Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Product Security Engineer

$180k - $247k

Okta

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Security Team

Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth.

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences.

Join our team! We're building a world where Identity belongs to you.

The Staff Product Security Engineer Opportunity

The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers.

The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale.

This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOTA frontier models and fine-tuning open-weight models to building production-grade security tooling across Product Security. While a main focus will be on creating intelligent, automated security capabilities that keep Okta continuously ahead of emerging threats, performing full security reviews of Okta's products, as well as agentic architectures and internal AI pipelines, to uncover, exploit and fix vulnerabilities is also part of the work.

The ideal candidate thinks creatively but also like an attacker, builds like an engineer, and publishes their findings. We actively support external research disclosure through white papers, blog posts, and conference presentations.

What You Will Do

  • Lead technical capability research evaluating frontier LLMs and customized open-weight models for advanced code analysis, autonomous attack and logical security reasoning.
  • Engineer production-grade, AI-assisted security tools that automate vulnerability discovery, triaging, and risk validation across codebases.
  • Architect context-aware code-repair engines that automatically recommend verified security fixes to software development teams.
  • Build automated Proof-of-Concept (PoC) exploit generators in sandboxed runtimes to safely perform root cause analysis on identified vulnerabilities.
  • Modify and fine-tune open-source models to carry out domain-specific defensive and offensive code analysis tasks.
  • Embed AI models, unified APIs, and model-agnostic execution frameworks across Product Security tools to multiply team capabilities.
  • Assess and secure internal AI platforms, agentic execution runtimes, and AI coding agent container environments.
  • Perform manual code review and AI-assisted deep dives of Okta's products and system implementations across multiple languages. 
  • Develop threat models for agentic architectures, orchestration layers, and LLM-integrated services.
  • Deliver technical reference blueprints and publish external research demonstrating how AI models transform modern security engineering.
  • Run the AI security vendor and tooling evaluation program: design and operate a benchmarking harness against AI security tools.
  • Conduct offensive security research focused on agentic AI systems: prompt injection, agent privilege escalation, tool-binding abuse, and agentic supply chain attacks against internal developer platforms.
  • Translate research findings into actionable guidance for engineering teams building AI-powered features and platforms.

What You Bring

  • 8+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security.
  • Experience building security tooling and automation (scripts, scanners, detection logic, or evaluation harnesses) that other engineers actually use.
  • Strong offensive mindset: the ability to model what an adversary does to break systems and how this translates to an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete.
  • Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures, not just familiarity with the concepts, but evidence of having found real vulnerabilities in them.
  • Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++).
  • Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems.
  • Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks.
  • Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues.
  • Experience producing external security research, publications, conference talks, blog posts, or open-source tooling.

Desired Skills and Abilities

  • Experience in vulnerability research and vulnerability discovery through source code auditing, as well as penetration testing skills.
  • Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures).
  • Experience with SAST, DAST, SCA, and fuzzing tooling applied to AI/ML pipelines or CI/CD systems.
  • Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws.
  • Ability to develop proof-of-concept exploits that demonstrate vulnerabilities to engineering and product leadership. Plus, if able to exploit AI/Agentic-specific vulnerabilities
  • Experience contributing to security standards, SDL processes, or vulnerability research programs.

#LI-SM1

#LI-Hybrid
#LI-Remote

P25264_3461996

The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $180,000—$247,000 USD

Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: .   

The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $161,000—$221,000 USD

The Okta Experience

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please  use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please  click here to view our full NYC AEDT Notice.
Vacancy posted 16 days ago
Similar jobs that could be interesting for youBased on the Staff Product Security Engineer in Washington DC vacancy
  • $156k - $253k

     ...computer vision, sensor fusion, and networking technology to the military in months, not years.ABOUT THE TEAMWe're seeking a product security engineer to own security for assigned products in your technical domain, provide expert consultation on security architectures,... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    11 hours ago
  •  ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on...  ...today and in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform... 
    Suggested
    Full time
    Local area
    Worldwide
    Flexible hours

    DataRobot

    Washington DC
    4 days ago
  • $135.4k - $201.85k

     ...enough to make a difference. Our cloud-first networking and security solutions already protect 70% of the Fortune 500 , and we’...  ...where you can be anything, Be Infoblox. Senior Product Security Engineer We are looking for a Senior Product Security Engineer... 
    Suggested
    Full time
    Temporary work
    Work experience placement
    Work at office
    Flexible hours
    Night shift

