Okta2 days ago

Staff DevSecOps Engineer, Enterprise Technology

Salary not specified
MARKET
26,667median for this role
DevOps Engineer · 7 jobs with disclosed pay
13,000half of the offers: 18,750–58,171100,000
The employer didn't disclose pay — compare with the market yourself.
Bengaluru

Responsibilities

  • 01Architect and scale enterprise-grade CI/CD and deployment frameworks across diverse systems (Salesforce via Gearset/Copado, AEM/Web via CircleCI/GitHub Actions, NetSuite, and Workday)
  • 02Integrate automated SAST, DAST, Software Composition Analysis (SCA), and secrets detection into workflows using tools like SonarQube, Snyk, PMD, GitGuardian, and OWASP ZAP
  • 03Standardize secrets management (e.g., HashiCorp Vault) and safeguard third-party dependencies, API integrations, and package deployments across all enterprise platforms
  • 04Manage, configure, and optimize enterprise CDN policies via Cloudflare (or platform CDNs) to protect web properties and API endpoints against DDoS, volumetric, and layer-7 attacks
  • 05Define and enforce Web Application Firewall (WAF) rules, rate limiting, ModSecurity policies, and bot management strategies to shield public-facing endpoints (AEM, Vercel apps, custom portals)
  • 06Collaborate with InfoSec to manage identity policies, RBAC, OAuth 2.0, JWT authentication, and SAML/SSO integrations across platforms (Salesforce, NetSuite, AEM Cloud, Workday, Okta/Entra ID)
  • 07Architect secure API gateways, protect GraphQL endpoints, manage CORS policies, and enforce API key lifecycle management for decoupled frontend applications (Next.js/React deployed on Vercel)
  • 08Build and optimize real-time SIEM logging and security analytics in Splunk (or Datadog) to track cross-platform threats, unauthorized changes, and anomalous API behavior
  • 09Lead technical response for platform security events, perform root cause analysis (RCA), and analyze heap/thread dumps, log trails, and network traffic
  • 10Establish continuous compliance controls for regulatory and corporate standards (SOX, SOC2, GDPR, ISO 27001) across SaaS and PaaS tools
  • 11Partner with Enterprise Architects, Engineering leads, and Information Security to establish DevSecOps standards and threat modeling practices
  • 12Drive self-service tooling, create developer security guidelines, and mentor senior and mid-level engineers in secure coding and automation best practices

Requirements

  • 018+ years of hands-on experience in DevSecOps, Site Reliability Engineering (SRE), or Security Engineering, with at least 3+ years in a senior or lead capacity supporting enterprise applications
  • 02Proven experience securing and automating deployments across two or more enterprise platforms: Salesforce, Adobe Experience Manager (AEM Cloud/AEMaaCS), NetSuite, or Workday
  • 03Deep expertise with modern SCM and automation pipelines including GitHub Actions, CircleCI, Jenkins, Gearset, and Copado
  • 04Advanced hands-on experience managing Cloudflare, Akamai, or similar edge security platforms (WAF rules, SSL/TLS automation, DDoS mitigation, DNS management)
  • 05Proficiency in embedding SAST/DAST/SCA and secrets scanning tools (Snyk, SonarQube, GitGuardian, OWASP ZAP, Prisma Cloud/Wiz) into developer workflows
  • 06Expertise with Splunk or Datadog for log aggregation, security dashboard creation, threat hunting, and automated alerting
  • 07Mastery in Python, Bash, or Go, alongside Infrastructure-as-Code (Terraform) for automated environment provisioning and security guardrails
  • 08Solid grasp of API security (REST, GraphQL, JWT, OAuth 2.0) and secure deployment patterns for modern frontend setups (Next.js/React on Vercel)