Principal Forward Deployed Engineer

Okta Okta · Enterprise · United Kingdom · Remote · Okta for AI Agents-764

Okta is seeking a Principal Forward Deployed Engineer to be the senior technical authority for agent identity within their AI for Agents initiative. This role involves defining reference architectures, leading complex deployments, mentoring teams, and shaping product roadmaps by synthesizing field learnings. The position requires deep expertise in distributed systems, identity protocols, agent security, and fine-grained authorization, with a proven track record of hands-on AI integration and influencing technical direction.

What you'd actually do

  1. Own the reference architecture. Define the canonical agent identity, delegation, audit, and kill-switch patterns that Senior FDEs deploy across the portfolio, and keep them current as the standards and the product move.
  2. Lead the hardest accounts. Personally own the most strategic, regulated, or technically novel deployments, the ones where there is no playbook yet.
  3. Raise the technical bar. Review other FDEs’ architectures, coach senior customer engineers and your own team, and set the standard for what good looks like in the field.
  4. Shape the roadmap. Synthesize patterns across every account into a clear point of view, and work directly with product and engineering leadership to prioritize what ships next.
  5. Represent Okta as a technical authority. Brief CISO, CIO, and Chief AI Officer audiences, contribute to the standards and frameworks shaping agent identity, and carry the external technical voice.

Skills

Required

  • 10+ years shipping production software
  • deep distributed systems and identity experience
  • track record of staying hands-on while setting direction
  • OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD and DCR, DPoP
  • OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS, plus MCP, A2A, ISO/IEC 42001, and the EU AI Act
  • ReBAC and ABAC with policy engines (OPA, Cedar, OpenFGA, or equivalent)
  • Production integrations across the major agent platforms and MCP
  • daily AI-native development
  • record of setting technical direction across multiple teams or accounts
  • mentoring senior engineers
  • Customer-facing authority
  • High agency, founder’s mindset

Nice to have

  • Contribution to standards or open source is a plus.

What the JD emphasized

  • deep integration, continuous tuning, and change management
  • Every agent needs an identity, a scope, an audit trail, and a way to be shut down when it goes wrong.
  • builders who see the cracks in enterprise agent identity that everyone else has learned to live with.
  • most senior technical field authority for agent identity
  • set the reference architecture
  • turn what the field learns into the direction the product takes
  • hardest and most strategic deployments
  • technical and political situations
  • Set the standard for evals and observability
  • Define how the team measures authorization latency, scope sprawl, delegation anomalies, audit completeness, and kill-switch verification
  • deep distributed systems and identity experience
  • track record of staying hands-on while setting direction
  • Authority-level identity protocols
  • Deep agent security fluency
  • Expert fine-grained authorization
  • Proven AI hands-on
  • Production integrations across the major agent platforms
  • daily AI-native development
  • Force multiplier. A record of setting technical direction across multiple teams or accounts, and of mentoring senior engineers.
  • Customer-facing authority. Credible from the IDE to the boardroom, trusted by CISOs and principal engineers alike, and steady when account politics get sharp.
  • High agency, founder’s mindset. Applied to building a function, not just an account.

Other signals

  • AI agents require identity, scope, audit trails, and shutdown mechanisms.
  • Building the infrastructure for enterprise AI agents.
  • Defining reference architectures for agent identity and security.