HireHire › Nagarro jobs › Senior Staff Engineer (Devops)

Senior Staff Engineer (Devops)

Apply for this role or explore on the map →

Requirements Experience : 7.5+ years Strong experience in DevOps and AWS , with hands-on exposure to enterprise cloud and security environments. Strong expertise in enterprise secrets management and end-to-end IAM . Strong knowledge of Azure Entra ID, RBAC, ABAC, and CyberArk . Proven experience delivering at least one enterprise transformation involving secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity. Strong understanding of authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls. Hands-on experience with Azure IAM services, including Entra ID, Azure Managed Identity, and Service Principals . Hands-on experience with AWS IAM, including IAM roles, policies, STS, and OIDC federation . Experience with at least two enterprise secrets management technologies such as Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver . Strong experience working across hybrid environments spanning cloud and on-premises workloads. Experience integrating secrets management and IAM controls with CI/CD platforms such as Azure DevOps, GitHub Actions, Jenkins, or GitLab . Experience with Kubernetes security, workload identity, service accounts, and secrets management. Ability to define enterprise standards, target-state architecture, migration plans, governance models, and practical engineering patterns. Strong stakeholder management skills across security, cloud, platform, infrastructure, application, risk, compliance, and audit teams. Experience working in regulated enterprise environments such as financial services, banking, insurance, healthcare, or similar industries. Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle management, or dynamic secrets . Experience with policy-as-code and security automation tools such as Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, or Wiz . Experience with secret scanning and remediation tools such as GitHub Advanced Security, GitGuardian, Gitleaks, or TruffleHog . Experience defining security dashboards and metrics for secrets compliance, IAM access hygiene, credential rotation, onboarding progress, exceptions, and risk reduction. Strong understanding of multi-cloud secrets management and IAM processes. Strong analytical, problem-solving, communication, and technical documentation skills. Ability to work effectively with geographically distributed engineering and security teams. Responsibilities Assess current enterprise secrets management and IAM practices across Azure, AWS, on-premises platforms, Kubernetes, CI/CD pipelines, applications, databases, APIs, and service accounts. Define target-state architecture for enterprise secrets management, IAM integration, workload identity, privileged access, credential rotation, auditing, and governance. Establish enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning. Define appropriate use cases for centralized secrets management platforms versus cloud-native services such as Azure Key Vault and AWS Secrets Manager. Design IAM access models using Azure Entra ID, AWS IAM, RBAC, ABAC, roles, policies, groups, service principals, managed identities, and OIDC federation. Implement least-privilege access models across cloud, application, infrastructure, and workload environments. Support application teams in onboarding and migrating from insecure, manual, or inconsistent secrets and IAM practices. Integrate secrets management and IAM controls with CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging, monitoring, and SIEM platforms. Design and support workload identity, machine identity, service accounts, privileged access, and automated credential rotatio

More roles at Nagarro

See Nagarro & thousands more on the map

Every tech & IT company hiring across India — with AI match scores — on one live map.

Open the map →