Staff Product Security Engineer
Job Description
Staff Product Security Engineer at Okta in New York, NY (hybrid) focuses on security reviews, guiding secure development practices, and handling externally reported vulnerabilities through code reviews, penetration testing, and architectural security assessments.
Responsibilities
- Perform security reviews for new features and major changes, including design reviews, threat modeling, and penetration testing.
- Conduct manual secure code reviews across multiple programming languages to identify vulnerabilities.
- Identify, prioritize, and mitigate security vulnerabilities, delivering clear remediation guidance to engineering teams.
- Lead product security incidents, assess risk, and coordinate remediation efforts across stakeholders.
- Develop security tooling and automation to enhance vulnerability detection and assessment.
- Mentor junior engineers and advise non-security staff on secure development practices.
- Represent Okta externally through security research, conference talks, and publications.
Requirements
- Proven ability to identify OWASP Top 10 and CWE Top 25 vulnerabilities via manual code review.
- Strong experience in penetration testing and secure development practices.
- Technical expertise in assessing Large Language Models (LLMs) and securing AI integrated software architectures.
- Proficiency with multiple programming languages such as Java, Go, Python, and C/C++.
- Deep understanding of authentication and authorization protocols, including OIDC, SAML, and OAuth.
- Excellent communication skills to explain risks and remediation to developers and leadership.
- Ability to automate security testing using LLMs and scripting languages (Python, Bash, etc.).
- Experience leading security incidents and conducting risk assessments.
Technologies
- Java
- Go
- Python
- C/C++
- Large Language Models (LLMs)
- SAML
- OAuth
- OIDC
- Bash
Benefits
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection and Community