IT Senior Architect - DevSecOps
Hopkinsville, Christian County, Kentucky, 42240, USA
Listed on 2026-10-09
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations, IT Consultant, Information Security & Data Protection
Maximus is currently seeking an IT Senior Architect – Dev Sec Ops . The IT Senior Architect – Dev Sec Ops / Tools Engineering serves as the senior-most individual contributor technical authority for Dev Sec Ops engineering, pipeline strategy, and secure software delivery across Maximus Enterprise Technology. Operating within the HO ET Architecture & Automation organization, this role provides principal-level guidance for the enterprise CI/CD platform (Jenkins Shared Libraries / Groovy), embedded security tooling, and end-to-end application delivery practices supporting 1,000+ government programs under FedRAMP, HIPAA, SOC 2, and PCI compliance requirements.
This is a high-visibility, enterprise-wide role requiring deep technical ownership, cross-functional influence with VP/Sr Director-level peers, and direct contribution to Maximus's $5B+ government services delivery mission.
This is a remote position.
Essential Duties and Responsibilities:- Oversee the automation processes for daily activities, build activities and new feature and functionality with public and private cloud
- Interact with other team members and groups within the IT organization
- Help enforce the standards for server builds and services deployed in AWS and the private cloud by the cloud solutions teams
- Perform other duties assigned by leadership.
Essential Duties and Responsibilities:
- Serve as the principal architect for the Maximus enterprise Dev Sec Ops platform, defining reference architectures, pipeline standards, and security guardrails across commercial, federal, and Gov Cloud deployment targets, with primary delivery via Jenkins Shared Libraries (Groovy), Terraform and Crossplane-based infrastructure provisioning.
- Establish and maintain the canonical CI/CD pipeline model, from source control through cloud deployment, inclusive of static code analysis, SAST/DAST security scans, artifact management, and policy-gated release gates.
- Provide authoritative architecture decisions for multi-environment deployment strategies (dev, staging, production) on AWS, Azure, and GCP.
- Embed automated security controls and vulnerability management into CI/CD pipelines, including integration with Dependency Track, Splunk, Rapid Fort (container hardening and CVE remediation), and Axway Managed File Transfer (MFT) solutions.
- Ensure all pipeline architectures align with NIST SSDF, FedRAMP, HIPAA, SOC 2, and PCI compliance requirements.
- Collaborate with the Information Security Office (ISO) on security architecture reviews, risk acceptance decisions, and continuous compliance monitoring.
- Champion "security left" practices across the Maximus developer community (300+ Dev Sec Ops practitioners).
- Participate in and provide technical authority within enterprise governance bodies, including SCM/Change Management governance groups alongside VP-level and Sr Director-level peers.
- Author and maintain enterprise-level architecture documents, white papers, and technical standards for OCDIO-wide consumption.
- Serve as a named technical reviewer and subject-matter authority for Dev Sec Ops capability sections in business development and proposal content at the capture/pre-award stage.
- Provide technical mentorship and upskilling guidance to T3/T4 architects and engineers across the tools and automation practice.
- Lead the internal Dev Sec Ops community of practice, driving platform adoption, knowledge sharing, and standardized delivery patterns across business lines.
- Define and maintain golden-path pipeline templates and launchpad configurations enabling 65-75% portfolio reuse.
- Partner with project teams on onboarding, consulting engagements,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).