Role: Enterprise DevOps Senior Engineer
Location: Charlotte, NC – need locals
Duration: 6+ months
Role Overview
Sunbelt is seeking an Enterprise DevOps Senior Engineer to architect,
standardize, and automate CI/CD, environment management, and delivery
frameworks across cloud, on-prem, legacy, CRM, integration, and analytics
platforms.
This role spans Azure, on-prem applications, MuleSoft, Salesforce, AS/400,
Databricks, Cybersecurity, and Infrastructure—creating unified DevOps patterns
for an enterprise undergoing modernization.
You’ll build and evolve pipelines, IaC, GitOps workflows, observability, IAM/Secrets
standards, and deployment automation that work consistently across this diverse
ecosystem.
Scope & Platforms Covered
• Cloud: Azure (AKS, App Services, Functions, API Management, VNets, Storage,
Key Vault, Azure Monitor).
• Data & Analytics: Azure Databricks (CI/CD, workspace automation, Unity
Catalog, cluster mgmt, jobs).
• On Prem: Windows/Linux servers, VMs, networks, load balancers, legacy apps.
• Integration: MuleSoft Anypoint Platform (CloudHub/Rtf CI/CD, gateways,
policies).
• CRM: Salesforce (Salesforce DX, metadata/api deployments, package-based
releases).
• Legacy/ERP: AS/400 (IBM i) modernization, Git-enabled workflows, automated
build/promotions.
• Cybersecurity: IAM, secrets, code scanning, compliance controls.
• Automation: Azure DevOps, GitHub Actions, Jenkins, Terraform/Bicep, Ansible,
GitOps, scripting.
Key Responsibilities
1) Enterprise DevOps Strategy
• Define enterprise DevOps standards applicable across cloud, on-prem,
integration, CRM, data, and legacy workloads.
• Create reusable templates, modules, pipelines, and golden paths for teams to
adopt.
• Uplift DevOps maturity across all business and technical squads.
2) Hybrid CI/CD –
Multi-Platform Delivery
Design, standardize, and operate CI/CD pipelines for:
• Azure workloads (.NET/Java/Node, Infrastructure, Functions, AKS).
• MuleSoft APIs (linting, tests, quality checks, policy enforcement, deployment
automation).
• Salesforce (SFDX pipelines, package-based deployments, sandbox mgmt).
• AS/400 (IBM i) (automated build/release via ARCAD/TurnOver or similar).
• Databricks (details below).
Databricks CI/CD
Responsibilities
• Build pipelines to automate notebooks, Delta Live Tables, ML models,
workflows, job clusters, and Unity Catalog objects.
• Implement CI/CD using Databricks CLI, REST APIs, Workspace Files, dbx, Delta
pipelines, or UCs.
• Automate deployment bundles, asset promotion, versioning, testing, and
environment synchronization.
• Standardize governance around Databricks objects—clusters, secrets scopes,
jobs, permissions.
• Integrate Databricks deployments with Azure DevOps, GitHub Actions, or
Jenkins.
• Ensure secure deployment patterns using Key Vault, service principals, PAT
lifecycle, and identity policies.
3) Infrastructure as Code (IaC)
& Config Management
• Build and manage IaC at scale using Terraform/Bicep for Azure resources,
networking, security, and platform services.
• Implement databricks_ Terraform resources* for workspaces, clusters, jobs,
permissions, repos, and catalogs.
• Use Ansible/PowerShell DSC for config mgmt of on-prem workloads.
• Implement policy-as-code (OPA/Conftest/Azure Policy) for governance.
________________________________________
4) Platform Engineering (Cloud, On Prem, Data, Integration, CRM)
• Design and operate stable, secure platforms spanning cloud apps, Mule APIs,
Salesforce pipelines, Databricks data workloads, and legacy systems.
• Drive modernization across hybrid environments, including networking,
SSO/IAM, secrets, and resilience patterns.
________________________________________
5) DevSecOps & Supply Chain Security
• Embed SAST/DAST/SCA scanning, secrets scanning, SBOM generation and artifact
signing into all pipelines.
• Enforce secure deployment patterns across MuleSoft, Salesforce, Databricks,
IBM i and Azure.
• Standardize secrets across Key Vault, Vault, or equivalent.
6) Observability & SRE
• Implement observability for application, API, infrastructure, and data
pipelines.
• Support Databricks observability (jobs, clusters, cost monitoring,
performance metrics).
• Define SLIs, SLOs, error budgets across core enterprise services.
7) Environment & Release
Management
• Standardize data/environment refresh patterns, including for Salesforce and
Databricks data sets.
• Manage releases across multi-tiered cloud + on-prem environments with gated
approvals and compliance.
Required Qualifications
• 10+ years in DevOps, Platform Engineering, or hybrid cloud engineering.
• Strong Azure experience: AKS, App Services, Functions, VNets, Key Vault,
Monitor, ACR.
• Experience building CI/CD pipelines for Databricks, including notebooks,
workflows, and Terraform/databricks provider.
• Strong IaC experience (Terraform/Bicep).
• CI/CD expertise with Azure DevOps, GitHub Actions, or Jenkins.
• Scripting: PowerShell, Bash, Python.
• Experience with at least two major enterprise platforms:
o Azure
o Salesforce
o MuleSoft
o Legacy/on-prem Windows/Linux apps
o Analytics/Data Engineering platforms (Databricks preferred)
• DevSecOps: security scanning, secrets mgmt, SBOM, artifact signing.
• Observability with Azure Monitor/App Insights/Grafana/ELK/Splunk.
Preferred Qualifications
• Certifications: AZ 400, AZ 305, Databricks Lakehouse Fundamentals, CKA/CKAD,
MuleSoft/Salesforce certs.
• Experience with GitOps (Argo CD/Flux) and declarative delivery for apps and
data.
• Deep experience with dbx, Databricks CLI, Workspace Files, repos automation.
• Service mesh (Istio/Linkerd/Consul) in hybrid environments.
• Test automation integrated into pipelines (unit/API/UI/perf/data validation).
• Experience with regulated envs (SOX/PCI/ISO27001).
Tooling (not limited to)
• CI/CD: Azure DevOps, GitHub Actions, Jenkins
• IaC: Terraform, Bicep
• Databricks Tools: dbx, Repos, Databricks CLI, DevOps extension, REST APIs,
Unity Catalog
• Integration: MuleSoft Anypoint Platform
• CRM: Salesforce DX, Copado/Gearset (if used)
• Legacy: ARCAD/TurnOver for IBM i
• Observability: Azure Monitor, App Insights, Log Analytics, OTel, Prometheus,
Grafana, Splunk
• Security: Key Vault, Vault, OPA, Checkov, SonarQube, Whitesource/Snyk