Staff Product Security Engineer

Okta Inc

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Bellevue, WAChicago, ILNew York, NYSan Francisco, CAToronto, Ontario, CanadaWashington, DC
Salary
$180,000–$247,500 / yr
Posted
43 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $183k
This role $214k
$117k most similar roles pay here $261k

This role pays more than 75% of similar roles. Most pay $153,462–$213,250 — the shaded band above. At the midpoint, this role pays about $214k versus about $183k for comparable roles.

Based on 240 similar postings.

Employer

About Okta Inc

Okta, Inc. is an American identity and access management company based in San Francisco. It provides cloud software that helps companies manage and secure user authentication into applications, and for developers to build identity controls into applications, websites, web services, and devices.[

Okta Inc currently has 137 open roles on FindRole.

Listed pay typically runs $174,000–$239,000 across 137 roles with salary data.

Most-posted roles

View all roles at Okta Inc

At a glance

TL;DR · Staff Product Security Engineer

As a Staff Product Security Engineer, Reviews, you will join the security team to safeguard products by conducting comprehensive security reviews, performing manual code reviews across multiple programming languages like Java, Go, Python, and C/C++, and executing penetration testing. You will manage product security incidents, perform threat modeling, and develop automated tools to identify vulnerabilities proactively. The role requires deep expertise in authentication protocols such as SAML, OAuth, and OIDC, alongside a strong understanding of OWASP Top 10 and CWE Top 25 risks. A critical component of this position involves assessing AI-integrated software architectures and securing Large Language Models against emerging threats. You will also communicate risk remediation to stakeholders and represent the company through public research and publications while ensuring the security of web applications, backend services, and mobile or desktop platforms.

What you'll do

  • Conduct security reviews including design assessments, threat modeling, and penetration testing for new features.
  • Perform manual secure code reviews across multiple programming languages to identify vulnerabilities.
  • Lead product security incidents by assessing risks and driving remediation efforts with engineering teams.
  • Develop automated tools and scripts to improve vulnerability detection and assessment processes.
  • Assess Large Language Model (LLM) architectures and secure AI-integrated software against emerging threats.
  • Communicate risk impact and remediation strategies to developers, leadership, and external audiences.
  • Mentor junior engineers and provide guidance on secure development practices to non-security staff.
  • Represent the company externally through security research, conference presentations, and published white papers.

What we're looking for

  • Expertise in identifying OWASP Top 10 and CWE Top 25 vulnerabilities through manual code review.
  • Experience in penetration testing and implementing secure development practices.
  • Deep technical background in securing Large Language Models (LLMs) and AI-integrated software architectures.
  • Proficiency in multiple programming languages including Java, Go, Python, and C/C++.
  • Deep understanding of authentication and authorization protocols such as OIDC, SAML, and OAuth.
  • Ability to automate security testing using scripting languages like Python and Bash.
  • Experience leading security incidents, performing risk assessments, and providing remediation guidance.
  • Strong communication skills to present technical risks and findings to developers and leadership.

More like this

Similar roles

Senior Security Engineer I, Product Security

Oscar Health

Remote (San Francisco, CA) 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Remote

Staff Product Security Engineer

Reddit

Remote 135 days ago $217,000$303,900
Go Python CI/CD LLM Authentication Authorization Cloud-Native Platforms Product Security Application Security Software Engineering
8+ yrs exp Remote

Staff Product Security Engineer

Abbott

St. Paul, MN 22 days ago $113,300$226,700
C/C++ Python Linux Embedded Systems Firmware Secure Boot PKI Certificate Management TPM STRIDE OWASP SBOM CVE NIST Cybersecurity Framework IEC 62304 ISO 14971 RTOS
8+ yrs exp

Staff Product Security Engineer

Qualcomm

San Diego, CA 15 days ago $149,600$224,400
Security Engineering C C++ Java Python System Verilog Risk Assessment Threat Analysis Security Code Review Software Security
4+ yrs exp

Product Security Engineer

Adobe

New York, NY +2 115 days ago $149,400$216,300
LLM Azure OpenAI Python React FastAPI Celery Redis Kubernetes Argo Vector Databases Prompt Engineering Retrieval-Augmented Generation Git CI/CD Azure JavaScript GitHub Copilot Cursor Threat Modeling
4+ yrs exp

Product Security Engineer

Cloudflare, Inc

Austin, TX 38 days ago
Application Security LLM SAST Fuzzing Penetration Testing Threat Modeling STRIDE Bug Bounty Triage JIRA Agile Vulnerability Management SaaS
5+ yrs exp Hybrid