Staff Software Engineer, Security Engineering

Okta Okta · Enterprise · Bellevue, WA · Security Engineering-695

Okta is seeking a Staff Software Engineer for their Auth0 Security Engineering team to design and build security guardrails for their multi-cloud environment. The role involves translating security and compliance standards into code-driven policies, focusing on cloud security strategy, IAM, infrastructure, and platform security architecture. The engineer will also design systems for real-time security posture validation and mentor junior engineers.

What you'd actually do

  1. Design organization-wide controls (SCPs, Azure Policy) that provide maximum protection with minimum developer friction.
  2. Architect templates and permission boundaries that govern how services and humans interact with our cloud environment with the principle of least privilege in mind.
  3. Define the security standards for VPC architecture, edge networking, and cross-account connectivity.
  4. Lead platform-related security reviews for new features and high-impact services, ensuring security is baked into the design phase.
  5. Design systems and processes to validate the security posture of the platform, ensuring our security policies are enforced in real-time with actionable feedback for engineering teams.

Skills

Required

  • 8+ years of proven experience in information security, specifically within cloud-native environments, Kubernetes (EKS, AKS), and cloud security.
  • Deep understanding of secure networking principles, including VPC peering/transit gateways, VPN implementations, edge protection, and managing public/private PKI infrastructures.
  • Strong background in building automated controls for enforcing Policy-as-Code within Terraform workflows.
  • Hands-on experience identifying attack vectors and conducting risk assessments for complex, distributed systems.
  • Experience working with security platforms for analyzing cloud permissions.
  • Exceptional communication skills with a track record of aligning multiple teams toward shared security goals.
  • Ability to access federal environments and/or have access to protected federal data.
  • U.S. Person status

Nice to have

  • Experience navigating compliance frameworks such as FedRAMP, SOC2, or HIPAA in a cloud environment.
  • Proficiency in one or more languages used for automation and tooling, such as Python, Go, or JavaScript.
  • Experience creating, managing, and securing containerized environments.
  • Experience with service mesh (Istio) security policies and zero-trust networking.

What the JD emphasized

  • security guardrails
  • programmatic, code-driven policies
  • minimum developer friction
  • principle of least privilege
  • security is baked into the design phase
  • enforced in real-time