Senior DevSecOps Engineer
At Experient, we provide experience, technology, and transformation support to our clients, creating a dynamic environment where talented professionals solve complex problems and deliver meaningful results. We value collaboration, effective communication, and practical execution. Our teams work closely with clients to design and deliver modern technology solutions that strengthen security, accelerate delivery, and create lasting business value.
As a Senior DevSecOps Engineer, you will provide technical leadership for the design, implementation, and evolution of secure, automated platforms and engineering practices across a complex enterprise environment. You will lead the integration of security into cloud, infrastructure, application, and DevOps ecosystems while helping establish scalable solutions.
This is a hands-on technical leadership role. You will define architecture, establish engineering standards, guide technical delivery, and partner with security, platform, infrastructure, cloud, and application teams to embed security and automation throughout the technology lifecycle. You will also serve as a trusted technical partner alongside internal stakeholders and external platform vendors and professional services teams.
What You'll Do
- Lead the architecture, design, and implementation of enterprise DevSecOps capabilities with a focus on security automation, platform engineering, PKI, and certificate lifecycle management.
- Develop and drive enterprise standards for secure certificate and key management, including certificate policies, cryptographic standards, key types, validity periods, rotation requirements, and revocation processes.
- Lead the technical migration from multiple Certificate Authorities and certificate management platforms to a modern centralized PKI platform, including Zero Touch PKI and other SaaS-backed CA capabilities.
- Build and oversee scalable automation for certificate provisioning, renewal, discovery, and remediation, reducing manual processes and improving platform reliability.
- Collaborate closely with platform vendors and professional services teams to ensure successful implementation, integration, and adoption of strategic security platforms.
- Identify technical risks, dependencies, and gaps across the environment and develop practical remediation strategies.
- Establish certificate discovery and inventory capabilities using CyberArk Certificate Manager across cloud environments, servers, load balancers, application services, Kubernetes, network devices, and other enterprise technologies.
- Enable secure developer and engineering self-service through APIs, automation, infrastructure-as-code, and integrations with enterprise platforms such as ServiceNow.
- Define and implement monitoring, alerting, and operational controls for certificate expirations, policy violations, integration failures, and other security risks.
- Define the target-state architecture for centralized certificate lifecycle management, including certificate issuance, renewal, revocation, discovery, inventory, monitoring, and policy enforcement.
- Drive security-by-design practices across infrastructure and application delivery, identifying opportunities to automate security controls and reduce operational risk.
- Lead technical delivery by setting architectural direction, breaking complex initiatives into executable work, reviewing technical solutions, and guiding engineers and partner teams.
- Serve as a senior technical advisor to client and business stakeholders, translating complex security and platform requirements into practical, scalable solutions.
What You'll Bring
- 8+ years of experience in DevOps, DevSecOps, Security Engineering, Platform Engineering, or related technical disciplines.
- Hands-on experience with cloud and automation technologies across environments such as AWS, Azure, GCP, Entra, Kubernetes, and infrastructure-as-code platforms.
- Proficiency in at least one scripting or programming language such as Python, Go, PowerShell, or similar.
- Experience managing security certificates.
- Strong experience building integrations through APIs and automating complex enterprise workflows.
- Experience with CI/CD pipelines and modern DevOps practices, with an understanding of how to embed security controls into software and infrastructure delivery.
- Ability to work with third-party vendors for solutions implementations.
- Strong communication and consulting skills with the ability to work effectively with technical teams, business stakeholders, and external partners.
- Experience leading technical delivery: setting architecture, reviewing work, and bringing a team along.
Nice to Have
- Experience with Zero Touch PKI and CyberArk Certificate Manager, formerly Venafi.
- Working knowledge of PKI and the X.509 certificate standard: certificate lifecycle, CAs, chains of trust, key management, and revocation.
- Experience automating certificate inventorying and provisioning across heterogeneous systems (Linux, Windows, AWS, GCP, Entra, IoT devices, Kubernetes, Cloudflare).
- Experience with enterprise PKI modernization or migration from Microsoft ADCS or other legacy Certificate Authority platforms.
- Knowledge of ACME, SCEP, and EST enrollment protocols.
- Experience integrating certificate management into Kubernetes, container platforms, and cloud-native workloads.
- Experience with cloud-native certificate, key, and secrets management services such as AWS ACM, Azure Key Vault, Azure Managed HSM, GCP Certificate Manager, Cloud KMS, or similar technologies.
Experient Group is an Equal Employment Opportunity (EEO) employer and welcomes all qualified applicants. Applicants will receive fair and impartial consideration without regard
#LI - HYBRID