A different kind of consulting company that delivers offshore and nearshore product development, user experience, app modernization, business intelligence, and business apps services.
Job Description
Job Title: Principal Software Engineer
Location: Bethesda,MD (Hybrid / Mostly On-Site)
Engagement Type: Full- Time
Clearance: Ableto obtain Public Trust clearance upon hire
Role Overview
Stackular is seeking a hands-on Principal Software Engineer to provide cross-stack technical leadership on a multi-year cloud-nativemodernization initiative supporting a federal research client within theNational Institutes of Health (NIH).
This role operates as the senior engineering voice on across-functional team that spans application development, cloud infrastructure,data integration, automation, and security. The portfolio under modernizationincludes roughly twenty legacy applications transitioning from .NET, Oracle,and SAP BusinessObjects on VM-based hosting to an AWS-managed,microservices-based platform delivered through a federated GraphQL API layerand a React/TypeScript frontend.
This position is ideal for engineers who can both writeproduction-grade code and exercise sound technical judgment when changes crossdomain boundaries — reviewing architecture, APIs, infrastructure, and data workside-by-side, and helping a newly integrated DevSecOps team deliver coherent,secure, operable systems.
Key Responsibilities
Technical Leadership& Code Review
- Providehands-on technical leadership across modernization engineering work,including application code, APIs, cloud infrastructure, automationpipelines, and database changes.
- Reviewpull requests that affect any layer of the stack; approve or recommendchanges based on implementation risk, API design, data impact, securityposture, deployment readiness, and architectural alignment.
- Enforceconsistent engineering patterns for APIs, distributed services, clouddeployment, data integration, observability, and secure configuration.
- Upholdthe program's modern engineering and cloud architecture standards,including microservice boundaries, schema governance, andinfrastructure-as-code guardrails.
Architecture &Engineering Execution
- Helpengineering teams translate target architecture decisions into working,maintainable code on the approved AWS technology stack.
- Guidedesign and implementation of containerized microservices using Python(FastAPI), GraphQL subgraphs (Apollo Federation), and React/TypeScriptfrontends.
- Adviseon data architecture decisions involving Amazon RDS PostgreSQL, AWS Gluedata pipelines, and legacy system integrations following the Strangler Figmigration pattern.
- Supportsecure-by-default cloud delivery on Amazon EKS using Terraform, GitHubActions CI/CD, and AWS-native services (Secrets Manager, CloudWatch,X-Ray, WAF, ALB).
- Contributeto and review Architecture Decision Records when implementation choicesdeviate from approved patterns or introduce new technologies.
- Partnerwith the project stakeholders to identify technical dependencies,blockers, and sequencing issues during backlog refinement, sprintplanning, and release coordination.
- Coordinatewith the Enterprise Architect, application development leads,infrastructure and operations engineers, and security personnel whenchanges require specialized review or have architectural, operational, orcompliance implications.
- Translatearchitecture and security guidance into practical, day-to-dayimplementation advice for engineers across the team.
- Mentorengineers on cloud-native delivery practices, distributed system patterns,secure development, observability, and operational ownership.
Required Skills &Qualifications
- 7+years of professional software engineering experience, with at least 2years in a technical lead, staff engineer, or principal engineer capacityon production cloud systems.
- Provenability to reason across the full stack —frontend, backend, API,database, cloud infrastructure, automation, and security — and to evaluatethe downstream impact of cross-boundary changes.
- Demonstratedexperience designing, building, or reviewing distributed systems andmicroservice-style architectures, including API contracts, data ownershipboundaries, and inter-service communication patterns.
- Strong,hands-on proficiency in Python (FastAPI or equivalent framework) and amodern frontend ecosystem (React with TypeScript preferred).
- Productionexperience with GraphQL APIs; familiarity with federated GraphQL (ApolloFederation, schema composition, schema governance, breaking-changedetection in CI) is strongly preferred.
- Deepworking knowledge of AWS cloud-native services, including EKS/Kubernetes,RDS PostgreSQL, S3, IAM, Secrets Manager, CloudWatch, and VPC networking.
- Practicalexperience with Infrastructure as Code (Terraform), containerized delivery(Docker), and CI/CD automation (GitHub Actions or equivalent).
- Experienceintegrating modern services with legacy systems (.NET, Oracle, SAPBusinessObjects, or comparable) and executing incremental migrations usingpatterns such as Strangler Fig.
- Workingknowledge of secure software delivery, including identity federation(OIDC, SAML 2.0, OAuth2), secrets management, RBAC, audit logging, andcompliance evidence collection.
- Strongwritten and verbal communication; ability to explain technical tradeoffsclearly to engineers, program leadership, and non-technical stakeholders.
- Collaborativetechnical leadership style suited to a cross-functional team whereinfluence comes from clarity, judgment, and trust rather than formalhierarchy.
Technical Skills
- APIs: GraphQL(Apollo Federation), REST, API gateway design, schema governance and versioning
- Frontend: Reactwith TypeScript, component-based design systems
- Data: PostgreSQL,AWS Glue ETL, SQL/NoSQL patterns, integration with legacy Oracle and reportingplatforms
- DevOps Tools: GitHubActions (preferred), GitLab CI, Jenkins, or equivalent CI/CD platforms
- Infrastructure asCode: Terraform (modules, remote state, policy-as-code)
- Observability: AmazonCloudWatch, AWS X-Ray, Prometheus, Grafana, ELK stack
- Security: OAuth2,OIDC, SAML 2.0, AWS Secrets Manager, IAM, container/image scanning, dependencyscanning, SAST/DAST integration in CI
PreferredQualifications
- Experiencesupporting federal modernization or compliance-driven environments (FISMA,NIST 800-53, FedRAMP Moderate/High).
- Backgroundproducing or guiding cATO-related technical evidence (control narratives,scan results, IaC posture, observability artifacts).
- Hands-onexperience with AWS Glue or comparable serverless ETL tooling for governeddata integration.
- Exposureto event-driven architectures and change-data-capture (Kafka, Amazon MSK,Debezium, etc.)
- Familiaritywith Apollo Federation tooling, schema registries, persisted queries, andbreaking-change detection workflows.
- Priorexperience working in or alongside cross-functional DevSecOps teams thatintegrate infrastructure, application development, and security personnel.
Nice to Have
- AWScertifications (Solutions Architect Professional, DevOps EngineerProfessional, or Security Specialty).
- CertifiedKubernetes Administrator (CKA) or comparable orchestration certification.
- Experiencewith zero-trust network architectures and federal identity integration(Entra ID, OIDC, SAML 2.0 federation).
- Exposureto AI/ML-assisted development practices and developer productivitytooling.
- Experiencecontributing to Architecture Decision Records and engineering guardrailsin regulated environments.
- Familiaritywith NIH or other federal research IT environments and their compliance,identity, and networking baselines.