Senior Staff Engineer (Devops)

Posted 11 Hours Ago
Be an Early Applicant
Gurugram, Haryana, IND
In-Office
Senior level
Artificial Intelligence • Information Technology • Machine Learning • Software • Virtual Reality • Analytics
The Role
Leads enterprise secrets management, IAM, privileged access, workload identity, and cloud security transformation across Azure, AWS, on-premises, Kubernetes, CI/CD, and application environments. Defines target architectures, security standards, governance, migration strategies, least-privilege models, credential rotation, policy automation, dashboards, and onboarding practices. Partners with security, platform, infrastructure, application, risk, compliance, and audit teams to implement DevSecOps and secure-by-design controls across hybrid and multi-cloud environments.
Summary Generated by Built In
Company Description

👋🏼We're Nagarro.

We are a Digital Product Engineering company that is scaling in a big way! We build products, services, and experiences that inspire, excite, and delight. We work at a scale — across all devices and digital mediums, and our people exist everywhere in the world (18500+ experts across 39 countries, to be exact). Our work culture is dynamic and non-hierarchical. We are looking for great new colleagues. That is where you come in!

Job Description

Requirements

  • Experience : 7.5+ years
  • Strong experience in DevOps and AWS, with hands-on exposure to enterprise cloud and security environments.
  • Strong expertise in enterprise secrets management and end-to-end IAM.
  • Strong knowledge of Azure Entra ID, RBAC, ABAC, and CyberArk.
  • Proven experience delivering at least one enterprise transformation involving secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity.
  • Strong understanding of authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls.
  • Hands-on experience with Azure IAM services, including Entra ID, Azure Managed Identity, and Service Principals.
  • Hands-on experience with AWS IAM, including IAM roles, policies, STS, and OIDC federation.
  • Experience with at least two enterprise secrets management technologies such as Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver.
  • Strong experience working across hybrid environments spanning cloud and on-premises workloads.
  • Experience integrating secrets management and IAM controls with CI/CD platforms such as Azure DevOps, GitHub Actions, Jenkins, or GitLab.
  • Experience with Kubernetes security, workload identity, service accounts, and secrets management.
  • Ability to define enterprise standards, target-state architecture, migration plans, governance models, and practical engineering patterns.
  • Strong stakeholder management skills across security, cloud, platform, infrastructure, application, risk, compliance, and audit teams.
  • Experience working in regulated enterprise environments such as financial services, banking, insurance, healthcare, or similar industries.
  • Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle management, or dynamic secrets.
  • Experience with policy-as-code and security automation tools such as Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, or Wiz.
  • Experience with secret scanning and remediation tools such as GitHub Advanced Security, GitGuardian, Gitleaks, or TruffleHog.
  • Experience defining security dashboards and metrics for secrets compliance, IAM access hygiene, credential rotation, onboarding progress, exceptions, and risk reduction.
  • Strong understanding of multi-cloud secrets management and IAM processes.
  • Strong analytical, problem-solving, communication, and technical documentation skills.
  • Ability to work effectively with geographically distributed engineering and security teams.

Responsibilities

  • Assess current enterprise secrets management and IAM practices across Azure, AWS, on-premises platforms, Kubernetes, CI/CD pipelines, applications, databases, APIs, and service accounts.
  • Define target-state architecture for enterprise secrets management, IAM integration, workload identity, privileged access, credential rotation, auditing, and governance.
  • Establish enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning.
  • Define appropriate use cases for centralized secrets management platforms versus cloud-native services such as Azure Key Vault and AWS Secrets Manager.
  • Design IAM access models using Azure Entra ID, AWS IAM, RBAC, ABAC, roles, policies, groups, service principals, managed identities, and OIDC federation.
  • Implement least-privilege access models across cloud, application, infrastructure, and workload environments.
  • Support application teams in onboarding and migrating from insecure, manual, or inconsistent secrets and IAM practices.
  • Integrate secrets management and IAM controls with CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging, monitoring, and SIEM platforms.
  • Design and support workload identity, machine identity, service accounts, privileged access, and automated credential rotation.
  • Define and implement governance processes covering ownership, support, access reviews, exception management, control monitoring, and reporting.
  • Develop practical reference architectures, engineering standards, onboarding playbooks, implementation patterns, and technical documentation.
  • Work closely with security, cloud, platform, infrastructure, application, risk, compliance, and audit teams to drive enterprise security initiatives.
  • Support IAM and secrets management transformation initiatives across hybrid and multi-cloud environments.
  • Define migration strategies, implementation roadmaps, and adoption plans for enterprise secrets and IAM capabilities.
  • Establish dashboards and metrics covering secrets compliance, IAM access hygiene, credential rotation, onboarding progress, exceptions, and risk reduction.
  • Support secret scanning and remediation initiatives across source code repositories and development environments.
  • Promote DevSecOps practices and secure-by-design principles across development and engineering teams.
  • Collaborate with development teams across India, the UK, and Dalian to drive consistent security practices and implementation standards.
  • Provide technical guidance on CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle management, and dynamic secrets.
  • Drive continuous improvement of enterprise IAM, secrets management, privileged access, and cloud security controls.

