Staff Product Security Engineer, Reviews
Senior
Application Security
Cybersecurity Tools
Dynamic Application Security Testing
Engineer
Fuzzing
Identity and Access Management
Incident Response
Information Security
InfoSec
Security
Security Automation
Security Testing
Software Security
Static Application Security Testing
Static Code Analysis
Job Description
A benefits-forward role with a hybrid Bellevue, WA location, offering a competitive salary range and a culture that prioritizes well-being, social impact, and growing talent. This position provides a path to lead secure development for Okta products, advance AI security, and collaborate across engineering teams. Salary: USD 180,000 - 247,500 per year.
Responsibilities
- Conduct security reviews, including design reviews, threat modeling, and penetration testing of new features and major changes.
- Perform manual secure code reviews across multiple programming languages.
- Identify and mitigate security vulnerabilities, providing clear guidance to engineering teams.
- Lead product security incidents, assess risks, and drive remediation efforts.
- Develop security tools and automation to improve vulnerability detection and assessment.
- Mentor junior engineers and provide guidance to non-security staff on secure development practices.
- Represent Okta externally through security research, conference talks, and publications.
Requirements
- Expertise in identifying OWASP Top 10 and CWE Top 25 vulnerabilities through manual code review.
- Strong experience in penetration testing and secure development practices.
- Deep technical background in assessing Large Language Models (LLMs) and securing AI integrated software architectures.
- Proficiency in multiple programming languages (Java, Go, Python, C/C++).
- Deep understanding of authentication and authorization protocols (OIDC, SAML, OAuth).
- Strong communication skills to explain risks and remediation to developers and leadership.
- Ability to automate security testing using LLMs and scripting (Python, Bash, etc.).
- Experience leading security incidents and risk assessments.
- Experience in mobile (iOS/Android) and desktop (Windows/macOS) security testing.
- Familiarity with SAST, DAST, SCA, and fuzzing tools.
- Strong cryptographic knowledge and secure implementation practices.
- Experience analyzing network protocols and traffic security.
- Ability to develop proof-of-concept exploits to demonstrate vulnerabilities.
Technologies
- Java
- Go
- Python
- C/C++
- OIDC
- SAML
- OAuth
- Large Language Models (LLMs)
- Bash
- SAST
- DAST
- SCA
- Fuzzing tools
Benefits
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
The Okta Experience
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community