Staff AI Security Engineer
About the role
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This is an opportunity to do career-defining work. We're all in on this mission.
Responsibilities
Secure AI Implementations: Design and deploy enterprise AI guardrails, gateways, and other controls to protect our agentic workflows from emerging threats.
Agent Hardening & Sandboxing: Establish security architectures for local and hosted agents to mitigate tool-calling, prompt injection, goal misalignment, and data exfiltration risks.
Define Paved Roads & Security Standards: Develop secure design patterns and developer tools that allow engineering teams to build and deploy AI features safely and quickly.
Threat Modeling for AI Workflows: Lead threat modeling and security reviews for agentic AI systems, enterprise deployments, and agent ecosystems.
AI Discovery & Visibility: Build systems to discover, inventory, and assess AI usage and data flows across the enterprise.
Agentic Platform Infrastructure: Design and operate internal AI security platforms and develop integrated AI capabilities that automate complex security operations.
Technical Leadership & Mentorship: Drive technical alignment across product, security, and infrastructure teams. Mentor engineers and security practitioners across domains.
Requirements
AI Security Expertise: Deep knowledge of the AI threat landscape, including OWASP, MITRE ATLAS, NIST AI RMF with practical experience prompt injection, excessive agency, and other AI-related threats.
Software Engineering: 8+ years of experience in security engineering or backend software development, with strong coding proficiency in Python or Go and hands-on cloud experience.
Agentic Framework Knowledge: Experience securing or auditing agentic frameworks (such as LangChain, Strands, Claude Agent SDK, or custom tool-calling agents) operating within sandboxed environments.
Architectural Expertise: Proven ability to design scalable cloud infrastructure (AWS/GCP), API gateways, proxy architectures, and access controls for enterprise systems.
Paved Road Construction: Track record of building developer-first security tools and platform controls that maintain engineering velocity.
Technical Leadership: Strong communication skills with a history of driving technical strategy, influencing engineering leaders, and mentoring engineers.
Qualifications
Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent practical experience.
Skills
Deep understanding of AI security principles and practices.
Experience with cloud platforms (AWS, GCP).
Strong problem-solving and critical thinking skills.
Excellent communication and collaboration skills.
Benefits
The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $180,000 USD - $247,500 USD
The annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington is between: $161,000 USD - $221,000 USD
Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.
To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.