Enable job alerts via email!

Staff Product Security Engineer, Offensive Security

Okta, Inc.

Toronto

Remote

CAD 141,000 - 211,000

Full time

7 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company in identity management is seeking a Staff Product Security Engineer for its Offensive Security team in Toronto. The ideal candidate will possess advanced knowledge in cloud security, penetration testing, and application security. This role focuses on identifying and mitigating complex security vulnerabilities with a proactive approach.

Benefits

Equity options
Health, dental, and vision insurance
RRSP with a match
Healthcare spending
Telemedicine
Paid leave, including PTO and parental leave

Qualifications

  • 5+ years of experience in penetration testing web applications and infrastructure.
  • Strong expertise in securing cloud environments (AWS, GCP, Azure).
  • Familiar with Threat Modeling concepts and frameworks.

Responsibilities

  • Apply attacker mindset to identify and exploit security gaps across app, cloud, and network layers.
  • Conduct targeted security assessments and deliver actionable findings.
  • Act as a security SME and represent Okta in internal and external forums.

Skills

Cloud Security
Operating Systems
Application Security
Authentication Protocols
Automation and Tooling
TechOps
Communication

Job description

Staff Product Security Engineer, Offensive Security

Toronto

Get to know Okta

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.

Join our team! We’re building a world where Identity belongs to you.

The Offensive Security Team, part of Product Security, actively assesses the security of Okta's products, services, and infrastructure, and we are seeking a highly technical and driven staff-level engineer to contribute to this effort. This role demands more than running vulnerability scans. Excelling here requires a thorough understanding of offensive security testing and a strong drive to identify and leverage security weaknesses. Above all, the most critical attribute of this role is an innate ability to think and operate as a sophisticated adversary. This skill is key to solving security challenges with deep technical expertise and creativity.

The ideal candidate will possess demonstrable expertise in the following areas:

  • Cloud Security: In-depth knowledge of AWS security architecture, services, and common attack vectors, with a proven ability to compromise AWS Compute resources. Experience with Google Cloud Compute and Azure is highly desirable.
  • Operating Systems: Deep familiarity with Linux and macOS operating systems, including their security features, command-line tools, and common attack surfaces.
  • Application Security: Strong understanding of application security principles, common vulnerabilities (OWASP Top 10, etc.), and backend testing methodologies and techniques.
  • Authentication Protocols: Familiarity with various authentication and authorization mechanisms, such as SAML, OAuth 2.0, and OIDC, and their associated security considerations
  • Automation and Tooling: A strong desire and proven ability to automate security tasks and develop custom tooling to facilitate security reviews and pentesting
  • TechOps: Experience with TechOps tooling and processes, such as Chef, Kubernetes, Terraform, and ArgoCD, enabling a comprehensive understanding of the operational environment.
  • Communication: Excellent written and verbal communication skills with the ability to clearly and concisely articulate vulnerabilities and remediation strategies to technical and non-technical audiences

We actively encourage and support the external publication of impactful security research and findings through papers, blog posts, and presentations at industry conferences.

What You Will Do
  • Apply attacker mindset to identify, plan, and exploit complex security gaps across app, cloud, and network layers.
  • Conduct targeted security assessments and pentests; deliver actionable findings, detailed exploit recreation, and architectural remediation guidance.
  • Act as a security SME across internal teams and represent Okta in internal and external forums when appropriate.
  • Design and deploy disposable, repeatable, verifiable automation and infrastructure to support rapid, on-demand security engagements.
  • Periodically triage internal vulnerability tickets and external bug bounty submissions.
  • As needed, design and deploy tooling, automation, or infrastructure to support security engagements.

What You Bring
  • Demonstrable experience in penetration testing web applications and infrastructure (5+ years preferred)
  • Strong expertise in securing cloud environments (AWS, GCP, Azure)
  • Proven ability to identify and demonstrate security vulnerabilities in infrastructure
  • Familiarity with Threat Modeling concepts and frameworks
  • Experience with Infrastructure as Code (e.g., Terraform) for building and testing environments.
  • Solid understanding of modern cryptographic principles and their application
  • Experience in automating security testing and streamlining offensive tasks.
  • Ability to think strategically and develop comprehensive attack scenarios
  • Effective communication skills for conveying technical security findings to various audiences
  • A proactive approach to learning about emerging threats and developing new security techniques.
  • Experience or interest in mentoring and sharing knowledge with team members.

#LI-REMOTE


#LI-SH1

Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit:https://rewards.okta.com/can .

The annual base salary range for this position for candidates located in Canada is between:

Get to know Okta

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.

Join our team! We’re building a world where Identity belongs to you.

The Offensive Security Team, part of Product Security, actively assesses the security of Okta's products, services, and infrastructure, and we are seeking a highly technical and driven staff-level engineer to contribute to this effort. This role demands more than running vulnerability scans. Excelling here requires a thorough understanding of offensive security testing and a strong drive to identify and leverage security weaknesses. Above all, the most critical attribute of this role is an innate ability to think and operate as a sophisticated adversary. This skill is key to solving security challenges with deep technical expertise and creativity.

