Staff DevSecOps Engineer, Enterprise Technology
Quick Summary
8+ years of hands-on experience in DevSecOps, Site Reliability Engineering (SRE), or Security Engineering, with at least 3+ years in a senior or lead capacity supporting enterprise applications.
Responsibilities
~1 min read- Multi-Platform CI/CD Governance: Architect and scale enterprise-grade CI/CD and deployment frameworks across diverse systems (Salesforce via Gearset/Copado, AEM/Web via CircleCI/GitHub Actions, NetSuite, and Workday).
- Shift-Left Security Pipeline: Integrate automated SAST, DAST, Software Composition Analysis (SCA), and secrets detection into workflows using tools like SonarQube, Snyk, PMD, GitGuardian, and OWASP ZAP.
- Secrets & Supply Chain Management: Standardize secrets management (e.g., HashiCorp Vault) and safeguard third-party dependencies, API integrations, and package deployments across all enterprise platforms.
- Global Edge Protection: Manage, configure, and optimize enterprise CDN policies via Cloudflare (or platform CDNs) to protect web properties and API endpoints against DDoS, volumetric, and layer-7 attacks.
- Traffic Filtering & WAF Management: Define and enforce Web Application Firewall (WAF) rules, rate limiting, ModSecurity policies, and bot management strategies to shield public-facing endpoints (AEM, Vercel apps, custom portals)
- Enterprise IAM & SSO Governance: Collaborate with InfoSec to manage identity policies, RBAC, OAuth 2.0, JWT authentication, and SAML/SSO integrations across platforms (Salesforce, NetSuite, AEM Cloud, Workday, Okta/Entra ID).
- Headless & API Security: Architect secure API gateways, protect GraphQL endpoints, manage CORS policies, and enforce API key lifecycle management for decoupled frontend applications (Next.js/React deployed on Vercel).
- Centralized Security Monitoring: Build and optimize real-time SIEM logging and security analytics in Splunk (or Datadog) to track cross-platform threats, unauthorized changes, and anomalous API behavior.
- Incident Management & Root Cause Analysis: Lead technical response for platform security events, perform root cause analysis (RCA), and analyze heap/thread dumps, log trails, and network traffic.
- Automated Compliance & Risk Auditing: Establish continuous compliance controls for regulatory and corporate standards (SOX, SOC2, GDPR, ISO 27001) across SaaS and PaaS tools.
- Cross-Functional Leadership: Partner with Enterprise Architects, Engineering leads, and Information Security to establish DevSecOps standards and threat modeling practices.
- DevSecOps Culture: Drive self-service tooling, create developer security guidelines, and mentor senior and mid-level engineers in secure coding and automation best practices.
Requirements
~1 min read- Experience: 8+ years of hands-on experience in DevSecOps, Site Reliability Engineering (SRE), or Security Engineering, with at least 3+ years in a senior or lead capacity supporting enterprise applications.
- Multi-Platform Ecosystem Knowledge: Proven experience securing and automating deployments across two or more enterprise platforms: Salesforce, Adobe Experience Manager (AEM Cloud/AEMaaCS), NetSuite, or Workday.
- DevOps & Pipeline Automation: Deep expertise with modern SCM and automation pipelines including GitHub Actions, CircleCI, Jenkins, Gearset, and Copado.
- Edge & WAF Security: Advanced hands-on experience managing Cloudflare, Akamai, or similar edge security platforms (WAF rules, SSL/TLS automation, DDoS mitigation, DNS management).
- Security Tooling Expertise: Proficiency in embedding SAST/DAST/SCA and secrets scanning tools (Snyk, SonarQube, GitGuardian, OWASP ZAP, Prisma Cloud/Wiz) into developer workflows.
- SIEM & Monitoring: Expertise with Splunk or Datadog for log aggregation, security dashboard creation, threat hunting, and automated alerting.
- Scripting & IaC: Mastery in Python, Bash, or Go, alongside Infrastructure-as-Code (Terraform) for automated environment provisioning and security guardrails.
- API & Frontend Integration Security: Solid grasp of API security (REST, GraphQL, JWT, OAuth 2.0) and secure deployment patterns for modern frontend setups (Next.js/React on Vercel).
Nice to Have
~1 min read- Industry certifications such as CISSP, CCSP, AWS Certified Security – Specialty, or platform-specific certifications (e.g., Salesforce Certified Development Lifecycle & Deployment Architect).
- Experience with cloud platforms (AWS, Azure, GCP) and container/serverless security.
- Familiarity with AI-assisted DevOps tools for code scanning, release predictability, and threat identification.
#LI_Linkedin
#P24849_3520495
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.
Location & Eligibility
Listing Details
- Posted
- August 21, 2026
- First seen
- August 21, 2026
- Last seen
- August 21, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- August 21, 2026
Signal breakdown

The foundation for secure connections between people and technology.
View company profilePlease let Okta know you found this job on Jobera.
3 other jobs at Okta
View all →Explore open roles at Okta.
Similar Enterprise jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.