{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/api-key-management"},"x-facet":{"type":"skill","slug":"api-key-management","display":"Api Key Management","count":2},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_affa7659-e53"},"title":"Senior AEM DevSecOps Engineer","description":"<p>Secure Every Identity, from AI to Human</p>\n<p>Identity is the key to unlocking the potential of AI. As an AEM DevSecOps Engineer at Okta, you will oversee and automate our AEM infrastructure with a primary focus on security, reliability, and automated compliance.</p>\n<p>Key Responsibilities:</p>\n<ul>\n<li>Identity &amp; Access Management: Configure and manage Auth0 integrations for AEM, including token validation, OIDC/SAML configurations, and custom login modules to ensure secure user authentication.</li>\n</ul>\n<ul>\n<li>Headless Security: Oversee the security of AEM Headless deployments, including protecting GraphQL endpoints, managing CORS policies, and ensuring secure communication for decoupled front-end frameworks (React/Angular).</li>\n</ul>\n<ul>\n<li>Edge &amp; CDN Protection: Manage and configure CDN (e.g., Cloudflare, Akamai, or Adobe-managed CDN) to optimize performance and implement DDoS mitigation strategies.</li>\n</ul>\n<ul>\n<li>Traffic Filtering: Implement and maintain Traffic Filter Rules and Web Application Firewall (WAF) configurations at the CDN level to block malicious spikes and sophisticated application-layer attacks.</li>\n</ul>\n<ul>\n<li>Automated Security Scanning: Integrate security tools (SAST/DAST) and secrets detection into CI/CD pipelines (Jenkins, GitLab) to identify vulnerabilities early in the development cycle.</li>\n</ul>\n<ul>\n<li>Environment Hardening: Install and manage AEM author, publish, and dispatcher instances with a focus on Dispatcher security hardening, SSL certificate automation, and ModSecurity configurations.</li>\n</ul>\n<ul>\n<li>Observability &amp; Incident Response: Monitor system performance and security logs using tools like Splunk or New Relic to proactively address threats and performance bottlenecks.</li>\n</ul>\n<ul>\n<li>Compliance Auditing: Regularly audit the platform and its integrations (Adobe Analytics, Target) to ensure alignment with corporate security policies and industry standards.</li>\n</ul>\n<p>Required Skills &amp; Experience:</p>\n<ul>\n<li>Experience: 5+ years in administering and securing AEM environments.</li>\n</ul>\n<ul>\n<li>Identity Services: Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication.</li>\n</ul>\n<ul>\n<li>Architectural Knowledge: Strong understanding of Headless CMS security best practices, including API key management and JWT authentication.</li>\n</ul>\n<ul>\n<li>Network Security: Expertise in managing CDNs and implementing DDoS mitigation and WAF rules.</li>\n</ul>\n<ul>\n<li>Technical Stack: Proficiency in Apache Sling, JCR, OSGi, and web servers like Nginx or Apache.</li>\n</ul>\n<ul>\n<li>Automation: Hands-on experience with scripting (Python) and CI/CD tools (Jenkins, CircleCI) to automate security and deployment workflows.</li>\n</ul>\n<ul>\n<li>Cloud Experience: Experience with cloud-based AEM implementations, such as AEM as a Cloud Service (AEMaaCS) or AWS/Azure.</li>\n</ul>\n<ul>\n<li>Diagnostic Skills: Proficiency in analyzing log files, thread dumps, and heap dumps to resolve security incidents or performance outages.</li>\n</ul>\n<p>The Okta Experience</p>\n<ul>\n<li>Supporting Your Well-Being</li>\n</ul>\n<ul>\n<li>Driving Social Impact</li>\n</ul>\n<ul>\n<li>Developing Talent and Fostering Connection + Community</li>\n</ul>\n<p>We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_affa7659-e53","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7688701","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["Experience in administering and securing AEM environments","Identity Services: Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication","Architectural Knowledge: Strong understanding of Headless CMS security best practices, including API key management and JWT authentication","Network Security: Expertise in managing CDNs and implementing DDoS mitigation and WAF rules","Technical Stack: Proficiency in Apache Sling, JCR, OSGi, and web servers like Nginx or Apache"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:45:10.099Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Poland"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"Experience in administering and securing AEM environments, Identity Services: Proven experience integrating Auth0 or similar Identity Providers (IdP) for enterprise-scale authentication, Architectural Knowledge: Strong understanding of Headless CMS security best practices, including API key management and JWT authentication, Network Security: Expertise in managing CDNs and implementing DDoS mitigation and WAF rules, Technical Stack: Proficiency in Apache Sling, JCR, OSGi, and web servers like Nginx or Apache"},{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_68e291fb-412"},"title":"Senior Security Engineer","description":"<p>Talent Wanted. For hazardous journey. Small wages, bitter cold, long months of complete darkness, constant danger, safe return doubtful. Honour and recognition in case of success.</p>\n<p>Fridtjof Nansen crossed the Arctic, going places no human had ever been. Together with our users, we&#39;re doing the same onchain , and someone needs to make sure we don&#39;t get killed on the way there.