Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Staff Security Engineer - Vulnerability Management US Public Sector

$180k - $247.5k

Okta, Inc.

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

Staff Security Engineer - Vulnerability Management, US Public Sector

The Okta Security team's mission is to strengthen Okta's position as the leading Identity-as-a-Service solutions through identifying and resolving risks to the employees, product, and most importantly, our customers. With the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business.


The Staff Security Engineer for Public Sector is a key member of the Okta Security team and an essential collaborator with our broader Engineering organization playing a key part in executing the Vulnerability Management Program's strategy. The Vulnerability Management Program is a crucial pillar of the security organizations' imperative to reduce the threats to Okta's infrastructure and applications. You'll be an integral part of building and sustaining strong and effective relationships across Okta with our Engineering, Product and Business Technology counterparts.

What you'll do
  • Own the full lifecycle operations of Asset and Vulnerability Management scanning and reporting infrastructure, including designing new cloud based and on-prem deployments as required.
  • Assess new and existing scan technologies to determine potential business value.
  • Monitor and respond to security inquiries, requests, and incidents, understanding the technical details of the published vulnerabilities as well as their real risk. Effectively communicate the perceived and real vulnerability impact given the infrastructure context.
  • Contribute to the definition and execution of internal processes that allow for accelerated remediation of critical vulnerabilities and zero-days.
  • Support audit, governance, risk and compliance teams in scanning and reporting on various regulatory compliance and industry best practices including PCI, ISO 27001/27017/27018 , NIST SP 800-53 and SOC 2.
  • Assist Okta's Public Sector compliance team in their preparation and maintenance of POAMs (Plan of Action & Milestones) and Continuous Monitoring (ConMon) processes.
  • Track and manage weaknesses or gaps in vulnerability related security controls, outlining tasks, required resources, milestones, and scheduled completion dates to achieve compliance with standards like NIST 800-171 and CMMC.
  • Participate in other special projects or strategic initiatives at the direction of the Security team.
What you'll bring
  • Must have ability to work independently on end to end delivery of infrastructure deployment and troubleshooting run time issues.
  • Proven experience in architecting, deploying, and operating self-hosted vulnerability management and cloud workload security solutions in AWS for regulated or restricted environments.
  • Must have proficiency in AWS core services such as host OS and container deployment, S3, DynamoDB, API Gateway, and others.
  • Experience working with AWS Lambda or similar serverless computing environments for automating vulnerability management scanning and reporting tasks.
  • Proficiency in Shell and python scripting and automation. Familiarity with other scripting and automation tools is a plus.
  • 5+ years of multifaceted cyber security experience in a technology-centric company.
  • 5+ years of experience in building vulnerability scanning solutions within a highly regulated environment such as FedRamp and various Impact Levels.
  • Functional knowledge of vulnerabilities, exploitation and remediation. You should be able to explain vulnerabilities and exploits as well as propose remediations for the most common vulnerabilities.
  • Experience with commercial or open-source vulnerability and misconfiguration scanners and reporting tools regarding Infrastructure/ IP based Assets, Containers, CSPM and CNAPP. Examples: Qualys, TenableSC, Prisma Cloud, Wiz, Orca, Lacework, Paramify, Atlassian Jira, ServiceNow etc. are a plus.
  • Familiarity with industry standards, frameworks and publications such as CVE, CVSS, EPSS, OWASP and CISA KEV catalog.
Who you are
  • You have a deep focus on execution, follow-through, accountability, and results.
  • You have a growth mindset; You thrive on challenge, you see learnings and opportunities, not failures.
  • You enjoy working with cross-functional teams and have exceptional stakeholder management skills.
  • You surround yourself with high energy, thriving teams to achieve quality outcomes.
Qualifications:
  • Bachelor's degree in Computer Science, Computer Engineering, or equivalent experience.
Additional requirements:
  • This position requires the ability to access federal environments and/or have access to protected federal data. As a condition of employment for this position, the successful candidate must be able to submit documentation establishing U.S. Person status (e.g. a U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee. 22 CFR 120.15) upon hire.
#LI-HYBRID

