Position: Senior Automation Engineer
Location: 100% REMOTE
Employment mode: Contract
Working Cadence
Agile / Scrum on a two-week sprint cadence aligned to end-customer's sprint cycle: sprint planning, reviews and demos, retrospectives, and backlog refinement
Client Context
End-customer is a Richmond, Virginia based regulated utility serving the Mid-Atlantic and Southeast, including Northern Virginia's "Data Center Alley." Data center demand there has pushed its contracted pipeline to more than 47 GW and its 2026 2030 capital plan to about $65B.
Environment Scale
Enterprise OpenShift platform across three environments: on-premises VCF-based clusters, Azure Red Hat OpenShift (ARO), and Red Hat OpenShift Service on AWS (ROSA). Four Electric Transmission (ET) applications in initial scope, with roughly 10 15 additional applications migrating from bare metal to virtual clusters.
Team Composition
Works alongside the Client Delivery Lead, Lead Automation Architect, Platform / OpenShift Engineer, potential Cloud Engineer, Analyst, and Domain Architects, and with Dominion s platform, COE, infrastructure, security, and ET application teams
About the Role
The Senior Automation Engineer is a hands-on technical delivery role on the Client's OpenShift Platform Readiness Program for the end-customer, a 32-week engagement to establish Red Hat OpenShift as Dominion s enterprise application hosting platform across on-premises, Azure, and AWS. The program runs two parallel delivery tracks: Track 1 stabilizes the existing on-premises OpenShift environment and takes it through an Operational Readiness Review (ORR) to production go-live for Electric Transmission (ET) workloads; Track 2 delivers production-ready ARO and ROSA platforms through repeatable, automated deployment patterns. In this role, you build the automation artifacts that underpin the platform operating model across all three environments.
Key Responsibilities
GitOps & Multi-Environment Delivery
Namespace Onboarding & Platform Guardrails
Secrets, Certificates & Observability Integration
Automation Artifact Library & Platform Readiness
Governance & Delivery
GitOps & Multi-Environment Delivery
- Refactor existing GitOps repositories in Azure DevOps to the approved branching model, environment promotion workflow, and merge approval gates
- Implement ArgoCD ApplicationSets using cluster generators and environment labels to target on-premises, ARO, and ROSA clusters from a common repository structure
- Implement the app-of-apps pattern for platform baseline configuration management
- Update ArgoCD RBAC to align with the agreed ownership model across the platform team, COE, and application teams
- Write Git repository documentation, including README files, branching strategy guide, contribution guide, and environment promotion runbooks
Namespace Onboarding & Platform Guardrails
- Build a standardized, automated namespace onboarding pipeline that delivers baseline RBAC, NetworkPolicies, resource quotas, and storage quotas consistently across all three environments
- Develop RBAC templates and NetworkPolicy configurations aligned to the agreed network policy ownership model across platform, COE, and application teams
- Implement Kyverno governance policies for platform-level guardrails, such as resource quota enforcement, image registry restrictions, and label and annotation standards
- Implement DomSI CA injection into pod trust stores via Kyverno (or the approved equivalent), enabling removal of the Broadcom SSL inspection bypasses
- Structure onboarding pipeline code, configuration, and documentation in a format compatible with Red Hat Developer Hub catalog integration
- Contribute to platform standards documentation covering image registry usage, network policy expectations, resource quota guidance, and GitOps promotion requirements
Secrets, Certificates & Observability Integration
- Implement the CyberArk Conjur CSI secretless pattern as the primary secrets management approach, and ESO with Reloader for exception use cases, on-premises and on ARO and ROSA
- Configure cert-manager integrated with Dominion s enterprise PKI, including automated renewal workflows and expiry alerting; support KUBE+ integration for front-end certificate management
- Automate Dynatrace Operator deployment and OneAgent rollout, and deliver dashboard and alerting configurations as code
- Support Splunk forwarding for platform audit events, compliance findings, and ACS runtime alerts
- Support Compliance Operator profile configurations for NIST scanning and ACS policy configurations as version-controlled artifacts
Automation Artifact Library & Platform Readiness
- Maintain version control hygiene across the Azure DevOps automation artifact library, including pull request reviews, README documentation, and contribution guide maintenance
- Develop Ansible Automation Platform playbooks and Terraform modules as reusable artifacts for Day-2 operations and provisioning workflows, with scope and format confirmed during Planning and Design
- Validate automation patterns in the client's Advanced Technology Center (ATC) before they are introduced into Dominion s production environments
- Support NetApp Trident StorageClass and snapshot policy definitions and Rubrik KUPR backup integration across on-premises, ARO, and ROSA
- Support the reference application deployment, the ARO availability-zone failover demonstration, and ORR evidence for ET production go-live
- Support namespace provisioning and onboarding as non-ET applications migrate from bare metal to virtual clusters and during hypercare
Governance & Delivery
- Participate fully in Agile ceremonies (sprint planning, sprint reviews and demos, retrospectives, and backlog refinement) on a two-week cadence aligned to Dominion s sprint cycle
- Work from the project backlog: pull stories that meet the Definition of Ready, and close them only when they meet the Definition of Done, including testing evidence
- Demonstrate working, tested increments at every sprint close; your sprint artifacts feed velocity and burndown metrics, the weekly status report, and Dominion s program milestone framewok
- Flag risks, blockers, and dependencies early, including infrastructure readiness gates for VCF, NetApp, and network/firewall, and escalate through the Delivery Lead rather than absorbing silently
- Route scope changes through the agreed change control process, and operate within Dominion s change management practices for production work
Required Technical Skills
Ansible / AAP (strong) 5+ yrs
GitOps with ArgoCD 3+ yrs
Terraform 3+ yrs
CI/CD pipelines 5+ yrs
Git / Azure DevOps Repos 5+ yrs
Python or Bash 5+ yrs
Testing frameworks 5+ yrs
OpenShift 4.x / Kubernetes 5+ yrs
Security, Policy & Multi-Tenancy
Secrets Management
Ingress, DNS & Certificates
Storage & DR
GPU Workloads (nice-to-have)
Minimum Experience
- 10+ years of infrastructure or platform engineering experience, with at least 5 years running OpenShift or Kubernetes in production
- Demonstrated experience taking automation code from lab/proof-of-concept to production operation at scale
- Hands-on experience operating Kubernetes at scale, across many clusters and regions
- Prior experience operating in an Agile / Scrum environment as a contributing engineer, not just as a participant
- Experience working in regulated industries (utilities and critical infrastructure, financial services, healthcare, public sector, or similar) with frameworks such as PCI and NIST 800-171, or comparable change-control discipline
Preferred Qualifications
- Red Hat Certified Specialist in OpenShift Administration (EX280)
- Red Hat Certified Engineer / Red Hat Certified Specialist in Ansible Automation
- Experience with Azure Red Hat OpenShift (ARO), Red Hat OpenShift Service on AWS (ROSA), or Azure Government
- Experience running backup and disaster recovery programs for OpenShift with Rubrik KUPR or OADP/Velero
- Hands-on experience with Red Hat ACS, Kyverno, and the OpenShift Compliance Operator
- Experience migrating application workloads from bare metal to virtualized OpenShift clusters
- Exposure to Red Hat Developer Hub (Backstage) catalog patterns
- Exposure to event-driven automation patterns (EDA with Ansible Rulebooks, webhook-triggered remediation, or equivalent)