Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Product Security Engineer

$180k - $247.5k

Okta

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Security Team

Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth.

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences.

Join our team! We're building a world where Identity belongs to you.

The Staff Product Security Engineer Opportunity

The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers.

The Staff Product Security Engineer joins a team with a single mandate: get ahead of the security risks introduced by agentic systems before they become operational reality at Okta. This is a research and engineering role. The work is long-horizon and adversarial: understanding how prompt injection propagates through an agent with write access to a code repository, how privilege escalation manifests in an orchestration model with dynamic tool bindings, and what an agentic supply-chain attack looks like against an internal developer platform. The findings this team produces shape SDL requirements, feed reusable security tooling across all of Product Security, and drive Okta's AI and agent-based system security approach at the design level.

The ideal candidate thinks like an attacker, builds like an engineer, and publishes their findings. We actively support external research disclosure through white papers, blog posts, and conference presentations.

What You Will Do

  • Conduct offensive security research focused on agentic AI systems: prompt injection, agent privilege escalation, tool-binding abuse, and agentic supply chain attacks against internal developer platforms.
  • Perform security assessments of Okta's AI platforms—including agentic systems and LLM-integrated products—across design, code, and runtime.
  • Build reusable security tooling that multiplies the entire Product Security team's capability.
  • Run the AI security vendor and tooling evaluation program: design and operate a benchmarking harness against AI security tools.
  • Perform manual code review of AI and agent-based system implementations across multiple languages.
  • Develop threat models for agentic architectures, orchestration layers, and LLM-integrated services.
  • Translate research findings into actionable guidance for engineering teams building AI-powered features and platforms.
  • Represent Okta externally through security research, conference presentations, white papers, and publications.
  • Mentor engineers across Product Security on AI/agentic security concepts, tooling, and assessment methodology.

What You Bring

  • 7+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security.
  • Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures—not just familiarity with the concepts, but evidence of having found real vulnerabilities in them.
  • Strong offensive mindset: the ability to model what an adversary does with an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete.
  • Experience building security tooling and automation—scripts, scanners, detection logic, or evaluation harnesses—that other engineers actually use.
  • Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++).
  • Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems.
  • Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks.
  • Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues.
  • Experience producing external security research—publications, conference talks, blog posts, or open-source tooling.

Desired Skills and Abilities

  • Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures).
  • Experience with SAST, DAST, SCA, and fuzzing tooling applied to AI/ML pipelines or CI/CD systems.
  • Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws.
  • Ability to develop proof-of-concept exploits that demonstrate AI/agentic vulnerabilities to engineering and product leadership.
  • Experience contributing to security standards, SDL processes, or vulnerability research programs.

#LI-SM1

#LI-Hybrid

P25264_3461996

Below is the annual base salary range for candidates located in San Francisco Bay Area. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: .   

The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $180,000—$247,500 USD


The Okta Experience

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please  use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please  click here to view our full NYC AEDT Notice.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Personnel and Job Candidate Privacy Notice at  .
Vacancy posted 8 days ago
Similar jobs that could be interesting for youBased on the Staff Product Security Engineer in Washington DC vacancy
  • $175k - $210k

     ...from the effects of infrastructure failure. Role at a Glance We are building the Product Security team to build and scale application security at Gecko. As a Product Security Engineer you will play a key role in shaping how security works across our product as we... 
    Suggested
    Work at office
    Local area
    Work from home
    Flexible hours

    Gecko Robotics

    Washington DC
    12 days ago
  • $140k - $165k

     ...Senior Product Security Engineer Uplight is creating a new category of energy. We make software that manages energy resources in homes and businesses—including things like smart thermostats, electric vehicles, solar panels, storage batteries, heat pumps, and even people... 
    Suggested
    Local area
    Flexible hours
    Shift work

    upLIGHT

    Washington DC
    1 day ago
  • $118.72k - $190.04k

     ...rapidly growing company supporting more than 90% of Fortune 500 companies. The Red Hat Product Security Compliance team is seeking a knowledgeable and proactive Product Security Engineer to achieve our security and compliance objectives.The team is growing and we have a... 
    Suggested
    Permanent employment
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Work from home
    Worldwide
    Flexible hours

