Staff Detection & Response Engineer

Okta Okta · Enterprise · Toronto, ON · Sec - Cyber Defense-774

Okta is seeking a Staff Detection & Response Engineer to lead threat hunting, detection engineering, and incident response within their Security Operations organization. This role involves influencing security decisions, architecting detection frameworks, and acting as a technical lead for major incidents, with a focus on securing AI and identity.

What you'd actually do

  1. Lead complex, hypothesis-driven threat hunts based on vague intelligence, and develop refined methodologies for the broader team to follow.
  2. Write novel detections and solve complex querying challenges. You will establish the frameworks and standards for detection engineering across the entire security organization.
  3. Design and validate the effectiveness of preventative control chains and influence the selection and architecture of new security solutions.
  4. Serve as the technical lead for major incidents, including investigating threats in "foreign" or uncommon environments by leveraging frameworks and your professional network.
  5. Own multi-quarter objectives and drive them to success, developing project plans that align with Okta’s strategic VMTs (Vision, Metrics, and Targets) and budget.

Skills

Required

  • Threat hunting
  • Detection engineering
  • Incident response
  • Security architecture
  • Querying languages
  • Detection frameworks (e.g., MITRE ATT&CK)
  • Modern IR toolsets
  • Crisis communication
  • Project leadership
  • Budget management
  • Automation of response workflows
  • Refining preventative controls
  • Understanding of threat actor TTPs
  • Communication skills (technical and executive)

Nice to have

  • Mentorship
  • Team advocacy
  • Cross-functional collaboration

What the JD emphasized

  • high-impact leadership role
  • strategic one
  • influence security decisions
  • drive innovation
  • force multiplier
  • career-defining work
  • lead complex, hypothesis-driven threat hunts
  • establish the frameworks and standards for detection engineering
  • Architectural Influence
  • technical lead for major incidents
  • Own multi-quarter objectives
  • drive innovation initiatives
  • Expert Investigator
  • Effective Communicator
  • Resilient Leader
  • Proven experience in a high-growth SaaS or security-focused environment
  • Expertise in querying languages, detection frameworks (e.g., MITRE ATT&CK), and modern IR toolsets.
  • Experience managing communications during crises or major security incidents.
  • Demonstrated ability to lead project teams and manage budget/resource requirements.
  • Strong background in automating response workflows and refining preventative controls.