Staff DevSecOps Engineer, Enterprise Technology
Owns enterprise DevSecOps architecture across Salesforce, NetSuite, Workday, AEM, and modern web platforms. The role requires 8+ years of DevSecOps, SRE, or security engineering experience, strong CI/CD and edge-security expertise, and leadership in secure automation, observability, identity, and compliance.
About the job
Responsibilities
Enterprise DevSecOps Architecture & CI/CD Security
- Architect and scale enterprise CI/CD and deployment frameworks across Salesforce, AEM/Web, NetSuite, and Workday.
- Integrate automated SAST, DAST, software composition analysis (SCA), and secrets detection using SonarQube, Snyk, PMD, GitGuardian, and OWASP ZAP.
- Standardize secrets management with tools such as HashiCorp Vault and secure third-party dependencies, API integrations, and package deployments.
Edge, WAF & Network Security
- Manage and optimize Cloudflare or platform CDN policies to protect web properties and APIs from DDoS and layer-7 attacks.
- Define WAF rules, rate limiting, ModSecurity policies, and bot-management strategies for public-facing endpoints.
Identity, Access & Platform Hardening
- Govern RBAC, OAuth 2.0, JWT, and SAML/SSO integrations across Salesforce, NetSuite, AEM Cloud, Workday, Okta, and Entra ID.
- Secure API gateways and GraphQL endpoints, manage CORS policies, and enforce API-key lifecycle management for Next.js/React applications on Vercel.
Observability, Incident Response & Auditing
- Build and optimize SIEM logging and security analytics in Splunk or Datadog.
- Lead technical response to platform security events, perform root cause analysis, and analyze heap/thread dumps, logs, and network traffic.
- Establish continuous compliance controls for SOX, SOC 2, GDPR, and ISO 27001.
- Partner with Enterprise Architecture, Engineering, and Information Security teams on DevSecOps standards and threat modeling.
- Drive self-service tooling, developer security guidelines, and mentoring in secure coding and automation practices.
Requirements
- 8+ years of hands-on experience in DevSecOps, SRE, or Security Engineering, including 3+ years in a senior or lead capacity supporting enterprise applications.
- Experience securing and automating deployments across at least two of Salesforce, AEM Cloud/AEMaaCS, NetSuite, or Workday.
- Expertise with GitHub Actions, CircleCI, Jenkins, Gearset, and Copado.
- Advanced experience with Cloudflare, Akamai, or similar edge-security platforms, including WAF, SSL/TLS, DDoS mitigation, and DNS management.
- Proficiency embedding SAST, DAST, SCA, and secrets-scanning tools such as Snyk, SonarQube, GitGuardian, OWASP ZAP, Prisma Cloud, or Wiz.
- Expertise with Splunk or Datadog for log aggregation, security dashboards, threat hunting, and alerting.
- Mastery of Python, Bash, or Go and Terraform for infrastructure provisioning and security guardrails.
- Strong understanding of REST, GraphQL, JWT, OAuth 2.0, and secure Next.js/React deployment patterns on Vercel.
Nice-to-Haves
- CISSP, CCSP, AWS Certified Security – Specialty, or platform-specific certifications.
- Experience with AWS, Azure, GCP, and container or serverless security.
- Familiarity with AI-assisted DevOps tools for code scanning, release predictability, and threat identification.
Skills
GitHub Actions, CircleCI, Jenkins, Gearset, Copado, Cloudflare, Waf, Snyk, Sonarqube, Gitguardian, Owasp Zap, Splunk, Datadog, Terraform, Python
Similar jobs
DevOps / SRE jobsBuild and operate a Kubernetes-native control plane for provisioning, scheduling, self-healing, and optimizing GPU inference infrastructure. The role requires strong software engineering, durable workflow orchestration, reconciliation systems, event-driven architecture, and platform API experience.
Build and operate declarative control planes, durable workflows, and self-healing systems that provision and manage GPU inference infrastructure. The role requires strong software engineering, reconciliation or orchestration experience, and event-driven systems expertise.
Builds and mentors development of scalable cloud tooling, Continuous Delivery platforms, Infrastructure as Code automation, and supporting microservices across AWS environments. The role requires substantial backend software development experience with Java, Go, or Python, plus Terraform, CI/CD, containers, and distributed systems expertise.
Build and operate high-performance customer compute environments spanning bare metal, Kubernetes, Slurm, GPUs, networking, storage, and observability. The role requires 5+ years of production Linux infrastructure experience and strong expertise in bare-metal Kubernetes, NVIDIA GPUs, virtualization, and networking.
Owns and evolves CI/CD, mobile release, testing, and deployment infrastructure for a production fintech application. The role requires 8+ years in DevOps or related platform disciplines, strong AWS and Kubernetes expertise, and experience with secure mobile release systems.