Staff Security Engineer - Vulnerability Management US Public Sector

Okta Okta · Enterprise · United States · Sec - Vulnerability Management & Sec Arch-772

Okta is seeking a Staff Security Engineer to manage vulnerability management for US Public Sector, focusing on securing identity infrastructure that supports AI. The role involves owning the lifecycle of asset and vulnerability management, assessing scan technologies, responding to security incidents, and supporting compliance with various regulations. The ideal candidate will have extensive experience in cybersecurity, particularly in regulated environments, with proficiency in AWS and scripting languages.

What you'd actually do

  1. Own the full lifecycle operations of Asset and Vulnerability Management scanning and reporting infrastructure, including designing new cloud based and on-prem deployments as required.
  2. Assess new and existing scan technologies to determine potential business value.
  3. Monitor and respond to security inquiries, requests, and incidents, understanding the technical details of the published vulnerabilities as well as their real risk. Effectively communicate the perceived and real vulnerability impact given the infrastructure context.
  4. Contribute to the definition and execution of internal processes that allow for accelerated remediation of critical vulnerabilities and zero-days.
  5. Support audit, governance, risk and compliance teams in scanning and reporting on various regulatory compliance and industry best practices including PCI, ISO 27001/27017/27018 , NIST SP 800-53 and SOC 2.

Skills

Required

  • AWS core services (host OS and container deployment, S3, DynamoDB, API Gateway)
  • AWS Lambda or similar serverless computing environments
  • Shell and python scripting and automation
  • Multifaceted cyber security experience
  • Building vulnerability scanning solutions in regulated environments (FedRamp)
  • Functional knowledge of vulnerabilities, exploitation and remediation
  • Experience with commercial or open-source vulnerability and misconfiguration scanners and reporting tools
  • Familiarity with industry standards, frameworks and publications (CVE, CVSS, EPSS, OWASP, CISA KEV)
  • Ability to work independently on end to end delivery of infrastructure deployment and troubleshooting run time issues.

Nice to have

  • Familiarity with other scripting and automation tools
  • Qualys, TenableSC, Prisma Cloud, Wiz, Orca, Lacework, Paramify, Atlassian Jira, ServiceNow

What the JD emphasized

  • Must have ability to work independently on end to end delivery of infrastructure deployment and troubleshooting run time issues.
  • Must have proficiency in AWS core services such as host OS and container deployment, S3, DynamoDB, API Gateway, and others.
  • 5+ years of experience in building vulnerability scanning solutions within a highly regulated environment such as FedRamp and various Impact Levels.