    Red Hat

    Washington DC
    2 days ago
  • $135k - $200k

     ...chain disruptions, locate missing children, and more. Our Product Security team works on secure-by-design and deep product partnership....  ...of the Product Security Team is to enable Palantir’s product engineering organizations to build, ship, and operate the most secure and... 
    Suggested
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir

    Washington DC
    4 days ago
  • $100k - $172.5k

     ...more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job...  ...We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work... 
    Suggested
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Adelphi, MD
    2 days ago
  • Red Hat, LLC is seeking a Product Security Engineer in Washington, D.C. to ensure security compliance for FedRAMP and commercial environments. Responsibilities include leading discussions with teams, researching security tools, and developing automation processes. The ideal... 
    Remote job

    Red Hat, LLC

    Washington DC
    4 days ago
  • $188k - $235k

     ...mission to make the world’s health data secure, accessible and actionable, we provide...  ...re Looking For We’re looking for a Product Security Engineering Manager who can lead a high-performing...  ...To ensure the safety of patients and staff, many of our clients require post-... 

    Datavant

    Washington DC
    1 day ago
  • Red Hat, Inc. is looking for a proactive Product Security Engineer to join their team in Washington, D.C. In this role, you will ensure security and compliance of systems, particularly related to FedRAMP. You'll collaborate with teams and utilize your problem-solving skills... 
    Remote job

    Red Hat, Inc.

    Washington DC
    16 hours ago
  • $40 per hour

     ...train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems, and provide feedback...  ...testing, red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or similar)Some... 
    Hourly pay
    Full time
    Part time
    Remote work

    DataAnnotation

    Washington DC
    2 days ago
  •  ...Whether the focus is on space exploration, national security, cyber security, or cutting‑edge engineering applications, I2X is ready to offer you the chance to...  ...customers. I2X Technologies is seeking a Product Manager to support ongoing activities for a customer... 
    Temporary work
    For contractors
    Work experience placement
    Long distance

    Isys Technologies

    Washington DC
    16 hours ago
  • ID.me is seeking a Product Security Engineer in McLean, VA, to enhance security solutions for millions of users. This role involves implementing security systems, troubleshooting production issues, and automating security processes using Python or Java. Candidates should... 

    I did my part and supported the Regular Toilet

    Mc Lean, VA
    2 days ago
  •  ...getting started. Our AI-powered cybersecurity platform secures operational technology (OT) and Internet of Things...  ..., and critical infrastructure. As we expand our product portfolio and global presence, our Engineering department is hiring a Product Security Engineer to... 
    For contractors
    Flexible hours

    Cacheflow

    Mc Lean, VA
    16 hours ago
  • $127.5k - $149.94k

     ...generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their...  ...learn more, visit Role Overview ID.me is looking for a Product Security Engineer to join our Product Security organization as an execution-... 
    Full time
    Temporary work
    Work at office
    Flexible hours

    I did my part and supported the Regular Toilet

    Mc Lean, VA
    2 days ago
  • $74.8k - $130.9k

     ...Unleash your talent and redefine what's possible. Job Description: Parsons is looking for an amazingly talented Security Systems Design Engineer to join our team! In this role you will get to develop and design Security Systems for Embassies and Consulates... 
    Work experience placement
    Work at office
    Local area
    Worldwide
    Flexible hours

    Parsons Company

    Alexandria, VA
    2 days ago
  • Associate Product Security Engineer Now is an amazing time to join Nozomi Networks as we build the future of OT and IoT cybersecurity. We defend some of the world’s largest organizations and critical infrastructure in more than 68 countries and we’re just getting started... 
    Internship
    Flexible hours

    Cacheflow

    Mc Lean, VA
    4 days ago
  • Cacheflow is seeking an Associate Product Security Engineer to support product security initiatives. You will assist in vulnerability assessments, code reviews, and learn about secure coding practices. Ideal candidates will have a degree in Computer Science or related fields... 
    Flexible hours

