Senior DevSecOps & Platform Engineering Lead

Phoenix Oversight Group LLC
$180,000 - $210,000Remote

About The Position

The Problem We're Hiring You to Solve A 20-year-old federal platform sits behind a home loan benefit that millions of American families depend on. Your job is to help retire it without anyone noticing. You will own the DevSecOps and platform engineering ecosystem for a modernization program that runs legacy and modern stacks side by side: pipelines that move code from commit to production in under an hour, zero-downtime production deployments, environments built and torn down as code, and observability deep enough to explain a failure before the customer reports it. You will do this inside real federal security constraints, with real authority over how the engineering system works, and with AI as a first-class engineering tool. The Opportunity Most DevSecOps roles hand you an inherited pipeline and a backlog of tickets. This one hands you an engineering system to shape. The program spans multiple applications, technology stacks, and platforms: a legacy suite that must stay stable and secure until it is decommissioned, and a modern cloud platform (Salesforce-centered, supplemented by serverless capabilities in a government cloud) where new capability lands every month. Production runs 24/7 against contractual availability targets. Releases ship to production at least monthly. Critical vulnerabilities must close in 30 days. The monitoring bar is full business transaction visibility, not “the server is up.” You will lead the engineers who make all of that true. Not from a status meeting. From the architecture, the pipeline definitions, the incident bridge, and the customer conversation. You will decide how code moves from a developer's hands to production, how failures get detected and diagnosed, how security gets enforced without slowing delivery, and where automation and AI replace manual work. The outcomes are measured, visible, and attached to a mission that matters. When deployments get faster and incidents get rarer, the customer sees it, and so do the people the program serves. A note on the stack. If “Salesforce” made you hesitate, read this twice. You will not become a Salesforce administrator, and this role will not narrow your career. The application platform is Salesforce. The engineering system around it is not. The CI/CD architecture, environment automation, serverless cloud components, observability, security automation, legacy systems, and AI-enabled workflows are general-purpose platform engineering, and that is where you will spend your time. A strong platform engineer picks up the Salesforce-specific pieces quickly. The reverse is not true, which is why we are hiring for the former.

Requirements

  • Deep hands-on DevSecOps and platform engineering. You have designed and operated CI/CD, infrastructure as code, and deployment automation for real production systems, across more than one stack, and you still write and review the code.
  • Federal delivery experience. You have engineered inside a regulated federal environment and understand authorizations to operate, federal security controls, vulnerability remediation SLAs, and mandated tooling as engineering constraints to design within, not excuses for slow delivery.
  • Production ownership. You have carried responsibility for availability, incident response, and root-cause analysis on systems people depend on, and you diagnose systemic causes instead of treating symptoms.
  • Security as an engineering discipline. You build controls, scanning, and evidence generation into the delivery process rather than bolting them on before an assessment.
  • Demonstrated AI-in-the-loop engineering. You can show us, concretely, how AI tools function in your daily workflow today and what they have made measurably better.
  • Technical leadership. You have led engineers directly, raised a team's standards, made architecture decisions you were accountable for, and explained hard technical tradeoffs to non-engineers clearly.
  • Judgment under ambiguity. You investigate, decide, and act when requirements are incomplete, and you gain alignment without waiting to be handed a spec.
  • Full-time W-2 employment with PhoenixTeam.
  • Must be based in the United States.
  • Fully remote.
  • Work supports a federal civilian agency.
  • Must be able to obtain and maintain the required federal Public Trust clearance. A Secret clearance is not required.

Nice To Haves

  • Salesforce platform or Copado pipeline experience. The delivery platform is partly cloud-native to Salesforce, and a strong engineer can learn it.
  • Experience with government cloud environments, Splunk, or enterprise monitoring integration.
  • Prior work supporting authorization packages, POA&M management, or Zero Trust initiatives.
  • Experience decommissioning legacy systems or running dual-stack transitions.
  • Mortgage or housing finance experience is not required. We will teach you the domain.

Responsibilities

  • The delivery platform. Design and run CI/CD that lets teams move code from commit to production across multiple applications, stacks, and environments with minimal manual intervention. The standard: builds, tests, and deployments complete in under an hour, and production releases ship monthly or faster.
  • Zero-downtime release engineering. Build deployment automation that verifies a release in production before users touch it, and rolls back cleanly when verification fails. Boring deployments are the goal.
  • Environments as code. Automate provisioning so a complete environment stands up or tears down in days, not months, and configuration drift stops being a source of incidents.
  • Security engineered into the pipeline. Make quality and security gates automatic, surface vulnerabilities early instead of at audit time, and drive remediation inside federal 30/60/90-day windows for critical, high, and medium findings. Support multi-year authorizations to operate and the program's Zero Trust alignment as engineering work, not paperwork theater.
  • Observability that explains itself. Build monitoring that covers infrastructure, applications, interfaces, batch jobs, and full business transactions, with alerts that tell the team what failed, why, and what to do about it. The target: no incident the customer discovers before we do.
  • Production reliability. Own incident and problem management, root-cause analysis, capacity and performance management, and tested disaster recovery for systems that run around the clock. Drive the change-caused incident rate toward zero.
  • The legacy-to-modern transition. Keep the legacy platform stable, patched, and authorized while the modern platform absorbs its functions, including the data bridges between them, until decommissioning finishes the job.
  • Developer experience and engineering metrics. Instrument the engineering system itself. Measure build times, deployment frequency, defect escape rates, and toil. Then improve them, visibly and repeatedly.
  • A stronger team. Lead, mentor, and grow the engineers who do this work with you, and set standards the whole program builds on.
  • AI is part of how PhoenixTeam works, and this role is expected to lead by example.
  • We are looking for someone who already uses tools like Claude Code, Cursor, or GitHub Copilot as a normal part of engineering, not someone whose AI experience is mostly conversational. In practice that looks like: generating and reviewing infrastructure definitions, accelerating scripting and pipeline work, diagnosing build and deployment failures faster, analyzing logs during incidents, expanding automated test coverage, keeping documentation current without hating your life, and spotting repetitive work that should stop being done by humans.
  • Beyond personal productivity, we want you to design AI-enabled capabilities that improve the engineering system itself: pipeline diagnostics, automated remediation, vulnerability analysis, engineering knowledge retrieval, developer self-service, and agentic workflows that reduce toil across the team.
  • You will have direct reports. You will hire, mentor, and grow engineers, set engineering standards, and be accountable for the quality of the team's work. You will also stay in the work: architecture decisions, pipeline engineering, gnarly production problems, and code review are yours, not things you delegate and forget.
  • You will work directly with federal customers and decision-makers. That means explaining complex technical decisions in plain language, defending engineering positions with evidence, and respectfully challenging technical direction when it is wrong, including ours. Silent disagreement is a failure mode here.
  • When something is ambiguous, you make the call, document the reasoning, and own the outcome.

Benefits

  • 100% employer-paid medical insurance.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service