Назад
5 дней назад

Staff Product Security Engineer (AI)

180 000 - 247 500$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Product Security Engineer, Reviews (AI): Conducting product security reviews, manual code reviews, threat modeling, penetration testing, and incident response for Okta’s identity platforms with an accent on authentication protocols, AI-integrated architectures, and LLM security. Focus on building security automation, identifying complex vulnerabilities, guiding remediation, and communicating research to engineering teams and external audiences.

Location: Hybrid in Bellevue, Washington; Chicago, Illinois; New York, New York; San Francisco, California; Washington, DC; or Toronto, Ontario, Canada

Annual base salary: $180,000–$247,500 USD for specified US locations; additional ranges are listed for other US locations and Canada.

Company

Okta builds identity and access management infrastructure that helps organizations securely adopt cloud and AI technologies.

What you will do

  • Conduct design reviews, threat modeling, penetration testing, and security assessments for new features and major changes.
  • Perform manual secure code reviews across multiple programming languages and identify product vulnerabilities.
  • Lead product security incidents, assess risk, and drive remediation with engineering teams.
  • Build security tools and automation to improve vulnerability detection and assessment.
  • Advise developers and non-security staff on secure development practices and mentor junior engineers.
  • Represent Okta through security research, conference presentations, and publications.

Requirements

  • Expertise identifying OWASP Top 10 and CWE Top 25 vulnerabilities through manual code review.
  • Strong experience with penetration testing, secure development, and security incident leadership.
  • Deep technical experience assessing Large Language Models and securing AI-integrated software architectures.
  • Proficiency in multiple programming languages, including Java, Go, Python, C, or C++.
  • Deep understanding of OIDC, SAML, OAuth, authentication, and authorization protocols.
  • Ability to automate security testing with LLMs and scripting tools such as Python and Bash.

Nice to have

  • Mobile, desktop, network protocol, cryptography, SAST, DAST, SCA, fuzzing, and proof-of-concept exploit development experience.

Culture & Benefits

  • Equity, bonus, health, dental, and vision insurance.
  • 401(k), flexible spending account, paid time off, and parental leave in the US.
  • RRSP matching, healthcare spending, telemedicine, and paid leave in Canada.
  • In-person onboarding and connection across a global community spanning more than 20 offices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →