Senior Data Streaming Engineer (Kafka & Flink)

CGI

• $89K — $198K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree and 10+ years of relevant IT experience, including senior engineering roles
  • 5+ years of experience in enterprise streaming or secure delivery contexts
  • Expert-level proficiency with Kafka, Flink, Java, Avro, and Confluent Schema Registry
  • Proven track record in defining CI/CD and DevSecOps best practices
  • Hands-on knowledge of secure microservices and Kafka client security configurations
  • Strong operational grasp of Kafka internals for diagnostics and support

Responsibilities

  • Define enterprise streaming patterns and architectures for Kafka and Flink
  • Develop shared libraries and reference implementations for mission teams
  • Guide application teams in evaluating streaming solution designs
  • Serve as a tier 3 escalation point for complex streaming issues
  • Collaborate with DevOps and Platform Engineering to establish CI/CD guardrails
  • Architect reusable CI/CD pipeline patterns for secure delivery
  • Maintain secure coding and vulnerability management standards across applications

Benefits

  • Competitive compensation
  • Comprehensive insurance options
  • 401(k) matching contributions
  • Paid time off including vacation and parental leave
  • Learning opportunities and tuition assistance
  • Wellness and well-being programs
Full Job Description
Find similar career opportunities

Senior Data Streaming Engineer (Kafka & Flink)

Category: Software Development/ Engineering

Main location: United States, Maryland, Baltimore

Position ID:J0926-2120

Employment Type: Full Time

Position Description:

CGI Federal is seeking a Sr DevSecOps Engineer (Data Streaming) to serve as a key member of an enterprise Center of Excellence (CoE) dedicated to mission critical, real time data streaming and secure software delivery. This role operates at a senior technical leadership level, guiding multiple application and platform teams in adopting best in class patterns for Kafka, Flink, CI/CD security, schema governance, microservices, and federal compliance.

This role serves as a technical force multiplier across the enterprise, elevating streaming engineering maturity through standardized patterns, shared libraries, and proactive enablement of mission development teams.

While some responsibilities include direct hands on engineering, the majority of the impact comes from defining enterprise patterns, establishing guardrails, reviewing designs, mentoring development teams, and providing deep troubleshooting expertise across the streaming ecosystem. A strong understanding of Kafka's operational behavior is essential-you will advise both developers and Kafka platform administrators, helping diagnose complex issues, design scalable solutions, and ensure reliable data flow across environments. Collaborate closely with Platform Engineering and DevOps teams to ensure streaming application design aligns with enterprise platform capabilities, without directly operating infrastructure.

***This position is located in Woodlawn, MD and requires individuals to be onsite 5 days/week***

Your future duties and responsibilities:

Enterprise Streaming & DevSecOps Leadership
. Define and maintain enterprise patterns, reference architectures, and guardrails for Kafka, Flink, Kafka Streams, CI/CD, schema governance, and secure microservice delivery.
. Develop shared streaming libraries, starter templates, and reference implementations to accelerate consistent adoption across mission teams.
. Provide strategic and hands on technical guidance to application teams evaluating streaming solution designs.
. Serve as a tier 3 escalation point for enterprise streaming issues, including consumer lag, serialization failures, state store anomalies, rebalancing behavior, and memory or performance bottlenecks.

CI/CD & Secure Delivery Integration
. Partner with DevOps and Platform Engineering teams to define secure, opinionated CI/CD guardrails that enforce policy driven security, schema validation, and deployment standards.
. Architect reusable pipeline patterns incorporating automated vulnerability scanning, dependency governance, artifact promotion controls, and remediation workflows.
. Define patterns for zero downtime stateful deployments, including safe rolling updates, versioned schema evolution, and checkpoint/snapshot aligned cutovers.
. Integrate automated topic provisioning validation into pipeline guardrails, ensuring naming, configuration, and RBAC compliance.

Technical Security & Vulnerability Management
. Develop secure coding and dependency management standards for Java/Kafka/Flink applications.
. Interpret vulnerability scan results, define remediation approaches, and coach teams through resolution.
. Maintain alignment with NIST controls, POAM lifecycle requirements, and federal patch management expectations.

Kafka Operational Engineering & Advisory
. Apply deep knowledge of Kafka internals-brokers, partitions, replication, consumer groups, ACLs, RBAC, retention, and cluster health-to guide both developers and operators.
. Support operational debugging of ISR fluctuations, replication delays

Required qualifications to be successful in this role:

. Ability to obtain and maintain a Public Trust clearance.
. Bachelor's Degree and 10+ years of progressive IT experience, including senior or advisory engineering roles.
. 5+ years of experience in enterprise scale streaming or secure delivery environments, with demonstrated ability to define patterns, mentor teams, and perform deep troubleshooting.
. Expert level proficiency with Kafka, Flink, Java, Avro, and Confluent Schema Registry, covering both developer facing and operational/administration aligned aspects.
. Experience with Kafka Streams or similar stateful streaming frameworks is a plus.
. Proven experience defining and implementing CI/CD and DevSecOps best practices, including secure pipeline design using Jenkins, Maven, Bitbucket, and Nexus.
. Demonstrated experience with enterprise vulnerability management, secure coding practices, and POAM aligned remediation workflows.
. Hands on experience designing secure microservices and Kafka client security configurations (SSL/MTLS, SASL/OAUTHBEARER), with the ability to advise on operational impacts.
. Strong operational understanding of Kafka internals-partitioning strategy, consumer groups, ISR behavior, replication, cluster health-allowing senior level diagnostic support across teams.
. Demonstrated ability to produce enterprise documentation, standards, reference architectures, and reusable patterns.

Desired qualifications/non essential skills required:
. Experience serving in a Center of Excellence, architecture council, or multi team governance body.
. Prior experience supporting federal agencies (SSA, CMS, DHS, DOJ, etc.) and operating within regulated mission environments.
. Experience designing or governing secure containerized workloads (Docker, Kubernetes/OpenShift) including admission control and CI/CD integration.
. Familiarity with Black Duck, SonarQube, Fortify, or similar security platforms-ideally including cross team onboarding and remediation coaching.
. Knowledge of Confluent Platform RBAC, enterprise security constructs, and cluster level operational controls.
. Experience supporting or architecting large scale streaming workloads, defining standards for partitioning, schema evolution, state management, and fault tolerance.
. Experience building shared libraries, starter templates, or reusable components for streaming and microservice adoption across multiple teams.
. Advanced experience with distributed system debugging and guiding production incident triage across cross service dependencies.

CGI is required by law in some jurisdictions to include a reasonable estimate of the compensation range for this role. The determination of this range includes various factors not limited to skill set, level, experience, relevant training, and licensure and certifications. To support the ability to reward for merit based performance, CGI typically does not hire individuals at or near the top of the range for their role. Compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range for this role in the U.S. is $89,600.00 $198,400.00.

CGI Federal's benefits are offered to eligible professionals on their first day of employment to include:
. Competitive compensation
. Comprehensive insurance options
. Matching contributions through the 401(k) plan and the share purchase plan
. Paid time off for vacation, holidays, and sick time
. Paid parental leave
. Learning opportunities and tuition assistance
. Wellness and Well being programs

#CGIFederalJob
#LI RJ1

Skills:
  • Apache Kafka
  • Containerization
  • Java
  • Technical Writing
  • Vulnerability management(IAVM)
  • Central and Federal Government
  • Google DevOps CI/CD
  • HP Fortify


Similar Jobs

More Jobs at CGI

More Information Technology Jobs

Find similar Senior Data Streaming Engineer (Kafka & Flink) jobs: