Senior DevOps Engineer (hybrid)

Johnson Controls
York, PA, United States
5 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$120,000.0 - $155,000.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Unit Testing Microsoft Azure Bash Shell Business Systems Cloud Computing Cyber Security Continuous Integration Data as a Services Data Infrastructure DevOps
+28 more
Middleware Github Identity and Access Management Virtual Private Networks (VPN) Python (Programming Language) Key Management SQL Azure Network Segmentation Windows PowerShell Role-Based Access Control Azure Machine Learning Software Deployment Management of Software Versions YAML Azure Service Bus Containerization AI Platforms Gitlab-ci Kubernetes Bicep Patch Management Data Management Machine Learning Operations Terraform Api Management Docker Key Vault Microservices

Job description

  • Azure DevOps as a platform - organization and project structure, YAML pipelines, repositories and branch policies, artifact feeds, service connections, environments, and self-hosted agent pools including agents inside plant and DMZ networks.
  • Build deployment paths for the systems we actually run. Microservices are the easy case; you will also need controlled, repeatable release processes for integration artifacts, API layers, and configuration for COTS platforms ([CPQ], [PLM], [ERP], [MES]) that do not deploy like modern applications.
  • Design approval gates, change records, and audit evidence appropriate to systems that control what gets manufactured and shipped, without turning every deployment into a two-week ceremony.
  • Plan and execute deployments around production reality - maintenance windows, shift schedules, quarter-end order volume, and the fact that the factory does not stop for a release.

Azure platform

  • Manage infrastructure as code across all environments. Manual portal changes are a defect, not a workflow.
  • Manage the estate: Functions, Azure SQL and storage, Service Bus and Event Hubs, API Management, and the data platform
  • Networking and identity - VNets, private endpoints, hub-and-spoke topology, [ExpressRoute / site-to-site VPN] connectivity to plants, Entra ID, managed identities, Key Vault, and RBAC.
  • Manage hybrid and edge footprint, including [Azure Arc] for on-premise servers and [IoT Edge / IoT Hub] where shop floor systems require local resilience and cannot depend on WAN availability.
  • Own environment strategy and lifecycle: dev, test, UAT, and production; environment refresh and provisioning; and test data management including masking of customer, pricing, and design data.

Build the AI platform

  • Stand up and operate [Azure Machine Learning / Azure AI Foundry] - workspaces, compute and GPU capacity, model registry, and managed inference endpoints.
  • Manage Azure OpenAI and model provider access: provisioning, quota and throughput planning, private networking, content filtering configuration, and key and identity management.
  • Extend CI/CD to AI workloads - versioning for models, prompts, and datasets; automated evaluation as a pipeline gate so a regression blocks a release the same way a failing unit test does; and reliable rollback.
  • Build observability for AI in production: latency, error and abstention rates, token consumption, drift signals, and per-feature cost attribution.
  • Deploy inference where it needs to run, including on-premise or edge at plants where latency, connectivity, or data policy rules out a cloud round trip.
  • Own AI cost management. Make spend attributable and forecastable, and raise the trade-offs early rather than at invoice time.

Reliability and security

  • Build monitoring and alerting that reflects business impact rather than resource metrics - a stalled BOM release matters more than CPU utilization. Own SLOs, dashboards, and incident response for production systems.
  • Drive incident management and blameless postmortems, and convert findings into platform changes.
  • Own security posture in the pipeline and the estate: secrets management, vulnerability and dependency scanning, container image hygiene, SBOM generation, and patch management coordination - including OT environments where patching windows are constrained.
  • Partner with IT, OT, and information security on segmentation, access control, and compliance requirements for plant-connected systems.

Improve how the team ships

  • Reduce friction and toil deliberately. Self-service environments, golden pipeline templates, and good documentation are deliverables, not side effects.
  • Mentor engineers on deployment, observability, and operational ownership of what they build.

Requirements

  • 5+ years in DevOps, platform, SRE, or cloud infrastructure engineering.
  • Hands-on Azure experience across compute, networking, identity, data services, and monitoring.
  • Azure DevOps expertise - YAML pipelines, self-hosted agents, environments and approvals, artifact management, and repository governance. Equivalent depth in GitHub Actions or GitLab CI with demonstrated ability to pick up Azure DevOps is acceptable.
  • Containerization and orchestration in production (Docker and Kubernetes).
  • Scripting and automation in Python and PowerShell or Bash.
  • Experience deploying into hybrid environments, not cloud-only. Firewalled targets, private connectivity, and on-premise servers should be familiar territory.
  • Demonstrated ownership of production systems - on-call, incident response, and measurable reliability improvement.

Preferred

  • MLOps experience: Azure Machine Learning, model registries and inference endpoints, GPU capacity management, or LLMOps including prompt and evaluation versioning and token cost management.
  • Experience supporting enterprise business systems - ERP, PLM, CPQ, MES, or integration middleware - and realistic expectations about what CI/CD looks like for commercial platforms.
  • Manufacturing or industrial environment experience, including OT network segmentation and plant cybersecurity practices.
  • Data platform operations: [Data Factory / Fabric], warehouse or lakehouse infrastructure, orchestration and pipeline reliability.
  • FinOps practice - cloud cost visibility, allocation, and optimization.
  • Azure certifications (AZ-400, AZ-104/305, or AI-102) and Kubernetes certifications (CKA).
  • Experience being an early platform hire and establishing standards rather than inheriting them.
  • Production infrastructure-as-code experience with [Terraform / Bicep], including managing multiple environments and state responsibly.

About the company

Johnson Controls, a global leader in thermal management, mission-critical building systems, energy efficiency, and decarbonization, helps customers use energy more productively, reduce carbon emissions, and operate with the precision and resilience required in rapidly expanding industries such as data centers, healthcare, pharmaceuticals, advanced manufacturing, and higher education.

For more than 140 years, Johnson Controls has delivered performance where it really matters. Backed by advanced technology, lifecycle services and an industry-leading field organization, we elevate customer performance, turn goals into real-world results and help move society forward.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

2:56 min

Provisioning a secure container infrastructure with Bicep

Matthias Falkenberg +1 · World Congress 2022

1:35 min

Centralizing configuration logic with native YAML block references

Matthieu Vincent Matthieu Vincent · Europe 2026 Virtual

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

4:09 min

Selecting infrastructure tools and determining proper abstraction layers

Alayshia Knighten Alayshia Knighten · World Congress 2024

Videos

See all

Related articles

See all