Staff Product Security Engineer, Red Team

Okta Okta · Enterprise · Toronto, ON · Sec - Corp Security-186

Staff Security Infrastructure Engineer for Okta's Red Team, focusing on building and maintaining the engineering backbone, platforms, infrastructure, and custom tooling that enables security operators. This role is infrastructure-focused, not an operator role, and aims to improve deployment speed, resilience, automation, and reliability.

What you'd actually do

  1. Design, build, maintain, and continuously improve the platforms, infrastructure, and custom tooling that our operators depend on to execute engagements.
  2. Own the engineering backbone that enables our operations.
  3. Work alongside operators but not report through an operator chain; you'll collaborate as a peer focused on a different discipline.
  4. Cultivate stakeholder collaboration and elevating our company’s security posture through strategic engagement and proactive measures.

Skills

Required

  • 8+ years of professional experience in infrastructure engineering, DevOps, platform engineering, or a similar role with significant automation responsibilities
  • Strong familiarity with Terraform (or equivalent IaC tooling) for multi-cloud infrastructure provisioning and management
  • Experience operating in cloud-native, SaaS, or identity-focused environments
  • Strong proficiency with configuration management tools (Ansible, or equivalent)
  • Proficiency in at least one systems programming or scripting language (Python, Go, Bash) with disciplined development practices (version control, code review, testing, documentation)
  • Solid understanding of Linux systems administration, networking fundamentals (DNS, HTTP/S, TCP/IP, proxying, TLS), and cloud platforms (AWS, GCP, or Azure)
  • Understanding of OPSEC principles as they apply to offensive infrastructure

Nice to have

  • Experience building and maintaining CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins, or similar)
  • Familiarity with containerization and orchestration (Docker, Kubernetes) as applicable to tooling and lab environments
  • Familiarity with C2 frameworks (Cobalt Strike, Mythic, Sliver, or similar) from an infrastructure and deployment perspective
  • Familiarity with detection evasion concepts as they relate to infrastructure
  • Working knowledge of Blue Team operations and related technologies
  • Experience with security tool development (implant development, payload engineering, evasion tooling)
  • Familiarity with Red Team maturity models and how infrastructure/tooling capabilities map to organizational maturity

What the JD emphasized

  • dedicated infrastructure and tooling engineer
  • first person in this role
  • not a traditional operator role
  • core mission is ensuring the team's infrastructure, workflows, tooling, and automation are reliable, repeatable, and mature