Qualifications

Bachelor’s or master’s degree in computer science, Information Technology, or a related field.

Skills Required

  • 7.5+ years of experience
  • Strong DevOps and AWS experience with enterprise cloud and security environments
  • Enterprise secrets management and end-to-end IAM expertise
  • Knowledge of Azure Entra ID, RBAC, ABAC, and CyberArk
  • Experience delivering an enterprise transformation involving secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity
  • Understanding of authentication, authorization, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls
  • Hands-on experience with Azure Entra ID, Azure Managed Identity, and Service Principals
  • Hands-on experience with AWS IAM roles, policies, STS, and OIDC federation
  • Experience with at least two enterprise secrets management technologies
  • Experience across hybrid cloud and on-premises environments
  • Experience integrating secrets management and IAM with Azure DevOps, GitHub Actions, Jenkins, or GitLab
  • Experience with Kubernetes security, workload identity, service accounts, and secrets management
  • Ability to define enterprise standards, target-state architecture, migration plans, governance models, and engineering patterns
  • Strong stakeholder management across security, cloud, platform, infrastructure, application, risk, compliance, and audit teams
  • Experience in regulated enterprise environments such as financial services, banking, insurance, or healthcare
  • Experience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle management, or dynamic secrets
  • Experience with policy-as-code and security automation tools
  • Experience with secret scanning and remediation tools
  • Experience defining security dashboards and metrics for secrets compliance and IAM access hygiene
  • Strong understanding of multi-cloud secrets management and IAM processes
  • Strong analytical, problem-solving, communication, and technical documentation skills
  • Ability to work effectively with geographically distributed engineering and security teams
  • Bachelor's or master's degree in computer science, information technology, or a related field

Nagarro Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Nagarro and has not been reviewed or approved by Nagarro.

  • Pay Growth & Progression — Compensation is at times described as competitive, with salary hikes and perks occurring on certain occasions. Better growth opportunities and compensation are also positioned as an advantage versus other service-based companies.
  • Flexible Benefits — Work arrangements are framed around a “work-from-anywhere” mindset with flexitime and family-friendly working models. This flexibility appears to add meaningful value to the overall rewards package for many roles.
  • Healthcare Strength — Medical, dental, and vision coverage are described as available for employees and dependents, alongside life insurance. Mental-health support is also included via an Employee Assistance Program (EAP).

Nagarro Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Munich
19,994 Employees
Year Founded: 1996

What We Do

Nagarro helps future-proof your business through a forward-thinking, fluidic, and CARING mindset. We excel at digital engineering and help our clients become human-centric, digital-first organizations, augmenting their ability to be responsive, efficient, intimate, creative, and sustainable. Today, we are 19,000 experts across 36 countries, forming a Nation of Nagarrians, ready to help our customers succeed.

Similar Jobs

In-Office or Remote
2 Locations
103 Employees

MongoDB Logo MongoDB

Associate, HR Shared Services

Big Data • Cloud • Software • Database
Easy Apply
Hybrid
Gurugram, Haryana, IND
5550 Employees

Optum Logo Optum

Machine Learning Engineer

Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
In-Office
Gurgaon, Gurugram, Haryana, IND
160000 Employees

ZS Logo ZS

Decision Analytics Associate

Artificial Intelligence • Healthtech • Professional Services • Analytics • Consulting
Hybrid
5 Locations
15000 Employees

Similar Companies Hiring

Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account