EngineerJobs.io
← Back to all jobs

Job Description

Join Okta in Chicago, IL on a hybrid schedule as a Staff Product Security Engineer focused on security reviews, threat modeling, and vulnerability management for Okta’s products. The role includes code reviews, penetration testing, and architectural security assessments with emphasis on authentication protocols and AI/LLM security. This position offers a competitive annual salary range of USD 180,000 to 247,500.

Benefits

  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

Responsibilities

  • Conduct security reviews that cover design assessments, threat modeling, and penetration testing for new features and major changes.
  • Perform manual secure code reviews across multiple programming languages.
  • Identify and mitigate security vulnerabilities, providing clear guidance to engineering teams.
  • Lead product security incidents, assess risk, and drive remediation efforts.
  • Develop security tools and automation to improve vulnerability detection and assessment.
  • Mentor junior engineers and advise non-security staff on secure development practices.
  • Represent Okta externally through security research, conference talks, and publications.

Requirements

  • Proven ability to identify OWASP Top 10 and CWE Top 25 vulnerabilities via manual code reviews.
  • Strong experience in penetration testing and secure development practices.
  • Deep technical background in evaluating Large Language Models and securing AI-enabled software architectures.
  • Proficiency with multiple programming languages, including Java, Go, Python, and C/C++.
  • Solid understanding of authentication and authorization protocols (OIDC, SAML, OAuth).
  • Effective communication skills to explain risks and remediation to developers and leadership.
  • Ability to automate security testing using LLMs and scripting (Python, Bash, etc.).
  • Experience leading security incidents and risk assessments.

Technologies

  • Java, Go, Python, C/C++, Bash
  • SAML, OAuth, OIDC
  • Large Language Models (LLMs)
  • SAST, DAST, SCA, fuzzing tools

Desired Skills and Abilities

  • Experience in mobile (iOS/Android) and desktop (Windows/macOS) security testing.
  • Familiarity with SAST, DAST, SCA, and fuzzing tools.
  • Strong cryptographic knowledge and secure implementation practices.
  • Experience analyzing network protocols and traffic security.
  • Ability to develop proof-of-concept exploits to demonstrate vulnerabilities.

Similar Jobs