Senior Software engineer - Advanced Threat Protection
Security Engineer, Customer Identity, Advanced Threat Protection
Get to know Okta
Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.
Join our team! We’re building a world where Identity belongs to you.
The Role
We seek a knowledgeable and research-focused Security Engineer to join a new Advanced Threat Protection team within Auth0 Customer Identity. This role does two things at once: it researches how attackers will use AI against identity systems, and it researches and builds how we use AI to defend our products, our infrastructure, and — most importantly — our customers' tenants.
This role is a key member of the Security team embedded within the Customer Identity product unit and works across multiple functions to get ahead of emerging AI threats, supporting the growth of our global Customer Identity business.
We are an engineering-focused team that seeks to stay on the cutting edge of security technology and the threat landscape. In this role you won't just assess our current AI security offering — you'll research what we should be protecting customers from one to two years ahead, turn that research into concrete protections, and help put AI-assisted defenses into the hands of the teams and customers who protect their tenants.
In this role you will work as part of a globally distributed team of talented engineers who share a passion for security and enjoy solving complex problems at scale. This role works closely with and alongside the members of the broader Okta Security team in support of Okta's company-wide security strategy and Okta’s Secure Identity Commitment.
This is a level-agnostic description; scope, autonomy, and leadership expectations scale with level (Senior through Staff).
Responsibilities:
Research and lead how we can use AI to protect customer tenants — both proactively (hardening posture before an attack) and during active incidents (accelerating detection, triage, and response)
Research and build protections against novel AI attacks that Auth0 and Auth0's customers can be subjected to — adversarial ML, prompt injection, abuse of agentic protocols (MCP, A2A, UCP, and emerging equivalents), model and data poisoning — as they apply to identity systems and customer tenants
Partner with the identity security teams to help customers strengthen their own tenant security posture through AI-assisted defenses
Research the emerging AI threat landscape and translate it into a forward-looking (12–24 month) view of what we need to protect ourselves and our customers from — then architect, recommend, and build the tooling to get there
Review and harden Auth0's AI security offering, identifying gaps and recommending mitigations before they're exploited
Partner across a globally distributed product-aligned team of security engineers to turn research into shipped protections for customer tenants
Establish a deep understanding of Okta Customer Identity products and infrastructure
Build, deploy & maintain scalable security solutions and automation that operationalize AI threat defenses at scale
Help meet our operational security commitments by thinking like an attacker, assessing the risk, and advising on mitigation strategies
Collaborate with the Okta Security team on security operations and, where relevant, support investigations and root cause analysis
What this position is not:
Dedicated application security, code review, or compliance-focused work
Reactive patch and vulnerability management as a primary function — this role is about getting ahead of threats, not chasing them
Requirements:
You have hands-on experience with AI/ML security — attacking, defending, or both (e.g., adversarial ML, LLM/prompt-injection attacks, agentic-system or model abuse), and an interest in using AI to build defenses, not just to study attacks
You have 4+ years of experience in security engineering, with a strong foundation in cloud infrastructure and/or product security
You have hands-on development experience — Go preferred — sufficient to prototype tooling, build AI-powered defenses, and operationalize your research
You have working knowledge and hands-on experience with one or more of the following:
AWS and/or Azure security
Kubernetes
You have strong knowledge of OWASP (including the OWASP Top 10 for LLM Applications) and secure coding best practices
You have a strong foundation in secure software development lifecycle best practices
You have strong written and verbal communication skills, with the ability to turn research into clear guidance for engineering and product teams
You have experience working with a globally distributed and remote team
Bonus points if:
You have published threat research, CVEs, or conference talks in AI/ML security or identity security
You have built AI/ML-powered security tooling or defensive automation in a production environment
You have working knowledge and experience with one or more of the following:
Adversarial ML, model red-teaming, or AI safety research
The AI agent / MCP ecosystem and its security implications
Identity and access management
Full-stack engineering
Site reliability engineering
Vulnerability and threat management
Governance, risk and compliance
#LI-Hybrid
#P25953_3566460