Senior DevOps Engineer

Atlanta. Boston. Newton. Charlotte. Philadelphia. Dallas

Senior DevOps Engineer

  • Atlanta, Georgia
  • Boston, Massachusetts
  • Newton, Massachusetts
  • Charlotte, North Carolina
  • Philadelphia, Pennsylvania
  • Dallas, Texas

Show More Show Less

  • Full time
  • Opening on: May 6 2026
  • Hybrid
  • Ascensus
View favorites

Ascensus is the leading independent technology and service platform powering savings plans across America, providing products and expertise that help nearly 16 million people save for a better today and tomorrow.

 

Section 1: Position Summary

We are seeking a Senior DevOps Engineer with 10+ years of hands‑on experience designing, building, and operating enterprise‑grade CI/CD platforms across hybrid environments (AWS and on‑premises). This role will lead platform standardization, progressive delivery, reliability engineering, and security‑by‑design to enable high‑quality, low‑risk software delivery at scale.

Key Responsibilities

CI/CD Platform & Environment Strategy

  • Design, implement, and operate a standardized CI/CD framework supporting Dev, QA, PartnerLab, Staging, and Production
  • Define promotion workflows with enforced quality gates and artifact immutability
  • Establish PartnerLab as a dedicated integration and validation environment with no direct path to Production
  • Ensure environment parity across AWS and on‑prem systems

Progressive Delivery & Release Engineering

  • Implement feature flags, canary deployments, blue‑green deployments, and phased rollouts
  • Enable automated rollback based on health checks, error rates, and SLO breaches
  • Maintain full release traceability from commit through production

Test Automation & Quality Engineering

  • Integrate unit, integration, regression, security, and performance testing into CI/CD pipelines
  • Enforce automated quality gates before environment promotion
  • Support manual validation workflows with controlled access, observability, and test artifacts

Database & Data Automation

  • Automate database schema versioning, migrations, rollbacks, and validation
  • Build lower‑environment refresh pipelines sourced from production data
  • Enforce data masking and PII anonymization for non‑production environments
  • Validate data integrity and consistency post‑refresh

Observability, Reliability & Operations

  • Define and enforce observability standards across logs, metrics, and traces
  • Implement service health dashboards, alerts, and incident signals
  • Integrate deployment health into automated release decisions
  • Support on‑call readiness, incident response, and post‑incident reviews

Security, Governance & Compliance

  • Embed security scanning, secrets management, and access controls into pipelines
  • Enforce least‑privilege IAM, credential rotation, and artifact integrity checks
  • Align CI/CD workflows with enterprise change management and audit requirements

Required Technical Skills

Cloud & Infrastructure

  • AWS (mandatory): ECS, EKS, Lambda, RDS, IAM, CloudFormation, CloudWatch
  • Hybrid infrastructure experience across on‑prem VMs, bare metal, and internal networks
  • Terraform for modular, reusable, policy‑compliant infrastructure

CI/CD & Platform Engineering

  • GitHub Enterprise & GitHub Actions (reusable workflows, templates, runners, environments)
  • CI/CD orchestration across hybrid AWS and on‑prem topologies
  • Artifact versioning, promotion, and immutability strategies

Containers & Orchestration

  • Docker image design, optimization, and security hardening
  • Kubernetes (EKS and on‑prem) deployment patterns, scaling, and lifecycle management
  • Helm for deployment standardization

Testing, Release Safety & Analysis

  • Automated testing frameworks (unit, integration, regression, performance)
  • Static and dynamic analysis tools (code quality, security, dependency scanning)
  • Feature flag platforms or equivalent internal capabilities

Database & Data Management

  • Oracle and Microsoft SQL Server (mandatory)
  • Schema migration tooling with automated rollback
  • Data masking, anonymization, and controlled refresh automation

Observability & Reliability Engineering

  • Metrics, logging, and tracing with Prometheus, Grafana, Splunk, New Relic, CloudWatch, OpenTelemetry, ELK
  • SLO‑driven alerting and deployment health evaluation (e.g., Uptrends, PagerDuty)
  • Automated failure containment and rollback strategies

Security & Secrets Management

  • HashiCorp Vault, AWS Secrets Manager, or equivalent
  • Secure pipeline design with controlled credential access
  • Compliance‑ready logging, approvals, and traceability

Soft Skills & Delivery Expectations

  • Experience in regulated or financial services environments
  • Strong documentation, runbooks, and architectural communication
  • Proven collaboration with application, infrastructure, security, and QA teams
  • Comfortable operating in enterprise, onshore delivery models

We are proud to be an Equal Opportunity Employer

The national average salary range for this role is  120-165k in base pay, exclusive of any bonuses and benefits. This base salary range represents the low and high end of the salary range for this position. Actual salary offered will vary and may be above or below the range based on various factors including but not limited to location, experience, performance, and internal pay alignment. We do not anticipate that candidates hired will begin at the top of the range however, from time to time, it may occur on a case-by-case basis.  Other rewards and benefits may include: 401(k) match, Medical, Dental, Vision, Paid-Time-Off, etc.  For more information, please visit careers.ascensus.com/#Benefits. 

Be aware of employment fraud. All email communications from Ascensus or its hiring managers originate from @ascensus.com or @futureplan.com email addresses. We will never ask you for payment or require you to purchase any equipment. If you are suspicious or unsure about validity of a job posting, we strongly encourage you to apply directly through our website.

For all virtual remote positions, in order to ensure associates can effectively perform their job duties with no distractions, we require an uninterrupted virtual work space and there is also an expectation of family care being in place during business hours. Additionally, there is an internet work speed requirement of 25 MBps or better for individual use. If more than one person is utilizing the same internet connection in the same household or building, then a stronger connection is required. If you are unsure of your internet speed, please check with your service provider. Note: For call center roles specifically, it is a requirement to either hardwire your equipment directly to the internet router or ensure your workstation is in close proximity to the router. Please ensure that you are able to meet these expectations before applying.

Ascensus provides equal employment opportunities to all associates and applicants for employment without regard to ancestry, race, color, religion, sex, (including pregnancy, childbirth, breastfeeding and/or related medical conditions), gender, gender identity, gender expression, national origin, age, physical or mental disability, medical condition (including cancer and genetic characteristics), marital status, military or veteran status, genetic information, sexual orientation, criminal conviction record or any other protected category in accordance with applicable federal, state, or local laws (“Protected Status”).