scripting skills in PowerShell and/or Bash.
- Experience enforcing code quality standards with ESLint and Prettier.
- Strong documentation habits, including runbooks and process documentation.
- Ability to explain technical standards clearly and train team members on new processes.
- Drive to learn and adopt new technologies, techniques, and CUTX-approved AI tools.
Core Competencies
Competency
Proficiency Level
Why This Matters in This Role
AI Literacy
Intermediate
The role uses AI-assisted code and configuration tools (Tier 2) and must recognize when AI output is wrong or insecure, apply required controls, and ensure human review before changes are merged.
Technical Excellence
Advanced
The role owns the design of pipelines, environments, and release processes that every CUTX application team will depend on.
Risk Awareness
Advanced
Pipeline, secrets, or access-control weaknesses can expose member data or disrupt services; the role must identify, remediate, and escalate security and change risk.
Operational Discipline
Advanced
Pipelines, infrastructure, and documentation must be repeatable, version-controlled, and audit-ready to meet change management and examination expectations.
Communication
Intermediate
The role must document standards clearly, train teams, and explain trade-offs to technical and non-technical partners.
Collaboration
Intermediate
Standardizing the SDLC requires working across development, operations, security, and compliance teams to drive adoption.
Compliance Orientation
Intermediate
SDLC controls must support GLBA data protection, NCUA information security requirements, and TRAIGA-aligned AI governance.
AI & Technology Expectations
AI-Augmented Workflows
The following workflows are AI-augmented in this role. The Senior DevOps Engineer is expected to work fluently within these workflows, exercise sound judgment over AI outputs, and follow all applicable controls.
- AI-assisted code generation and refactoring for Node.js applications.
- AI-assisted authoring of pipeline YAML, Infrastructure as Code templates, and scripts.
- AI-assisted triage and remediation of SAST (JFrog), DAST (Invicti), dependency (JFrog Xray), code quality (SonarQube), and secret scan findings.
- AI-assisted log, trace, alert, and incident analysis using Datadog APM, Datadog Logs, and Azure Monitor data.
- AI-assisted drafting of runbooks, wiki documentation, and training materials.
AI Tier and Human-in-the-Loop Responsibility
This role operates in AI Tier 2 for its principal AI-augmented workflows (see Appendix A). The Senior DevOps Engineer retains accountability for any decision, communication, or member/employee-impacting action influenced by AI output, consistent with the CUTX Generative AI Usage Policy §3.4.
The Senior DevOps Engineer is required to:
- Review, test, and validate all AI-generated code, pipeline definitions, IaC templates, and scripts before they are merged or run against any environment.
- Route every AI-assisted change through the standard pull request, code review, and pipeline quality gates; AI output never bypasses these controls.
- Verify AI-suggested remediations for security findings against authoritative sources before applying them.
- Escalate to the Hiring Manager, IT Security, and the AI Council any use case that would let AI make changes to production systems without human approval, which is treated as Tier 3 and requires additional controls.
- Stop reliance on AI output and escalate immediately if the output appears inaccurate, insecure, non-compliant, or outside the role's documented scope (Generative AI Usage Policy §3.5).
- Refrain from entering secrets, credentials, connection strings, member non-public personal information (NPI), or confidential CUTX source code into any AI tool not explicitly approved for that data classification.
- Complete all required AI training within thirty (30) days of hire and maintain annual currency.
Approved AI Tools
The role is approved to use the following AI tools in performing essential functions (subject to the Generative AI Usage Policy and any tool-specific guidance issued by the AI Council):
- CUTX-approved internal AI assistants (e.g., Sam) for general productivity and approved knowledge tasks.
- Microsoft Copilot for office productivity (drafting, summarization, spreadsheet support).
- CUTX-approved code-assistance tools used within sanctioned development environments and CUTX repositories.
- AI features built into CUTX-approved DevOps, security scanning, and monitoring platforms (e.g., Azure DevOps, JFrog, SonarQube, Invicti, Datadog, and Azure Monitor).
Use of AI tools outside this list requires prior approval from the role's department leader and the AI Council, per the Generative AI Usage Policy §4.
