Skip to content
OktaOkta

Staff Product Security Engineer, PSIRT

Leads Okta’s product security incident response and disclosure programs, including bug bounty operations, vulnerability triage, remediation coordination, and stakeholder communication. Requires 6+ years in information security with experience in product or application security, code review, incident response, and risk management.

About the job

Responsibilities

  • Define, improve, formalize, and implement Okta’s Product Security Incident Response Program across products and business units.
  • Operate the bug bounty program, including researcher engagement, vulnerability triage and validation, severity assessment, remediation coordination, reward recommendations, and process improvements.
  • Oversee the lifecycle from vulnerability discovery through resolution, including triage, impact assessment, engineering coordination, fix validation, and timely stakeholder communication.
  • Lead the security disclosure program from triage through disclosure.
  • Report on program health and activity status.
  • Collaborate with internal teams to improve vulnerability and risk workflows, governance, and communication.
  • Work cross-functionally with Engineering, IT, Product, Legal, and Security teams.
  • Mentor junior engineers on incident response procedures, technical investigations, and vulnerability remediation.
  • Partner with leadership on proactive threat detection and vulnerability management.

Requirements

  • 6+ years of experience in information security, focused on Product Security, Application Security, Vulnerability Management, and Security Operations.
  • Experience conducting comprehensive security code reviews to identify vulnerabilities and code flaws.
  • Experience with application security vulnerabilities.
  • Experience with product security concepts.
  • Experience with risk management.
  • Experience handling incident response for product-related issues.
  • Knowledge of incident and log management tools.
  • Excellent communication and collaboration skills, including technical writing, process documentation, and executive presentations.

Compensation and Benefits

  • Annual base salary for candidates located in Spain: €74,000–€101,000 EUR.
  • Equity, where applicable, bonus, comprehensive healthcare coverage, paid time off, and parental leave in accordance with applicable plans and policies.

Skills

Product Security, Application Security, Vulnerability Management, Security Operations, Security Code Review, Incident Response, Risk Management, Bug Bounty, Security Disclosure, Incident Management, Log Management, Technical Writing

Docker

Docker

United Kingdom
Senior Security Engineer, Offensive Security
€119k+/yrRemote5+ YOESecurity Engineering

Senior offensive security engineer responsible for penetration testing, adversary emulation, exploit development, threat modeling, and security automation across cloud, container, SaaS, and AI/ML systems. Requires at least 3 years of security engineering experience, strong development skills, and hands-on offensive security expertise.

Monarch

Monarch

Remote

Senior Security GRC Analyst
$180k+/yrRemote5+ YOESecurity Engineering

Own and scale security governance, risk, compliance, and customer assurance programs, including audits, controls monitoring, third-party risk, policies, and security questionnaires. The role requires 3–5 years of security GRC experience and hands-on understanding of IAM, endpoint, and cloud controls.

Vanta

Vanta

Remote

Lead Product GRC Subject Matter Expert
$230k+/yrRemote10+ YOESecurity Engineering

Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.

Wiz

Wiz

Berlin, Germany
Security Engineer - Product
No salary listedOn-site7+ YOESecurity Engineering

Security Engineer responsible for threat modeling, security reviews, vulnerability management, cloud and Kubernetes security, and detection and response across products and production infrastructure. Requires 7+ years of cloud security experience and hands-on expertise with IAM, infrastructure as code, automation, and security tooling.

Vanta

Vanta

Remote

Manager, Security Operations
$178k+/yrRemote5+ YOESecurity Engineering

Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.