Sr DevOps Engineer

Credit Union of Texas•Allen, TX
•Hybrid

About The Position

The Senior DevOps Engineer supports Credit Union of Texas's vision to be the trusted financial partner for our members and our community by building and owning the end-to-end software development lifecycle (SDLC) on Azure DevOps. The role modernizes and standardizes the SDLC for existing applications, implements CI/CD and multi-environment (Dev, UAT, Prod) strategies, and makes the Node.js application code changes needed to support them. The role establishes secure secrets management, artifact management, static and dynamic application security testing (SAST with JFrog and DAST with Invicti), code quality and test coverage gates (SonarQube), Infrastructure as Code, automated testing, and observability practices (Datadog APM and Logs) that make releases repeatable, traceable, and audit-ready. Once the foundation is in place, the Senior DevOps Engineer contributes to Node.js development and onboards new applications onto the standardized SDLC. The role uses CUTX-approved AI tools under defined governance, with mandatory human review of any AI-assisted code or configuration before it reaches production.

Requirements

  • Bachelor's degree in Computer Science, Software Engineering, Information Systems, or a related field, or equivalent practical experience.
  • Five (5) or more years of experience in DevOps, with a strong background in software development.
  • Strong hands-on experience with Azure DevOps (Repos, Pipelines, YAML, Releases, Environments).
  • Solid Node.js development experience, enough to independently read, modify, and ship production code.
  • Hands-on experience refactoring application code to use a secrets manager (Azure Key Vault preferred) with Managed Identity.
  • Experience with the JFrog Platform (Artifactory, Xray, and Advanced Security SAST) in CI/CD workflows.
  • Experience with SonarQube for code quality and test coverage quality gates in CI/CD workflows.
  • Experience with dynamic application security testing (DAST) integrated into CI/CD pipelines; Invicti preferred.
  • Experience building automated testing into CI/CD pipelines, including unit testing (Jest) and end-to-end testing (Playwright or Cypress).
  • Experience with application security scanning tools for dependencies, vulnerabilities, and secrets (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks).
  • Experience with Datadog APM and Log Management, including tracer instrumentation, log pipelines, dashboards, and monitors; experience with Azure Monitor and Application Insights.
  • Experience with feature flags (Azure App Configuration or similar).
  • Experience with Docker and containerized application deployment.
  • Experience with Azure Boards or similar work tracking tools, including linking work items to code and releases.
  • Proven experience introducing CI/CD and environment standardization to existing applications.
  • Working knowledge of Azure services such as App Service, Functions, AKS, virtual machines, and networking.
  • Experience with Infrastructure as Code (Terraform or Bicep preferred).
  • Git expertise, including branching strategies such as GitFlow or trunk-based development.
  • Scripting skills in PowerShell and/or Bash.
  • Experience enforcing code quality standards with ESLint and Prettier.
  • Strong documentation habits, including runbooks and process documentation.
  • Ability to explain technical standards clearly and train team members on new processes.
  • Drive to learn and adopt new technologies, techniques, and CUTX-approved AI tools.
  • Intermediate AI Literacy: The role uses AI-assisted code and configuration tools (Tier 2) and must recognize when AI output is wrong or insecure, apply required controls, and ensure human review before changes are merged.
  • Advanced Technical Excellence: The role owns the design of pipelines, environments, and release processes that every CUTX application team will depend on.
  • Advanced Risk Awareness: Pipeline, secrets, or access-control weaknesses can expose member data or disrupt services; the role must identify, remediate, and escalate security and change risk.
  • Advanced Operational Discipline: Pipelines, infrastructure, and documentation must be repeatable, version-controlled, and audit-ready to meet change management and examination expectations.
  • Intermediate Communication: The role must document standards clearly, train teams, and explain trade-offs to technical and non-technical partners.
  • Intermediate Collaboration: Standardizing the SDLC requires working across development, operations, security, and compliance teams to drive adoption.
  • Intermediate Compliance Orientation: SDLC controls must support GLBA data protection, NCUA information security requirements, and TRAIGA-aligned AI governance.
  • AI-Augmented Workflows: The role is expected to work fluently within AI-augmented workflows, exercise sound judgment over AI outputs, and follow all applicable controls.
  • AI Tier 2 Responsibility: The Senior DevOps Engineer retains accountability for any decision, communication, or member/employee-impacting action influenced by AI output, consistent with the CUTX Generative AI Usage Policy §3.4.
  • Use of AI tools outside the approved list requires prior approval from the role's department leader and the AI Council, per the Generative AI Usage Policy §4.
  • Enterprise Compliance Obligations: Responsible for all enterprise compliance obligations applicable to a CUTX team member, including BSA/AML, OFAC, USA PATRIOT Act/CIP/CDD, GLBA and the Safeguards Rule, Fair Lending laws (ECOA/Reg B, Fair Housing Act), UDAAP, Information Security and Acceptable Use, and the CUTX Code of Conduct.
  • AI-Specific Compliance Obligations: Responsible for the CUTX Generative AI Usage Policy (TRAIGA / HB 149-aligned), the CUTX AI Playbook (including Tier 2 obligations applicable to this role), and Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149) requirements applicable to the role.
  • Role-Specific Compliance Obligations: CUTX Change Management, Release Management, and Secure SDLC standards covering approvals, segregation of duties, testing, and rollback.
  • Gramm-Leach-Bliley Act (GLBA) and the Safeguards Rule, and NCUA Part 748 information security program requirements, as applied to systems, pipelines, and environments that handle member data.
  • FFIEC IT Examination Handbook expectations for development, acquisition, and operations, including change traceability and audit evidence.
  • CUTX Information Security, Access Management, and Secrets Management policies, including least-privilege access and credential rotation.
  • CUTX Vendor and Third-Party Risk Management requirements for DevOps, cloud, artifact and security testing (JFrog, Invicti), code quality (SonarQube), and observability (Datadog) tools.
  • CUTX Data Governance and Data Classification policies as applied to non-production environments, code repositories, and logs, including masking of member NPI and secrets before logs and traces are sent to Datadog.

