Staff Product Security Engineer, PSIRT
Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every box - we’re looking for lifelong learners and people who can improve us with their unique experiences.
Join our team! We’re building a world where Identity belongs to you.
The Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers. With the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business.
The Staff Product Security Engineer, PSIRT position is crucial in ensuring that Okta’s systems and services meet the highest security standards and align with our customers’ requirements. This position requires leadership, an innovative mindset, and expertise in security operations, responsible disclosure, vulnerability management, and program management. This position is available to candidates in Ireland and Spain.
What You Will Do
Responsible for defining, improving, formalizing, and implementing Okta’s Product Security Incident Response Program for all products and business units
Responsible for the day-to-day operations of the bug bounty program, including researcher engagement, vulnerability triage and validation, severity assessment, remediation coordination, reward recommendations, and program process improvements.
Oversee the entire lifecycle from discovery to resolution, including triaging, impact assessment, coordination with engineering teams, and validating fixes while ensuring timely communication with internal and external stakeholders
Lead the overall security disclosure program, from triaging to disclosure
Report on the health of the program and the overall status of its activities
Collaborate with internal teams to improve workflows, governance, and communication of vulnerabilities and risks
Work closely with Engineering, IT, Product, Legal, and Security teams on cross-functional initiatives
Mentor and provide guidance to junior engineers on incident response procedures, technical investigations, and vulnerability remediation
Partner with leadership to drive proactive threat detection and vulnerability management
What You Bring
6+ years of experience in Information Security with a focus on Product Security, Application Security, Vulnerability Management, and Security Operations
Working experience in conducting comprehensive security code reviews to identify vulnerabilities and code flaws
Working experience in Application Security vulnerabilities
Working experience in Product Security concepts
Working experience in risk management
Working experience in handling incident response for product-related issues
Knowledge of incident and log management tools
Excellent communication and collaboration skills, particularly in technical writing, process documentation, and executive presentations
#P25517_3504023
Below is the annual salary range for candidates located in Spain. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and comprehensive healthcare coverage and financial benefits including paid time off and parental leave in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit: https://rewards.okta.com/esp.
The annual base salary range for this position for candidates located in Spain is between:
€74.000—€101.000 EUR