- Location
- Dallas TX - 12377 Merit Dr., United States of America · Morrisville NC, 3015 Carrington Mill Blvd · Charlotte NC - 600 S Tryon St. · Alpharetta GA - 3460 Preston Ridge Rd
- Type
- Full-time
- Department
- Engineering
- Seniority
- Senior
- Source
- Workday
Description
The position is described below. If you want to apply, click the Apply button at the top or bottom of this page. You'll be required to create an account or sign in to an existing one.
If you have a disability and need assistance with the application, you can request a reasonable accommodation. Send an email to Accessibility (accommodation requests only; other inquiries won't receive a response).
Regular or Temporary:
RegularLanguage Fluency: English (Required)
Work Shift:
1st Shift (United States of America)Please review the following job description:
CRC Group is seeking a Senior DevOps Engineer to own three tightly connected pieces of our platform: administration and governance of GitHub Enterprise, infrastructure-as-code design using Terraform, and the CI/CD pipelines and cloud deployment architecture that move code from development to production on Microsoft Azure.The successful candidate combines hands-on GitHub Enterprise administration with strong DevOps engineering skills — Terraform, GitHub Actions and Azure DevOps Pipelines, cloud-native deployment on Azure — and sufficient coding ability to build the automation and integrations the platform needs. They are motivated to bring AI-assisted development (GitHub Copilot, AI agents, Model Context Protocol services) into the workflow safely and at scale, and can partner effectively with cloud engineers, network engineers, security engineers, software developers, and identity/access governance professionals.
Essential Responsibilities
GitHub Enterprise Administration & Governance
Administer GitHub Enterprise Cloud at the enterprise and organization level: enterprise settings, organization structure, teams, roles, and permission models.
Own identity integration with Microsoft Entra ID, including SAML SSO, SCIM provisioning, and Enterprise Managed Users (EMU) where applicable; manage the join/move/leave lifecycle and periodic access reviews.
Define and enforce repository governance through rulesets, branch protection, required reviews, CODEOWNERS, commit signing, and repository creation/visibility policies.
Govern GitHub Apps, OAuth apps, personal access tokens (fine-grained PATs), deploy keys, and third-party integrations; maintain an approval and review process for new connectors.
Configure and operate GitHub Advanced Security: code scanning (CodeQL), secret scanning with push protection, Dependabot alerts and updates, and security overview reporting.
Infrastructure as Code & Platform Engineering
Design and codify platform infrastructure as Terraform modules — repositories, teams, rulesets, Actions and Azure DevOps configuration — with disciplined state management and module design, so platform changes are reviewable, versioned, and repeatable rather than made by hand.
Design and operate the runner strategy: GitHub-hosted, larger runners, and self-hosted runners (including Actions Runner Controller on Kubernetes or Azure VM scale sets), with hardening, patching, and scaling.
Implement keyless cloud authentication from pipelines using OpenID Connect (OIDC) federation to Azure; eliminate long-lived credentials from CI/CD.
Manage pipeline secrets and environments (GitHub Environments, Azure Key Vault integration), deployment approvals, and protection rules.
Implement software supply-chain controls: dependency review, SBOM generation, artifact attestation/provenance, and pinned action versions.
CI/CD Engineering & Deployment
Design, build, and maintain reusable GitHub Actions workflows, composite actions, and reusable workflow libraries that standardize build, test, security scan, and deployment stages across teams.
Administer Azure DevOps (organizations, projects, agent pools, service connections, Pipelines) and lead migrations or coexistence strategies between Azure DevOps and GitHub.
Define branching, release, and versioning strategies with development teams; support monorepo and polyrepo patterns as needed.
Build integrations between GitHub and enterprise systems (Entra ID, ServiceNow/ITSM, Azure Monitor, Teams, security tooling).
Troubleshoot pipeline failures, runner issues, and platform incidents; act as escalation point for GitHub-related production issues.
Development, Automation & AI Enablement
Develop scripts and internal tooling against the GitHub REST and GraphQL APIs to automate administration, reporting, and compliance.
Evaluate and pilot AI-enabled development capabilities — Copilot features, AI agents, and MCP services — and define the guardrails for their use in the platform.
Produce and maintain platform documentation, runbooks, architecture decision records, and developer onboarding guides.
Participate in Agile ceremonies and collaborate with architects, security engineers, and business stakeholders to prioritize platform work.
Required Qualifications
Experience
5+ years in DevOps, platform engineering, or software engineering roles.
Experience administering GitHub Enterprise (Cloud or Server) at the organization or enterprise level in a multi-team environment.
Demonstrated experience designing, building, and supporting production CI/CD pipelines, including infrastructure-as-code with Terraform.
Experience integrating source control platforms with an enterprise identity provider (SSO/SCIM).
Experience working within Agile development teams.
GitHub Enterprise Skills
Enterprise and organization administration, roles, and permission models.
Rulesets, branch protection, CODEOWNERS, and repository governance.
GitHub Actions: workflow authoring, reusable workflows, runner management.
GitHub Advanced Security (code scanning, secret scanning, Dependabot).
GitHub REST and GraphQL APIs; GitHub CLI.
Audit log, security overview, and enterprise reporting.
Infrastructure as Code & DevOps Skills
Terraform and Infrastructure as Code principles, including state management and module design — required, hands-on experience.
Secrets management and pipeline identity (OIDC federation, Azure Key Vault).
Azure DevOps administration and Pipelines.
Containers and container registries; familiarity with Kubernetes for runner hosting.
Git internals and branching/release strategies.
Programming Skills
Comfortable scripting in at least one of Python, PowerShell, or JavaScript/TypeScript (Node.js) to support automation and tooling work. Deep software engineering skill is not the primary focus of this role.
Communication
Strong written and verbal communication; able to write clear policy, runbooks, and technical documentation.
Able to explain platform and security decisions to both engineers and non-technical stakeholders.
Strong problem-solving and analytical skills.
Location: This position can sit hybrid in Dallas, Charlotte, Raleigh or Atlanta.
General Description of Available Benefits for Eligible Employees of CRC Group: At CRC Group, we're committed to supporting every aspect of teammates' well-being – physical, emotional, financial, social, and professional. Our best-in-class benefits program is designed to care for the whole you, offering a wide range of coverage and support. Eligible full-time teammates enjoy access to medical, dental, vision, life, disability, and AD&D insurance; tax-advantaged savings accounts; and a 401(k) plan with company match. CRC Group also offers generous paid time off programs, including company holidays, vacation and sick days, new parent leave, and more. Eligible positions may also qualify for restricted stock units and/or a deferred compensation plan.
CRC Group supports a diverse workforce and is an Equal Opportunity Employer that does not discriminate against individuals on the basis of race, gender, color, religion, citizenship or national origin, age, sexual orientation, gender identity, disability, veteran status or other classification protected by law. CRC Group is a Drug Free Workplace.
EEO is the Law Pay Transparency Nondiscrimination Provision E-Verify