Okta

Staff Product Security Engineer

Okta$161K — $221K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of information security experience, focusing on application security, offensive research, or AI/ML security.
  • Hands-on experience assessing real vulnerabilities in LLM-integrated systems and agentic AI architectures.
  • Advanced threat modeling, manual code review, and penetration testing skills for complex distributed systems.
  • Strong communication skills for both technical and non-technical audiences, with a record of producing external security research.
  • Proficiency in at least two programming languages, including Python and one from Go, Java, TypeScript, or C/C++.

Responsibilities

  • Conduct offensive security research on agentic AI systems and related attack vectors.
  • Perform security assessments for Okta's AI platforms, ensuring robust defense measures.
  • Build security tooling to enhance the capabilities of the Product Security team.
  • Design and manage evaluations of AI security vendors and tools.
  • Review code for AI and agent-based systems across various programming languages.
  • Develop threat models for complex agentic architectures and orchestration layers.
  • Translate research findings into practical guidance for engineering teams.

Benefits

  • Flexible work environment with remote and hybrid options.
  • Comprehensive health, dental, and vision insurance.
  • 401(k) plan with company match.
  • Paid time off including parental leave.
  • Supportive onboarding experience to enhance team integration.
Full Job Description
The Staff Product Security Engineer Opportunity

The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers.

The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale.

This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOTA frontier models and fine-tuning open-weight models to building production-grade security tooling across Product Security. While a main focus will be on creating intelligent, automated security capabilities that keep Okta continuously ahead of emerging threats, performing full security reviews of Okta's products, as well as agentic architectures and internal AI pipelines, to uncover, exploit and fix vulnerabilities is also part of the work.

The ideal candidate thinks creatively but also like an attacker, builds like an engineer, and publishes their findings. We actively support external research disclosure through white papers, blog posts, and conference presentations.

What You Will Do
  • Lead technical capability research evaluating frontier LLMs and customized open-weight models for advanced code analysis, autonomous attack and logical security reasoning.
  • Engineer production-grade, AI-assisted security tools that automate vulnerability discovery, triaging, and risk validation across codebases.
  • Architect context-aware code-repair engines that automatically recommend verified security fixes to software development teams.
  • Build automated Proof-of-Concept (PoC) exploit generators in sandboxed runtimes to safely perform root cause analysis on identified vulnerabilities.
  • Modify and fine-tune open-source models to carry out domain-specific defensive and offensive code analysis tasks.
  • Embed AI models, unified APIs, and model-agnostic execution frameworks across Product Security tools to multiply team capabilities.
  • Assess and secure internal AI platforms, agentic execution runtimes, and AI coding agent container environments.
  • Perform manual code review and AI-assisted deep dives of Okta's products and system implementations across multiple languages.
  • Develop threat models for agentic architectures, orchestration layers, and LLM-integrated services.
  • Deliver technical reference blueprints and publish external research demonstrating how AI models transform modern security engineering.
  • Run the AI security vendor and tooling evaluation program: design and operate a benchmarking harness against AI security tools.
  • Conduct offensive security research focused on agentic AI systems: prompt injection, agent privilege escalation, tool-binding abuse, and agentic supply chain attacks against internal developer platforms.
  • Translate research findings into actionable guidance for engineering teams building AI-powered features and platforms.


What You Bring
  • 8+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security.
  • Experience building security tooling and automation (scripts, scanners, detection logic, or evaluation harnesses) that other engineers actually use.
  • Strong offensive mindset: the ability to model what an adversary does to break systems and how this translates to an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete.
  • Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures, not just familiarity with the concepts, but evidence of having found real vulnerabilities in them.
  • Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++).
  • Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems.
  • Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks.
  • Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues.
  • Experience producing external security research, publications, conference talks, blog posts, or open-source tooling.


Desired Skills and Abilities
  • Experience in vulnerability research and vulnerability discovery through source code auditing, as well as penetration testing skills.
  • Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures).
  • Experience with SAST, DAST, SCA, and fuzzing tooling applied to AI/ML pipelines or CI/CD systems.
  • Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws.
  • Ability to develop proof-of-concept exploits that demonstrate vulnerabilities to engineering and product leadership. Plus, if able to exploit AI/Agentic-specific vulnerabilities
  • Experience contributing to security standards, SDL processes, or vulnerability research programs.


#LI-SM1

#LI-Hybrid
#LI-Remote



The annual base salary range for this position for candidates located in the San Francisco Bay area is between:

$180,000-$247,000 USD

Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.

The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between:

$161,000-$221,000 USD

The Okta Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

About Okta

Okta is a leading provider of identity and access management solutions for enterprises. The company's cloud-based platform enables organizations to securely connect people and technology, providing secure access to applications and data from any device, anywhere, at any time. Okta's solutions are used by thousands of organizations worldwide, including many Fortune 500 companies. The company was founded in 2009 and is headquartered in San Francisco, California. Okta is committed to providing innovative solutions that help organizations stay secure and productive in today's digital world.
Learn more about Okta
Size
5,342 employees
Market Cap
$10.5 billion
Industry
Net Income
-$266.3 million
Founded
2009
5 Year Trend
+51.9%
Revenue
$835.4 million
NASDAQ

Similar Jobs

More Jobs at Okta

More Information Technology Jobs

Find similar Staff Product Security Engineer jobs: