This position is no longer accepting applications
Closed on August 24, 2026.
This role is filled β get an email when new Engineering roles open on EngineerJobs.io:
Staff Product Security Engineer, Reviews
Ai Security
Api Security
Application Security
Cybersecurity Tools
Dynamic Application Security Testing
Engineering
Identity and Access Management
Incident Response
Information Security
InfoSec
Security
Security As Code
Security Assurance
Security Automation
Security Testing
Software Security
View similar jobs
Get alerted when similar jobs are posted — set up a New Engineering jobs on EngineerJobs.io alert.
See other roles at Okta.
Job Description
The Staff Product Security Engineer will conduct security reviews, guide secure development practices, and handle externally reported vulnerabilities across Okta's products, including code reviews, penetration testing, and architectural security assessments.
Responsibilities
- Conduct security reviews including design reviews, threat modeling, and penetration testing for new features and major changes.
- Perform manual secure code reviews across multiple programming languages.
- Identify and mitigate security vulnerabilities, providing clear guidance to engineering teams.
- Lead product security incidents, assess risks, and drive remediation efforts.
- Develop security tools and automation to improve vulnerability detection and assessment.
- Mentor junior engineers and provide guidance to non-security staff on secure development practices.
- Represent Okta externally through security research, conference talks, and publications.
Requirements
- Expertise in identifying OWASP Top 10 and CWE Top 25 vulnerabilities through manual code review.
- Strong experience in penetration testing and secure development practices.
- Deep technical background in assessing Large Language Models and securing AI integrated software architectures.
- Proficiency in multiple programming languages, including Java, Go, Python, and C/C++.
- Deep understanding of authentication and authorization protocols (OIDC, SAML, OAuth).
- Strong communication skills to explain risks and remediation to developers and leadership.
- Ability to automate security testing using large language models and scripting (Python, Bash, etc.).
- Experience leading security incidents and risk assessments.
Technologies
- Java
- Go
- Python
- C/C++
- OIDC
- SAML
- OAuth
- Large Language Models (LLMs)
- SAST
- DAST
- SCA
- Fuzzing tools
Benefits
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
The Okta Experience
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community