Job Highlights
AI-extracted key information
The Staff Product Security Engineer at Okta is responsible for conducting offensive security research focused on agentic AI systems and performing security assessments of Okta's AI platforms. This role involves building reusable security tooling and running evaluations of AI security vendors and tools to enhance the security posture of the organization.
Salary Range
$180k - $248k/year
Experience Level
Senior Level
Benefits & Perks
Staff Product Security Engineer
Posted 3 days ago
Full-Time
Employment Type
Remote
Work Location
$180,000 - $247,500
per year
About This Role
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.
The Security Team
Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences.
Join our team! We're building a world where Identity belongs to you.
The Staff Product Security Engineer Opportunity
The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers.
The Staff Product Security Engineer joins a team with a single mandate: get ahead of the security risks introduced by agentic systems before they become operational reality at Okta. This is a research and engineering role. The work is long-horizon and adversarial: understanding how prompt injection propagates through an agent with write access to a code repository, how privilege escalation manifests in an orchestration model with dynamic tool bindings, and what an agentic supply-chain attack looks like against an internal developer platform. The findings this team produces shape SDL requirements, feed reusable security tooling across all of Product Security, and drive Okta's AI and agent-based system security approach at the design level.
The ideal candidate thinks like an attacker, builds like an engineer, and publishes their findings. We actively support external research disclosure through white papers, blog posts, and conference presentations.
What You Will Do
Conduct offensive security research focused on agentic AI systems: prompt injection, agent privilege escalation, tool-binding abuse, and agentic supply chain attacks against internal developer platforms.
Perform security assessments of Okta's AI platforms—including agentic systems and LLM-integrated products—across design, code, and runtime.
Build reusable security tooling that multiplies the entire Product Security team's capability.
Run the AI security vendor and tooling evaluation program: design and operate a benchmarking harness against AI security tools.
Perform manual code review of AI and agent-based system implementations across multiple languages.
Develop threat models for agentic architectures, orchestration layers, and LLM-integrated services.
Translate research findings into actionable guidance for engineering teams building AI-powered features and platforms.
Represent Okta externally through security research, conference presentations, white papers, and publications.
Mentor engineers across Product Security on AI/agentic security concepts, tooling, and assessment methodology.
What You Bring
7+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security.
Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures—not just familiarity with the concepts, but evidence of having found real vulnerabilities in them.
Strong offensive mindset: the ability to model what an adversary does with an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete.
Experience building security tooling and automation—scripts, scanners, detection logic, or evaluation harnesses—that other engineers actually use.
Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++).
Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems.
Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks.
Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues.
Experience Producing External Security Research—publications, Conference Talks, Blog Posts, Or Open-source Tooling.
Desired Skills And Abilities
Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures).
Experience With Sast, Dast, Sca, And Fuzzing Tooling Applied To Ai/ml Pipelines Or Ci/cd Systems.
Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws.
Ability to develop proof-of-concept exploits that demonstrate AI/agentic vulnerabilities to engineering and product leadership.
Experience Contributing To Security Standards, Sdl Processes, Or Vulnerability Research Programs.
1
P25264_3461996
Below is the annual base salary range for candidates located in San Francisco Bay Area. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit:
https://rewards.okta.com/us
.
The annual base salary range for this position for candidates located in the San Francisco Bay area is between:
$180,000
—
$247,500 USD
The Okta Experience
Supporting Your Well-Being
Driving Social Impact
Developing Talent and Fostering Connection + Community
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please
use this Form
to request an accommodation.
Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please
click here
to view our full NYC AEDT Notice.
Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Personnel and Job Candidate Privacy Notice at
https://www.okta.com/legal/personnel-policy/
.
Compensation
$180,000 - $247,500
Annual salary
Ready to Apply?
Click the button below to submit your application directly to Okta. Make sure your resume is up to date and highlights relevant experience for this role.
Apply Now at OktaApply to Multiple Jobs with AI
Let our AI automatically apply to hundreds of remote jobs on your behalf. Just upload your resume and set your preferences.
500+
Jobs Applied
24/7
Auto-Apply
5 min
Setup Time
You Might Also Like
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of th...
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of th...
About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what’s next. For more than a decade, Vercel has shaped h...
