Staff Product Security Engineer
$180k - $247kOkta
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.The Security Team
Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences.
Join our team! We're building a world where Identity belongs to you.
The Staff Product Security Engineer Opportunity
The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers.
The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale.
This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOTA frontier models and fine-tuning open-weight models to building production-grade security tooling across Product Security. While a main focus will be on creating intelligent, automated security capabilities that keep Okta continuously ahead of emerging threats, performing full security reviews of Okta's products, as well as agentic architectures and internal AI pipelines, to uncover, exploit and fix vulnerabilities is also part of the work.
The ideal candidate thinks creatively but also like an attacker, builds like an engineer, and publishes their findings. We actively support external research disclosure through white papers, blog posts, and conference presentations.
What You Will Do
- Lead technical capability research evaluating frontier LLMs and customized open-weight models for advanced code analysis, autonomous attack and logical security reasoning.
- Engineer production-grade, AI-assisted security tools that automate vulnerability discovery, triaging, and risk validation across codebases.
- Architect context-aware code-repair engines that automatically recommend verified security fixes to software development teams.
- Build automated Proof-of-Concept (PoC) exploit generators in sandboxed runtimes to safely perform root cause analysis on identified vulnerabilities.
- Modify and fine-tune open-source models to carry out domain-specific defensive and offensive code analysis tasks.
- Embed AI models, unified APIs, and model-agnostic execution frameworks across Product Security tools to multiply team capabilities.
- Assess and secure internal AI platforms, agentic execution runtimes, and AI coding agent container environments.
- Perform manual code review and AI-assisted deep dives of Okta's products and system implementations across multiple languages.
- Develop threat models for agentic architectures, orchestration layers, and LLM-integrated services.
- Deliver technical reference blueprints and publish external research demonstrating how AI models transform modern security engineering.
- Run the AI security vendor and tooling evaluation program: design and operate a benchmarking harness against AI security tools.
- Conduct offensive security research focused on agentic AI systems: prompt injection, agent privilege escalation, tool-binding abuse, and agentic supply chain attacks against internal developer platforms.
- Translate research findings into actionable guidance for engineering teams building AI-powered features and platforms.
What You Bring
- 8+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security.
- Experience building security tooling and automation (scripts, scanners, detection logic, or evaluation harnesses) that other engineers actually use.
- Strong offensive mindset: the ability to model what an adversary does to break systems and how this translates to an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete.
- Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures, not just familiarity with the concepts, but evidence of having found real vulnerabilities in them.
- Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++).
- Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems.
- Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks.
- Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues.
- Experience producing external security research, publications, conference talks, blog posts, or open-source tooling.
Desired Skills and Abilities
- Experience in vulnerability research and vulnerability discovery through source code auditing, as well as penetration testing skills.
- Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures).
- Experience with SAST, DAST, SCA, and fuzzing tooling applied to AI/ML pipelines or CI/CD systems.
- Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws.
- Ability to develop proof-of-concept exploits that demonstrate vulnerabilities to engineering and product leadership. Plus, if able to exploit AI/Agentic-specific vulnerabilities
- Experience contributing to security standards, SDL processes, or vulnerability research programs.
#LI-SM1
#LI-Hybrid
#LI-Remote
P25264_3461996
The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $180,000—$247,000 USD Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: .
The Okta Experience
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.$156k - $253k
...computer vision, sensor fusion, and networking technology to the military in months, not years.ABOUT THE TEAMWe're seeking a product security engineer to own security for assigned products in your technical domain, provide expert consultation on security architectures,...SuggestedFull timeWork experience placementImmediate start- ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on... ...today and in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform...SuggestedFull timeLocal areaWorldwideFlexible hours
$135.4k - $201.85k
...enough to make a difference. Our cloud-first networking and security solutions already protect 70% of the Fortune 500 , and we’... ...where you can be anything, Be Infoblox. Senior Product Security Engineer We are looking for a Senior Product Security Engineer...SuggestedFull timeTemporary workWork experience placementWork at officeFlexible hoursNight shift$174k - $253k
...experience. ~5 years of experience with security engineering, computer and network security and... ...with securing Cloud infrastructure and products running in Cloud environments. Understanding... ...guidance for engineers and support staff. Design and drive implementation of...SuggestedFull timeTemporary work- ...Job Description Job Description Senior Product Manager- Security Engineering Washington DC 20006 – 100% ONSITE Per Federal contract U.S. Citizenship Required Must be able to pass enhanced background screen (criminal, financial, drug) for Public Trust clearance...SuggestedContract workTemporary workFor contractorsLocal area
- ...Job Description Job Description Custom Software Systems, Inc. (CSS) is seeking an experienced Product Manager to support the Security Engineering team within our client's IT division. This is a high-impact role focused on driving the strategy, development, and delivery...Temporary work
$137.7k - $186.3k
Mid-Level or Senior Product Security Engineer - Public Key Infrastructure (PKI) and Cloud Architect Company: The Boeing Company Boeing Commercial Airplanes is seeking a Mid-Level (Level 3) or Senior (Level 4 or Level 5) Product Security Engineer - Public Key Infrastructure...Permanent employmentFull timeWork experience placementCurrently hiringRelocationVisa sponsorshipWork visaFlexible hoursShift work- ...Job Description Job Description TS/SCI w POLY Required **About the Role:** Join our team as a Security Product Reverse Engineer to analyze and audit security products, focusing on vulnerability research and code exploitation. This role involves hands-on work with...
