Principal Product Manager, Iam Security & Agentic Identity

Okta Okta · Enterprise · United States · Sec - IAM-185

Principal Product Manager to drive the Identity Security & Agentic Identity portfolio, focusing on governing non-human, autonomous AI workloads (O4AA, A4AA), defining authentication/authorization for AI agents, and implementing next-gen guardrails for secure agent-to-data interactions. The role also involves architecting defenses against session cookie thievery using hardware-bound tokens and managing advanced threat/posture management for human and machine identities.

What you'd actually do

  1. Develop and refine the strategic roadmap for the Identity Security portfolio. Act as a key stakeholder who directly shapes and prioritizes the core Okta and Auth0 Product roadmaps based on internal deployment findings.
  2. Ensure that as Alpha features are released, Okta’s internal IAM team rigorously tests them and provides real-time feedback through the SDLC process. Own the internal rollout of these features through Early Availability (EA), driving adoption so Okta successfully "drinks its own champagne."
  3. Design the internal rollout blueprint and external product strategy for how Okta DBSSO and Chrome DBSC complement one another, creating a layered defense that protects corporate endpoints from token and cookie exfiltration.
  4. Define the operational and technical guardrails for deploying AI Agents internally and externally—ensuring secure integration via identity gateways, downscoped runtime permissions, and an unbreakable audit trail.
  5. Act as the primary liaison between business units, development, and engineering teams. Lead planning activities, author comprehensive PRDs/user stories, and prioritize features within Scrum/Kanban frameworks.

Skills

Required

  • Product Management
  • Technical Program Management
  • Enterprise Architecture
  • IAM technologies
  • developer platforms
  • enterprise security
  • machine-to-machine infrastructure
  • AI agents
  • LLM applications
  • security gateways
  • developer APIs
  • authentication
  • authorization
  • modern communication patterns
  • MCP
  • OAuth 2.0
  • identity threat vectors
  • AiTM phishing
  • session hijacking
  • cryptographic hardware-binding
  • TPM
  • Secure Enclave
  • session state

Nice to have

  • Auth0
  • Chrome Device Bound Session Credentials (DBSC)
  • Okta Device Bound SSO (DBSSO)
  • Model Context Protocol (MCP)

What the JD emphasized

  • secure every identity
  • AI
  • agentic identity
  • AI Agents
  • agentic workflows
  • AI Agent & Agentic Identity Security
  • AI Agents
  • AI Agents
  • agent-to-data interactions
  • AI Agents
  • AI Agents

Other signals

  • AI Agents
  • Agentic Identity
  • Governing non-human, autonomous AI workloads
  • Securing AI workloads