{"id":1992032,"url":"https://alion.io/job/nagarro-senior-staff-engineer-devops-7","title":"Senior Staff Engineer (Devops)","company":{"id":2457,"name":"Nagarro","domain":"nagarro.com","url":"https://alion.io/company/nagarro","size_band":"5000+","is_staffing_agency":false,"employer_type":"services","is_intermediary":false,"listed_via":null,"ats_vendor":"SmartRecruiters","truth_index":{"grade":"A","score":92,"open_postings":65,"ghost_share":0,"stale_share":0.323,"repost_share":0,"time_to_fill_p50_days":23,"computed_at":"2026-10-07T05:47:15Z"}},"role":"DevOps","role_family":"DevOps","seniority":"staff","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Gurgaon, India"],"countries":["IN"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":27000,"max_usd":62000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":700},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Azure DevOps","optional":false},{"name":"Checkov","optional":false},{"name":"CI/CD","optional":false},{"name":"CyberArk","optional":false},{"name":"External Secrets","optional":false},{"name":"GitGuardian","optional":false},{"name":"GitHub","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitLab","optional":false},{"name":"Gitleaks","optional":false},{"name":"HashiCorp Vault","optional":false},{"name":"IAM","optional":false},{"name":"Jenkins","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Prisma Cloud","optional":false},{"name":"SIEM","optional":false},{"name":"Terraform","optional":false},{"name":"TruffleHog","optional":false},{"name":"Vault","optional":false},{"name":"Wiz","optional":false}],"status":"live","first_seen_at":"2026-10-07T06:22:36Z","employer_posted_date":"2026-10-07","last_verified_at":"2026-10-07T23:20:55Z","board_verified":true,"closed_at":null,"days_open":0,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":0},"description":"We're Nagarro.\nWe are a Digital Product Engineering company that is scaling in a big way! We build products, services, and experiences that inspire, excite, and delight. We work at a scale - across all devices and digital mediums, and our people exist everywhere in the world (18500+ experts across 39 countries, to be exact). Our work culture is dynamic and non-hierarchical. We are looking for great new colleagues. That is where you come in!\n Requirements\nExperience : 7.5+ years\nStrong experience in DevOps and AWS, with hands-on exposure to enterprise cloud and security environments.\nStrong expertise in enterprise secrets management and end-to-end IAM.\nStrong knowledge of Azure Entra ID, RBAC, ABAC, and CyberArk.\nProven experience delivering at least one enterprise transformation involving secrets management, IAM, PAM, DevSecOps, cloud security, or machine identity.\nStrong understanding of authentication, authorization, RBAC, ABAC, least privilege, federation, workload identity, privileged access, service accounts, access reviews, and audit controls.\nHands-on experience with Azure IAM services, including Entra ID, Azure Managed Identity, and Service Principals.\nHands-on experience with AWS IAM, including IAM roles, policies, STS, and OIDC federation.\nExperience with at least two enterprise secrets management technologies such as Azure Key Vault, AWS Secrets Manager, HashiCorp Vault, CyberArk Conjur, Akeyless, Thales CipherTrust, External Secrets Operator, or Secrets Store CSI Driver.\nStrong experience working across hybrid environments spanning cloud and on-premises workloads.\nExperience integrating secrets management and IAM controls with CI/CD platforms such as Azure DevOps, GitHub Actions, Jenkins, or GitLab.\nExperience with Kubernetes security, workload identity, service accounts, and secrets management.\nAbility to define enterprise standards, target-state architecture, migration plans, governance models, and practical engineering patterns.\nStrong stakeholder management skills across security, cloud, platform, infrastructure, application, risk, compliance, and audit teams.\nExperience working in regulated enterprise environments such as financial services, banking, insurance, healthcare, or similar industries.\nExperience with CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle management, or dynamic secrets.\nExperience with policy-as-code and security automation tools such as Terraform, Azure Policy, AWS Organizations/SCPs, OPA, Sentinel, Checkov, Prisma Cloud, or Wiz.\nExperience with secret scanning and remediation tools such as GitHub Advanced Security, GitGuardian, Gitleaks, or TruffleHog.\nExperience defining security dashboards and metrics for secrets compliance, IAM access hygiene, credential rotation, onboarding progress, exceptions, and risk reduction.