Staff Product Security Engineer, Reviews
Job description
About the role
You will perform comprehensive security reviews that span design, implementation, and deployment of Okta's platforms. The work involves guiding engineering teams toward safer development habits while handling externally reported vulnerabilities with precision. You will conduct code reviews, penetration testing, and architectural security assessments to validate system integrity. The goal is to ensure the security and resilience of Okta's platforms and features across the entire product lifecycle. This position is not for those who depend solely on automated vulnerability scanning or lack deep manual investigation skills. It requires a deep technical understanding of web applications, backend services, and advanced penetration testing methodologies. You will build tools that proactively identify vulnerabilities and automate security processes to scale protection. You will communicate risks, impact, and remediation strategies to developers, leadership, and external audiences through documentation, presentations, and publications. The role includes assessing AI-integrated software architectures and securing Large Language Models against emerging threats and modern vulnerability classes. You will influence security standards and contribute to the broader security community through research and thought leadership.
Key facts
Location options include Bellevue, Washington; Chicago, Illinois; New York, New York; San Francisco, California; Toronto, Ontario, Canada; Washington, DC. The engagement model is hybrid. The base compensation is $252620 annually.
What you will do
You will architect secure flows before implementation, guiding engineering teams toward safer designs and preventing issues early in the lifecycle. You will build custom scanners and analysis tools that surface hidden risks in code and infrastructure, reducing manual effort and increasing coverage. You will champion external disclosures through papers, talks, and detailed publications that highlight findings and improve industry knowledge. You will conduct rigorous penetration tests that mimic real adversaries to test platform resilience and uncover subtle weaknesses. You will lead product security incidents, assess risks accurately, and drive remediation efforts to closure in a timely manner. You will mentor engineers across multiple languages so that secure practices become default habits and reduce rework. You will review authentication protocols such as OIDC, SAML, and OAuth for design and implementation flaws that could lead to compromise. You will assess AI-integrated features and Large Language Models for emerging threat vectors and novel attack surfaces. You will prioritize findings based on impact, exploitability, and business risk to focus remediation effectively. You will collaborate with cross-functional teams to define security requirements and ensure alignment with compliance frameworks and best practices.
Requirements
You must manually review code to identify OWASP Top 10 and CWE Top 25 issues without relying only on tools, ensuring thorough analysis. You must understand web applications, backend services, and penetration testing methodologies at a deep level to assess complex systems. You must have strong experience with authentication and authorization protocols including OIDC, SAML, and OAuth to evaluate their secure implementation. You must assess AI-integrated software architectures and defend Large Language Models against modern vulnerabilities and adversarial techniques. You must communicate risk clearly to developers, leadership, and external audiences in writing and talks to enable informed decisions. You must automate security testing using scripts and LLMs to scale vulnerability detection and improve efficiency. You must lead product security incidents, evaluate impact accurately, and drive remediation to closure with measurable progress. You must have years of experience handling security incidents and performing threat assessments to respond to sophisticated threats. You must demonstrate a track record of identifying and mitigating high-severity vulnerabilities in production environments. You must be comfortable working in a fast-paced environment where priorities shift based on emerging risks and business needs.
Nice to have
Experience in mobile iOS, Android, and desktop Windows, macOS security testing to broaden assessment coverage. Familiarity with SAST, DSA, SCA, and fuzzing tools to enhance testing capabilities and efficiency. Strong cryptographic knowledge and secure implementation practices to prevent common pitfalls. Experience analyzing network protocols and traffic security to identify weaknesses in communication channels. Ability to develop proof of concept exploits to demonstrate vulnerabilities and validate risk realistically.
Skills & tools
Java, Go, Python, C/C++, SAML, OAuth, OIDC.
What you'll do
The Okta and Auth0 Platforms enable secure access, authentication, and automation - putting identity at the heart of business security and growth.