- ...Job Description Job Description Description: Job Description: EMD LLC is looking for a Security Systems Design Engineer to join our team! In this role you will get to develop and design Technical Security Systems for Embassies and Consulates Worldwide ....Work experience placementWork at officeLocal areaWorldwide
$63.6k - $111.3k
...and redefine what’s possible. Job Description: Job Description: Parsons is looking for an amazingly talented Security Systems Design Engineer to join our team! In this role you will get to develop and design Technical Security Systems for Embassies and...Work experience placementWork at officeLocal areaWorldwideFlexible hours$180k - $247.5k
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building... ...all in on this mission. If you are too, let's talk. The Staff Product Security Engineer Opportunity As a Staff Product Security Engineer, you...Local areaWorldwideFlexible hours- EMD LLC is seeking a Security Systems Design Engineer to develop and design Technical Security Systems for Embassies and Consulates Worldwide. The role includes site surveys, conceptual design, and complete security system design packages across multi-discipline campuses...Worldwide
$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global... ..., build, and scale securely. The Product Security Team within CPSS supports a large... ...work, we provide opportunities for our engineers to pursue projects they are passionate about...InternshipFlexible hours$107.9k - $195.05k
Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires... ...tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity...Full timeNight shift$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within... ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the...InternshipFlexible hours$100k - $110k
...architectures that support the bank’s information security operations functions. This role performs... ...as a technical resource for security engineering initiatives, applying advanced knowledge... ...Life, access to voluntary benefit products such as Cancer, Term & Universal Life,...Temporary workRemote workFlexible hours$107.93k - $188.9k
...Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis... ...skillsMeticulous attention to detail and quality of work productAbility to build and sustain professional relationshipsAbility...Remote work$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering... ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance...InternshipFlexible hoursShift work- ...on delivering end-to-end solutions and products. Since 1998, we have successfully serviced... ...:· Establish system-wide information security requirements based on policy and regulatory... ...Responsibilities include secure systems engineering and development. This includes systems...
- The Evolvers Group is seeking a Product Manager to support the Security Engineering team, shaping strategy and delivery for cloud, local, and hybrid environments. You will translate complex security requirements into well-defined product features, manage backlogs, and drive...Local area
$97.7k - $162.8k
Position Summary Our Deloitte AI & Engineering team to transform technology platforms, drive innovation, and help make a significant... ...as a Service team, you will be responsible for:Define product vision, target users, and value proposition for delivery efforts...Local areaFlexible hours- ...Reporting to the Program Manager, the Web Developer Embeds security across the SDLC for mission-critical web apps, APIs, and sensitive... ...~ Log analysis, FIM, WAF management ~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl. .NET (C# MVC, WCF), HTML5,...Full time
- ...teams support the federal government’s most critical national security and defense priorities, helping protect the nation, strengthen... ...mission begins. Ardent is seeking a Web Developer Security Engineer to join our team. This position is based in Washington, DC...Full timeLocal areaRemote workFlexible hours
$100k - $110k
...require a bachelors degree in information security or another computer-related discipline,... ...areas: networking infrastructure products such as routers, switches, and wireless;... ...while aligning with our standards. We engineer, implement, and deploy advanced security...Full timeTemporary workRemote workFlexible hours$107.93k - $188.9k
...s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across... ...Meticulous attention to detail and quality of work product Ability to build and sustain professional relationships...Remote work$165k - $215k
...us create it. Who you are Metropolis is seeking a highly technical, developer-oriented Senior Security Engineer to focus on securing our software engineering and product environments across web applications, mobile applications, APIs, AI/CV platforms, and cloud-...Temporary workWork at officeLocal area$77.6k - $176k
AI-Powered Cyber Defense Product Sales EngineerThe Opportunity:Join a team delivering next... ...defense solutions that transform how Security Operations Centers (SOCs) detect, investigate... ...to cyber threats. As a Senior Sales Engineer, you'll serve as the technical lead throughout...Full timeContract workPart timeWork at officeLocal areaRemote work$221.2k - $387.1k
...It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy... ...people. Job Description About SSO The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions...Permanent employmentFull timeWork at officeImmediate startRemote workFlexible hoursShift work- ...Senior Product Engineer, Treasury (Elixir) Remote — US-based, working EST hours About Vic.ai Vic.ai is building the autonomous finance platform for the modern enterprise. We use AI to automate accounts payable and treasury workflows so finance teams operate with more...Remote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!
- software engineer staff Washington DC
- assistant engineer Washington DC
- engineering aide Washington DC
- staff engineer Washington DC
- senior staff systems engineer Washington DC
- technology administrator Washington DC
- project engineer assistant project manager Washington DC
- senior staff engineer Washington DC
- data center design engineer Washington DC
- cad design engineer solidworks Washington DC