#LI-SM1

P24528_3344434

The annual base salary range for this position for candidates located in the San Francisco Bay area is between:


$180,000-$247,500 USD

Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit:


The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between:

$161,000-$221,000 USD

The Okta Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Personnel and Job Candidate Privacy Notice at
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the Staff Security Engineer - Vulnerability Management US Public Sector in Washington DC vacancy
  • $218.03k - $256.5k

     ...that demands the best of us, every day, as we build the...  ...The Identity and Access Management (IAM) program, housed within Security, is a cross-functional...  ...program, partnering with Engineering, IT, Platform, and business...  ...architecture, with a deep, Staff-level focus on Identity... 
    Suggested
    For contractors
    Local area

    Coinbase

    Washington DC
    4 days ago
  • $65 - $75 per hour

     ...cybersecurity operational environment and Vulnerability Management related requirements/needs; Engage...  ...scanning; Work Cyber related security operations ITSM (ServiceNow) assigned...  ...workstation anti-virus software, DAT, and engineer updates. Performs virus scans and... 
    Suggested
    Full time

    Aditi Consulting

    Washington DC
    10 hours ago
  • $218.03k - $256.5k

     ...demands the best of us, every day, as we build...  ...Infrastructure Security (InfraSec) is at the...  ...partners closely with engineering teams to design, implement...  ...configurations to identify vulnerabilities and recommend...  ...technical decisions, risk management strategies, and... 
    Suggested
    Local area

    Coinbase

    Washington DC
    5 days ago
  • $210k - $230k

     ...Upside is seeking an experienced Security Engineer to identify and mitigate application vulnerabilities. This role requires expertise in application security and a deep understanding of AWS architecture. Responsibilities include innovating security solutions and conducting... 
    Suggested
    Work at office

    Upside

    Washington DC
    3 days ago
  •  ...range of consulting services to US Federal Government, US...  ...Commercial clients. Services include Management & IT Consulting, Program &...  ...on IT Services and Cyber Security for clients in Civil and DoD...  ...Arcetyp LLC is looking for an Vulnerability Management Analyst (senior) to... 
    Suggested
    Full time
    H1b

    6AM City, LLC

    Washington DC
    3 days ago
  • $191k - $253k

     ...Anduril Industries is seeking a Staff Security Engineer to join their Application and Security Engineering team in Washington, D.C. In this role, you'll create and maintain applications that enforce the company's identity framework, develop integrations to unify identities... 

    Slope

    Washington DC
    4 days ago
  • $182k - $202k

     ...Continuous Threat Exposure Management (CTEM). The...  ...community of security researchers to continuously...  ...like bug bounty, vulnerability disclosure,...  ...Senior Security Engineer, Detection and Response...  ...that gives us the freedom to do...  ...Retirement plans Paid public holidays and unlimited... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    hackerone

    Washington DC
    10 days ago
  •  ...penetration testing and attack surface management. We help enterprises continuously find and fix vulnerabilities through our human‑AI combined...  ...for a technically strong Sales Engineer with an offensive security background to join our US sales team. You will be the trusted... 
    Remote job

    BreachLock, Inc.

    Washington DC
    2 days ago
  • $90k - $150k

     ...both cybersecurity and US Government policy. We'...  ...to ambiguous security requirements. Our mission...  ...Forward Deployed Security Engineer, you support a variety...  ...designing, building and managing systems Ability to...  ...encryption, networking, vulnerability scanning, audit logs)... 
    Work experience placement
    Work at office
    Remote work
    Work from home
    Relocation package

