US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Platform & DevSecOps Delivery Architect

About the Opportunity & The Mission 

STChealth has nearly 40 years safeguarding communities by building the systems that report and verify more than a quarter of all childhood and adult vaccinations nationwide.

As part of the Harris family of software companies, we deliver mission-critical public sector technology where platform stability directly protects public health. 

We are seeking a Platform & DevSecOps Delivery Architect to act as the primary owner and builder of our modern "Golden Path" deployment platform. 

This role is not about babysitting infrastructure or handling one-off developer support tickets.

It is about building an automated, secure, self-service software delivery platform that makes shipping safe, compliant code effortless for development teams.

You will bridge our high-throughput modern platform and our existing production systems, ensuring every build meets rigorous DevSecOps and Operational Readiness standards—regardless of where the code ultimately lands. 

If you love clean pipeline architecture, automated security rails, and solving complex distributed systems puzzles with a high degree of autonomy, this role is built for you.

What You Will Build and Own

1.

The Paved Road / "Golden Path" Delivery Engine


* Universal CI/CD Pipelines: Architect, implement, and maintain centralized, reusable pipeline templates (GitHub Actions / GitLab CI) that abstract underlying infrastructure away from software developers.



* Dual-Target Dispatching: Build a modular release architecture that runs universal scanning and sanitization upstream, while intelligently branching to specific downstream delivery targets:



* Modern Engine: GitOps promotion (ArgoCD / Kargo) with progressive canary rollouts (Argo Rollouts) to Amazon EKS.



* Core VM Engine: Automated machine-image pipelines (HashiCorp Packer, AWS Launch Templates) and blue/green agent updates (EC2 / ClearData Docker) for state production systems.



* Shift-Down Self-Service: Provide engineering teams with pre-configured project scaffolding and Helm/IaC modules so they can stand up new services independently within compliant guardrails.

2.

DevSecOps & Security Gate Automation


* Automated Pipeline Gates: Embed automated vulnerability scanning directly into the build process:



* Static Application Security Testing (SAST) and Software Composition Analysis (SCA) dependency checks.



* Container image hygiene and snapshot CVE detection prior to promotion.



* Pre-commit and pipeline secret-detection to eliminate static credential leaks.



* Automated Compliance & Audit Trails: Build automated generation of software artifacts and deployment logs to satisfy strict SOC 2 Type II, HIPAA, and federal public-health security audits without manual spreadsheets. 



* Runtime Identity & Secrets Governance: Design and operate programmatic secrets distribution via External Secrets Operator (ESO) syncing from AWS Secrets Manager / Paramete...




Share Job