← Back to job listings
OK
Staff Product Security Engineer
Okta · Washington, United States
About The Role
Join Okta, the leading Identity-as-a-Service solutions provider, as a Staff Product Security Engineer. In this research and engineering role, you will focus on identifying and resolving security risks associated with agentic AI systems. Your work will shape security requirements, drive reusable security tooling, and influence Okta's AI and agent-based system security approach. You will conduct offensive security research, perform security assessments, build reusable security tooling, and represent Okta externally through research and publications.
- Conduct offensive security research focused on agentic AI systems, including prompt injection and privilege escalation.
- Perform security assessments of Okta's AI platforms, build reusable security tooling, and run the AI security vendor evaluation program.
- Mentor engineers across Product Security on AI/agentic security concepts, tooling, and assessment methodology.
- Desired Skills and Abilities
- 8+ years of experience in information security, with meaningful depth in application security, offensive research, or AI/ML security
- Strong offensive mindset: the ability to model what an adversary does to break systems and how this translates to an agentic system, identify where the model's reasoning or the orchestration layer breaks down, and construct scenarios that make the risk concrete
- Experience building security tooling and automation (scripts, scanners, detection logic, or evaluation harnesses) that other engineers actually use
- Advanced experience in threat modeling, manual code review, and penetration testing, applied to complex distributed systems
- Experience producing external security research, publications, conference talks, blog posts, or open-source tooling
- Demonstrated hands-on experience assessing LLM-integrated systems and agentic AI architectures, not just familiarity with the concepts, but evidence of having found real vulnerabilities in them
- Knowledge of authentication and authorization protocols (OIDC, OAuth 2.0, SAML) and their implementation risks
- Strong communication skills: the ability to write clearly for technical and non-technical audiences, document research findings with precision, and present at external venues
- Proficiency in at least two programming languages (Python and one of: Go, Java, TypeScript, C/C++)
- Familiarity with agentic framework internals (tool-use protocols, MCP, function-calling patterns, agent orchestration architectures)
- Experience in vulnerability research and vulnerability discovery through source code auditing, as well as penetration testing skills
- Experience with SAST, DAST, SCA, and fuzzing tooling applied to AI/ML pipelines or CI/CD systems
- Strong cryptographic knowledge and experience in identifying cryptographic implementation flaws
- Ability to develop proof-of-concept exploits that demonstrate vulnerabilities to engineering and product leadership. Plus, if able to exploit AI/Agentic-specific vulnerabilities
- Experience contributing to security standards, SDL processes, or vulnerability research programs
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring