Staff Product Security Engineer
$180k - $247kOkta
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.The Security Team
Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences.
Join our team! We're building a world where Identity belongs to you.
The Staff Product Security Engineer Opportunity
The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers.
The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale.
This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOTA frontier models and fine-tuning open-weight models to building production-grade security tooling across Product Security. While a main focus will be on creating intelligent, automated security capabilities that keep Okta continuously ahead of emerging threats, performing full security reviews of Okta's products, as well as agentic architectures and internal AI pipelines, to uncover, exploit and fix vulnerabilities is also part of the work.
The ideal candidate thinks creatively but also like an attacker, builds like an engineer, and publishes their findings. We actively support external research disclosure through white papers, blog posts, and conference presentations.
What You Will Do
- Lead technical capability research evaluating frontier LLMs and customized open-weight models for advanced code analysis, autonomous attack and logical security reasoning.
- Engineer production-grade, AI-assisted security tools that automate vulnerability discovery, triaging, and risk validation across codebases.
- Architect context-aware code-repair engines that automatically recommend verified security fixes to software development teams.
- Build automated Proof-of-Concept (PoC) exploit generators in sandboxed runtimes to safely perform root cause analysis on identified vulnerabilities.
- Modify and fine-tune open-source models to carry out domain-specific defensive and offensive code analysis tasks.
- Embed AI models, unified APIs, and model-agnostic execution frameworks across Product Security tools to multiply team capabilities.
- Assess and secure internal AI platforms, agentic execution runtimes, and AI coding agent container environments.
- Perform manual code review and AI-assisted deep dives of Okta's products and system implementations across multiple languages.
- Develop threat models for agentic architectures, orchestration layers, and LLM-integrated services.
- Deliver technical reference blueprints and publish external research demonstrating how AI models transform modern security engineering.
- Run the AI security vendor and tooling evaluation program: design and operate a benchmarking harness against AI security tools.
- Conduct offensive security research focused on agentic AI systems: prompt injection, agent privilege escalation, tool-binding abuse, and agentic supply chain attacks against internal developer platforms.
- Translate research findings into actionable guidance for engineering teams building AI-powered features and platforms.
What You Bring
- 8+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security.
- Experience building security tooling and automation (scripts, scanners, detection logic, or evaluation harnesses) that other engineers actually use.
- Strong offensive mindset: the ability to model what an adversary does to break systems and how this translates to an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete.
- Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures, not just familiarity with the concepts, but evidence of having found real vulnerabilities in them.
- Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++).
- Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems.
- Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks.
- Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues.
- Experience producing external security research, publications, conference talks, blog posts, or open-source tooling.
Desired Skills and Abilities
- Experience in vulnerability research and vulnerability discovery through source code auditing, as well as penetration testing skills.
- Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures).
- Experience with SAST, DAST, SCA, and fuzzing tooling applied to AI/ML pipelines or CI/CD systems.
- Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws.
- Ability to develop proof-of-concept exploits that demonstrate vulnerabilities to engineering and product leadership. Plus, if able to exploit AI/Agentic-specific vulnerabilities
- Experience contributing to security standards, SDL processes, or vulnerability research programs.
#LI-SM1
#LI-Hybrid
#LI-Remote
P25264_3461996
The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $180,000—$247,000 USD Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: .
The Okta Experience
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.$156k - $253k
...computer vision, sensor fusion, and networking technology to the military in months, not years.ABOUT THE TEAMWe're seeking a product security engineer to own security for assigned products in your technical domain, provide expert consultation on security architectures,...SuggestedFull timeWork experience placementImmediate start- ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on... ...today and in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform...SuggestedFull timeLocal areaWorldwideFlexible hours
- ...Job Description Job Description Job title: Product Security PKI and Cloud Environment Architect \tLeads the development, implementation... ...environment architect \t5+ years of experience \tAny Engineering or computer science BS or BS information systems degree...SuggestedContract workFor contractorsWork experience placementImmediate startRemote work
- ...Secure Every Identity Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges...SuggestedRemote workFlexible hours
$162.35k - $234.6k
Senior Product Security Engineer - Avionics DevelopmentCompany:The Boeing CompanyBoeing is seeking an innovative and experienced Senior Product Security Engineer - Avionics Development to join our growing team as part of an integrated Product Security Organization, located...SuggestedPermanent employmentFull timeWork experience placementRelocationVisa sponsorshipWork visaFlexible hoursShift work- ...Job Description Job Description Senior Product Manager- Security Engineering Washington DC 20006 – 100% ONSITE Per Federal contract U.S. Citizenship Required Must be able to pass enhanced background screen (criminal, financial, drug) for Public Trust clearance...Contract workTemporary workFor contractorsLocal area
- ...Job Description Job Description TS/SCI w POLY Required **About the Role:** Join our team as a Security Product Reverse Engineer to analyze and audit security products, focusing on vulnerability research and code exploitation. This role involves hands-on work with...
