CNA logo

Senior AI Software Engineer

CNA

  • Chicago, Illinois
  • 30+ days ago
  • $72,000–$141,000 Per Year
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Applications Securityunmatched
  • Architectural Servicesunmatched
  • Artificial Intelligence (AI)unmatched
  • Automationunmatched
  • Best Practicesunmatched
  • Communication Skillsunmatched
  • Computer Securityunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • Data Setsunmatched
  • Engineeringunmatched
  • Financial Servicesunmatched
  • GCP (Good Clinical Practices)unmatched
  • GitHubunmatched
  • Instrumentationunmatched
  • Insuranceunmatched
  • Interpersonal Skillsunmatched
  • Leadershipunmatched
  • Machine Toolunmatched
  • Mentoringunmatched
  • Metricsunmatched
  • Onboardingunmatched
  • Open Sourceunmatched
  • Policy Developmentunmatched
  • Product Engineeringunmatched
  • Programming Toolsunmatched
  • Public/Media/Press/Analyst Relationsunmatched
  • Radiographyunmatched
  • Regulatory Complianceunmatched
  • Reporting Dashboardsunmatched
  • Scaffoldingunmatched
  • Security Infrastructureunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Software Engineeringunmatched
  • Technical Consultingunmatched
  • Technical Leadershipunmatched
  • Test Plan/Scheduleunmatched

Description

You have a clear vision of where your career can go. And we have the leadership to help you get there. At CNA, we strive to create a culture in which people know they matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential. 

Senior individual contributor on the Developer Experience (DevX) platform team, responsible for designing, building, and operating an AI-native software delivery platform across five capability domains: FeedBack (AI intelligence, observability, DORA metrics), Enterprise Enablement (Internal Developer Portal, golden-path onboarding), Build & Delivery (CI/CD/CT, GitHub Actions, ArgoCD, Harness), Safety / Application Security (Veracode, SonarCloud, JFrog Xray, supply-chain security), and App Accelerator (container base images, dev containers, starter app templates). Leads the development of AI agentic SDLC workflows — autonomous and human-in-the-loop agents that accelerate code generation, PR review, test authoring, vulnerability remediation, and deployment across engineering teams — in direct support of the platform's north-star goal of taking a developer from template selection to a running pre-production application in 10 minutes or less. Acts as a force multiplier for DevX, partnering with platform, security, container, and product engineering to embed AI assistance into every stage of the SDLC.

JOB DESCRIPTION:

Essential Duties & Responsibilities

Performs a combination of duties in accordance with departmental guidelines:

  • Own and evolve the Internal Developer Platform (Harness IDP) — self-service catalog, scaffolding templates, and golden-path workflows targeting the platform's north-star goal: developer selects a template and has an application deployed to pre-production in 10 minutes or less.

  • Architect and own CI/CD/CT pipelines on GitHub Actions,ArgoCD, and Harness across the Build & Delivery domain; designfor reliability, security, and progressive delivery — able to design andoperateend-to-end, not just configure.

  • Design and build AI agentic SDLC workflows: event-driven agents that autonomously perform code generation, PR review, test authoring, Veracode vulnerability auto-remediation,SonarCloudgate enforcement, and release orchestration across the delivery pipeline.

  • Implement evaluation frameworks for agentic systems (Arize, Phoenix, or equivalent) — define ground truth datasets, regression suites, guardrails, and online/offline evals to ensure AI agentsoperatinginside the SDLC remain safe,accurate, and auditable.

  • Drive supply-chain security inside the Application Security domain: integrate SBOM generation (JFrogXray,Syft, orAnchore) into delivery pipelines, contribute to the Binary Authorization and container image hardening initiative for Kubernetes workloads, and design automated policy gates and remediation flows.

  • Contribute to the App Accelerator domain —maintainand evolve container base images, dev container definitions, and starter app templates so that golden-path scaffolded applications are current, secure, and ready for AI-assisted development from day one.

  • Operate feature flag and progressive-delivery platforms (LaunchDarkly, Unleash, GCP-native, or equivalent); design kill-switches, canary patterns, and safe rollout strategies that protect production while enabling continuous delivery.

  • Embed observability (Datadog, Dynatrace, Elastic, or equivalent) into platform services and delivery pipelines across theFeedBackdomain; own DORA metric instrumentation (deployment frequency, lead time, change failure rate, MTTR) and Application Health dashboards used to measure engineering performance.

  • Champion adoption of AI coding assistants (Claude Code, Cursor, GitHub Copilot) in an AI-native SDLC; build the guardrails, prompt patterns, and developer workflows that make AI-assisted development repeatable and safe at enterprise scale; contribute to the Code Quality as a Service offering alongside Veracode andSonarCloud.

  • Mentor engineers across theDevXand App Acceleratorteams;act as a technical consultant for platform adoption, agentic AI patterns, and delivery best practices.

  • Partner with security, infrastructure, architecture, and product engineering counterparts on platform direction, roadmap, and architectural standards; representDevXin cross-team initiatives spanning container governance, GitHub security controls, and CI/CD policy.

May perform additional duties as assigned.

