Software Engineer Ii, Security Engineering (auth0)

Okta Okta · Enterprise · Toronto, ON · Security Engineering-695

Software Engineer II for Auth0 Security Engineering at Okta, focusing on building and maintaining security guardrails for a multi-cloud environment. The role involves implementing security and compliance standards as code, managing IAM, and contributing to infrastructure security. A key aspect is exploring the application of AI to streamline security tasks and governance.

What you'd actually do

  1. Implement and maintain organization-wide controls (SCPs, Azure Policy) balancing protection with developer experience.
  2. Build and update templates and permission boundaries that govern how services and humans interact with our cloud, applying the principle of least privilege.
  3. Contribute to the security standards for VPC architecture, edge networking, and cross-account connectivity.
  4. Help build systems and processes that validate the security posture of the platform, enforcing our security policies and surfacing actionable feedback for engineering teams.
  5. Partner with teammates across the organization, share what you learn, and continually deepen your security expertise.

Skills

Required

  • 3+ years of experience in software engineering or information security
  • hands-on exposure to cloud-native environments
  • Kubernetes (EKS, AKS)
  • cloud security concepts
  • Experience building or maintaining automated controls and infrastructure-as-code
  • Terraform workflows
  • eagerness to identify attack vectors
  • think through risk in distributed systems
  • Familiarity with security or cloud tooling
  • interest in applying AI to streamline security tasks and governance
  • Strong communication skills
  • ability to collaborate effectively across teams
  • Bachelor's degree in Computer Science, Information Security, Systems Engineering, or a related field, or equivalent practical experience

Nice to have

  • Exposure to compliance frameworks such as SOC2, or HIPAA in a cloud environment
  • Proficiency in one or more languages used for automation and tooling, such as Python, Go, or JavaScript
  • Experience creating, managing, or securing containerized environments
  • Familiarity with service mesh (Istio) security policies and zero-trust networking concepts

What the JD emphasized

  • security guardrails
  • security and compliance standards
  • security posture
  • security expertise