Skip to content

Staff Product Security Engineer

141k – 248kBellevue, WAChicago, ILNew York, NYSan Francisco, CASecurity EngineeringHybrid7+ YOE
Summary

Staff-level product security engineer leading security reviews, threat modeling, penetration testing, and LLM/AI security assessments for Okta's identity platform. Requires deep manual security expertise and strong communication skills.

About the role

What You Will Do

  • Conduct security reviews, including design reviews, threat modeling, and penetration testing of new features and major changes.
  • Perform manual secure code reviews across multiple programming languages.
  • Identify and mitigate security vulnerabilities, providing clear guidance to engineering teams.
  • Lead product security incidents, assess risks, and drive remediation efforts.
  • Develop security tools and automation to improve vulnerability detection and assessment.
  • Mentor junior engineers and provide guidance to non-security staff on secure development practices.
  • Represent Okta externally through security research, conference talks, and publications.

What You Bring

  • Expertise in identifying OWASP Top 10 / CWE Top 25 vulnerabilities through manual code review.
  • Strong experience in penetration testing and secure development practices.
  • Deep technical background in assessing Large Language Models (LLMs) and securing AI-integrated software architectures.
  • Proficiency in multiple programming languages (e.g., Java, Go, Python, C/C++).
  • Deep understanding of authentication & authorization protocols (OIDC, SAML, OAuth).
  • Strong communication skills to explain risks and remediation to developers and leadership.
  • Ability to automate security testing using LLMs and scripting (Python, Bash, etc.).
  • Experience leading security incidents and risk assessments.

Desired Skills and Abilities

  • Experience in mobile (iOS/Android) and desktop (Windows/macOS) security testing.
  • Familiarity with SAST, DAST, SCA, and fuzzing tools.
  • Strong cryptographic knowledge and secure implementation practices.
  • Experience analyzing network protocols and traffic security.
  • Ability to develop proof-of-concept exploits to demonstrate vulnerabilities.
Skills
Penetration TestingThreat ModelingSecure Code ReviewOWASP Top 10SAMLOAuthOIDCPythonJavaGoC/C++LLM SecuritySASTDASTCryptography
Similar roles at this salary range
All Security Engineering jobs →
Novig

Security Engineer

Build and maintain security automation pipelines, AI agents, SOAR/SIEM integrations, vulnerability management, and IAM systems for a sports prediction market platform.

150k – 200kNew York, NYSecurity EngineeringOn-site5+ YOECDKIAM
Metropolis

Security Engineer II

Security Engineer II responsible for monitoring and responding to security alerts, administering enterprise security tools, supporting vulnerability and IAM programs, and securing cloud environments. Requires 3+ years in cybersecurity or related fields and scripting experience.

115k – 160kNew York, NYSecurity EngineeringOn-site3+ YOEAWSmacOS
Fable Security

Head of IT & Information Security

Lead security, compliance, and IT functions including SOC 2, ISO 27001, privacy, risk management, and external industry presence. Requires 7+ years in security/compliance/IT with direct experience leading compliance programs.

160k – 225kUnited StatesSecurity EngineeringRemote7+ YOEGDPRSOC 2
Grow Therapy

Senior Engineer, Security

Senior Security Engineer owning data security infrastructure including classification, masking, encryption, and AI data pipelines. Hands-on builder who defines and executes the data protection roadmap.

152k – 250kNew York, NY +2Security EngineeringRemote5+ YOEEncryptionData Masking
Cribl

Staff Security Operations Engineer

Lead security operations and threat detection engineering for a remote-first telemetry platform company. Design detection logic, manage incidents, and optimize SIEM/EDR tooling.

128k – 200kUnited StatesSecurity EngineeringRemote7+ YOEEDRKQL