Reporting Relationship

Typically Director or above

Skills, Knowledge & Abilities

  • 7+ years in platform engineering with deep CI/CD pipeline ownership in a regulated, enterprise-scale environment (insurance, financial services, or equivalent).

  • Hands-on with GitHub Actions,ArgoCD, Harness, or comparable CD platforms — able to design andoperateend-to-end, not just configure.

  • Proficient using AI coding tools (Claude Code, Cursor, GitHub Copilot, or equivalent) in an AI-native SDLC workflow; experience building guardrails and adoption patterns for these tools atteamor enterprise scale.

  • Direct experience building oroperatingan Internal Developer Platform (Harness IDP, Backstage, Port) with a self-service catalog, golden-path scaffolding, and measurable time-to-value metrics (e.g., time to first deployment).

  • Feature flags and progressive-delivery experience (LaunchDarkly, Unleash, GCP-native, or equivalent) including kill-switch design and canary rollout patterns.

  • SBOM and supply-chain integration experience (JFrogXray,Syft,Anchore) inside a delivery pipeline, including Binary Authorization or equivalent container image hardening and policy-gate design.

  • Hands-on with observability platforms (Datadog, Dynatrace, Elastic, or equivalent); able to instrument DORA metrics, define SLOs, and build actionable engineering-performance dashboards.

  • Familiarity with SAST/DAST tooling (Veracode,SonarCloud, or equivalent) in an enterprise pipeline context — ideally including automated triage or remediation workflows.

  • Experience designing and building event-driven AI agents that autonomously complete SDLC tasks, and building evals for agentic systems usingArize, Phoenix, or equivalent.

  • Strong analytical and problem-solving skills; excellent communication and interpersonal skills; able to work effectively with engineers, IT leadership, security, and business stakeholders.

  • Demonstrated ability to lead platform initiatives, drive cross-team adoption, and mentor engineers.

Preferred

  • Insurance orfinancial-servicesindustry background; familiarity with regulatory and compliance requirements for software delivery.

  • Experience with security-as-code, OPA/Rego policy authoring, or compliance-automation pipelines (e.g., GitHub governance at scale, branch protection policy-as-code).

  • Hands-on with container base image pipelines, dev container standards, or starter app template frameworks.

  • Open-source contributions to platform engineering, developer tooling, or AI-agent projects.

Education & Experience

  • Bachelor's degree in Computer Scienceor related discipline, or equivalent work experience.

  • Minimum of7years of platform and software engineering experience, including direct ownership of enterprise CI/CD pipelines in a regulated industry.

  • Previoustechnical leadership experience on platform, developer-tooling, or AI-engineering initiatives.

  • Applicable certifications preferred (e.g., GitHub Actions, Kubernetes, cloud provider, or Harness certifications).

  • #LI-KJ1 #LI-HYBRID

In certain jurisdictions, CNA is legally required to include a reasonable estimate of the compensation for this role. In District of Columbia,California, Colorado, Connecticut, Illinois,Maryland, Massachusetts, New York and Washington,the national base pay range for this job level is $72,000 to $141,000 annually. Salary determinations are based on various factors, including but not limited to, relevant work experience, skills, certifications and location. CNA offers a comprehensive and competitive benefits package to help our employees – and their family members – achieve their physical, financial, emotional and social wellbeing goals.  For a detailed look at CNA’s benefits, please visit cnabenefits.com.

CNA utilizes AI-enabled technology during the recruiting process. For more information, please visit our careers page.

CNA is committed to providing reasonable accommodations to qualified individuals with disabilities in the recruitment process. To request an accommodation, please contact 

leaveadministration@cna.com

Numbers & Facts

LocationChicago, Illinois
IndustryOther/Not Classified
Salary$72,000–$141,000 Per Year
Company Size100 to 499 employees
Year Founded1940
Websitehttps://www.cna.org/

About Company

CNA's approach to research is a modern iteration of the Newtonian principle that complex, dynamic processes are best understood through direct observation of events and people. That was the methodology CNA analysts first applied in the 1940s when they pioneered the field of operations research by helping the Navy address the German U-boat threat. Not content to study the problem from afar, this small group of MIT scientists insisted on deploying with Navy forces in order to observe operations and collect the data needed for meaningful analyses. Their groundbreaking work, and the anti-submarine warfare equations it produced, set a standard for operations research methods that CNA has maintained for 75 years. Today, with more than 500 professionals at our headquarters and 50 researchers in the field, CNA still takes a multi-disciplinary, real-world approach to our work. On-site analysts carefully observe all aspects of a process—people, decisions, actions, consequences—and then collaborate with a headquarters-based research team to assess data and arrive at findings. CNA's objective, empirical research and analysis helps decision makers develop sound policies, make better-informed decisions, and manage programs more effectively. Our work, which in its early decades focused solely on defense-related matters, has grown to include investigation and analysis of a broad range of national security, defense, and public interest issues including education, homeland security and air traffic management. Through our Center for Naval Analyses and Institute for Public Research, we provide public-sector organizations with the tools they need to tackle the complex challenges of making government more efficient and keeping our country safe and strong.

Similar Jobs