About the Role
Secure Every Identity, from AI to Human. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.
Responsibilities
- Architect the technical blueprints and deployment strategies for Okta’s premier identity security offerings across both our workforce and developer platforms.
- Architect how Okta governs non-human, autonomous AI workloads across O4AA (Okta for AI Agents) and A4AA (Auth0 for AI Agents), defining secure authentication and authorization patterns.
- Design token exchange patterns, security gateways, and implement the Model Context Protocol (MCP) to secure agent-to-data interactions.
- Design Okta’s defense against session cookie thievery by leveraging cryptographically hardware-bound tokens (Okta DBSSO and Chrome DBSC).
- Deploy Identity Threat Protection (ITP) for continuous risk evaluation and Identity Security Posture Management (ISPM) to eliminate hidden vulnerabilities across human and machine identities.
- Design and enforce modern access governance, including automated lifecycle management, self-service access request workflows, and continuous access certification using Okta Identity Governance.
- Architect secure, just-in-time (JIT) access to critical infrastructure, managing secrets, and securing privileged sessions using Okta Privileged Access.
- Lead the internal Customer Zero deployment of Okta IGA and PAM, blueprinting workflows for least-privilege access, ensuring robust compliance and security over Okta's most sensitive administrative, server, and infrastructure entitlements.
- Act as the lead architect testing and deploying Alpha identity security features within Okta’s internal IAM environment, authoring technical rollout blueprints and providing critical feedback to engineering teams.
- Design the internal implementation blueprint for how Okta DBSSO and Chrome DBSC complement one another, creating an ironclad, layered defense that protects corporate endpoints from token and cookie exfiltration.
- Lead the technical effort to open-source complimentary tools built by the Customer Zero team, transitioning internal innovations into a community effort.
- Help lead a dedicated 'how-to' video series and potential podcast, and take the stage at major events to share the internal playbook.
- Define how Okta identity is woven into modern orchestration layers (LangChain/Graph, n8n, AWS AgentCore, Google Vertex ADK) and model providers (Azure Foundry, AWS Bedrock, OpenAI, Anthropic).
- Collaborate closely with strategic engineering and identity infrastructure teams at major enterprise tech companies, leading cloud service providers, and top-tier security vendors.
Requirements
- 8+ years of overall IT/software development and technical architecture experience.
- 3+ years specifically focused on IAM/Security Architecture.
- Proven track record of securing non-human identities (NHIs) or machine-to-machine infrastructure in production.
- Demonstrated experience deploying Identity Governance (IGA) and Privileged Access Management (PAM) solutions, including just-in-time (JIT) access, infrastructure security, lifecycle management, and access certification.
- Knowledge of core protocols: OAuth2/OIDC (especially Token Exchange), SAML, mTLS, JWT, and Model Context Protocol (MCP).
- Strong technical understanding of modern identity threat vectors (AiTM phishing, info-stealer malware, session hijacking).
- Ability to author clear Architecture Decision Records (ADRs) and confidently influence at the VP/CTO level, serving as a true peer to product management and product engineering.
- Elite verbal and written communication skills.
- Ability to translate deep, ambiguous technical architecture into compelling business value for C-suite executives.
- Excel in front of a camera or a live audience.
Skills
- IAM/Security Architecture
- Securing non-human identities (NHIs)
- Machine-to-machine infrastructure security
- Identity Governance (IGA)
- Privileged Access Management (PAM)
- Just-in-time (JIT) access
- Infrastructure security
- Lifecycle management
- Access certification
- OAuth2/OIDC
- Token Exchange
- SAML
- mTLS
- JWT
- Model Context Protocol (MCP)
- AiTM phishing
- Info-stealer malware
- Session hijacking
- Architecture Decision Records (ADRs)
- Technical influence
- Verbal communication
- Written communication
- Public speaking
- Video production
- Podcast production
- Open-source contribution
- LangChain/Graph
- n8n
- AWS AgentCore
- Google Vertex ADK
- Azure Foundry
- AWS Bedrock
- OpenAI
- Anthropic
Location
- Hybrid
Work Type
- Hybrid
- Full-time
Experience Level
- 8+ years overall IT/software development and technical architecture experience
- 3+ years IAM/Security Architecture experience
Benefits
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
- Immersive, in-person onboarding experience
About the Company
- Secure Every Identity, from AI to Human. Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era.
- We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate.
Equal Opportunity
- Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
- If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
- Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.
