Verified today
Staff DevSecOps Engineer
About the role
Okta's Enterprise Technology (ET) team seeks a Staff DevSecOps Engineer to serve as the technical authority and architectural owner for embedding security, compliance, and automated release practices across enterprise applications including Salesforce, NetSuite, Workday, Adobe Experience Manager (AEM), and modern web stacks (Vercel/Next.js). Day-to-day, you will design and scale multi-platform CI/CD and shift-left security pipelines, manage edge/WAF and CDN protection, govern enterprise IAM/SSO and API security, and build centralized SIEM monitoring and automated compliance controls. You will also lead incident response, root cause analysis, and cross-functional threat modeling while mentoring engineers and driving a DevSecOps culture. This role is based in Bengaluru, India.
What you’ll do
- Architect and scale enterprise-grade CI/CD and deployment frameworks across diverse systems (Salesforce via Gearset/Copado, AEM/Web via CircleCI/GitHub Actions, NetSuite, and Workday).
- Integrate automated SAST, DAST, Software Composition Analysis (SCA), and secrets detection into workflows using tools like SonarQube, Snyk, PMD, GitGuardian, and OWASP ZAP.
- Standardize secrets management (e.g., HashiCorp Vault) and safeguard third-party dependencies, API integrations, and package deployments across all enterprise platforms.
- Manage, configure, and optimize enterprise CDN policies via Cloudflare (or platform CDNs) to protect web properties and API endpoints against DDoS, volumetric, and layer-7 attacks.
- Define and enforce Web Application Firewall (WAF) rules, rate limiting, ModSecurity policies, and bot management strategies to shield public-facing endpoints (AEM, Vercel apps, custom portals).
- Collaborate with InfoSec to manage identity policies, RBAC, OAuth 2.0, JWT authentication, and SAML/SSO integrations across platforms (Salesforce, NetSuite, AEM Cloud, Workday, Okta/Entra ID).
- Architect secure API gateways, protect GraphQL endpoints, manage CORS policies, and enforce API key lifecycle management for decoupled frontend applications (Next.js/React deployed on Vercel).
- Build and optimize real-time SIEM logging and security analytics in Splunk (or Datadog) to track cross-platform threats, unauthorized changes, and anomalous API behavior.
What you’ll bring
- 8+ years of hands-on experience in DevSecOps, Site Reliability Engineering (SRE), or Security Engineering, with at least 3+ years in a senior or lead capacity supporting enterprise applications.
- Proven experience securing and automating deployments across two or more enterprise platforms: Salesforce, Adobe Experience Manager (AEM Cloud/AEMaaCS), NetSuite, or Workday.
- Deep expertise with modern SCM and automation pipelines including GitHub Actions, CircleCI, Jenkins, Gearset, and Copado.
- Advanced hands-on experience managing Cloudflare, Akamai, or similar edge security platforms (WAF rules, SSL/TLS automation, DDoS mitigation, DNS management).
- Proficiency in embedding SAST/DAST/SCA and secrets scanning tools (Snyk, SonarQube, GitGuardian, OWASP ZAP, Prisma Cloud/Wiz) into developer workflows.
- Expertise with Splunk or Datadog for log aggregation, security dashboard creation, threat hunting, and automated alerting.
- Mastery in Python, Bash, or Go, alongside Infrastructure-as-Code (Terraform) for automated environment provisioning and security guardrails.
- Solid grasp of API security (REST, GraphQL, JWT, OAuth 2.0) and secure deployment patterns for modern frontend setups (Next.js/React on Vercel).
Nice to have
- Industry certifications such as CISSP, CCSP, AWS Certified Security – Specialty, or platform-specific certifications (e.g., Salesforce Certified Development Lifecycle & Deployment Architect).
- Experience with cloud platforms (AWS, Azure, GCP) and container/serverless security.
- Familiarity with AI-assisted DevOps tools for code scanning, release predictability, and threat identification.
Skills
Benefits
- Immersive, in-person onboarding experience designed to accelerate impact and connect to Okta's mission and team from day one.
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
- Global community spanning over 20 offices worldwide