Summary
DSFederal is seeking a DevOps Engineer to modernize the National Water Prediction Service within the NWS Enterprise Cloud AWS environment. The role builds and maintains cloud infrastructure, CI/CD pipelines, containerized sandbox environments, automated quality gates, security scanning, and release processes while supporting NOAA deployment requirements.
Responsibilities
- Design, implement, and maintain vendor-agnostic CI/CD pipelines in VLab GitLab and GitHub Actions for automated building, testing, security scanning, and deployment of microservices across development, staging (UAT), and production environments
- Develop, refactor, and maintain modular Terraform configurations to manage AWS cloud resources (AWS Fargate/ECS, Amazon Aurora PostgreSQL, S3, Lambda, API Gateway, CloudWatch, IAM roles), eliminating configuration drift and supporting cloud-agnostic deployment patterns
- Integrate continuous security and quality tools into pipelines including static code analysis, container image vulnerability scanners, dependency checks (Dependabot, AddressSanitizer, Ruff, Flake8, Black) ensuring 0 medium/high static linting errors and enforcing the mandatory =80% statement test coverage threshold before code merge
- Maintain a containerized, sanitized 'sandbox' version of the NWPS environment using standardized 'canned' datasets and Docker manifests, allowing external researchers and community contributors to test code without exposure to sensitive credentials or live production feeds
- Monitor cloud resource utilization and compute/storage costs using AWS CloudWatch, optimizing auto-scaling parameters, S3 storage lifecycle policies, and Fargate compute allocations
- Support the execution of automated zero-downtime releases, manage protected branch deployment rules, prepare technical release artifacts, and assist technical leads during NOAA Change Control Board (CCB) deployment reviews
- Administer least-privilege Identity and Access Management (IAM) policies, automate credential rotation via AWS Secrets Manager, and maintain user access matrices across development, staging, and production environments
Skills
- Bachelor's Degree in Computer Science, Computer Engineering, Information Technology, or a related technical discipline
- Minimum of 3 to 5 years
- Hands-on experience in DevOps, DevSecOps, cloud engineering, and system automation
- Demonstrated experience managing production AWS cloud infrastructure natively using Terraform and Docker container orchestration
- Proven track record building automated CI/CD pipelines (GitLab CI/GitHub Actions) integrated with automated testing frameworks, static analysis, and security scanning tools
- Advanced experience with Terraform, Docker, container image registries, and container scanning tools
- Direct experience with AWS Fargate / ECS, Amazon S3, Amazon Aurora PostgreSQL, AWS Lambda, AWS CloudWatch, and IAM / Secrets Manager
- Expertise with VLab GitLab CI/CD, GitHub Actions, Git branching strategies (Conventional Branching), and automated pipeline security scanning
- Proficiency in Python and Bash for build automation, deployment scripting, and system monitoring
- Deep understanding of DevSecOps best practices, NIST security controls, least-privilege access enforcement, secret management, and vulnerability remediation
- Experience configuring monitoring dashboards using AWS CloudWatch or Grafana, alongside Jira/VLab Redmine issue tracking
- 5+ years
Qualifications
Must Haves
- Bachelor's Degree in Computer Science, Computer Engineering, Information Technology, or a related technical discipline
- Minimum of 3 to 5 years
- hands-on experience in DevOps, DevSecOps, cloud engineering, and system automation
- Demonstrated experience managing production AWS cloud infrastructure natively using Terraform and Docker container orchestration
- Proven track record building automated CI/CD pipelines (GitLab CI/GitHub Actions) integrated with automated testing frameworks, static analysis, and security scanning tools
- Advanced experience with Terraform, Docker, container image registries, and container scanning tools
- Direct experience with AWS Fargate / ECS, Amazon S3, Amazon Aurora PostgreSQL, AWS Lambda, AWS CloudWatch, and IAM / Secrets Manager
- Expertise with VLab GitLab CI/CD, GitHub Actions, Git branching strategies (Conventional Branching), and automated pipeline security scanning
- Proficiency in Python and Bash for build automation, deployment scripting, and system monitoring
- Deep understanding of DevSecOps best practices, NIST security controls, least-privilege access enforcement, secret management, and vulnerability remediation
- Experience configuring monitoring dashboards using AWS CloudWatch or Grafana, alongside Jira/VLab Redmine issue tracking
Nice to Haves