Enter a job title or keyword

Senior Staff Engineer (Devops)

Nagarro


Job Location:

Gurugram - India

Monthly Salary: Not provided by the employer
Posted: 8 October 2026 (8 hours ago)
Application Deadline: 5 January 2027
Vacancies: 1 Vacancy

Department:

Engineering

Job Summary

Requirements

  • Experience : 7.5 years
  • Strong experience in DevOps and AWS with hands-on exposure to enterprise cloud and security environments.
  • Strong expertise in enterprise secrets management and end-to-end IAM.
  • Strong knowledge of Azure Entra ID RBAC ABAC and CyberArk.
  • Proven experience delivering at least one enterprise transformation involving secrets management IAM PAM DevSecOps cloud security or machine identity.
  • Strong understanding of authentication authorization RBAC ABAC least privilege federation workload identity privileged access service accounts access reviews and audit controls.
  • Hands-on experience with Azure IAM services including Entra ID Azure Managed Identity and Service Principals.
  • Hands-on experience with AWS IAM including IAM roles policies STS and OIDC federation.
  • Experience with at least two enterprise secrets management technologies such as Azure Key Vault AWS Secrets Manager HashiCorp Vault CyberArk Conjur Akeyless Thales CipherTrust External Secrets Operator or Secrets Store CSI Driver.
  • Strong experience working across hybrid environments spanning cloud and on-premises workloads.
  • Experience integrating secrets management and IAM controls with CI/CD platforms such as Azure DevOps GitHub Actions Jenkins or GitLab.
  • Experience with Kubernetes security workload identity service accounts and secrets management.
  • Ability to define enterprise standards target-state architecture migration plans governance models and practical engineering patterns.
  • Strong stakeholder management skills across security cloud platform infrastructure application risk compliance and audit teams.
  • Experience working in regulated enterprise environments such as financial services banking insurance healthcare or similar industries.
  • Experience with CyberArk PAM HashiCorp Vault Enterprise machine identity certificate lifecycle management or dynamic secrets.
  • Experience with policy-as-code and security automation tools such as Terraform Azure Policy AWS Organizations/SCPs OPA Sentinel Checkov Prisma Cloud or Wiz.
  • Experience with secret scanning and remediation tools such as GitHub Advanced Security GitGuardian Gitleaks or TruffleHog.
  • Experience defining security dashboards and metrics for secrets compliance IAM access hygiene credential rotation onboarding progress exceptions and risk reduction.
  • Strong understanding of multi-cloud secrets management and IAM processes.
  • Strong analytical problem-solving communication and technical documentation skills.
  • Ability to work effectively with geographically distributed engineering and security teams.

Responsibilities

  • Assess current enterprise secrets management and IAM practices across Azure AWS on-premises platforms Kubernetes CI/CD pipelines applications databases APIs and service accounts.
  • Define target-state architecture for enterprise secrets management IAM integration workload identity privileged access credential rotation auditing and governance.
  • Establish enterprise standards for secrets storage access rotation ownership naming tagging expiry exception handling and decommissioning.
  • Define appropriate use cases for centralized secrets management platforms versus cloud-native services such as Azure Key Vault and AWS Secrets Manager.
  • Design IAM access models using Azure Entra ID AWS IAM RBAC ABAC roles policies groups service principals managed identities and OIDC federation.
  • Implement least-privilege access models across cloud application infrastructure and workload environments.
  • Support application teams in onboarding and migrating from insecure manual or inconsistent secrets and IAM practices.
  • Integrate secrets management and IAM controls with CI/CD pipelines Kubernetes databases APIs legacy applications logging monitoring and SIEM platforms.
  • Design and support workload identity machine identity service accounts privileged access and automated credential rotation.
  • Define and implement governance processes covering ownership support access reviews exception management control monitoring and reporting.
  • Develop practical reference architectures engineering standards onboarding playbooks implementation patterns and technical documentation.
  • Work closely with security cloud platform infrastructure application risk compliance and audit teams to drive enterprise security initiatives.
  • Support IAM and secrets management transformation initiatives across hybrid and multi-cloud environments.
  • Define migration strategies implementation roadmaps and adoption plans for enterprise secrets and IAM capabilities.
  • Establish dashboards and metrics covering secrets compliance IAM access hygiene credential rotation onboarding progress exceptions and risk reduction.
  • Support secret scanning and remediation initiatives across source code repositories and development environments.
  • Promote DevSecOps practices and secure-by-design principles across development and engineering teams.
  • Collaborate with development teams across India the UK and Dalian to drive consistent security practices and implementation standards.
  • Provide technical guidance on CyberArk PAM HashiCorp Vault Enterprise machine identity certificate lifecycle management and dynamic secrets.
  • Drive continuous improvement of enterprise IAM secrets management privileged access and cloud security controls.

Qualifications :

Bachelors or masters degree in computer science Information Technology or a related field.


Remote Work :

No


Employment Type :

Full-time


About Company

Company Logo

Nagarro helps future-proof your business through a forward-thinking, fluidic, and CARING mindset. We excel at digital engineering and help our clients become human-centric, digital-first organizations, augmenting their ability to be responsive, efficient, intimate, creative, and susta ... View more

View Profile View Profile