The ideal candidate will possess demonstrable expertise in the following areas:

  • Cloud Security: In-depth knowledge of AWS security architecture, services, and common attack vectors, with a proven ability to compromise AWS Compute resources. Experience with Google Cloud Compute and Azure is highly desirable.
  • Operating Systems: Deep familiarity with Linux and macOS operating systems, including their security features, command-line tools, and common attack surfaces.
  • Application Security: Strong understanding of application security principles, common vulnerabilities (OWASP Top 10, etc.), and backend testing methodologies and techniques.
  • Authentication Protocols: Familiarity with various authentication and authorization mechanisms, such as SAML, OAuth 2.0, and OIDC, and their associated security considerations
  • Automation and Tooling: A strong desire and proven ability to automate security tasks and develop custom tooling to facilitate security reviews and pentesting
  • TechOps: Experience with TechOps tooling and processes, such as Chef, Kubernetes, Terraform, and ArgoCD, enabling a comprehensive understanding of the operational environment.
  • Communication: Excellent written and verbal communication skills with the ability to clearly and concisely articulate vulnerabilities and remediation strategies to technical and non-technical audiences

We actively encourage and support the external publication of impactful security research and findings through papers, blog posts, and presentations at industry conferences.

What You Will Do
  • Apply attacker mindset to identify, plan, and exploit complex security gaps across app, cloud, and network layers.
  • Conduct targeted security assessments and pentests; deliver actionable findings, detailed exploit recreation, and architectural remediation guidance.
  • Act as a security SME across internal teams and represent Okta in internal and external forums when appropriate.
  • Design and deploy disposable, repeatable, verifiable automation and infrastructure to support rapid, on-demand security engagements.
  • Periodically triage internal vulnerability tickets and external bug bounty submissions.
  • As needed, design and deploy tooling, automation, or infrastructure to support security engagements.

What You Bring
  • Demonstrable experience in penetration testing web applications and infrastructure (5+ years preferred)
  • Strong expertise in securing cloud environments (AWS, GCP, Azure)
  • Proven ability to identify and demonstrate security vulnerabilities in infrastructure
  • Familiarity with Threat Modeling concepts and frameworks
  • Experience with Infrastructure as Code (e.g., Terraform) for building and testing environments.
  • Solid understanding of modern cryptographic principles and their application
  • Experience in automating security testing and streamlining offensive tasks.
  • Ability to think strategically and develop comprehensive attack scenarios
  • Effective communication skills for conveying technical security findings to various audiences
  • A proactive approach to learning about emerging threats and developing new security techniques.
  • Experience or interest in mentoring and sharing knowledge with team members.

#LI-REMOTE


#LI-SH1

Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit:https://rewards.okta.com/can .

The annual base salary range for this position for candidates located in Canada is between: $141,000 — $211,000 CAD

What you can look forward to as a Full-Time Okta employee!

  • Amazing Benefits
  • Making Social Impact
  • Developing Talent and Fostering Connection + Community at Okta

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! https://www.okta.com/company/careers/ .

Some roles may require travel to one of our office locations for in-person onboarding.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at https://www.okta.com/privacy-policy/ .

U.S. Equal Opportunity Employment Information
Read more

The foundation for secure connections between people and technology

Okta is the leading independent provider of identity for the enterprise. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With over 7,000 pre-built integrations to applications and infrastructure providers, Okta customers can easily and securely use the best technologies for their business. More than 19,300 organizations, including JetBlue, Nordstrom, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.

Follow Okta

First Name

Last Name

Email

Phone

Resume

Upload PDF

Paste

Upload Resume/CV (PDF must be less than 8 MB )

Upload PDF

Paste

Upload Cover Letter (PDF must be less than 8 MB )

LinkedIn Profile

Website

Are you legally authorized to work in the country you reside?

Will you now or in the future require Visa Sponsorship?

To the best of your knowledge, do you have any family members / relatives or personal relationships at Okta or at any suppliers, partners, or vendors that have a business relationship with Okta?(For purposes of this question, a “family member / relative or personal relationship” is defined as close personal friends (including sexual and/or romantic relationships), close relatives (spouse, partner, children, cousins, aunts, uncles, nieces, nephews, grandparents or grandchildren), someone who lives in your household, or anyone else with whom you have a close enough personal relationship or connection that it could improperly bias your conduct or decision making or be perceived to be capable of impacting your conduct or decision making.

If yes, please identify name of person / vendor and describe relationship / association:

Do you have any outside business activity(ies) (advisory, consulting, or board roles, or side businesses) that you would continue engaging in or plan to engage in if you joined Okta in this role?

If yes, please describe:

Have you worked for Okta in the past?

I acknowledge and agree to the processing of my personal data in accordance with Okta's Privacy Policy.

I would like to be considered for future positions at Okta.

Yes

Do you have 5+ years of experience with penetration testing?

Do you have 3+ years of experience with Cloud security(ideally AWS)?

Please confirm your city, province and timezone. (all 3)

Are you located in the GTA?(Greater Toronto Area)

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Staff, Application Security Engineer (Remote - Canada)

Jobgether

Remote

CAD 143.000 - 178.000

5 days ago
Be an early applicant