# Staff Product Security Engineer, PSIRT

**Company:** [Okta](https://hotfix.jobs/companies/okta)
**Location:** Barcelona, Spain
**Role:** Security Engineering
**Salary:** €74k – €101k/yr
**Experience:** 7+ years
**Skills:** Product Security, Application Security, Vulnerability Management, Security Operations, Security Code Review, Incident Response, Risk Management, Bug Bounty, Security Disclosure, Incident Management, Log Management, Technical Writing
**Posted:** 2026-07-31

> Leads Okta’s product security incident response and disclosure programs, including bug bounty operations, vulnerability triage, remediation coordination, and stakeholder communication. Requires 6+ years in information security with experience in product or application security, code review, incident response, and risk management.

## Job Description

## Responsibilities
- Define, improve, formalize, and implement Okta’s Product Security Incident Response Program across products and business units.
- Operate the bug bounty program, including researcher engagement, vulnerability triage and validation, severity assessment, remediation coordination, reward recommendations, and process improvements.
- Oversee the lifecycle from vulnerability discovery through resolution, including triage, impact assessment, engineering coordination, fix validation, and timely stakeholder communication.
- Lead the security disclosure program from triage through disclosure.
- Report on program health and activity status.
- Collaborate with internal teams to improve vulnerability and risk workflows, governance, and communication.
- Work cross-functionally with Engineering, IT, Product, Legal, and Security teams.
- Mentor junior engineers on incident response procedures, technical investigations, and vulnerability remediation.
- Partner with leadership on proactive threat detection and vulnerability management.

## Requirements
- 6+ years of experience in information security, focused on Product Security, Application Security, Vulnerability Management, and Security Operations.
- Experience conducting comprehensive security code reviews to identify vulnerabilities and code flaws.
- Experience with application security vulnerabilities.
- Experience with product security concepts.
- Experience with risk management.
- Experience handling incident response for product-related issues.
- Knowledge of incident and log management tools.
- Excellent communication and collaboration skills, including technical writing, process documentation, and executive presentations.

## Compensation and Benefits
- Annual base salary for candidates located in Spain: €74,000–€101,000 EUR.
- Equity, where applicable, bonus, comprehensive healthcare coverage, paid time off, and parental leave in accordance with applicable plans and policies.

## Similar jobs

- [Senior Security Engineer, Offensive Security](https://hotfix.jobs/jobs/e6f5289c-9cb8-4a13-b321-e0ecc9a54c96) - Docker - Remote - €119k – €170k/yr
- [Senior Security GRC Analyst](https://hotfix.jobs/jobs/b54fb115-3bb7-4d88-8fdc-b7901d26d90d) - Monarch - Remote - $180k – $215k/yr
- [Lead Product GRC Subject Matter Expert](https://hotfix.jobs/jobs/57c937d5-05e3-4033-875a-890645c4aa6b) - Vanta - Remote - $230k – $270k/yr
- [Security Engineer - Product](https://hotfix.jobs/jobs/d32dc9fa-f31b-4fc4-a7c6-eade39acfb64) - Wiz - Berlin, Germany
- [Manager, Security Operations](https://hotfix.jobs/jobs/0a4637da-6072-4ec3-a0a9-8b6d4a412d45) - Vanta - Remote - $178k – $209k/yr

**Apply:** https://hotfix.jobs/jobs/8df9ad33-edd9-489d-a30f-a4ce385438cf
**Canonical:** https://hotfix.jobs/jobs/8df9ad33-edd9-489d-a30f-a4ce385438cf