Staff Product Security Engineer, Offensive Security

Toronto

Get to know Okta

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth. 

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences. 

Join our team! We’re building a world where Identity belongs to you.

The Offensive Security Team, part of Product Security, actively assesses the security of Okta's products, services, and infrastructure, and we are seeking a highly technical and driven staff-level engineer to contribute to this effort. This role demands more than running vulnerability scans. Excelling here requires a thorough understanding of offensive security testing and a strong drive to identify and leverage security weaknesses. Above all, the most critical attribute of this role is an innate ability to think and operate as a sophisticated adversary. This skill is key to solving security challenges with deep technical expertise and creativity.

The ideal candidate will possess demonstrable expertise in the following areas:

  • Cloud Security: In-depth knowledge of AWS security architecture, services, and common attack vectors, with a proven ability to compromise AWS Compute resources. Experience with Google Cloud Compute and Azure is highly desirable.
  • Operating Systems: Deep familiarity with Linux and macOS operating systems, including their security features, command-line tools, and common attack surfaces.
  • Application Security: Strong understanding of application security principles, common vulnerabilities (OWASP Top 10, etc.), and backend testing methodologies and techniques.
  • Authentication Protocols: Familiarity with various authentication and authorization mechanisms, such as SAML, OAuth 2.0, and OIDC, and their associated security considerations
  • Automation and Tooling: A strong desire and proven ability to automate security tasks and develop custom tooling to facilitate security reviews and pentesting
  • TechOps: Experience with TechOps tooling and processes, such as Chef, Kubernetes, Terraform, and ArgoCD, enabling a comprehensive understanding of the operational environment.
  • Communication: Excellent written and verbal communication skills with the ability to clearly and concisely articulate vulnerabilities and remediation strategies to technical and non-technical audiences

We actively encourage and support the external publication of impactful security research and findings through papers, blog posts, and presentations at industry conferences.

What You Will Do

  • Apply attacker mindset to identify, plan, and exploit complex security gaps across app, cloud, and network layers.
  • Conduct targeted security assessments and pentests; deliver actionable findings, detailed exploit recreation, and architectural remediation guidance.
  • Act as a security SME across internal teams and represent Okta in internal and external forums when appropriate.
  • Design and deploy disposable, repeatable, verifiable automation and infrastructure to support rapid, on-demand security engagements.
  • Periodically triage internal vulnerability tickets and external bug bounty submissions.
  • As needed, design and deploy tooling, automation, or infrastructure to support security engagements.

What You Bring

  • Demonstrable experience in penetration testing web applications and infrastructure (5+ years preferred)
  • Strong expertise in securing cloud environments (AWS, GCP, Azure)
  • Proven ability to identify and demonstrate security vulnerabilities in infrastructure
  • Familiarity with Threat Modeling concepts and frameworks
  • Experience with Infrastructure as Code (e.g., Terraform) for building and testing environments.
  • Solid understanding of modern cryptographic principles and their application
  • Experience in automating security testing and streamlining offensive tasks.
  • Ability to think strategically and develop comprehensive attack scenarios
  • Effective communication skills for conveying technical security findings to various audiences
  • A proactive approach to learning about emerging threats and developing new security techniques.
  • Experience or interest in mentoring and sharing knowledge with team members.

#LI-REMOTE


#LI-SH1

Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit: https://rewards.okta.com/can.

The annual base salary range for this position for candidates located in Canada is between:$141,000$211,000 CAD

What you can look forward to as a Full-Time Okta employee!

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! https://www.okta.com/company/careers/.

Some roles may require travel to one of our office locations for in-person onboarding.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at https://www.okta.com/privacy-policy/

Apply

Resume
Upload Resume/CV (PDF must be less than 8 MB )
Cover Letter
Upload Cover Letter (PDF must be less than 8 MB )
I acknowledge and agree to the processing of my personal data in accordance with Okta's Privacy Policy.

https://www.okta.com/privacy-policy/

(California residents, click here)

I would like to be considered for future positions at Okta.