    Palantir Technologies

    Washington DC
    2 days ago
  • $114.39k - $240.35k

     ...and licensed security support to ensure...  ...Security Engineer/Analyst provides...  ...planning, risk management, certification...  ...security risks, vulnerabilities, and threats,...  ...civilian sectors. Learn more and...  ...please contact us ( . EEO is...  ...time or on-call staff, compensation... 
    Full time
    Contract work
    Part time
    Local area
    Remote work

    Noblis

    Washington DC
    5 days ago
  • $90k - $100k

     ...Dobbs Defense Solutions, LLC in Washington, DC, is seeking a Mid Level Systems Security Engineer. This role supports cybersecurity operations, vulnerability management, and RMF compliance activities for U.S. Coast Guard systems. Candidates should possess a Bachelor's... 

    Dobbs Defense Solutions, LLC

    Washington DC
    3 days ago
  •  ...SVP, Vulnerability Management & Cloud Security Posture Platform Engineering We're seeking a team member for the role of SVP, Vulnerability Management & Cloud Security Posture Platform Engineering to join our Cybersecurity Engineering Tools & Platforms team. This role... 
    Work experience placement

    BNY

    Washington DC
    2 days ago
  • $210k - $230k

     ...Director, Information Security and build relationships...  ...remediate application vulnerabilities. This individual...  ...posture and enable our engineers to code safely. Innovate...  ...coding and vulnerability management Assist penetration...  ...basis. Compensation: The US base salary range for... 
    Full time
    Work at office
    Flexible hours

    Upside

    Washington DC
    2 days ago
  • $191k - $253k

     ...ABOUT THE TEAM Anduril's Application and Security Engineering team is looking for a Staff Security Engineer to focus on Identity and Access Management and build and maintain world class...  ..., Azure, or GCP ecosystems and tooling US Salary Range: $191,000 — $253,000 USD The... 
    Full time
    Work experience placement

    Slope

    Washington DC
    3 days ago
  •  ...Description RiVidium is seeking a Vulnerability Management Analyst to support our planned MODES...  ...applicable Government personnel security requirements for the assigned role. For...  ...supporting cybersecurity operations, engineering, compliance, or analysis activities... 
    Full time
    Contract work
    Part time

    Rividium Inc

    Alexandria, VA
    2 days ago
  •  ...True Zero Vulnerability Management Position True Zero Technologies, a veteran-owned small business...  ...service posture for program office and engineering partners. Job Qualifications ~ Bachelor's degree ~3 years security-related experience. ~ Experience... 
    Work at office

    True Zero Technologies, LLC

    Washington DC
    1 day ago
  • Rividium Inc is seeking a Vulnerability Management Analyst to join their team supporting Military Community and Family Policy. This role involves analyzing vulnerabilities and coordinating corrective actions while maintaining rigorous remediation processes to support IT... 

    Rividium Inc

    Alexandria, VA
    3 days ago
  • # Vulnerability Management AnalystJobs via DiceBe an Early ApplicantFull TimemidWashington, District of Columbia, USPosted Today## Job DescriptionDice...  ...ServiceNow GRC module.* Need experience with ServiceNow Security Operations (SecOps)* Need experience with ServiceNow SecOps... 
    Work at office

    TryApplyNow

    Washington DC
    3 days ago
  •  ...active Top Secret Security Clearance Node is...  ...cybersecurity vulnerability analysis support...  ...practices, risk management techniques, critical...  ...Conduct prevalence and sector analysis of...  ...Science, Computer Engineering, Computer Information...  ...Core Values help us in our mission.... 