    Infoblox

    Washington DC
    2 days ago
  • $174k - $253k

     ...experience. ~5 years of experience with security engineering, computer and network security and...  ...with securing Cloud infrastructure and products running in Cloud environments. Understanding...  ...guidance for engineers and support staff. Design and drive implementation of... 
    Suggested
    Full time
    Temporary work

    Google

    Washington DC
    13 days ago
  •  ...Job Description Job Description Senior Product Manager- Security Engineering Washington DC 20006 – 100% ONSITE Per Federal contract U.S. Citizenship Required Must be able to pass enhanced background screen (criminal, financial, drug) for Public Trust clearance... 
    Suggested
    Contract work
    Temporary work
    For contractors
    Local area

    System One

    Washington DC
    17 days ago
  •  ...Job Description Job Description Custom Software Systems, Inc. (CSS) is seeking an experienced Product Manager to support the Security Engineering team within our client's IT division. This is a high-impact role focused on driving the strategy, development, and delivery... 
    Temporary work

    Custom Software Systems Inc.

    Washington DC
    17 days ago
  • $137.7k - $186.3k

    Mid-Level or Senior Product Security Engineer - Public Key Infrastructure (PKI) and Cloud Architect Company: The Boeing Company Boeing Commercial Airplanes is seeking a Mid-Level (Level 3) or Senior (Level 4 or Level 5) Product Security Engineer - Public Key Infrastructure... 
    Permanent employment
    Full time
    Work experience placement
    Currently hiring
    Relocation
    Visa sponsorship
    Work visa
    Flexible hours
    Shift work

    Boeing

    Washington DC
    1 day ago
  •  ...Job Description Job Description TS/SCI w POLY Required **About the Role:** Join our team as a Security Product Reverse Engineer to analyze and audit security products, focusing on vulnerability research and code exploitation. This role involves hands-on work with... 

    Falls Technology

    McLean, VA
    10 days ago
  •  ...Job Description Job Description Description: Job Description: EMD LLC is looking for a Security Systems Design Engineer to join our team! In this role you will get to develop and design Technical Security Systems for Embassies and Consulates Worldwide .... 
    Work experience placement
    Work at office
    Local area
    Worldwide

    EMD LLC

    Alexandria, VA
    a month ago
  • $63.6k - $111.3k

     ...and redefine what’s possible. Job Description: Job Description: Parsons is looking for an amazingly talented Security Systems Design Engineer to join our team! In this role you will get to develop and design Technical Security Systems for Embassies and... 
    Work experience placement
    Work at office
    Local area
    Worldwide
    Flexible hours

    Parsons Company

    Alexandria, VA
    2 days ago
  • $180k - $247.5k

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building...  ...all in on this mission. If you are too, let's talk. The Staff Product Security Engineer Opportunity As a Staff Product Security Engineer, you... 
    Local area
    Worldwide
    Flexible hours

    Okta

    Washington DC
    16 days ago
  • EMD LLC is seeking a Security Systems Design Engineer to develop and design Technical Security Systems for Embassies and Consulates Worldwide. The role includes site surveys, conceptual design, and complete security system design packages across multi-discipline campuses... 
    Worldwide

    Emd, Llc

    Alexandria, VA
    1 day ago
  • $178.4k - $226.7k

    Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global...  ..., build, and scale securely. The Product Security Team within CPSS supports a large...  ...work, we provide opportunities for our engineers to pursue projects they are passionate about... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    11 hours ago
  • $107.9k - $195.05k

    Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires...  ...tenant, particularly in a federal agency context. This senior engineering role sits at the center of the organization’s device, identity... 
    Full time
    Night shift

    Leidos

    Washington DC
    4 days ago
  • $178.4k - $226.7k

    AHAS reduces the risk of human and operator access to AWS production systems and customer environments. As the Senior Security Engineer embedded with an AHAS software development team, you own the security design decisions for the operator-access tooling this team builds... 
    Internship
    Remote work
    Flexible hours

    Amazon

    Arlington, VA
    3 days ago
  • $159.3k - $202.4k

    Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within...  ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    11 hours ago
  • $100k - $110k

