Okta

Senior Forward Deployed Engineer

Okta$200K — $275K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in production software engineering with a hands-on role in IDEs.
  • Deep understanding of identity protocols including OAuth 2.0, OIDC, SAML, and SCIM.
  • Familiarity with agent security frameworks like OWASP Top 10 for Agentic Applications and HIPAA compliance.
  • Experience with fine-grained authorization techniques such as ReBAC and ABAC, and policy engines like OPA and Cedar.
  • Practical experience building AI integrations with platforms such as ChatGPT, Microsoft Copilot, and LangChain.
  • Ability to effectively communicate at all levels, from customer standups to CISO briefings.
  • Self-motivated with a strong founder's mindset, capable of driving initiatives from concept to execution.

Responsibilities

  • Act as the trusted technical voice for customers regarding agent security, participating in design reviews and incident responses.
  • Architect and integrate Okta's security solutions into customer infrastructure, leading the deployment process.
  • Engage and brief senior leadership on security decisions and architecture, translating technical workflows into business-critical risks.
  • Oversee seamless deployment of agents, ensuring full compliance with security and governance standards.
  • Align architectural choices with best practices and industry regulations, providing defensible deployment strategies.
  • Integrate Okta's solutions with various customer platforms to enhance agent lifecycle management and security posture.
  • Transform field insights into product solutions, addressing common gaps faced by users and enhancing service delivery.

Benefits

  • Health, dental, and vision insurance.
  • 401(k) with company contributions.
  • Flexible spending accounts.
  • Paid time off, including parental leave.
  • Equity options and performance bonuses.
Full Job Description
The Role

You embed inside four to five of Okta's most strategic enterprise customers as their dedicated technical partner for agent identity. You sit alongside their identity, platform, and security engineering teams, write production code in their environment, and own the technical outcome from prototype through production.

You are a builder-consultant. You go past architecture diagrams to code, debug, and ship bespoke agent identity solutions inside the customer's environment. You ship secure agents faster for the customer, and you feed real field insight back to Okta product engineering.
Responsibilities
  • Become the customer's trusted technical voice on agent security. Sit in their standups, design reviews, and incident response. Earn a seat on their architecture review board and security council for agent risk decisions.
  • Architect and deploy with the customer's team. Build Okta's agent security stack into their infrastructure: Cross-App Access (XAA), Fine-Grained Authorization (FGA), MCP Gateway, and agent client registration. Own the identity, delegation, audit, and kill-switch architecture end to end, and coach their engineers on the patterns.
  • Engage senior leadership. Brief the CISO, CIO, identity leaders, Chief AI Officer, and principal architects. Translate token-exchange flows into board-level agent risk, and AI governance mandates into architecture.
  • Deliver white-glove deployment. Agents in production with full identity coverage, security review passed, governance requirements met, and posture visibility online. The customer points to you as the reason their agent program is real.
  • Keep deployments defensible. Align architecture decisions to OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS, and to HIPAA, FedRAMP, or SOC 2 where the customer is regulated.
  • Wire Okta into the customer's stack. Connect O4AA to their IdP for human-to-agent links, IGA for agent lifecycle, ISPM for posture, SIEM and EDR for behavior coverage, and policy engines for runtime decisions.
  • Build evals and observability. Authorization decision latency, scope sprawl across agents, anomalous delegation chains, audit completeness, kill-switch verification, and rogue agent detection.
  • Turn field patterns into product. Extract the recurring gaps from their architects and governance leads, and convert them into reusable modules and roadmap fixes that ship for every other customer.
  • Be on site. Regular presence at customer locations. Trust and governance alignment happen in the room.
Requirements
  • Engineering pedigree. 7+ years shipping production software, still hands-on in the IDE, with on-call experience and operational maturity in systems that authenticate and authorize at high throughput.
  • Identity protocols. OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD and DCR, DPoP.
  • Agent security frameworks. Working knowledge of OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS. Familiarity with MCP, A2A, ISO/IEC 42001, and the EU AI Act. Comfortable mapping deployments to HIPAA, FedRAMP, and SOC 2.
  • Fine-grained authorization. ReBAC and ABAC with policy engines (OPA, Cedar, OpenFGA, or equivalent), and a working understanding of how agents acquire tokens, call APIs, and delegate.
  • AI hands-on. Built production integrations with Claude, ChatGPT, Microsoft Copilot, Agentforce, Bedrock, LangChain, CrewAI, the OpenAI Agents SDK, or MCP servers.
  • AI-native development. Daily use of Claude Code, Cursor, GitHub Copilot, or equivalent.
  • Customer-facing range. At home in a customer standup and a CISO briefing on the same day. You build trust with senior engineering leaders and you stay in the room when their internal politics get sharp.
  • High agency, founder's mindset. A zero-to-one self-starter who owns outcomes end to end.

#LI-Remote



Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.

The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between:

$200,000-$275,000 USD

The Okta Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

About Okta

Okta is a leading provider of identity and access management solutions for enterprises. The company's cloud-based platform enables organizations to securely connect people and technology, providing secure access to applications and data from any device, anywhere, at any time. Okta's solutions are used by thousands of organizations worldwide, including many Fortune 500 companies. The company was founded in 2009 and is headquartered in San Francisco, California. Okta is committed to providing innovative solutions that help organizations stay secure and productive in today's digital world.
Learn more about Okta
Size
5,342 employees
Market Cap
$10.5 billion
Industry
Net Income
-$266.3 million
Founded
2009
5 Year Trend
+51.9%
Revenue
$835.4 million
NASDAQ

Similar Jobs

More Jobs at Okta

More Enterprise Technology Jobs

Find similar Senior Forward Deployed Engineer jobs: