Okta on Okta Identity Architect

Okta

Bellevue (WA)

On-site

USD 216,000 - 332,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Equity
Bonus
Health insurance
Dental insurance
Vision insurance
401(k)

Job summary

Okta is seeking an elite engineer for the Okta on Okta Identity Architect, the top technical execution tier above Principal Engineer. You will be hands-on configuring, deploying, and testing the platform within Okta's own corporate IAM tenant.

Reporting to the VP of IAM, you will shape features from Alpha through EA, collaborate with customer engineers, and contribute playbooks and content to advance the platform globally.

Qualifications

  • Extensive hands-on experience managing Okta in complex enterprise environments.
  • Active mastery of OIE, Directory Integrations, Advanced Policies, Workflows and Platform APIs.
  • Knowledge of OAuth2/OIDC, SAML, mTLS, JWT and MCP.
  • Experience securing platform deployments for non-human AI workloads.
  • Excellent ability to communicate with peer engineers and document solutions.

Responsibilities

  • Serve as the Customer Zero, configuring and deploying Alpha platform capabilities within Okta’s tenant.
  • Lead architecture for AI Agent security, token exchange and authorization patterns.
  • Design defenses against session hijacking using Okta Identity Engine.
  • Collaborate with platform teams and share deployment lessons from real-world tenants.
  • Contribute to technical content and playbooks (videos, roundtables, etc.).

Skills

Okta platform expertise
OAuth2/OIDC
SAML
Threat literacy
Technical influence
Communication

Tools

Okta Identity Engine
Okta Platform APIs
Directory Integrations
Workflows

Job description

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Okta on Okta Identity Architect Opportunity

This is not a traditional architect role. At Okta, an Okta on Okta Identity Architect is the premier technical execution tier above Principal Engineer—acting as the ultimate hands‑on practitioner of our own cloud platform. While you won't be writing application code, you will get your hands dirty configuring, extending, and testing the boundaries of the platform. You are the builder who proves our platform works in the real world.

As organizations successfully adopt phishing‑resistant MFA, attackers have shifted their tactics—increasingly deploying Adversary‑in‑the‑Middle (AiTM) phishing kits and info‑stealer malware to execute session hijacking via cookie theft. Furthermore, with the explosive rise of autonomous AI workloads, securing human identity is no longer enough; we must now protect and govern a fast‑growing sprawl of non‑human, agentic workflows.

Are you an elite engineer running Okta at a customer organization today? Have you ever configured our platform, pushed Okta Platform Services to their limits, and thought: "If I worked at Okta, I know exactly how we could make this platform better"?

We are looking for a highly mature, technical leader who is already a deeply experienced, hands‑on Okta customer practitioner to drive the technical execution of our Identity Security & Agentic Identity portfolio. In this role, you will transition from being an external customer to becoming the technical cornerstone of the internal "Okta on Okta" team, acting as Customer Zero. Reporting directly to the VP of IAM, you will configure, deploy, and battle‑test cutting‑edge platform features from Alpha through Early Availability (EA)—giving you the unique leverage to directly shape, influence, and improve the core Okta platform before these solutions scale globally.

Why This Role is Different

If you stay at a traditional customer organization, you can only deploy what we build. In this role, you get to cross the table, become the elite practitioner of a world‑class security platform, get early access to cutting‑edge features, and directly influence the future of the platform. You will collaborate directly with other top‑tier engineers across our customer base and partner with the absolute pioneers of the identity industry to shape the tools you've spent your career using.