     ...architectures that support the bank’s information security operations functions. This role performs...  ...as a technical resource for security engineering initiatives, applying advanced knowledge...  ...Life, access to voluntary benefit products such as Cancer, Term & Universal Life,... 
    Temporary work
    Remote work
    Flexible hours

    WesBanco

    Bowie, MD
    2 days ago
  • $107.93k - $188.9k

     ...Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis...  ...skillsMeticulous attention to detail and quality of work productAbility to build and sustain professional relationshipsAbility... 
    Remote work

    Deloitte

    Rosslyn, VA
    1 day ago
  • $136k - $184k

    Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering...  ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance... 
    Internship
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    11 hours ago
  •  ...on delivering end-to-end solutions and products. Since 1998, we have successfully serviced...  ...:· Establish system-wide information security requirements based on policy and regulatory...  ...Responsibilities include secure systems engineering and development. This includes systems... 

    Comtech

    Washington DC
    4 days ago
  • The Evolvers Group is seeking a Product Manager to support the Security Engineering team, shaping strategy and delivery for cloud, local, and hybrid environments. You will translate complex security requirements into well-defined product features, manage backlogs, and drive... 
    Local area

    The Evolvers Group

    Washington DC
    4 days ago
  • $97.7k - $162.8k

    Position Summary Our Deloitte AI & Engineering team to transform technology platforms, drive innovation, and help make a significant...  ...as a Service team, you will be responsible for:Define product vision, target users, and value proposition for delivery efforts... 
    Local area
    Flexible hours

    Deloitte

    Rosslyn, VA
    2 days ago
  •  ...Reporting to the Program Manager, the Web Developer Embeds security across the SDLC for mission-critical web apps, APIs, and sensitive...  ...~ Log analysis, FIM, WAF management ~3+ Web AppSec / AppSec Engineering / SSDLC ~ Modern web tech incl. .NET (C# MVC, WCF), HTML5,... 
    Full time

    Base Camp Consulting

    Washington DC
    11 hours ago
  •  ...teams support the federal government’s most critical national security and defense priorities, helping protect the nation, strengthen...  ...mission begins. Ardent is seeking a  Web Developer Security Engineer to join our team. This position is based in Washington, DC... 
    Full time
    Local area
    Remote work
    Flexible hours

    Ardentmc

    Washington DC
    11 hours ago
  • $100k - $110k

     ...require a bachelors degree in information security or another computer-related discipline,...  ...areas: networking infrastructure products such as routers, switches, and wireless;...  ...while aligning with our standards. We engineer, implement, and deploy advanced security... 
    Full time
    Temporary work
    Remote work
    Flexible hours

    WesBanco Bank, Inc.

    Bowie, MD
    2 days ago
  • $107.93k - $188.9k

     ...s Cyber Defense and Resilience offering is seeking a SIEM Engineer to support security monitoring, detection engineering, and incident analysis across...  ...Meticulous attention to detail and quality of work product Ability to build and sustain professional relationships... 
    Remote work

    Deloitte LLP

    Washington DC
    17 days ago
  • $165k - $215k

     ...us create it. Who you are Metropolis is seeking a highly technical, developer-oriented Senior Security Engineer to focus on securing our software engineering and product environments across web applications, mobile applications, APIs, AI/CV platforms, and cloud-... 
    Temporary work
    Work at office
    Local area

    Metropolis

    Washington DC
    a month ago
  • $77.6k - $176k

    AI-Powered Cyber Defense Product Sales EngineerThe Opportunity:Join a team delivering next...  ...defense solutions that transform how Security Operations Centers (SOCs) detect, investigate...  ...to cyber threats. As a Senior Sales Engineer, you'll serve as the technical lead throughout... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    1 day ago
  • $221.2k - $387.1k

     ...It all started when engineer Fred Luddy wrote code that automated a tedious task for his coworker, Phyllis. She cried tears of joy...  ...people. Job Description About SSO The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions... 
    Permanent employment
    Full time
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Shift work

    ServiceNow

    Washington DC
    4 days ago
  •  ...Senior Product Engineer, Treasury (Elixir) Remote — US-based, working EST hours About Vic.ai Vic.ai is building the autonomous finance platform for the modern enterprise. We use AI to automate accounts payable and treasury workflows so finance teams operate with more... 
    Remote work
    Flexible hours

    GrabJobs

    Washington DC
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!