Prohibited AI Use
In addition to the prohibited uses defined in the Generative AI Usage Policy §3.6, the following are specifically prohibited in this role:
- Merging or deploying AI-generated code, configuration, or infrastructure changes without documented human review and passing pipeline quality gates.
- Entering secrets, credentials, keys, connection strings, member NPI, or confidential CUTX source code into any AI tool not explicitly approved for that data classification.
- Granting AI agents or tools autonomous write access to production environments, pipelines, or secrets stores without governance review and required approvals.
- Using unsanctioned third-party AI services for CUTX code generation, infrastructure changes, or log and data analysis.
Compliance & Regulatory Responsibilities
Enterprise Compliance Obligations
The Senior DevOps Engineer is responsible for all enterprise compliance obligations applicable to a CUTX team member, including BSA/AML, OFAC, USA PATRIOT Act/CIP/CDD, GLBA and the Safeguards Rule, Fair Lending laws (ECOA/Reg B, Fair Housing Act), UDAAP, Information Security and Acceptable Use, and the CUTX Code of Conduct.
AI-Specific Compliance Obligations
The Senior DevOps Engineer is responsible for the CUTX Generative AI Usage Policy (TRAIGA / HB 149-aligned), the CUTX AI Playbook (including Tier 2 obligations applicable to this role), and Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149) requirements applicable to the role.
Role-Specific Compliance Obligations
- CUTX Change Management, Release Management, and Secure SDLC standards covering approvals, segregation of duties, testing, and rollback.
- Gramm-Leach-Bliley Act (GLBA) and the Safeguards Rule, and NCUA Part 748 information security program requirements, as applied to systems, pipelines, and environments that handle member data.
- FFIEC IT Examination Handbook expectations for development, acquisition, and operations, including change traceability and audit evidence.
- CUTX Information Security, Access Management, and Secrets Management policies, including least-privilege access and credential rotation.
- CUTX Vendor and Third-Party Risk Management requirements for DevOps, cloud, artifact and security testing (JFrog, Invicti), code quality (SonarQube), and observability (Datadog) tools.
- CUTX Data Governance and Data Classification policies as applied to non-production environments, code repositories, and logs, including masking of member NPI and secrets before logs and traces are sent to Datadog.
Working Conditions & Physical Requirements
This role is performed primarily on-site at the CUTX Corporate Office in the Dallas–Fort Worth, TX area, with hybrid eligibility subject to manager approval and CUTX policy. The work environment is office-based with no significant hazardous or unpleasant conditions. Occasional after-hours or weekend work may be required to support production releases, maintenance windows, or incident response. Essential physical activities include the ability to remain stationary at a workstation for extended periods; operate a computer, telephone, and standard office equipment; perform frequent repetitive motions of the hands, wrists, and fingers (keyboard and mouse use); communicate clearly by phone, email, video, and in person with technical and business partners; and read, analyze, and interpret detailed written and on-screen information. The role requires the ability to apply reasoning to problems involving many variables and to communicate complex technical concepts in plain language. Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions of this role, consistent with the Americans with Disabilities Act and CUTX policy.
Acknowledgement & Disclaimer
This job description is intended to describe the general nature and level of work being performed by individuals assigned to this position. It is not intended to be an exhaustive list of all responsibilities, duties, and skills required, and CUTX reserves the right to modify, add to, or remove duties at any time as business needs require.
Employment with CUTX is at-will. This job description does not constitute an employment contract.
Similar roles
-
DevOps Engineer
GRVTY Lackland AFB, Texas, United States · $104K–$169K/yr
-
DevOps Engineer
Booz Allen Hamilton Dayton, Ohio, United States · $78K–$176K/yr
-
Senior Forward Deployed Engineer (DevOps)
Cloudflare San Francisco, California, United States · $194K–$266K/yr
-
SAP NS2 Senior DevOps Administrator
SAP IT Business Systeme Herndon, Virginia, United States · $117K–$246K/yr
-
Especialista en Infraestructura / DevOps
Initiumsoft Panama City, Panamá Province, Panama
-
DevOps Engineer
MANTECH Doral, Florida, United States