Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Product Security Engineer

$161k - $247k
Full-time

Okta

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Security Team

Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth.

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box—we're looking for lifelong learners and people who can improve us with their unique experiences.

Join our team! We're building a world where Identity belongs to you.

The Staff Product Security Engineer Opportunity

The Security team's mission is to strengthen Okta's position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers.

The Staff AI Product Security Engineer joins a team with a clear mission: to shape the future of application security by researching and building systems that prove how AI can fundamentally augment, automate, and scale defense. This is a hybrid research, offensive and software engineering role centered on leveraging AI to uncover vulnerabilities, automate root cause analysis, automate exploitation, and generate secure code patches at cloud scale.

This role is built for engineers who want to push the limits of what AI can do for security, from benchmarking SOTA frontier models and fine-tuning open-weight models to building production-grade security tooling across Product Security. While a main focus will be on creating intelligent, automated security capabilities that keep Okta continuously ahead of emerging threats, performing full security reviews of Okta's products, as well as agentic architectures and internal AI pipelines, to uncover, exploit and fix vulnerabilities is also part of the work.

The ideal candidate thinks creatively but also like an attacker, builds like an engineer, and publishes their findings. We actively support external research disclosure through white papers, blog posts, and conference presentations.

What You Will Do

  • Lead technical capability research evaluating frontier LLMs and customized open-weight models for advanced code analysis, autonomous attack and logical security reasoning.
  • Engineer production-grade, AI-assisted security tools that automate vulnerability discovery, triaging, and risk validation across codebases.
  • Architect context-aware code-repair engines that automatically recommend verified security fixes to software development teams.
  • Build automated Proof-of-Concept (PoC) exploit generators in sandboxed runtimes to safely perform root cause analysis on identified vulnerabilities.
  • Modify and fine-tune open-source models to carry out domain-specific defensive and offensive code analysis tasks.
  • Embed AI models, unified APIs, and model-agnostic execution frameworks across Product Security tools to multiply team capabilities.
  • Assess and secure internal AI platforms, agentic execution runtimes, and AI coding agent container environments.
  • Perform manual code review and AI-assisted deep dives of Okta's products and system implementations across multiple languages.
  • Develop threat models for agentic architectures, orchestration layers, and LLM-integrated services.
  • Deliver technical reference blueprints and publish external research demonstrating how AI models transform modern security engineering.
  • Run the AI security vendor and tooling evaluation program: design and operate a benchmarking harness against AI security tools.
  • Conduct offensive security research focused on agentic AI systems: prompt injection, agent privilege escalation, tool-binding abuse, and agentic supply chain attacks against internal developer platforms.
  • Translate research findings into actionable guidance for engineering teams building AI-powered features and platforms.

What You Bring

  • 8+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security.
  • Experience building security tooling and automation (scripts, scanners, detection logic, or evaluation harnesses) that other engineers actually use.
  • Strong offensive mindset: the ability to model what an adversary does to break systems and how this translates to an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete.
  • Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures, not just familiarity with the concepts, but evidence of having found real vulnerabilities in them.
  • Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++).
  • Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems.
  • Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks.
  • Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues.
  • Experience producing external security research, publications, conference talks, blog posts, or open-source tooling.

Desired Skills and Abilities

  • Experience in vulnerability research and vulnerability discovery through source code auditing, as well as penetration testing skills.
  • Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures).
  • Experience with SAST, DAST, SCA, and fuzzing tooling applied to AI/ML pipelines or CI/CD systems.
  • Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws.
  • Ability to develop proof-of-concept exploits that demonstrate vulnerabilities to engineering and product leadership. Plus, if able to exploit AI/Agentic-specific vulnerabilities
  • Experience contributing to security standards, SDL processes, or vulnerability research programs.

#LI-SM1

#LI-Hybrid
#LI-Remote

P25264_3461996

The annual base salary range for this position for candidates located in the San Francisco Bay area is between:

$180,000—$247,000 USD

Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit:

The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between:

$161,000—$221,000 USD

The Okta Experience

  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Staff Product Security Engineer in Washington DC vacancy
  • $156k - $253k

     ...computer vision, sensor fusion, and networking technology to the military in months, not years.ABOUT THE TEAMWe're seeking a product security engineer to own security for assigned products in your technical domain, provide expert consultation on security architectures,... 
    Suggested
    Full time
    Work experience placement
    Immediate start

    Anduril Industries

    Washington DC
    10 hours ago
  •  ...SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life on Mars.PRODUCT SECURITY ENGINEER (STARSHIELD)Starshield leverages SpaceX’s Starlink technology and launch capability to support national security efforts.... 
    Suggested
    Permanent employment
    Temporary work
    Immediate start
    Flexible hours
    Weekend work

