About this role
You will write production code, design the systems it belongs to, and stay accountable for how it behaves after release.
Most engineering roles stop at "feature complete." This one does not. You will define what a service looks like, build it, prove it works through automated testing, ship it through our delivery pipeline, and own its behaviour in production.
You will set the technical standard for application engineering across the organization, architecture, code quality, and test discipline — and you will do it by building, not by reviewing from a distance.
This is an AI-augmented role. We expect coding agents to be part of how you work daily, and we expect you to define what responsible, verifiable use of them looks like here.
What You Will Do:
- Ideation through design. Turn ambiguous business problems into technical direction. Produce architecture and interface designs that other engineers can build against. Make and defend technology selection and build-vs-buy decisions.
- Full stack implementation. Design and build front end applications and the services, APIs, and data layers behind them. Write production code at a standard that raises the bar for the engineers around you.
- Test strategy and coverage. Own the automated testing approach for your systems. Enforce unit test coverage as a merge gate. Build integration test suites against real service contracts. Author and maintain functional and end-to-end browser tests in Playwright, and keep them fast and non-flaky enough that teams trust them.
- Delivery to production. Package your services as containers. Author the deployment configuration for your workloads and promote changes through the GitOps pipeline. You are expected to be fluent in the platform — reading and modifying the Terraform and Kubernetes manifests that describe your service — while our Platform/DevOps team owns the platform itself.
- AI-augmented delivery. You use coding agents as a core part of how you work — decomposing problems into agent-executable units, directing multi-step implementation, and reviewing generated output with the same rigor you would apply to a strong junior engineer's pull request. You are expected to deliver scope that would conventionally require a larger team, and to establish the guardrails, review standards, and verification practices that let other engineers do the same safely.
- Security and compliance as code. Security is a build gate, not a review meeting. You write code that clears automated SAST, DAST, dependency, secret, and container scanning on every commit, and you remediate findings at the source rather than deferring them to a backlog. You design services so that authentication, authorization, encryption, and data handling meet control requirements by construction.
- Auditability and evidence generation. You instrument services to emit structured, tamper-evident audit logs covering access, privileged action, and data handling — sufficient to satisfy an auditor without manual reconstruction. Compliance evidence is produced automatically as a byproduct of the pipeline: test results, scan results, approvals, and deployment records are captured as artifacts at build time. You are expected to treat "we can prove it" as part of the definition of done.
- You will work in a CMMC Level 2 environment. Familiarity with what that means for code provenance, change control, and access logging is a meaningful advantage.
- Production accountability. Instrument what you build. Define the signals that indicate your service is healthy, participate in incident response for your systems, and drive permanent remediation rather than repeat mitigation.
- Technical leadership. Mentor senior and mid-level engineers. Lead design reviews. Influence engineering direction across teams without formal authority.
What You Will Need:
Education and Experience
- 10+ years of professional software engineering experience, including 3+ years at Staff or Principal level
- Bachelor's degree in computer science (MS is preferred), Engineering, or a related field
- Delivery experience in regulated or compliance-bound environments (CMMC, FedRAMP, SOC 2, ISO 27001)
- Azure or Azure Government Cloud
- Legacy modernization — decomposing monolithic enterprise applications into services
- Hands-on delivery under CMMC, FedRAMP, SOC 2, or ISO 27001 control frameworks, including evidence and audit preparation
- Supply chain security: SBOM generation, artifact signing, and provenance attestation (SLSA or equivalent)
- Policy-as-code enforcement (OPA, Conftest, or equivalent) in delivery pipelines
- Observability instrumentation (OpenTelemetry, Prometheus, Grafana, Azure Monitor)
- Distributed systems and event-driven architecture
- Database engineering depth across relational and non-relational stores
Knowledge Skills and Abilities
- Expert proficiency in a modern backend language (C#/.NET, Java, Python, Go, or Node.js) and a modern front-end framework (React, Angular, or Vue)
- Demonstrated ownership of services in production — you have been the person accountable when your code failed at 2am
- Automated testing depth: unit, integration, and end-to-end, with hands-on Playwright experience and a track record of enforcing coverage standards rather than aspiring to them
- Working fluency with containerized deployment on Kubernetes and with infrastructure defined as code
- Comfort operating in a Git-based delivery workflow where changes reach production through automated pipelines
- Demonstrated production delivery using agentic coding tools (Claude Code, Cursor, GitHub Copilot Workspace, or equivalent), including sound judgment about where agent-generated code requires human architectural intervention
- Ability to define review and verification standards for AI-generated code, using automated test coverage as the enforcement mechanism rather than manual inspection, including provenance and review attestation sufficient to satisfy audit requirements at agent-generated volume
- Secure SDLC practice as a daily discipline: SAST/DAST, dependency and container scanning, secret detection, and remediation of findings at the source
- Experience building services that produce audit-grade logging and automated compliance evidence rather than reconstructing it after the fact
- Ability to explain technical tradeoffs clearly to non-technical stakeholders
Reporting Relationships
Reports directly to Senior Level Leadership.
Working Conditions
Work is primarily sedentary; exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull, or otherwise move objects.