DevOps Engineer
Fully Remote
Description

The DevOps Engineer is a specialized cloud and DevSecOps engineer responsible for building, automating, and maintaining the cloud infrastructure, CI/CD pipelines, container registries, and automated quality gates. This position plays a central role in modernizing the National Water Prediction Service (NWPS), supporting automated deployments for new features such as NOAA Atlas 15 precipitation frequency tools, expanded Flood Inundation Mapping (FIM), and Quantitative Precipitation Estimate (QPE) processing pipelines.


Operating within the NWS Enterprise Cloud (NEC) Amazon Web Services (AWS) environment, the DevOps Engineer utilizes Terraform Infrastructure as Code (IaC), Docker containerization, and AWS serverless/Fargate orchestration to maintain cloud-agnostic, reproducible environments. This role automates static code analysis, vulnerability scanning, and testing harnesses to enforce strict security standards, manages the publicly accessible containerized NWPS 'sandbox' environment for community contributions, and supports seamless release promotions through the NOAA Change Control Board (CCB) process.

Requirements
• CI/CD Pipeline Automation & Maintenance: Design, implement, and maintain vendor-agnostic CI/CD pipelines in VLab GitLab and GitHub Actions for automated building, testing, security scanning, and deployment of microservices across development, staging (UAT), and production environments.• Infrastructure as Code (IaC): Develop, refactor, and maintain modular Terraform configurations to manage AWS cloud resources (AWS Fargate/ECS, Amazon Aurora PostgreSQL, S3, Lambda, API Gateway, CloudWatch, IAM roles), eliminating configuration drift and supporting cloud-agnostic deployment patterns.• Automated Quality Gates & Security Scanning: Integrate continuous security and quality tools into pipelines including static code analysis, container image vulnerability scanners, dependency checks (Dependabot, AddressSanitizer, Ruff, Flake8, Black) ensuring 0 medium/high static linting errors and enforcing the mandatory =80% statement test coverage threshold before code merge.• Public Sandbox & Community Contribution Support: Maintain a containerized, sanitized 'sandbox' version of the NWPS environment using standardized 'canned' datasets and Docker manifests, allowing external researchers and community contributors to test code without exposure to sensitive credentials or live production feeds.• Cloud Cost Optimization & Performance Tuning: Monitor cloud resource utilization and compute/storage costs using AWS CloudWatch, optimizing auto-scaling parameters, S3 storage lifecycle policies, and Fargate compute allocations.• Release & Change Control Support: Support the execution of automated zero-downtime releases, manage protected branch deployment rules, prepare technical release artifacts, and assist technical leads during NOAA Change Control Board (CCB) deployment reviews.• Environment Provisioning & Identity Management: Administer least-privilege Identity and Access Management (IAM) policies, automate credential rotation via AWS Secrets Manager, and maintain user access matrices across development, staging, and production environments.
Experience Required• Education: Bachelor’s Degree in Computer Science, Computer Engineering, Information Technology, or a related technical discipline.• Total Professional Experience: Minimum of 3 to 5 years (with 5+ years preferred) of hands-on experience in DevOps, DevSecOps, cloud engineering, and system automation.• Cloud & IaC Expertise: Demonstrated experience managing production AWS cloud infrastructure natively using Terraform and Docker container orchestration.• Pipeline & Quality Assurance: Proven track record building automated CI/CD pipelines (GitLab CI/GitHub Actions) integrated with automated testing frameworks, static analysis, and security scanning tools.
Technical Skills Required• Infrastructure as Code & Containers: Advanced experience with Terraform, Docker, container image registries, and container scanning tools.• AWS Cloud Infrastructure: Direct experience with AWS Fargate / ECS, Amazon S3, Amazon Aurora PostgreSQL, AWS Lambda, AWS CloudWatch, and IAM / Secrets Manager.• CI/CD & Version Control: Expertise with VLab GitLab CI/CD, GitHub Actions, Git branching strategies (Conventional Branching), and automated pipeline security scanning.• Scripting & Automation: Proficiency in Python and Bash for build automation, deployment scripting, and system monitoring.• Security & Compliance: Deep understanding of DevSecOps best practices, NIST security controls, least-privilege access enforcement, secret management, and vulnerability remediation.• Monitoring & Tooling: Experience configuring monitoring dashboards using AWS CloudWatch or Grafana, alongside Jira/VLab Redmine issue tracking.