About the company
Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
Responsibilities
- Architect and scale enterprise-grade CI/CD and deployment frameworks across diverse systems (Salesforce via Gearset/Copado, AEM/Web via CircleCI/GitHub Actions, NetSuite, and Workday).
- Integrate automated SAST, DAST, Software Composition Analysis (SCA), and secrets detection into workflows using tools like SonarQube, Snyk, PMD, GitGuardian, and OWASP ZAP.
- Standardize secrets management (e.g., HashiCorp Vault) and safeguard third-party dependencies, API integrations, and package deployments across all enterprise platforms.
- Manage, configure, and optimize enterprise CDN policies via Cloudflare (or platform CDNs) to protect web properties and API endpoints against DDoS, volumetric, and layer-7 attacks.
- Define and enforce Web Application Firewall (WAF) rules, rate limiting, ModSecurity policies, and bot management strategies to shield public-facing endpoints (AEM, Vercel apps, custom portals).
- Collaborate with InfoSec to manage identity policies, RBAC, OAuth 2.0, JWT authentication, and SAML/SSO integrations across platforms (Salesforce, NetSuite, AEM Cloud, Workday, Okta/Entra ID).
- Architect secure API gateways, protect GraphQL endpoints, manage CORS policies, and enforce API key lifecycle management for decoupled frontend applications (Next.js/React deployed on Vercel).
- Build and optimize real-time SIEM logging and security analytics in Splunk (or Datadog) to track cross-platform threats, unauthorized changes, and anomalous API behavior.
- Lead technical response for platform security events, perform root cause analysis (RCA), and analyze heap/thread dumps, log trails, and network traffic.
- Establish continuous compliance controls for regulatory and corporate standards (SOX, SOC2, GDPR, ISO 27001) across SaaS and PaaS tools.
- Partner with Enterprise Architects, Engineering leads, and Information Security to establish DevSecOps standards and threat modeling practices.
- Drive self-service tooling, create developer security guidelines, and mentor senior and mid-level engineers in secure coding and automation best practices.
Requirements
- 8+ years of hands-on experience in DevSecOps, Site Reliability Engineering (SRE), or Security Engineering, with at least 3+ years in a senior or lead capacity supporting enterprise applications.
- Proven experience securing and automating deployments across two or more enterprise platforms: Salesforce, Adobe Experience Manager (AEM Cloud/AEMaaCS), NetSuite, or Workday.
- Deep expertise with modern SCM and automation pipelines including GitHub Actions, CircleCI, Jenkins, Gearset, and Copado.
- Advanced hands-on experience managing Cloudflare, Akamai, or similar edge security platforms (WAF rules, SSL/TLS automation, DDoS mitigation, DNS management).
- Proficiency in embedding SAST/DAST/SCA and secrets scanning tools (Snyk, SonarQube, GitGuardian, OWASP ZAP, Prisma Cloud/Wiz) into developer workflows.
- Expertise with Splunk or Datadog for log aggregation, security dashboard creation, threat hunting, and automated alerting.
- Mastery in Python, Bash, or Go, alongside Infrastructure-as-Code (Terraform) for automated environment provisioning and security guardrails.
- Solid grasp of API security (REST, GraphQL, JWT, OAuth 2.0) and secure deployment patterns for modern frontend setups (Next.js/React on Vercel).
Conditions
- Industry certifications such as CISSP, CCSP, AWS Certified Security – Specialty, or platform-specific certifications (e.g., Salesforce Certified Development Lifecycle & Deployment Architect) are preferred.
- Experience with cloud platforms (AWS, Azure, GCP) and container/serverless security is a plus.
- Familiarity with AI-assisted DevOps tools for code scanning, release predictability, and threat modeling is a plus.