Nice To Haves

  • Kubernetes (AKS) experience preferred.
  • Experience with container image scanning and broader DevSecOps practices preferred.
  • Prior experience in financial services or another regulated industry preferred.
  • Microsoft Azure certifications (AZ-400 DevOps Engineer Expert, AZ-104 Azure Administrator) preferred.

Responsibilities

  • Design and implement CI/CD pipelines (YAML) in Azure DevOps for existing and new applications.
  • Manage Azure Repos, including branching strategy, branch policies, pull request workflows, and code review gates.
  • Design and implement multi-environment strategies (Dev, UAT, Prod) with automated promotion, including the infrastructure and application changes required to support them.
  • Set up release strategies such as approvals, environment promotion, and rollback.
  • Implement feature flags using Azure App Configuration to reduce release risk.
  • Implement and standardize secrets management using Azure Key Vault and Managed Identity across applications, including the Node.js code changes needed to load secrets and configuration securely at runtime.
  • Establish secure secret lifecycle practices, including rotation and access controls.
  • Implement static application security testing (SAST) using JFrog Advanced Security, with critical and high findings blocking merges and releases.
  • Integrate SonarQube for code quality and unit test coverage analysis (coverage thresholds, bugs, code smells, duplication, and maintainability), with quality gates enforced on every pull request and pipeline run.
  • Integrate Invicti for dynamic application security testing (DAST) against deployed applications in Dev and UAT, with critical and high findings blocking promotion to Production.
  • Coordinate triage and remediation of SAST, DAST, dependency, and secret scanning findings with development teams and Information Security, and track them to closure in Azure Boards.
  • Implement dependency, vulnerability, and secret scanning (such as JFrog Xray, Snyk, GitHub Advanced Security for Azure DevOps, or Gitleaks) with results enforced in pipelines.
  • Enforce code consistency standards with ESLint and Prettier in pull request checks.
  • Implement Infrastructure as Code (Terraform, Bicep, or ARM) for repeatable environment provisioning.
  • Set up and manage JFrog Artifactory for package and artifact management, including npm and Docker registries.
  • Containerize applications with Docker where appropriate, and support a future move to Azure Kubernetes Service (AKS).
  • Build automated testing into pipelines, including unit tests (Jest) and end-to-end tests (Playwright or Cypress).
  • Set up monitoring and observability with Datadog APM and Datadog Log Management across all environments, alongside Azure Monitor and Application Insights for Azure platform metrics.
  • Instrument Node.js applications with the Datadog APM tracer and structured logging, correlate traces with logs, and build dashboards, monitors, and alerts for service health, performance, and release impact.
  • Make code changes in Node.js applications to support DevOps practices such as configuration management, health checks, logging, and automated tests.
  • Contribute to Node.js feature development and bug fixes as DevOps priorities allow.
  • Onboard new applications onto the standardized SDLC process.
  • Set up Azure Boards for work tracking, with work items linked to commits, pull requests, and releases for end-to-end traceability and audit readiness.
  • Document pipelines, environments, runbooks, and processes in the Azure DevOps Wiki, and train team members on them.
  • Coordinate with Application Development, IT Operations, Information Security, and Compliance to align SDLC standards with enterprise priorities and control requirements.
  • Review, test, and validate all AI-generated code, pipeline definitions, IaC templates, and scripts before they are merged or run against any environment.
  • Route every AI-assisted change through the standard pull request, code review, and pipeline quality gates; AI output never bypasses these controls.
  • Verify AI-suggested remediations for security findings against authoritative sources before applying them.
  • Escalate to the Hiring Manager, IT Security, and the AI Council any use case that would let AI make changes to production systems without human approval, which is treated as Tier 3 and requires additional controls.
  • Stop reliance on AI output and escalate immediately if the output appears inaccurate, insecure, non-compliant, or outside the role's documented scope (Generative AI Usage Policy §3.5).
  • Refrain from entering secrets, credentials, connection strings, member non-public personal information (NPI), or confidential CUTX source code into any AI tool not explicitly approved for that data classification.
  • Complete all required AI training within thirty (30) days of hire and maintain annual currency.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service