Peraton is seeking a talented and motivated Full Stack & DevSecOps Engineer to join a dynamic team building and operating a cutting-edge Agentic AI platform. This hybrid role sits at the intersection of application engineering and platform operations — combining the responsibilities of a Full Stack Engineer specializing in Agentic AI and External Integrations with those of a DevSecOps / Platform Engineer.
In this role, you will design, develop, and maintain the integrations and intelligent agent capabilities that power a next-generation decision-support platform, while also owning the delivery infrastructure, CI/CD pipelines, cloud operations, and platform health that keep it running securely and reliably. You will work across the full stack to connect AI agents with diverse external data sources, package real-world capabilities as reliable agent tools, and ensure that the systems you build are secure, scalable, observable, and production ready.
If you are passionate about applied AI, thrive in fast-moving environments, and take pride in building platforms that real users depend on — from the application layer down to the infrastructure — this is an opportunity to make a meaningful impact supporting critical missions.
Location: Columbus, Ohio — candidates must currently reside in the area or be willing to relocate.
Key Responsibilities
Full Stack & Agentic AI Engineering
- Design and build integrations to external sources of information, including public APIs, licensed data feeds, partner systems, customer enterprise systems, web content, document repositories, and structured databases
- Package external capabilities as agent tools and skills with clean interfaces, predictable inputs/outputs, sound error handling, and documentation usable by both AI agents and human configurators
- Develop and maintain full-stack components spanning FastAPI/Python backends, React frontends, Docker containerization, and PostgreSQL
- Build and consume web APIs (REST, GraphQL, or comparable), handling production integration concerns such as authentication, pagination, rate limiting, retry/backoff, schema mapping, deduplication, and caching
- Implement and maintain workflow and task orchestration pipelines using systems such as Airflow, Prefect, Celery, or comparable agent orchestration patterns
- Integrate LLMs into production or near-production applications, leveraging APIs such as OpenAI, Anthropic, or AWS Bedrock
- Apply security best practices specific to agentic and external integration work — including secrets management, OAuth and API-key handling, defensive parsing, and prompt-injection awareness
- Collaborate across teams with a product mindset, keeping the end-user experience central to technical decisions
DevSecOps & Platform Engineering
- Build and maintain CI/CD pipelines across GitHub Actions and/or GitLab CI, enabling secure, repeatable, and efficient delivery workflows
- Implement and improve automated testing and quality gates within the software delivery lifecycle, including build validation, integration checks, security testing, and deployment controls
- Plan and execute releases and deployments — coordinating change windows, managing release artifacts, running deployment automation, validating post-deployment health, and supporting rollback procedures
- Support operational ownership of Amazon EKS / Kubernetes environments, including cluster lifecycle activities, upgrades, troubleshooting, RBAC, Helm-based deployments, pod identity, and GitOps-aligned workflows
- Build and maintain AWS infrastructure supporting platform and application needs across services such as VPC, IAM, S3, RDS, CloudTrail, and KMS
- Contribute to infrastructure provisioning and lifecycle management through OpenTofu / Terraform and related infrastructure-as-code practices
- Administer user management for the platform — identity provider integration (SSO/SAML/OIDC), RBAC, provisioning and deprovisioning workflows, and periodic access reviews
- Design and operate a mature monitoring, logging, and alerting stack using CloudWatch, Prometheus/Grafana, or equivalent tooling
- Routinely assess system logs to detect anomalies, configuration drift, misuse, and security-relevant events; triage findings and drive remediation
- Build and maintain synthetic and transactional monitoring that exercises real authentication flows, user journeys, and critical service transactions
- Track and remediate Information Assurance Vulnerability Management (IAVM) notices and other vulnerability advisories — maintain inventory accuracy, drive patching to closure, and produce compliance reporting evidence
- Implement and maintain DAST and runtime security testing in delivery pipelines using tools such as OWASP ZAP, Burp, Nuclei, or equivalent
- Support security-focused CI/CD practices including secrets management, least privilege, software supply chain integrity, and audit evidence generation