Staff DevSecOps Engineer, Enterprise Technology

United States Digital Space LLC

Bengaluru

On-site

INR 3,500,000 - 5,500,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

United States Digital Space LLC seeks a Staff DevSecOps Engineer to own security-focused automation across critical enterprise apps such as Salesforce, NetSuite and Workday, and to lead threat modeling and secure-by-design architectures.

You will drive automated governance, SAST/DAST/SCA integrations, and centralized security observability across cloud-native stacks like Next.js/React on Vercel.

Qualifications

  • 8+ years of hands-on experience in DevSecOps, SRE, or Security Engineering; 3+ years in senior/lead capacity.
  • Proven experience securing and automating deployments across multiple enterprise platforms.
  • Deep expertise with modern SCM and automation pipelines (GitHub Actions, CircleCI, Jenkins, Gearset, Copado).
  • Advanced edge security experience with Cloudflare, Akamai or similar platforms.
  • Proficiency in embedding SAST/DAST/SCA and secrets scanning tools into workflows.
  • Experience with SIEM tooling (Splunk or Datadog) for security analytics and alerting.
  • Scripting and IaC skills in Python, Bash, Go and Terraform for guardrails and provisioning.
  • Strong knowledge of API security (REST/GraphQL, JWT, OAuth 2.0) and modern frontend security patterns.

Responsibilities

  • Architect and scale enterprise-grade CI/CD and deployment frameworks across Salesforce, AEM, NetSuite, and Workday.
  • Shift-Left security: integrate SAST/DAST/SCA and secrets detection into workflows.
  • Standardize secrets management and safeguard third-party dependencies and API integrations.
  • Manage global edge protection and configure CDN policies to protect endpoints against attacks.
  • Define and enforce WAF rules, rate limiting, and bot management for public sites and apps.
  • Collaborate on IAM/SSO governance across platforms and implement secure API gateways.
  • Lead incident response, RCA, and continuous auditing with SOC/ISO controls.
  • Drive DevSecOps culture, tooling, and secure coding practices across teams.

Tools

Salesforce
Adobe Experience Manager (AEM)
NetSuite
Workday
GitHub Actions
CircleCI
Jenkins
Gearset
Copado
Cloudflare
Akamai
Snyk
SonarQube
GitGuardian
OWASP ZAP
Prisma Cloud
Wiz
Splunk
Datadog
Terraform
Python
Bash
Go
REST
GraphQL
JWT
OAuth 2.0
Next.js
React
Vercel
CISSP
CCSP
AWS Certified Security – Specialty
AWS
Azure
GCP
AI-assisted DevOps tools

Job description

**Secure Every Identity, from AI to Human

**Identity is the key to unlocking the potential of AI. the company secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

As a Staff DevSecOps Engineer in the ET team, you will be the technical authority and architectural owner responsible for embedding security, compliance, and automated release practices across our enterprise applications ecosystem—including Salesforce, NetSuite, Workday, Adobe Experience Manager (AEM), and modern web stacks (Vercel/Next.js).

In this role, you will bridge development, security, and enterprise ops. You will design, scale, and maintain automated security pipelines, unified observability, edge defense, and identity management across critical business systems. You will serve as a technical leader—driving secure-by-design architectures, threat modeling, and automated governance across complex enterprise platforms.

