# Principal Forward Deployed Engineer

**Company:** [Okta](https://hotfix.jobs/companies/okta)
**Location:** Unspecified
**Role:** Solutions Architecture
**Experience:** 7+ years
**Skills:** Oauth 2.0, OIDC, SAML, SCIM, Python, Mcp, Rebac, Abac, Opa, Cedar, Openfga, LangChain, Crewai, Openai Agents Sdk, Github Copilot
**Posted:** 2026-07-31

> Embeds with strategic enterprise customers to architect, build, and deploy secure AI-agent identity solutions from prototype through production. The role requires 7+ years of production software engineering experience, deep identity and authorization expertise, hands-on AI integration skills, and strong executive-facing communication.

## Job Description

## Responsibilities

- Become the customer’s trusted technical voice on agent security through standups, design reviews, incident reviews, architecture review boards, and security councils.
- Architect and deploy Okta’s agent security stack—including Cross-App Access (XAA), Fine-Grained Authorization (FGA), MCP Gateway, and agent client registration—within customer infrastructure.
- Own identity, delegation, audit, and kill-switch architecture end to end, and coach customer engineers on implementation patterns.
- Brief CISOs, CIOs, identity leaders, Chief AI Officers, and principal architects on agent risk and AI governance architecture.
- Deliver production deployments with identity coverage, completed security reviews, governance compliance, and posture visibility.
- Align architecture with OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS, and applicable HIPAA, FedRAMP, or SOC 2 requirements.
- Integrate Okta for AI Agents with identity providers, IGA, ISPM, SIEM, EDR, and runtime policy engines.
- Build evaluations and observability for authorization latency, scope sprawl, delegation anomalies, audit completeness, kill-switch verification, and rogue-agent detection.
- Convert recurring field patterns into reusable modules and product roadmap improvements.
- Maintain regular onsite presence at customer locations and travel internationally up to 35%.

## Requirements

- 7+ years shipping production software, with current hands-on development, on-call experience, and operational maturity in high-throughput authentication and authorization systems.
- Experience with OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD, DCR, and DPoP.
- Working knowledge of OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS.
- Familiarity with Python, MCP, A2A, ISO/IEC 42001, and the EU AI Act.
- Experience mapping deployments to HIPAA, FedRAMP, and SOC 2.
- Experience with ReBAC and ABAC using policy engines such as OPA, Cedar, or OpenFGA.
- Understanding of how agents acquire tokens, call APIs, and delegate.
- Production integration experience with Claude, ChatGPT, Microsoft Copilot, Agentforce, Bedrock, LangChain, CrewAI, the OpenAI Agents SDK, or MCP servers.
- Daily use of AI-native development tools such as Claude Code, Cursor, or GitHub Copilot.
- Ability to work effectively in customer standups and executive security briefings.
- High agency and an end-to-end ownership mindset.
- Ability to travel internationally on occasion, up to 35%.

## Similar jobs

- [Principal Solutions Architect, APJC - Mandarin Speaking](https://hotfix.jobs/jobs/41663a48-cd6e-471f-bd55-1767288e5f1d) - Cloudflare
- [Principal Services Solution Manager](https://hotfix.jobs/jobs/38ceb359-19c1-408f-a26c-6918ae41c025) - Snowflake - Remote - $157k – $206k/yr
- [Principal Services Solutions Manager - Federal](https://hotfix.jobs/jobs/669f8430-6718-4ce0-9a99-8e2a3ea6f341) - Snowflake - Remote - $184k – $242k/yr
- [Director of Solutions Architecture](https://hotfix.jobs/jobs/f7276fd1-306a-453f-b1cd-d6c25c5e659f) - Clickhouse - Remote
- [Senior Director, Solutions Architecture, APAC](https://hotfix.jobs/jobs/d8134d67-639e-41ed-95c2-b1d572b09144) - Cohere - Remote

**Apply:** https://hotfix.jobs/jobs/dbddc61a-429e-4974-bd5c-bc34329c7ae5
**Canonical:** https://hotfix.jobs/jobs/dbddc61a-429e-4974-bd5c-bc34329c7ae5