    Node.Digital LLC

    Arlington, VA
    4 days ago
  • Sr IT Security/Vulnerability Management Specialist AAC is seeking Senior Security Analyst...  ...science, cyber security, engineering, or a related technical...  ..., program, and technology staff. Expert knowledge of Tenable...  ...). Must obtain an agency public trust suitability... 
    Work experience placement
    3 days per week

    AAC

    Bethesda, MD
    3 days ago
  •  ...Information Security Engineer Nightwing provides technically advanced...  ...cyber defense and resiliency, vulnerability research, ubiquitous technical...  ...rapid deployment and management of secure cloud-based engagement...  ...you for considering joining us as we embark on this new journey... 
    Contract work
    Local area

    Nightwing

    Arlington, VA
    2 days ago
  •  ...Contribute to leading-edge security and resilience...  ...identify risks and vulnerabilities in people,...  ...and simulations (or manage a highly-skilled team...  ...testing ~ Knowledge of US financial services sector cybersecurity or...  ...Experience in reverse engineering standalone, thick... 
    Worldwide

    JPMorgan Chase & Co.

    Washington DC
    2 days ago
  • $220k - $235k

     ...Threat Exposure Management (CTEM). The HackerOne...  ...community of security researchers to...  ...like bug bounty, vulnerability disclosure,...  ...accountability. Staff Applications Engineer, GTM Systems...  ...approach that gives us the freedom to...  ...Retirement plans Paid public holidays and... 
    Apprenticeship
    Local area
    Remote work
    Flexible hours
    Shift work

    hackerone

    Washington DC
    8 days ago
  • $150k - $165k

     ...Title: Information System Security Engineer (ISSE) Team Lead (Navy RMF /...  ...security solutions to a range of US Government and US commercial...  ...cybersecurity and Risk Management Framework (RMF) activities for...  ...Manage POA&M tracking, vulnerability remediation, and risk mitigation... 
    Full time
    Temporary work
    Immediate start
    Remote work
    Flexible hours

    JFL Consulting

    Washington DC
    10 hours ago
  •  ...About Us Onyx Government Services, LLC., is a Service-Disable...  .... We specialize in data management, integration, and analysis...  ...Matter Expert (SME)–level Lead Security Engineer to lead application...  ...testing, threat modeling, and vulnerability remediation across a System... 
    Contract work
    Work at office
    Flexible hours

    Onyx Government Services,LLC

    Suitland, MD
    1 day ago
  • $110k - $230k

     ...being there when they need us most. We thrive through relentless...  ...This role is designed for a staff-level security practitioner with deep Cyber...  .... The Staff Security Engineer owns the end-to-end automated...  ...Ownership of control change management for new and modified controls... 
    Hourly pay
    Work experience placement
    Local area
    Remote work
    Flexible hours

    GEICO

    Bethesda, MD
    1 day ago
  • $237.6k - $297k

     ...seeking a highly technical Security Engineer to join our Product Security...  ...potential security vulnerabilities. You will also structure complex...  ...and efficient infrastructure management. Guide engineering teams...  ...the same role. This allows us to ensure a fair and thorough... 

    Scale AI, Inc.

    Washington DC
    3 days ago
  •  ...Inc. offers a diverse set of management and technology consulting...  ...community. Why Work with Us? We trust,...  ...an experienced Application Security Engineer to support the security and...  ...mitigating application security vulnerabilities through the use of industry... 
    Full time
    Remote work

    MBL Technologies

    Washington DC
    10 hours ago
  • $104.73k - $160k

     ...0 - $160,000.00 Security Clearance: TS/SCI...  ...Information System Security Manager (ISSM) for our...  ...of the Security Staff as required. ~...  ...STIGS, SCAP, SCC, vulnerability scanning and...  ...(AI/ML) experts; engineers; technologists; scientists...  ...-co.com and let us know the nature of... 
    Full time
    Work experience placement
    Work at office
    Local area
    Worldwide

    Huntington Ingalls Industries

    Alexandria, VA
    8 days ago
  •  ...highly skilled Senior Vulnerability Code Analyst...  ...critical in ensuring the security of our client’s platforms...  ...Experience with Ruby version management tools (e.g., RVM,...  ...Security, Software Engineering, or a related field...  ...project management or staff augmentation. CODICE... 

    6AM City, LLC

    Washington DC
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Staff Security Engineer - Vulnerability Management US Public Sector. Be the first to apply!