    Cacheflow

    Mc Lean, VA
    4 days ago
  • Phase2 Technology in McLean, Virginia, is looking for a Product Engineer Intern to aid in developing AI-powered security systems. You will engage in building autonomous cyber threat defense solutions and work directly with security operations teams to enhance response... 
    Internship

    Phase2 Technology

    Mc Lean, VA
    1 day ago
  • $92.3k - $166.85k

     ...operations for a significant opportunity with a Health Agency in Montgomery County, MD. The positions available include Network Engineers, Security Engineers, System Administrators, and Network Architects. Candidates must have relevant experience, with a pay range of $92,3... 
    Contract work

    Via Logic LLC

    Bethesda, MD
    1 day ago
  • Creative Information Technology India is looking for a Product Manager in Falls Church, VA. The successful candidate will support the Security Engineering team at the Federal Reserve, focusing on product strategy, backlog management, and stakeholder communication. Must... 

    Creative Information Technology India

    Falls Church, VA
    3 days ago
  •  ...the U.S. Department of State's Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining...  ...eligible employees, Dexis provides healthcare insurance in addition to other staff welfare benefits and perks.
    Contract work
    Work at office

    Dexis Online

    Washington DC
    1 day ago
  • $237.6k - $297k

     ...Security Engineer, Product Security We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security... 
    Full time

    Scale AI

    Washington DC
    1 day ago
  •  ...Cyber Security Design Engineer Comtech LLC is a woman-owned small business focused on delivering end-to-end solutions and products. Since 1998, we have successfully serviced enterprises across the public and private sectors, and the Department of Defense. Our services... 

    Comtech LLC

    Washington DC
    1 day ago
  • $155k - $210k

     ...that helps families stay afloat—turning financial stress into stability through flexible, affordable payment solutions. As a Product Engineer with a frontend focus, you’ll shape the way people directly experience that mission. You’ll design and build intuitive, high... 
    Permanent employment
    Full time
    Work at office
    Local area
    Immediate start
    Flexible hours

    Promise

    Washington DC
    12 days ago
  • $60k

     ...Maximus is a trusted federal partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining, operating, and improving essential government systems and services, with proven operational excellence... 
    Contract work
    Remote work

    MAXIMUS

    Washington DC
    5 days ago
  • $107.9k - $195.05k

    Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires...  ...tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity... 
    Night shift
    Day shift

    Koitecc Solutions

    Washington DC
    3 days ago
  • $110k - $135k

     ...Reporting to the Program Manager, the Web Developer Embeds security across the SDLC for mission-critical web apps, APIs, and sensitive...  ...~ Log analysis, FIM, WAF management ~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl. .NET (C# MVC, WCF), HTML5,... 

    BaseCamp Consulting & Solutions

    Washington DC
    9 days ago
  • threatER is seeking a Full Stack Developer to lead the integration of AI technologies and deliver scalable software solutions in Washington, D.C. The ideal candidate will have over 4 years of experience, particularly in AWS environments, and be proficient in languages such...

    threatER

    Washington DC
    4 days ago
  • $150k - $185k

     ...alongside a cross‑functional team to implement, iterate, and debug product features that drive forward both the company and the user. Own...  ...a student and a teacher, continually seeking to grow as an engineer and help those around you grow as well. You're not just interested... 
    Temporary work
    Work at office
    Local area

    Truebill

    Washington DC
    3 days ago
  • A fintech company is seeking an experienced developer to join the team in building scalable financial features used by millions. Candidates should have over 5 years of expertise with Node.js, TypeScript, React, GraphQL, and a strong interest in user-driven solutions. The...
    Work at office

    Truebill

    Washington DC
    3 days ago
  • $130k - $150k

     ...businesses worldwide rely on TRM to make the world safer and more secure. At TRM, writing code can literally save lives. Our platform...  ...terrorist financing to human trafficking. The Full‑Stack Product Engineering team builds core products and services that make this... 
    Summer work
    Internship
    Work at office
    Worldwide
    3 days per week

    TRM Labs Inc.

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!