</p>\n<p>We&#39;re building the single best platform for onchain investing , agentic trading, staking infrastructure, AI-powered analytics , and we&#39;re scaling fast. Fast enough that security can&#39;t be an afterthought bolted on later. It has to be built in, from the start, by someone who knows what they&#39;re doing.</p>\n<p><strong>Our mission:</strong></p>\n<p>Surface the signal and create winners.</p>\n<p><strong>What you&#39;ll do at Nansen</strong></p>\n<p>You&#39;ll be the person who makes sure we can move fast without breaking things that matter. That means embedding security into everything we build , cloud infrastructure, applications, CI/CD pipelines, AI systems, staking operations , across a generalist role that spans the full surface area.</p>\n<ul>\n<li>Run security assessments across systems, architectures, and code , find the vulnerabilities before someone else does</li>\n<li>Advise engineering teams on secure design decisions. You&#39;re a partner, not a blocker</li>\n<li>Deploy and maintain security infrastructure: SIEM, vulnerability scanning, endpoint protection, logging , the things that let us sleep at night</li>\n<li>Secure our CI/CD pipelines and deployment workflows end-to-end</li>\n<li>Own secrets management, key management, and access controls. No shortcuts</li>\n<li>Address LLM security head-on: API key management, prompt injection prevention, and the risks that come with shipping AI-powered products at speed</li>\n<li>Coordinate penetration tests and security audits with external vendors</li>\n<li>Create and maintain secure coding guidelines and code review processes that engineers actually follow</li>\n<li>Represent the Security Team in the incident response process</li>\n<li>Drive compliance readiness , SOC 2, ISO 27001 , pragmatically, not bureaucratically</li>\n</ul>\n<p><strong>What we&#39;re looking for</strong></p>\n<ul>\n<li>You&#39;ve built and hardened production security at scale , you know the difference between a policy document and an actually secure system</li>\n<li>Strong cloud security knowledge (AWS, GCP or equivalent). Container security and network security fundamentals</li>\n<li>Hands-on experience implementing security tooling, not just evaluating it</li>\n<li>Secrets and key management expertise , you&#39;ve managed this at a company where it actually mattered</li>\n<li>You understand the security implications of AI/LLM and agent-based systems. This is new territory and we need someone thinking about it seriously</li>\n<li>CI/CD pipeline security is second nature</li>\n<li>Pragmatic about compliance , you can get us to SOC 2 without drowning the engineering team in process</li>\n<li>You don&#39;t just use AI as a tool. You think with it. AI-first isn&#39;t a checkbox , it&#39;s how you work</li>\n<li>Strong async communication skills , we&#39;re remote-first, Slack-and-docs-heavy, and EMEA hours are preferred for team overlap</li>\n<li>Bonus: blockchain, smart contract, or staking infrastructure security experience. Kubernetes and Terraform security. Incident response or security operations background</li>\n</ul>\n<p><strong>What we offer our crew</strong></p>\n<ul>\n<li>Competitive salary. Meaningful equity. Real ownership in what you build</li>\n<li>Fully remote with two no-meeting days a week , because deep work doesn&#39;t happen in a Google Meet</li>\n<li>Annual company retreat and team off-sites in one of our offices: Singapore, Bangkok, London, and Oslo , flights and accommodation covered</li>\n<li>Unlimited AI tokens , Claude, OpenAI, whatever helps you move fast</li>\n<li>Your own OpenClaw for work</li>\n<li>Nansen Pro account: giving you full access to the most detailed onchain data in the market</li>\n<li>A team that started as data engineers and data scientists that has grown to over 80 builders. Your craft is respected here.</li>\n<li>Speed, ownership, curiosity, courage. These aren&#39;t values on a wall , they&#39;re how we run.</li>\n<li>A front-row seat (and a hand in building) the next chapter of finance</li>\n</ul>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_68e291fb-412","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Nansen","sameAs":"https://nansen.ai/","logo":"https://logos.yubhub.co/nansen.ai.png"},"x-apply-url":"https://job-boards.greenhouse.io/nansen/jobs/5811520004","x-work-arrangement":"remote","x-experience-level":"senior","x-job-type":"full-time","x-salary-range":null,"x-skills-required":["cloud security","container security","network security","security tooling","secrets management","key management","access controls","API key management","prompt injection prevention","LLM security","CI/CD pipeline security","compliance","SOC 2","ISO 27001"],"x-skills-preferred":["blockchain security","smart contract security","staking infrastructure security","Kubernetes security","Terraform security","incident response","security operations"],"datePosted":"2026-04-17T12:47:56.366Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote Europe | Remote Asia"}},"jobLocationType":"TELECOMMUTE","employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"cloud security, container security, network security, security tooling, secrets management, key management, access controls, API key management, prompt injection prevention, LLM security, CI/CD pipeline security, compliance, SOC 2, ISO 27001, blockchain security, smart contract security, staking infrastructure security, Kubernetes security, Terraform security, incident response, security operations"}]}