Senior DevOps Engineer
Ascensus
Job Description
<p><a href="https://himalayas.app/companies/ascensus">Ascensus</a> is the leading independent technology and service platform powering savings plans across America, providing products and expertise that help nearly 16 million people save for a better today and tomorrow.</p><h3>Section 1: Position Summary</h3><div>
<p>We are seeking a <b>Senior DevOps Engineer</b> with <b>10+ years of hands‑on experience</b> designing, building, and operating <b>enterprise‑grade CI/CD platforms</b> across <b>hybrid environments (AWS and on‑premises)</b>. This role will lead platform standardization, progressive delivery, reliability engineering, and security‑by‑design to enable <b>high‑quality, low‑risk software delivery at scale</b>.</p>
<h3>Key Responsibilities</h3>
<h3>CI/CD Platform & Environment Strategy</h3>
<ul>
<li>Design, implement, and operate a standardized CI/CD framework supporting <b>Dev, QA, PartnerLab, Staging, and Production</b>
</li>
<li>Define promotion workflows with <b>enforced quality gates</b> and <b>artifact immutability</b>
</li>
<li>Establish <b>PartnerLab</b> as a dedicated integration and validation environment with <b>no direct path to Production</b>
</li>
<li>Ensure <b>environment parity</b> across AWS and on‑prem systems</li>
</ul>
<h3>Progressive Delivery & Release Engineering</h3>
<ul>
<li>Implement <b>feature flags</b>, <b>canary deployments</b>, <b>blue‑green deployments</b>, and <b>phased rollouts</b>
</li>
<li>Enable <b>automated rollback</b> based on health checks, error rates, and SLO breaches</li>
<li>Maintain full <b>release traceability</b> from commit through production</li>
</ul>
<h3>Test Automation & Quality Engineering</h3>
<ul>
<li>Integrate <b>unit, integration, regression, security, and performance testing</b> into CI/CD pipelines</li>
<li>Enforce <b>automated quality gates</b> before environment promotion</li>
<li>Support <b>manual validation workflows</b> with controlled access, observability, and test artifacts</li>
</ul>
<h3>Database & Data Automation</h3>
<ul>
<li>Automate <b>database schema versioning, migrations, rollbacks, and validation</b>
</li>
<li>Build <b>lower‑environment refresh pipelines</b> sourced from production data</li>
<li>Enforce <b>data masking and PII anonymization</b> for non‑production environments</li>
<li>Validate <b>data integrity and consistency</b> post‑refresh</li>
</ul>
<h3>Observability, Reliability & Operations</h3>
<ul>
<li>Define and enforce <b>observability standards</b> across logs, metrics, and traces</li>
<li>Implement <b>service health dashboards, alerts, and incident signals</b>
</li>
<li>Integrate deployment health into <b>automated release decisions</b>
</li>
<li>Support <b>on‑call readiness</b>, incident response, and post‑incident reviews</li>
</ul>
<h3>Security, Governance & Compliance</h3>
<ul>
<li>Embed <b>security scanning, secrets management, and access controls</b> into pipelines</li>
<li>Enforce <b>least‑privilege IAM</b>, credential rota