Назад
9 дней назад

Staff Product Security Engineer (AI)

141 000 - 193 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Product Security Engineer, Reviews (AI/Cybersecurity): Conducting product security reviews, threat modeling, penetration testing, and secure code reviews for Okta’s identity platforms with an accent on authentication protocols, AI-integrated architectures, and LLM security. Focus on building security automation, leading vulnerability and incident remediation, developing proof-of-concept exploits, and communicating risks to engineering teams and external audiences.

Location: Hybrid role in Toronto, Ontario, Canada

Salary: $141,000–$193,000 USD annual base salary for candidates located in Canada. Equity, bonus, and benefits may also apply.

Company

Okta builds trusted identity infrastructure that helps organizations securely manage access for people and AI-enabled systems.

What you will do

  • Conduct design reviews, threat modeling, penetration testing, and security assessments for new features and major product changes.
  • Perform manual secure code reviews across multiple programming languages and identify product vulnerabilities.
  • Provide engineering teams with clear remediation guidance and lead product security incidents and risk assessments.
  • Develop security tools and automation to improve vulnerability detection and assessment.
  • Mentor junior engineers and advise non-security staff on secure development practices.
  • Represent Okta through security research, conference presentations, publications, and external communication.

Requirements

  • Expertise identifying OWASP Top 10 and CWE Top 25 vulnerabilities through manual code review.
  • Strong experience with penetration testing, secure development practices, and security incident leadership.
  • Deep technical experience assessing Large Language Models and securing AI-integrated software architectures.
  • Proficiency in multiple programming languages, such as Java, Go, Python, C, or C++.
  • Deep understanding of OIDC, SAML, OAuth, authentication, and authorization protocols.
  • Ability to automate security testing with LLMs and scripting tools such as Python and Bash, and communicate risks to developers and leadership.

Nice to have

  • Mobile security testing experience across iOS and Android, or desktop security testing across Windows and macOS.
  • Familiarity with SAST, DAST, SCA, and fuzzing tools.
  • Strong cryptographic knowledge and experience analyzing network protocols and traffic security.
  • Ability to develop proof-of-concept exploits to demonstrate vulnerabilities.

Culture & Benefits

  • Hybrid work environment with an in-person onboarding experience.
  • Health, dental, and vision insurance.
  • RRSP matching, healthcare spending support, and telemedicine.
  • Paid leave, including PTO and parental leave.
  • Opportunities to publish security research and present at conferences.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →