Sr DevOps Engineer

Credit Union of Texas•Allen, TX
•Hybrid

About The Position

The Senior DevOps Engineer supports Credit Union of Texas's vision to be the trusted financial partner for our members and our community by building and owning the end-to-end software development lifecycle (SDLC) on Azure DevOps. The role modernizes and standardizes the SDLC for existing applications, implements CI/CD and multi-environment (Dev, UAT, Prod) strategies, and makes the Node.js application code changes needed to support them. The role establishes secure secrets management, artifact management, static and dynamic application security testing (SAST with JFrog and DAST with Invicti), code quality and test coverage gates (SonarQube), Infrastructure as Code, automated testing, and observability practices (Datadog APM and Logs) that make releases repeatable, traceable, and audit-ready. Once the foundation is in place, the Senior DevOps Engineer contributes to Node.js development and onboards new applications onto the standardized SDLC. The role uses CUTX-approved AI tools under defined governance, with mandatory human review of any AI-assisted code or configuration before it reaches production.

Requirements

  • Bachelor's degree in Computer Science, Software Engineering, Information Systems, or a related field, or equivalent practical experience.
  • Five (5) or more years of experience in DevOps, with a strong background in software development.
  • Strong hands-on experience with Azure DevOps (Repos, Pipelines, YAML, Releases, Environments).
  • Solid Node.js development experience, enough to independently read, modify, and ship production code.
  • Hands-on experience refactoring application code to use a secrets manager (Azure Key Vault preferred) with Managed Identity.
  • Experience with the JFrog Platform (Artifactory, Xray, and Advanced Security SAST) in CI/CD workflows.
  • Experience with SonarQube for code quality and test coverage quality gates in CI/CD workflows.
  • Experience with dynamic application security testing (DAST) integrated into CI/CD pipelines; Invicti preferred.
  • Experience building automated testing into CI/CD pipelines, including unit testing (Jest) and end-to-end testing (Playwright or Cypress).
  • Experience with application security scanning tools for dependencies, vulnerabilities, and secrets (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks).
  • Experience with Datadog APM and Log Management, including tracer instrumentation, log pipelines, dashboards, and monitors; experience with Azure Monitor and Application Insights.
  • Experience with feature flags (Azure App Configuration or similar).
  • Experience with Docker and containerized application deployment.
  • Experience with Azure Boards or similar work tracking tools, including linking work items to code and releases.
  • Proven experience introducing CI/CD and environment standardization to existing applications.
  • Working knowledge of Azure services such as App Service, Functions, AKS, virtual machines, and networking.
  • Experience with Infrastructure as Code (Terraform or Bicep preferred).
  • Git expertise, including branching strategies such as GitFlow or trunk-based development.
  • Scripting skills in PowerShell and/or Bash.
  • Experience enforcing code quality standards with ESLint and Prettier.
  • Strong documentation habits, including runbooks and process documentation.
  • Ability to explain technical standards clearly and train team members on new processes.
  • Drive to learn and adopt new technologies, techniques, and CUTX-approved AI tools.
  • Intermediate AI Literacy.
  • Advanced Technical Excellence.
  • Advanced Risk Awareness.
  • Advanced Operational Discipline.
  • Intermediate Communication.
  • Intermediate Collaboration.
  • Intermediate Compliance Orientation.

Nice To Haves

  • Kubernetes (AKS) experience preferred.
  • Experience with container image scanning and broader DevSecOps practices preferred.
  • Prior experience in financial services or another regulated industry preferred.
  • Microsoft Azure certifications (AZ-400 DevOps Engineer Expert, AZ-104 Azure Administrator) preferred.

