Senior Aem Devsecops Engineer

Okta Okta · Enterprise · Poland · BT Go To Market Technology-173

This role focuses on securing and automating Adobe Experience Manager (AEM) infrastructure, with a strong emphasis on identity and access management, particularly for AI-related initiatives. The engineer will manage AEM environments, Auth0 integrations, headless AEM security, CDN protection, and integrate security scanning into CI/CD pipelines.

What you'd actually do

  1. Configure and manage Auth0 integrations for AEM, including token validation, OIDC/SAML configurations, and custom login modules to ensure secure user authentication.
  2. Oversee the security of AEM Headless deployments, including protecting GraphQL endpoints, managing CORS policies, and ensuring secure communication for decoupled front-end frameworks (React/Angular).
  3. Manage and configure CDN (e.g., Cloudflare, Akamai, or Adobe-managed CDN) to optimize performance and implement DDoS mitigation strategies.
  4. Implement and maintain Traffic Filter Rules and Web Application Firewall (WAF) configurations at the CDN level to block malicious spikes and sophisticated application-layer attacks.
  5. Integrate security tools (SAST/DAST) and secrets detection into CI/CD pipelines (Jenkins, GitLab) to identify vulnerabilities early in the development cycle.

Skills

Required

  • 5+ years in administering and securing AEM environments
  • Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication
  • Strong understanding of Headless CMS security best practices, including API key management and JWT authentication
  • Expertise in managing CDNs and implementing DDoS mitigation and WAF rules
  • Proficiency in Apache Sling, JCR, OSGi, and web servers like Nginx or Apache
  • Hands-on experience with scripting (Python) and CI/CD tools (Jenkins, CircleCI) to automate security and deployment workflows
  • Experience with cloud-based AEM implementations, such as AEM as a Cloud Service (AEMaaCS) or AWS/Azure
  • Proficiency in analyzing log files, thread dumps, and heap dumps to resolve security incidents or performance outages

What the JD emphasized

  • 5+ years in administering and securing AEM environments
  • Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication
  • Expertise in managing CDNs and implementing DDoS mitigation and WAF rules