Key Responsibilities:Enterprise DevSecOps Architecture & CI/CD Security
  • Multi-Platform CI/CD Governance: Architect and scale enterprise-grade CI/CD and deployment frameworks across diverse systems (Salesforce via Gearset/Copado, AEM/Web via CircleCI/GitHub Actions, NetSuite, and Workday).
  • Shift-Left Security Pipeline: Integrate automated SAST, DAST, Software Composition Analysis (SCA), and secrets detection into workflows using tools like SonarQube, Snyk, PMD, GitGuardian, and OWASP ZAP.
  • Secrets & Supply Chain Management: Standardize secrets management (e.g., HashiCorp Vault) and safeguard third-party dependencies, API integrations, and package deployments across all enterprise platforms.
Edge, WAF & Network Security
  • Global Edge Protection: Manage, configure, and optimize enterprise CDN policies via Cloudflare (or platform CDNs) to protect web properties and API endpoints against DDoS, volumetric, and layer-7 attacks.
  • Traffic Filtering & WAF Management: Define and enforce Web Application Firewall (WAF) rules, rate limiting, ModSecurity policies, and bot management strategies to shield public-facing endpoints (AEM, Vercel apps, custom portals)
Identity Access and Platform Hardening
  • Enterprise IAM & SSO Governance: Collaborate with InfoSec to manage identity policies, RBAC, OAuth 2.0, JWT authentication, and SAML/SSO integrations across platforms (Salesforce, NetSuite, AEM Cloud, Workday, the company/Entra ID).
  • Headless & API Security: Architect secure API gateways, protect GraphQL endpoints, manage CORS policies, and enforce API key lifecycle management for decoupled frontend applications (Next.js/React deployed on Vercel).
Observability, Incident Response and Auditing
  • Centralized Security Monitoring: Build and optimize real-time SIEM logging and security analytics in Splunk (or Datadog) to track cross-platform threats, unauthorized changes, and anomalous API behavior.
  • Incident Management & Root Cause Analysis: Lead technical response for platform security events, perform root cause analysis (RCA), and analyze heap/thread dumps, log trails, and network traffic.
  • Automated Compliance & Risk Auditing: Establish continuous compliance controls for regulatory and corporate standards (SOX, SOC2, GDPR, ISO 27001) across SaaS and PaaS tools.
  • Cross-Functional Leadership: Partner with Enterprise Architects, Engineering leads, and Information Security to establish DevSecOps standards and threat modeling practices.
  • DevSecOps Culture: Drive self-service tooling, create developer security guidelines, and mentor senior and mid-level engineers in secure coding and automation best practices.
Required Qualification and Experience
  • Experience:8+ years of hands-on experience in DevSecOps, Site Reliability Engineering (SRE), or Security Engineering, with at least 3+ years in a senior or lead capacity supporting enterprise applications.
  • Multi-Platform Ecosystem Knowledge: Proven experience securing and automating deployments across two or more enterprise platforms: Salesforce, Adobe Experience Manager (AEM Cloud/AEMaaCS), NetSuite, or Workday.
  • DevOps & Pipeline Automation: Deep expertise with modern SCM and automation pipelines including GitHub Actions, CircleCI, Jenkins, Gearset, and Copado.
  • Edge & WAF Security: Advanced hands-on experience managing Cloudflare, Akamai, or similar edge security platforms (WAF rules, SSL/TLS automation, DDoS mitigation, DNS management).
  • Security Tooling Expertise: Proficiency in embedding SAST/DAST/SCA and secrets scanning tools (Snyk, SonarQube, GitGuardian, OWASP ZAP, Prisma Cloud/Wiz) into developer workflows.
  • SIEM & Monitoring: Expertise with Splunk or Datadog for log aggregation, security dashboard creation, threat hunting, and automated alerting.
  • Scripting & IaC: Mastery in Python, Bash, or Go, alongside Infrastructure-as-Code (Terraform) for automated environment provisioning and security guardrails.
  • API & Frontend Integration Security: Solid grasp of API security (REST, GraphQL, JWT, OAuth 2.0) and secure deployment patterns for modern frontend setups (Next.js/React on Vercel).
Preferred /Nice to Have
  • Industry certifications such as CISSP, CCSP, AWS Certified Security – Specialty, or platform-specific certifications (e.g., Salesforce Certified Development Lifecycle & Deployment Architect).
  • Experience with cloud platforms (AWS, Azure, GCP) and container/serverless security.
  • Familiarity with AI-assisted DevOps tools for code scanning, release predictability, and threat identification.

#LI_Linkedin#P24849_3520495

The the company Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

the company is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, ph

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff DevSecOps Engineer, Enterprise Technology
Staff DevSecOps Engineer, Enterprise Technology

Triwill Group • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Staff Software Engineer, Security
Staff Software Engineer, Security

United States Digital Space LLC • Bengaluru

Hybrid
INR 2,500,000 - 4,500,000
Site Reliability Engineer II
Site Reliability Engineer II

United States Digital Space LLC • Bengaluru

Hybrid
INR 2,000,000 - 3,200,000
Manager- Site Reliability Engineering
Manager- Site Reliability Engineering

United States Digital Space LLC • Bengaluru

Hybrid
INR 3,000,000 - 5,500,000
Senior Software Engineer – Tooling & Platform (Terraform)
Senior Software Engineer – Tooling & Platform (Terraform)

United States Digital Space LLC • Bengaluru

Hybrid
INR 2,800,000 - 4,600,000
Sr. DevSecOps Engineer
Sr. DevSecOps Engineer

Maruti Suzuki India Ltd. • Gurgaon

On-site
INR 1,500,000 - 2,000,000
Staff Software Engineer - PAM
Staff Software Engineer - PAM

United States Digital Space LLC • Bengaluru

Hybrid
INR 3,500,000 - 6,000,000
Equity in the company
Flexible work options
Deep learning & AI-enabled development
Staff Site Reliability Engineer - Ecosystem
Staff Site Reliability Engineer - Ecosystem

United States Digital Space LLC • Bengaluru

Hybrid
INR 4,000,000 - 6,000,000
Senior Manager - Application Security & AI Security
Senior Manager - Application Security & AI Security

Pine Labs • Dadri

On-site
INR 4,500,000 - 7,500,000
Staff Site Reliability Engineer - Core iDaaS
Staff Site Reliability Engineer - Core iDaaS

United States Digital Space LLC • Bengaluru

On-site
INR 4,000,000 - 7,000,000