Staff Product Security Engineer, Reviews
Job Description
Okta, a leader in identity and access management, is seeking a Staff Product Security Engineer to lead security reviews, threat modeling, and vulnerability management across its product portfolio. Based in Chicago with a hybrid work arrangement, this role focuses on secure design, code analysis, and the security of authentication protocols and AI-enabled features. The position offers a compensation range of USD 180,000 to 247,500 per year.
Responsibilities
- Perform security assessments on new features and major changes, including design reviews, threat modeling, and penetration testing.
- Carry out manual secure-code reviews across multiple programming languages.
- Identify vulnerabilities and guide engineering teams on remediation strategies.
- Take the lead on product security incidents, assess risks, and steer remediation efforts.
- Create security tooling and automation to enhance vulnerability detection and evaluation.
- Mentor junior engineers and advise non-security staff on secure development practices.
- Represent Okta in external security research, conference presentations, and publications.
Requirements
- Proficient at identifying OWASP Top 10 and CWE Top 25 vulnerabilities via manual code review.
- Solid background in penetration testing and secure development lifecycle practices.
- Deep technical expertise in evaluating Large Language Models and securing AI-enabled software architectures.
- Proficient in multiple languages such as Java, Go, Python, and C/C++.
- Strong understanding of authentication and authorization protocols including OIDC, SAML, and OAuth.
- Excellent communication skills to convey risks and remediation plans to developers and leadership.
- Ability to automate security testing using LLMs and scripting languages like Python and Bash.
- Experience leading security incidents and conducting risk assessments.
Technologies
- Java, Go, Python, C/C++, Bash
- SAML, OAuth, OIDC
- Large Language Models (LLMs)
- SAST, DAST, SCA, fuzzing tools
Benefits
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
Desired Skills and Abilities
- Experience conducting security testing on mobile (iOS/Android) and desktop (Windows/macOS) platforms.
- Familiarity with SAST, DAST, SCA and fuzzing tools.
- Strong cryptographic knowledge and secure implementation practices.
- Experience analyzing network protocols and securing network traffic.
- Ability to develop proof-of-concept exploits to demonstrate vulnerabilities.