    SpaceX

    Washington DC
    3 days ago
  •  ...deliver predictive and generative AI, and enables leaders to secure their AI assets. Organizations worldwide rely on...  ...today and in the future. DataRobot is seeking an experienced Staff Product Security Engineer to drive security innovation while ensuring our platform... 
    Suggested
    Full time
    Local area
    Worldwide
    Flexible hours

    DataRobot

    Washington DC
    4 days ago
  • $180k - $240k

     ...better, brighter future for the next generation depends on it. We are seeking a seasoned and highly accomplished Senior Staff Product Security Engineer to join our security leadership team. This is a senior individual contributor role that carries significant... 
    Suggested
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours
    Day shift

    GrabJobs

    Arlington, VA
    3 days ago
  •  ...United States Digital Space LLC is seeking a highly technical Security Engineer to join our Product Security team. You will conduct in-depth code reviews, implement security best practices, and influence our security strategy for AI/ML software ecosystems. The role... 
    Suggested

    United States Digital Space LLC

    Washington DC
    3 days ago
  •  ...Job Description Job Description Job title: Product Security PKI and Cloud Environment Architect \tLeads the development, implementation...  ...environment architect \t5+ years of experience \tAny Engineering or computer science BS or BS information systems degree... 
    Contract work
    For contractors
    Work experience placement
    Immediate start
    Remote work

    Systemart LLC

    Washington DC
    20 days ago
  •  ...Responsibilities Investigate and respond to critical security issues across Apple products. Reverse engineer exploits and provide analysis of vulnerabilities, attack vectors, and security risks. Create tools and automation to identify security bugs. Collaborate... 
    Full time

    Apple

    Washington DC
    3 days ago
  • $144.8k - $261.45k

     ...The Opportunity Are you passionate about securing global systems and mitigating risks in a fast-paced environment? Adobe Security...  ...its Vulnerability Operation Center (VOC). As a VOC Senior Product Security Engineer, you will analyze and triage incoming identified... 
    Full time
    Temporary work
    Local area
    Worldwide

    Adobe

    McLean, VA
    4 days ago
  •  ...Job Description Job Description Senior Product Manager- Security Engineering Washington DC 20006 – 100% ONSITE Per Federal contract U.S. Citizenship Required Must be able to pass enhanced background screen (criminal, financial, drug) for Public Trust clearance... 
    Contract work
    Temporary work
    For contractors
    Local area

    System One

    Washington DC
    20 days ago
  •  ...Job Description Job Description TS/SCI w POLY Required **About the Role:** Join our team as a Security Product Reverse Engineer to analyze and audit security products, focusing on vulnerability research and code exploitation. This role involves hands-on work with... 

    Falls Technology

    McLean, VA
    20 days ago
  • $184k - $245k

     ...people to create extraordinary experiences together. Bring your whole self. The Role and Team We are seeking a Senior Staff Product Security Engineer to lead Medallia's security strategy and assurance efforts for AI-powered products, agentic systems, next-generation... 
    Temporary work
    Work experience placement
    Local area
    3 days per week

    Medallia

    Mc Lean, VA
    2 days ago
  • Job Description EMD LLC is looking for a Security Systems Design Engineer to join our team! In this role you will get to develop and design Technical Security Systems for Embassies and Consulates Worldwide . What You'll Be Doing Site surveys Conceptual design development... 
    Work experience placement
    Work at office
    Local area
    Worldwide

    Emd, Llc

    Alexandria, VA
    6 days ago
  • EMD LLC is seeking a Security Systems Design Engineer to develop and design Technical Security Systems for Embassies and Consulates Worldwide. The role includes site surveys, conceptual design, and complete security system design packages across multi-discipline campuses... 
    Worldwide

    Emd, Llc

    Alexandria, VA
    6 days ago
  • $134.5k - $265.1k

     ...Summary As a Cyber Forward Deployed Engineer (FDE), you will work at the intersection...  ...to deal shaping, influencing product direction, and providing appropriate support...  ...cybersecurity concepts (e.g., application security, cloud security, identity, detection engineering... 
    Local area
    Visa sponsorship

    Deloitte

    Rosslyn, VA
    3 days ago
  • $159.3k - $202.4k

    Amazon is seeking qualified Security Engineers to join our innovative, high energy Information Security team. In this role you will work within...  ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    10 hours ago
  • $178.4k - $226.7k

    Corporate Services Security (CPSS) is the Amazon security team aligned with Finance & Global...  ..., build, and scale securely. The Product Security Team within CPSS supports a large...  ...work, we provide opportunities for our engineers to pursue projects they are passionate about... 
    Internship
    Flexible hours