\nStrong understanding of multi-cloud secrets management and IAM processes.\nStrong analytical, problem-solving, communication, and technical documentation skills.\nAbility to work effectively with geographically distributed engineering and security teams.\nResponsibilities\nAssess current enterprise secrets management and IAM practices across Azure, AWS, on-premises platforms, Kubernetes, CI/CD pipelines, applications, databases, APIs, and service accounts.\nDefine target-state architecture for enterprise secrets management, IAM integration, workload identity, privileged access, credential rotation, auditing, and governance.\nEstablish enterprise standards for secrets storage, access, rotation, ownership, naming, tagging, expiry, exception handling, and decommissioning.\nDefine appropriate use cases for centralized secrets management platforms versus cloud-native services such as Azure Key Vault and AWS Secrets Manager.\nDesign IAM access models using Azure Entra ID, AWS IAM, RBAC, ABAC, roles, policies, groups, service principals, managed identities, and OIDC federation.\nImplement least-privilege access models across cloud, application, infrastructure, and workload environments.\nSupport application teams in onboarding and migrating from insecure, manual, or inconsistent secrets and IAM practices.\nIntegrate secrets management and IAM controls with CI/CD pipelines, Kubernetes, databases, APIs, legacy applications, logging, monitoring, and SIEM platforms.\nDesign and support workload identity, machine identity, service accounts, privileged access, and automated credential rotation.\nDefine and implement governance processes covering ownership, support, access reviews, exception management, control monitoring, and reporting.\nDevelop practical reference architectures, engineering standards, onboarding playbooks, implementation patterns, and technical documentation.\nWork closely with security, cloud, platform, infrastructure, application, risk, compliance, and audit teams to drive enterprise security initiatives.\nSupport IAM and secrets management transformation initiatives across hybrid and multi-cloud environments.\nDefine migration strategies, implementation roadmaps, and adoption plans for enterprise secrets and IAM capabilities.\nEstablish dashboards and metrics covering secrets compliance, IAM access hygiene, credential rotation, onboarding progress, exceptions, and risk reduction.\nSupport secret scanning and remediation initiatives across source code repositories and development environments.\nPromote DevSecOps practices and secure-by-design principles across development and engineering teams.\nCollaborate with development teams across India, the UK, and Dalian to drive consistent security practices and implementation standards.\nProvide technical guidance on CyberArk PAM, HashiCorp Vault Enterprise, machine identity, certificate lifecycle management, and dynamic secrets.\nDrive continuous improvement of enterprise IAM, secrets management, privileged access, and cloud security controls.\n Bachelor’s or master’s degree in computer science, Information Technology, or a related field.","description_format":"text","description_chars":5964,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[{"language":"English","level":"All levels","optional":false}]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["IT Consulting & Digital Transformation","IT Outsourcing & Dedicated Teams","Custom Software Development","Cloud Consulting & Migration"],"lifecycle":[{"event":"open","at":"2026-10-07T06:49:09Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":23,"reasons":["conf:2","win:early","comp:brand"],"computed_at":"2026-10-08T01:40:25Z"},"pay":null,"html_url":"https://alion.io/job/nagarro-senior-staff-engineer-devops-7","json_url":"https://alion.io/job/nagarro-senior-staff-engineer-devops-7.json","meta":{"generated_at":"2026-10-08T01:40:25Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2911,"day_limit":5000,"remaining_today":2089,"minute_limit":60,"resets_at":"2026-10-09T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2457},"rest":"https://alion.io/mcp/rest/get_company?id=2457"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fnagarro-senior-staff-engineer-devops-7"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fnagarro-senior-staff-engineer-devops-7"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fnagarro-senior-staff-engineer-devops-7"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/nagarro-senior-staff-engineer-devops-7\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fnagarro-senior-staff-engineer-devops-7"}]}