- ...Job Description Job Description Description: Job Description: EMD LLC is looking for a Security Systems Design Engineer to join our team! In this role you will get to develop and design Technical Security Systems for Embassies and Consulates Worldwide ....Work experience placementWork at officeLocal areaWorldwide
- EMD LLC is seeking a Security Systems Design Engineer to develop and design Technical Security Systems for Embassies and Consulates Worldwide. The role includes site surveys, conceptual design, and complete security system design packages across multi-discipline campuses...Worldwide
$134.5k - $265.1k
...Summary As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection... ...to deal shaping, influencing product direction, and providing appropriate support... ...cybersecurity concepts (e.g., application security, cloud security, identity, detection engineering...Local areaVisa sponsorship$178.4k - $226.7k
AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds...InternshipRemote workFlexible hours- Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our mission and...Temporary workWork at officeRemote workWork from homeFlexible hours
$178.4k - $226.7k
Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global... ..., build, and scale securely. The Product Security Team within CPSS supports a large... ...work, we provide opportunities for our engineers to pursue projects they are passionate about...InternshipFlexible hours$136k - $184k
Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering... ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance...InternshipFlexible hoursShift work- ...the U.S. Department of State’s Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining... ...eligible employees, Dexis provides healthcare insurance in addition to other staff welfare benefits and perks.Contract workWork at office
$159.3k - $202.4k
Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within... ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the...InternshipFlexible hours- ...on delivering end-to-end solutions and products. Since 1998, we have successfully serviced... ...:· Establish system-wide information security requirements based on policy and regulatory... ...Responsibilities include secure systems engineering and development. This includes systems...
$97.7k - $162.8k
Position Summary Our Deloitte AI & Engineering team to transform technology platforms, drive innovation, and help make a significant... ...as a Service team, you will be responsible for: Define product vision, target users, and value proposition for delivery efforts...Local areaFlexible hours$320k - $405k
...Security Engineer, Corporate Security San Francisco, CA | Seattle, WA | New York City, NY | Washington, DC About Anthropic Anthropic... ...Location-based hybrid policy: Currently, we expect all staff to be in one of our offices at least 25% of the time. However...Visa sponsorshipFlexible hours$77.6k - $176k
AI-Powered Cyber Defense Product Sales EngineerThe Opportunity:Join a team delivering next... ...defense solutions that transform how Security Operations Centers (SOCs) detect, investigate... ...to cyber threats. As a Senior Sales Engineer, you'll serve as the technical lead throughout...Full timeContract workPart timeWork at officeLocal areaRemote work$10 per hour
...configuration drift across our critical SaaS applications. Own security configuration for the SaaS tools hundreds of Flexporters use... ...years of experience in corporate, enterprise, or IT security engineering — we care more about what you've shipped than the exact number...Work at officeImmediate startFlexible hours$320k - $405k
...zero-trust access controls while balancing security protections with employee workflow needs... .... Partner with Security, IT, and Engineering on telemetry, detections, shared standards... .... Hybrid policy currently requiring staff to work from an office at least 25% of the...Full timeWork at officeVisa sponsorshipFlexible hours- ...s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across... ...Meticulous attention to detail and quality of work product Ability to build and sustain professional relationships...Remote work
$60k
...Maximus is a trusted federal partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining, operating, and improving essential government systems and services, with proven operational excellence...Contract workRemote work$130k - $150k
...businesses worldwide rely on TRM to make the world safer and more secure. At TRM, writing code can literally save lives. Our platform... ...terrorist financing to human trafficking. The Full‑Stack Product Engineering team builds core products and services that make this...Summer workInternshipWork at officeWorldwide3 days per week- ...project management, applications development, infrastructure, Cyber security, and enterprise content/data management services. We have... ...Washington, DCJob DescriptionThe Identity and Authentication Security Engineer/Admin will be responsible for technical support to security...Remote work
$125.12k - $187.68k
...solutions for the nation’s most mission-critical facilities, secure environments, complex infrastructure, and global enterprises.... ...secure, and innovative power and technology solutions through engineering expertise and smart systems integration.Why Join Us?Our people...Work at officeLocal areaFlexible hoursNight shift- ...solutions, tested leadership, and trusted results to enable national security missions worldwide.Job Description*** This position is... ...contract award ***OverviewSOSi is seeking a Cybersecurity Security Engineer III to support cybersecurity engineering activities in...Contract workWork at officeWorldwideMonday to FridayWeekend workAfternoon shift
$5,000 per month
...Candidates who are not U.S. citizens are not eligible for this role. Imagine One Technology & Management, Ltd. is seeking two (2) Security Engineers. This position is contingent upon award of the associated work and will be performed in Dahlgren, Virginia.The Security...Work at office$160k - $205k
...cybersecurity and looking to work with some of the best information security professionals in the world in challenging environments? Bank... ..., share your knowledge and experience by mentoring junior engineers, and assist with monitoring and response functions, so those teams...Full timeWork at officeRemote workShift workDay shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!
- project engineer assistant project manager Washington DC
- senior staff systems engineer Washington DC
- assistant engineer Washington DC
- engineering aide Washington DC
- software engineer staff Washington DC
- senior staff engineer Washington DC
- technology administrator Washington DC
- staff engineer Washington DC
- product engineer Washington DC
- cad design engineer solidworks Washington DC


