yoinka

Staff DevSecOps Engineer, Enterprise Technology

Okta

Bengaluru, IndiaStaffH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Bengaluru, India
Work model
On-Site
Level
Staff
H-1B history
52 approvals (FY2023)
Posted
1h ago

Skills

AWSAzureCI/CDCybersecurityDatadogGCPGitGitHub ActionsGraphQLJavaScriptJenkinsMachine LearningNext.jsOAuthPrismaPythonRESTReactSalesforceServerlessShellSplunkTerraformWorkday

About this role

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

As a Staff DevSecOps Engineer in the ET team, you will be the technical authority and architectural owner responsible for embedding security, compliance, and automated release practices across our enterprise applications ecosystem—including Salesforce, NetSuite, Workday, Adobe Experience Manager (AEM), and modern web stacks (Vercel/Next.js).

In this role, you will bridge development, security, and enterprise ops. You will design, scale, and maintain automated security pipelines, unified observability, edge defense, and identity management across critical business systems. You will serve as a technical leader—driving secure-by-design architectures, threat modeling, and automated governance across complex enterprise platforms.

Key Responsibilities

Enterprise DevSecOps Architecture & CI/CD Security

• Multi-Platform CI/CD Governance: Architect and scale enterprise-grade CI/CD and deployment frameworks across diverse systems (Salesforce via Gearset/Copado, AEM/Web via CircleCI/GitHub Actions, NetSuite, and Workday).

• Shift-Left Security Pipeline: Integrate automated SAST, DAST, Software Composition Analysis (SCA), and secrets detection into workflows using tools like SonarQube, Snyk, PMD, GitGuardian, and OWASP ZAP.

• Secrets & Supply Chain Management: Standardize secrets management (e.g., HashiCorp Vault) and safeguard third-party dependencies, API integrations, and package deployments across all enterprise platforms.

Edge, WAF & Network Security

• Global Edge Protection: Manage, configure, and optimize enterprise CDN policies via Cloudflare (or platform CDNs) to protect web properties and API endpoints against DDoS, volumetric, and layer-7 attacks.

• Traffic Filtering & WAF Management: Define and enforce Web Application Firewall (WAF) rules, rate limiting, ModSecurity policies, and bot management strategies to shield public-facing endpoints (AEM, Vercel apps, custom portals)

Identity Access and Platform Hardening

• Enterprise IAM & SSO Governance: Collaborate with InfoSec to manage identity policies, RBAC, OAuth 2.0, JWT authentication, and SAML/SSO integrations across platforms (Salesforce, NetSuite, AEM Cloud, Workday, Okta/Entra ID).

• Headless & API Security: Architect secure API gateways, protect GraphQL endpoints, manage CORS policies, and enforce API key lifecycle management for decoupled frontend applications (Next.js/React deployed on Vercel).

Observability, Incident Response and Auditing

• Centralized Security Monitoring: Build and optimize real-time SIEM logging and security analytics in Splunk (or Datadog) to track cross-platform threats, unauthorized changes, and anomalous API behavior.

• Incident Management & Root Cause Analysis: Lead technical response for platform security events, perform root cause analysis (RCA), and analyze heap/thread dumps, log trails, and network

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Staff DevSecOps Engineer, Enterprise Technology at Okta, Bengaluru, India | Yoinka