Staff Site Reliability Engineer, Security- Gcp

Okta Okta · Enterprise · Bangalore, India · Security Engineering-695

Okta is seeking a Staff Site Reliability Engineer to join their Security Engineering team in Bengaluru. The role focuses on designing and developing security solutions to harden cloud infrastructure, particularly for AI-related security. Responsibilities include leading security initiatives, incident response, automating security processes, and evolving monitoring platforms. The ideal candidate will have extensive experience in cloud-native security, GCP and AWS environments, Infrastructure as Code, and automation scripting.

What you'd actually do

  1. Lead initiatives to strengthen our security posture for critical infrastructure and promote best practices across the engineering organization.
  2. Respond to production security incidents, perform root cause analysis, and build automated preventions to ensure high performance and reliability.
  3. Identify manual security processes and automate them using custom tooling and CI/CD integrations.
  4. Develop technical documentation, runbooks, and procedures for a 24x7 online environment.
  5. Continuously evolve our monitoring platforms, moving from simple auditing to active, automated prevention.

Skills

Required

  • 8+ years of experience architecting and running complex cloud networking and infrastructure
  • 7+ years specialized in DevSecOps or Cloud Security
  • Minimum 3+ years of deep, hands-on experience securing GCP (GKE, GCE, Shared VPC etc)
  • 10+ years of experience using Terraform and Chef to manage complex cloud resources and OS hardening
  • Expert-level proficiency in Go, Python, or Ruby for building custom security tooling and automated remediation
  • Proven track record of securing containerized workloads, including image scanning, K8s RBAC, and runtime security tools
  • Strong grasp of Linux internals, OS hardening (CIS benchmarks), and IP protocols (TLS/SSL, DNSSEC, BGP)
  • BS in Computer Science or equivalent professional experience
  • Design and maintain large-scale production IAM policies and secrets management workflows
  • Implement and maintain Public Key Infrastructure (PKI) and ensure all GCE/GKE environments meet strict compliance standards
  • Utilize industry-standard tools like OSQuery, Splunk, Chronicle, Nessus, or Qualys/ Crowdstrike to monitor system health and security telemetry
  • Lead the phased transition of security policies from Audit/Detection mode to Blocking/Prevention mode

Nice to have

  • Experience designing a unified IAM framework across AWS and GCP
  • Deep understanding of multi-cloud reliability patterns
  • Advanced experience securing GKE, EKS, and kOps
  • Security Reviews & Threat Modeling at both Design & Implemen

What the JD emphasized

  • security-first SRE engineer
  • proven track record of hardening large-scale GCP and AWS environments
  • Minimum 3+ years of deep, hands-on experience securing GCP
  • security-at-scale mindset
  • security-centric