    Amazon

    Arlington, VA
    10 hours ago
  • Washington DCTechnology - Security /RemoteThe Senior Security Engineer II will be responsible for designing, implementing, and maintaining security services that support our business. You will understand data and automation are important ingredients to our mission and... 
    Temporary work
    Work at office
    Remote work
    Work from home
    Flexible hours

    Aledade

    Washington DC
    2 days ago
  •  ...the U.S. Department of State’s Bureau of Diplomatic Security (DS) - Training - Technical Security Engineering. The Advisor will play a critical role in refining...  ...eligible employees, Dexis provides healthcare insurance in addition to other staff welfare benefits and perks.
    Contract work
    Work at office

    Dexis Consulting Group

    Washington DC
    2 days ago
  • $136k - $184k

    Amazon’s Threat Hunting team is looking for a Security Engineer, Threat Hunting who is excited by the idea of searching for and uncovering...  ...maintaining a high bar for security across all of Amazon’s products and services. We offer talented security professionals the chance... 
    Internship
    Flexible hours
    Shift work

    Amazon

    Arlington, VA
    10 hours ago
  •  ...on delivering end-to-end solutions and products. Since 1998, we have successfully serviced...  ...:· Establish system-wide information security requirements based on policy and regulatory...  ...Responsibilities include secure systems engineering and development. This includes systems... 

    Comtech

    Washington DC
    4 days ago
  • $237.6k - $297k

     ...We are seeking a highly technical Security Engineer to join our Product Security team. This role is integral to ensuring the security and integrity of our products and services. You will conduct in-depth code reviews, implement security best practices, and influence the... 
    Full time

    United States Digital Space LLC

    Washington DC
    3 days ago
  • $117.2k - $176.7k

     ...of AI, and you are the future of Salesforce.The ExperienceThe security team at Salesforce deals with the most challenging problems in information security and we are seeking a Product Vulnerability Engineer to join one of the world's leading vulnerability response teams... 
    Full time

    Salesforce

    Washington DC
    1 day ago
  • $105.4k - $207.8k

     ...future of Deloitte’s business through new AI-native platforms and products. The team is responsible for identifying, nurturing, scaling,...  ...organizations. Position Summary As a Product Forward Deployed Engineer (pFDE), this role is the technical engine of the FastForward pre... 
    Work experience placement
    Local area

    Deloitte

    Rosslyn, VA
    1 day ago
  • $97.7k - $162.8k

    Position Summary Our Deloitte AI & Engineering team to transform technology platforms, drive innovation, and help make a significant...  ...as a Service team, you will be responsible for: Define product vision, target users, and value proposition for delivery efforts... 
    Local area
    Flexible hours

    Deloitte

    Rosslyn, VA
    10 hours ago
  • $77.6k - $176k

    AI-Powered Cyber Defense Product Sales EngineerThe Opportunity:Join a team delivering next...  ...defense solutions that transform how Security Operations Centers (SOCs) detect, investigate...  ...to cyber threats. As a Senior Sales Engineer, you'll serve as the technical lead throughout... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    McLean, VA
    2 days ago
  •  ...Responsibilities Conduct threat modeling with product teams and design secure architectures for new features....  ...security patterns and libraries for engineering teams. Design security features...  ...role is open to mid, senior, and staff-level candidates. Benefits... 
    Full time
    Flexible hours

    WRITER

    Washington DC
    9 days ago
  •  ...Senior Product Engineer, Treasury (Elixir) Remote — US-based, working EST hours About Vic.ai Vic.ai is building the autonomous finance platform for the modern enterprise. We use AI to automate accounts payable and treasury workflows so finance teams operate with more... 
    Remote work
    Flexible hours

    GrabJobs

    Arlington, VA
    3 days ago
  • $174k - $210k

     ...representation to best serve the people who use our products. We believe in creating inclusive and...  ...We are looking for a Senior Product Engineer with 8+ years of experience to improve...  ...times per day Proactively address security, observability, and telemetry in everything... 
    Full time
    Seasonal work
    Remote work
    Home office

    GrabJobs

    Arlington, VA
    4 days ago
  • $146k - $234k

    ResponsibilitiesPeraton is seeking an Information Systems Security Engineer - to support its Federal Strategic Cyber programs.Location: Washington...  ..., analysis, and test of information security systems and products.8 years of experience applying methods, standards and... 
    Contract work
    For contractors
    Shift work

    Peraton Corporation

    Washington DC
    2 days ago
  • $145k - $200k

    Washington, D.C.Information Security /Full-time /HybridA World-Changing CompanyPalantir builds...  ...Offensive Security team probes our own products, infrastructure, and cloud environment...  ...would. As an Offensive Security Engineer, you will test internal applications and... 
    Full time
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Product Security Engineer. Be the first to apply!