| Location | St. Louis, MO |
Summary
We are seeking an experienced DevSecOps platform engineer to join the DevSecOps platform team that owns the enterprise DevSecOps toolchain supporting the full software development lifecycle for 300+ developers.
This is a dual-mandate role: the consultant must become productive on our existing self-hosted toolchain on AWS EKS quickly enough to carry real operational load, while contributing to our consolidation and migration to a SaaS-based toolchain.
Environment
Current : GitHub Enterprise Server, CloudBees CI (Jenkins) on EKS, JFrog Artifactory & Xray, SonarQube, Jira/Confluence Data Center on EKS; AWS (EKS, EC2, ECS, VPC, IAM, S3, Route 53, KMS, EFS, RDS); Terraform; Helm; Docker; Prometheus/Grafana; Azure AD/SSO
Target : GitHub Enterprise Cloud (EMU) with Azure AD federation and SCIM GitHub Actions replacing CloudBees CI Actions Runner Controller (ARC) self-hosted runners on EKS repository migration at scale via GitHub Enterprise Importer consolidated code security scanning Atlassian Cloud
Responsibilities
Operate the current platform :-
- Administer CloudBees CI on EKS and GitHub Enterprise Server - lifecycle, upgrades, access governance, patching, and build troubleshooting
- Operate Artifactory, Xray, and SonarQube; support integrations
- Maintain and extend Terraform infrastructure code through PR-based pipeline workflows
- Manage Kubernetes workloads on EKS - Helm releases, storage, scaling, troubleshooting
- Resolve production incidents across compute, storage, networking, identity, and certificate layers; support 300+ developers
- Drive vulnerability remediation and patch cadence; produce runbooks and documentation
Drive consolidation and migration :-
- Build and operate ARC self-hosted runners on EKS, including hardening and private VPC connectivity
- Convert Jenkins shared-library pipelines to GitHub Actions reusable workflows
- Plan and execute phased repository migration waves, with validation and rollback
- Configure enterprise identity, SSO/SCIM, and access governance in the target platform
- Support developer onboarding and enablement; contribute to decommissioning plans
Required Qualifications
-Bachelor's degree is required
-7+ years in DevOps / DevSecOps / platform engineering
- Hands-on administration of an enterprise CI platform (Jenkins/CloudBees preferred) and pipeline development using shared/reusable libraries
- Practical GitHub Actions experience - workflows, reusable workflows, runners, secrets
- Strong hands-on AWS (EKS, EC2, VPC, IAM, S3, Route 53, KMS, EFS) and production Kubernetes
- Terraform at production scale - modules, state management, multi-environment, pipeline-driven plan/apply; plus Helm and Docker
- Pipeline security tooling: SAST, SCA, SBOM, container scanning, quality gates
- Core systems fundamentals (non-negotiable) :-
- Linux administration and troubleshooting
- Networking - TCP/IP, DNS, routing, firewalls, load balancing, proxies, VPN/Transit Gateway, packet-level diagnostics
- Certificates and TLS - PKI, issuance, and renewal, truststores, mTLS
- Identity - LDAP, Azure AD / SAML / OIDC, SSO, SCIM, RBAC
- Scripting in Python, Bash, and Groovy
- Ability to work independently with broad ownership; strong documentation discipline; participation in on-call rotation
Preferred Qualifications
- Prior GHES ? GitHub Enterprise Cloud / EMU migration or Jenkins ? GitHub Actions conversion at enterprise scale
- GitHub Enterprise Importer (GEI) and Actions Runner Controller (ARC) production experience
- Artifactory/Xray, SonarQube, or Atlassian Cloud migration experience
- AWS certification (DevOps Engineer Professional or Solutions Architect)
- Experience in a regulated enterprise environment with formal change management
Required Skills :
Basic Qualification :
Additional Skills :
Background Check : No
Drug Screen : No