Staff Product Security Engineer
Staff-level product security engineer leading security reviews, threat modeling, penetration testing, and LLM/AI security assessments for Okta's identity platform. Requires deep manual security expertise and strong communication skills.
About the job
What You Will Do
- Conduct security reviews, including design reviews, threat modeling, and penetration testing of new features and major changes.
- Perform manual secure code reviews across multiple programming languages.
- Identify and mitigate security vulnerabilities, providing clear guidance to engineering teams.
- Lead product security incidents, assess risks, and drive remediation efforts.
- Develop security tools and automation to improve vulnerability detection and assessment.
- Mentor junior engineers and provide guidance to non-security staff on secure development practices.
- Represent Okta externally through security research, conference talks, and publications.
What You Bring
- Expertise in identifying OWASP Top 10 / CWE Top 25 vulnerabilities through manual code review.
- Strong experience in penetration testing and secure development practices.
- Deep technical background in assessing Large Language Models (LLMs) and securing AI-integrated software architectures.
- Proficiency in multiple programming languages (e.g., Java, Go, Python, C/C++).
- Deep understanding of authentication & authorization protocols (OIDC, SAML, OAuth).
- Strong communication skills to explain risks and remediation to developers and leadership.
- Ability to automate security testing using LLMs and scripting (Python, Bash, etc.).
- Experience leading security incidents and risk assessments.
Desired Skills and Abilities
- Experience in mobile (iOS/Android) and desktop (Windows/macOS) security testing.
- Familiarity with SAST, DAST, SCA, and fuzzing tools.
- Strong cryptographic knowledge and secure implementation practices.
- Experience analyzing network protocols and traffic security.
- Ability to develop proof-of-concept exploits to demonstrate vulnerabilities.
Skills
Penetration Testing, Threat Modeling, Secure Code Review, Owasp Top 10, SAML, OAuth, OIDC, Python, Java, Go, C/C++, Llm Security, SAST, DAST, Cryptography
Similar jobs
Security Engineering jobsLeads cloud security detection and response engineering, building AI-enabled agents, threat-hunting capabilities, and automated security tooling. Requires deep security expertise, cloud experience, and strong knowledge of SIEM, SOAR, infrastructure as code, and AI threat frameworks.
Leads enterprise AI security architecture and develops security systems, automation, and agentic AI identity strategies at scale. Requires 7+ years in security or infrastructure security, enterprise technical leadership, cloud and container security expertise, and strong programming skills.
Own the architecture and automation of enterprise identity governance, privileged access, and identity security posture programs. The role requires advanced IGA/PAM experience, production RBAC and lifecycle expertise, and the ability to lead technical direction and communicate with executives.
Staff Identity Engineer serving as a technical authority for enterprise IAM, owning Okta architecture, cloud identity guardrails, automation, and AI identity security. Requires deep Okta and authentication-protocol expertise, multi-cloud experience, and technical leadership.
The Staff Information Systems Security Officer will secure and accredit classified information systems by implementing RMF and NIST controls, managing vulnerabilities, supporting audits and incident response, and overseeing Cross Domain Solutions. The role requires 8 years of classified-environment cybersecurity experience and expertise in DoD and IC requirements.