Responsibilities

  • Design and implement CI/CD pipelines (YAML) in Azure DevOps for existing and new applications.
  • Manage Azure Repos, including branching strategy, branch policies, pull request workflows, and code review gates.
  • Design and implement multi-environment strategies (Dev, UAT, Prod) with automated promotion, including the infrastructure and application changes required to support them.
  • Set up release strategies such as approvals, environment promotion, and rollback.
  • Implement feature flags using Azure App Configuration to reduce release risk.
  • Implement and standardize secrets management using Azure Key Vault and Managed Identity across applications, including the Node.js code changes needed to load secrets and configuration securely at runtime.
  • Establish secure secret lifecycle practices, including rotation and access controls.
  • Implement static application security testing (SAST) using JFrog Advanced Security, with critical and high findings blocking merges and releases.
  • Integrate SonarQube for code quality and unit test coverage analysis (coverage thresholds, bugs, code smells, duplication, and maintainability), with quality gates enforced on every pull request and pipeline run.
  • Integrate Invicti for dynamic application security testing (DAST) against deployed applications in Dev and UAT, with critical and high findings blocking promotion to Production.
  • Coordinate triage and remediation of SAST, DAST, dependency, and secret scanning findings with development teams and Information Security, and track them to closure in Azure Boards.
  • Implement dependency, vulnerability, and secret scanning (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks) with results enforced in pipelines.
  • Enforce code consistency standards with ESLint and Prettier in pull request checks.
  • Implement Infrastructure as Code (Terraform, Bicep, or ARM) for repeatable environment provisioning.
  • Set up and manage JFrog Artifactory for package and artifact management, including npm and Docker registries.
  • Containerize applications with Docker where appropriate, and support a future move to Azure Kubernetes Service (AKS).
  • Build automated testing into pipelines, including unit tests (Jest) and end-to-end tests (Playwright or Cypress).
  • Set up monitoring and observability with Datadog APM and Datadog Log Management across all environments, alongside Azure Monitor and Application Insights for Azure platform metrics.
  • Instrument Node.js applications with the Datadog APM tracer and structured logging, correlate traces with logs, and build dashboards, monitors, and alerts for service health, performance, and release impact.
  • Make code changes in Node.js applications to support DevOps practices such as configuration management, health checks, logging, and automated tests.
  • Contribute to Node.js feature development and bug fixes as DevOps priorities allow.
  • Onboard new applications onto the standardized SDLC process.
  • Set up Azure Boards for work tracking, with work items linked to commits, pull requests, and releases for end-to-end traceability and audit readiness.
  • Document pipelines, environments, runbooks, and processes in the Azure DevOps Wiki, and train team members on them.
  • Coordinate with Application Development, IT Operations, Information Security, and Compliance to align SDLC standards with enterprise priorities and control requirements.
  • Work fluently within AI-augmented workflows, exercise sound judgment over AI outputs, and follow all applicable controls.
  • Review, test, and validate all AI-generated code, pipeline definitions, IaC templates, and scripts before they are merged or run against any environment.
  • Route every AI-assisted change through the standard pull request, code review, and pipeline quality gates; AI output never bypasses these controls.
  • Verify AI-suggested remediations for security findings against authoritative sources before applying them.
  • Escalate to the Hiring Manager, IT Security, and the AI Council any use case that would let AI make changes to production systems without human approval.
  • Stop reliance on AI output and escalate immediately if the output appears inaccurate, insecure, non-compliant, or outside the role's documented scope.
  • Refrain from entering secrets, credentials, connection strings, member non-public personal information (NPI), or confidential CUTX source code into any AI tool not explicitly approved for that data classification.
  • Complete all required AI training within thirty (30) days of hire and maintain annual currency.
  • Adhere to all enterprise compliance obligations, including BSA/AML, OFAC, USA PATRIOT Act/CIP/CDD, GLBA and the Safeguards Rule, Fair Lending laws (ECOA/Reg B, Fair Housing Act), UDAAP, Information Security and Acceptable Use, and the CUTX Code of Conduct.
  • Adhere to the CUTX Generative AI Usage Policy, the CUTX AI Playbook, and Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149) requirements.
  • Adhere to CUTX Change Management, Release Management, and Secure SDLC standards.
  • Adhere to Gramm-Leach-Bliley Act (GLBA) and the Safeguards Rule, and NCUA Part 748 information security program requirements.
  • Adhere to FFIEC IT Examination Handbook expectations for development, acquisition, and operations.
  • Adhere to CUTX Information Security, Access Management, and Secrets Management policies.
  • Adhere to CUTX Vendor and Third-Party Risk Management requirements.
  • Adhere to CUTX Data Governance and Data Classification policies.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service