Lantana Consulting Group provides services and software for standards-based health-information exchange. We have established ourselves as a trusted leader in the industry with two decades of expertise in developing and deploying technical specifications and interoperability solutions. As a rapidly growing distributed, employee-owned company, we hire exceptional talent nationwide and offer flexible remote work arrangements. We take pride in our mission to improve public health and quality of care and to advance research.
Primary purpose:
Leads and integrates DevOps, release management, and security efforts to align with technical standards and security frameworks. Provides hands-on leadership to guide infrastructure integration, streamline security compliance, and support project delivery. Serves as a key technical liaison between internal teams and IT stakeholders.
A successful candidate will do the following:
- Drive the daily integration of secure development practices, infrastructure automation, and release coordination across multiple federal-facing projects
- Work closely with software engineers, quality assurance, infrastructure, and security teams to design and maintain scalable CI/CD pipelines, align with NIST 800-53 controls, and implement continuous security monitoring and vulnerability-remediation strategies
- Manage and evolve DevOps workflows using industry-standard tools to support timely, compliant, Cloud-based deployments
- Review and improve build and deployment processes
- Support release planning and coordination
- Mentor team members
- Serve as a technical liaison between development and Centers for Disease Control and Prevention (CDC) IT operations
Requirements
- Bachelor’s degree in Information Technology, Computer Science, or a related field
- A minimum of 12 years of experience in DevOps and CI/CD implementation with a strong foundation in principles of software development
- A minimum of five (5) years of experience in security engineering, including applying NIST 800-53 controls, conducting SA&A processes, and remediating vulnerabilities in federal environments
- A minimum of three (3) years of experience managing technical teams, setting priorities, allocating resources, and developing team capabilities
- Demonstrable progression from technical roles to team-leadership positions in technology delivery
- Hands-on automation experience using languages such as Python, PowerShell, or Bash, with a focus on using tools such as Azure DevOps to integrate security and optimize pipelines
- Experience developing and implementing strategic DevSecOps roadmaps that align with organizational objectives and federal compliance requirements
- Ability to translate technical requirements into implementation plans
- Experience creating, documenting, and implementing standardized DevSecOps processes and security protocols across multiple teams and projects, and driving adoption while complying with federal requirements
- Experience collaborating with cross-functional technical teams (software engineers, QA, security, infrastructure) to support secure software-delivery pipelines
- Experience supporting federal agencies such as CDC or Centers for Medicare and Medicaid Services (CMS); and knowledge of federal IT environments, security frameworks, and compliance protocols
- Strong communication skills, including providing updates to leadership
- Experience mentoring junior staff
- Experience using tools such as Jira and Confluence to document technical infrastructure, including Cloud environments, security protocols, and CI/CD pipelines
- Strong understanding of data-encryption best practices, including enforcing policies for data at rest and in transit and responding to security threats using tools like Tenable.sc
- Ability to work and thrive in a fast-paced environment
- Ability to successfully complete a Position of Public Trust Level 5 background investigation
Preferred qualifications:
- Familiarity with Cloud-based development and deployment environments
- Ability to implement and manage containerized applications using Docker and Kubernetes in Cloud-based environments
- Experience streamlining operational workflows through automation, reducing manual processes, and improving system reliability
- Experience collaborating with development and infrastructure teams for release management
- Experience designing and automating secure, scalable Azure infrastructure using IaC tools such as Terraform and Ansible, with supporting diagrams and runbooks
- Experience implementing automated testing and security monitoring to support compliance, key management, and system reliability in Cloud environments
- Familiarity with CDC’s Continuous Monitoring tools such as Tenable.sc and Fortify
- Current CompTIA Security+ certification or equivalent
Additional information:
- We are a remote organization, but we prioritize in-person collaboration during key events such as our annual company meeting.
- We are an equal-opportunity employer. All qualified applicants for current openings will be considered for employment without regard to race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), parental status, national origin, age, disability, genetic information (including family medical history), political affiliation, military service, or other non-merit based factors.
- For this position, the candidate must reside in the United States.