What You’ll Be Doing (Platform Execution & Impact)
  • The Ultimate "Customer Zero" Platform Practitioner (Alpha to EA): Bring your real‑world customer deployment perspective directly into our tenant. Act as the lead hands‑on architect configuring and deploying Alpha platform capabilities within Okta’s own corporate IAM tenant. You will serve as the bridge to our core platform product teams, providing the vital, practitioner‑level feedback that shapes final platform design.
  • AI Agent & Agentic Identity Security: Lead the hands‑on architecture and configuration of how the Okta Platform governs non‑human, autonomous AI workloads across O4AA (Okta for AI Agents), defining secure authentication, token exchange, and authorization patterns.
  • Designing Anti‑Session Hijacking Defenses: Build the internal technical deployment blueprints for how Okta DBSSO and Chrome DBSC complement one another, leveraging Okta Identity Engine (OIE) to create an ironclad, layered defense that protects corporate endpoints from token and cookie exfiltration.
  • Platform‑to‑Platform Collaboration: Act as a technical peer and trusted advisor to fellow hands‑on practitioners at our customer organizations. You will share your direct, real‑world tenant deployment experiences, trade‑offs, and lessons learned with the engineers actually building and securing their Okta platforms in the wild.
  • Sharing the Playbook: Contribute to our technical content efforts (such as a deep‑dive "how‑to" video series, co‑hosting internal podcasts, or presenting to fellow practitioners in highly focused, interactive roundtable breakout sessions at Oktane) to share the actual deployment architectures, tenant configurations, and technical playbooks we’ve built.
What You’ll Bring To The Role
  • Proven Okta Platform Expertise: Extensive, practical experience managing, configuring, and troubleshooting Okta in complex enterprise production environments. You possess active, hands‑on mastery of the Okta Identity Engine (OIE), Directory Integrations, Advanced Policies, Workflows, and Okta Platform APIs—whether you learned this on the job or proved it through certifications.
  • Protocol & Threat Literacy: Deep, hands‑on knowledge of core protocols: OAuth2/OIDC (especially Token Exchange), SAML, mTLS, JWT, and Model Context Protocol (MCP). Strong technical understanding of modern identity threat vectors (AiTM phishing, info‑stealer malware, session hijacking).
  • Technical Influence: Serve as an equal technical peer to product management and product engineering, collaborating on feasibility, platform architecture paths, and real‑world system behaviors.
  • Practitioner Empathy & Communication: Exceptional ability to connect with and speak the language of other hands‑on platform engineers and security administrators. You excel at translating highly complex platform configurations into clear, peer‑to‑peer technical explanations, whether in documentation, video walkthroughs, or collaborative technical workshops.
  • Nice To Have: Okta Certified Administrator or Okta Certified Consultant (These are a great plus, but are not required if you have equivalent, proven hands‑on engineering experience).

Below is the annual base salary range for candidates located in the San Francisco Bay area: $242,000 – $332,000 USD. For candidates in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington: $216,000 – $297,000 USD. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.

The Okta Experience
  • Supporting Your Well‑Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in‑person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Identity Engineer
Staff Identity Engineer

Okta • Washington

On-site
USD 161,000 - 221,000
Staff Identity Engineer
Staff Identity Engineer

Socket.dev • Bellevue (WA)

On-site
USD 161,000 - 221,000
Equity
Bonus
Health insurance
+2
Staff Identity Engineer
Staff Identity Engineer

Triwill Group • Washington (IL), Northern (KY)

Hybrid
USD 161,000 - 221,000
Staff Identity Engineer
Staff Identity Engineer

Okta • Chicago (IL)

On-site
USD 161,000 - 221,000
Technical Architect
Technical Architect

Triwill Group • Northern (KY)

Hybrid
USD 200,000 - 308,000
Technical Architect
Technical Architect

Okta • San Francisco (CA)

On-site
USD 224,000 - 308,000
Technical Architect
Technical Architect

Segment (Twilio) • Chicago (IL), New York (NY), Bellevue (WA)

On-site
USD 200,000 - 275,000
Health, dental, and vision insurance
401(k)
Paid leave including PTO and parental leave
Technical Architect
Technical Architect

Okta • Bellevue (WA)

On-site
USD 200,000 - 275,000
Health insurance
401(k) plan
Paid leave
+1
Staff Identity Engineer
Staff Identity Engineer

Okta • Bellevue (WA)

On-site
USD 161,000 - 221,000
Principal Forward Deployed Engineer, Okta for AI Agents
Principal Forward Deployed Engineer, Okta for AI Agents

Okta • Bellevue (WA)

On-site
USD 240,000 - 360,000
Health insurance
Flexible spending account
Paid leave including PTO and parental leave