Principal Machine Learning Engineer, SecureAI

Empleora

San Francisco, Northern (CA, KY)

Hybrid

USD 238,000 - 326,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equity
Bonus
Health insurance
Dental insurance
Vision insurance
401(k)
Flexible spending account
Paid leave

Job summary

Okta’s AI Agents team is hiring a Principal ML Engineer to advance unified identity security for agent-based AI. You will replace static systems with dynamic AI security, delivering real-time threat inspection, intent evaluation, and behavioral analysis to ensure safe autonomous agents within defined bounds.

Lead features for the Identity Security Fabric and collaborate across product and engineering to scale innovative agent access management at enterprise scale.

Qualifications

  • 10+ years of software development experience with Python (Go or TS a plus).
  • Hands-on ML experience from feature engineering to fine-tuning models.
  • Experience with modern Generative AI platforms (AWS Bedrock, OpenAI, Anthropic, etc.).
  • Deep understanding of retrieval-augmented generation, embeddings, and knowledge-base workflows.

Responsibilities

  • Implement intent-based enforcement to verify agent runtime requests.
  • Apply LLM reasoning and prompt parsing to interpret prompts and intents.
  • Integrate low-latency inference or semantic evaluation engines into API paths.
  • Score alignment using embeddings, vector search, or zero-shot classification.
  • Design confidence-scored engines feeding policy frameworks like Cedar.
  • Establish evaluation benchmarks and guardrails against misuse.
  • Architect scalable ML/GenAI systems integrating retrieval, inference, and evaluation.
  • Optimize prompting and RAG workflows for Claude-based systems.
  • Build automated evaluation pipelines for model quality and safety.
  • Implement schema validation and guardrails for reliable outputs.
  • Mentor engineers to support team growth.

Skills

Python
Go
Typescript
Applied ML
LLM platforms
RAG
LangChain
PyTorch
TensorFlow
fastAPI
Airflow
Knowledge-base workflows
MCP
LangGraph
LlamaIndex
Security

Education

Bachelor’s or Master’s in Computer Science or related field

Tools

AWS Bedrock
OpenAI
Anthropic
LangChain
LlamaIndex
MCP
LiteLLM
LangGraph

Job description

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

About Okta Secures AI Team

The Okta for AI Agents Team is building the future of digital identity management. The way companies are using agents and allowing them access is undergoing a fundamental shift, enabling teams to move fast while staying secure.

Our North Star is clear: To get AI right, you have to get identity right. We are not just managing identities; we are building the industry's first Identity Security Fabric for the agentic era. As organizations rapidly deploy AI, these non-human entities are acting with access to critical tools, often bypassing traditional perimeters and creating a 'Shadow AI' crisis. Our mission is to move identity from a reactive gatekeeper to a unified control plane, transforming AI risk into business ROI.

We are tackling this by implementing a comprehensive four-pillar maturity model: Discover, Onboard, Protect, and Govern. We are driving innovation by defining the standards for Agentic Identity—including pioneer work with securing AI Agents and support for protocols like MCP. You will be helping us build the infrastructure that allows enterprises to scale AI safely, ensuring every access decision—whether made by a human or an automated agent—is authenticated, authorized, and audited at scale.

We are a diverse team of engineers, product managers, and designers who are bringing Okta’s expertise in identity to define the future of Agent Identity management, focusing on enablement while staying secure.

About the role

In this role, you will join the Agent Access Policies sub-team under Okta Secures AI as a Principal Machine Learning (ML) Engineer to advance Okta's authorization capabilities. By replacing static, rule-based systems with dynamic AI security mechanisms, you will deliver real-time threat inspection, agent intent evaluation, and behavioral analysis—ensuring autonomous AI agents operate safely within specified bounds.

Your core mission will be architecting and driving features for our unified control plane to establish the premier Identity Security Fabric for the agentic era. In doing so, you will help execute our guiding principle: "To get AI right, you have to get identity right."

What you’ll be doing
  • Implement intent-based enforcement to verify agent runtime requests match their intended purpose, requiring key capabilities.
  • Apply LLM reasoning and prompt parsing to interpret prompts, tool payloads, and intent in real time.
  • Integrate low-latency inference or semantic evaluation engines directly into the API gateway request path.
  • Use embeddings, vector search, or zero-shot classification to score alignment between agent intent and executed actions.
  • Design confidence-scored decision engines that feed semantic verification results into policy frameworks (e.g., Cedar).
  • Establish evaluation benchmarks, prompt injection defenses, and guardrails to prevent bypasses or false positives.
  • Architect scalable ML and Generative AI systems integrating retrieval, inference, and evaluation pipelines.
  • Optimize prompting, context retrieval, and RAG workflows for accuracy, safety, and efficiency in Claude-based systems.
  • Build automated evaluation pipelines to measure model quality, correctness, groundedness, and safety in production.
  • Implement schema validation, structured output enforcement, and guardrails to ensure reliable, compliant AI outputs.
  • Mentor and coach engineers to support team and community growth.
What you’ll bring to the role
  • 10+ years of software development experience, with strong programming expertise in Python (and familiarity with Go or Typescript a plus).
  • Hands‑on experience with applied machine learning, from feature engineering to training and fine‑tuning models.
  • Hands‑on experience with modern Generative AI platforms (AWS Bedrock, OpenAI, Anthropic, etc.).
  • Deep understanding of retrieval-augmented generation (RAG), embeddings, and knowledge‑base workflows.
  • Hands‑on experience with LiteLLM, LangGraph, LangChain, LlamaIndex, MCP, or other related AI agent frameworks.
  • Familiarity with ML frameworks (FastAPI, PyTorch, TensorFlow, Spark ML) and workflow orchestration tools (Airflow, etc.).
  • Experience defining evaluation metrics, pipelines, and feedback loops for ML/GenAI systems.
  • Proven ability to collaborate with product and engineering teams to drive greenfield initiatives forward, navigate unknowns, and iterate quickly and frequently.
  • Experience building tools or infrastructure for AI/ML applications, with a deep understanding of the developer lifecycle in an AI-native world.
Extra credit
  • Experience integrating AI-driven systems with identity, authentication, or security products.
  • Exposure to ethical AI, model risk, or compliance frameworks.
  • Familiarity with evaluation datasets, synthetic data generation, or LLM-as-a-judge methods.

Education:Bachelor’s or Master's degree in Computer Science or related field

(P25822_3552624)

#LI-Hybird

#LI-BB1

Below is the annual base salary range for candidates located in San Francisco Bay Area. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.

The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $238,000—$326,000 USD.

The Okta Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal AI Scientist, Identity & Security (Hybrid)
Principal AI Scientist, Identity & Security (Hybrid)

Okta • San Francisco (CA)

Hybrid
USD 274,000 - 376,000
Principal Applied AI Scientist (Auth0)
Principal Applied AI Scientist (Auth0)

Okta • San Francisco (CA)

Hybrid
USD 274,000 - 376,000
Principal Forward Deployed Engineer, Okta for AI Agents
Principal Forward Deployed Engineer, Okta for AI Agents

Okta • Bellevue (WA)

On-site
USD 240,000 - 360,000
Health insurance
Flexible spending account
Paid leave including PTO and parental leave
Senior Forward Deployed Engineer - Okta for AI Agents
Senior Forward Deployed Engineer - Okta for AI Agents

Okta • Dallas (TX)

On-site
USD 200,000 - 275,000
Health insurance
Dental insurance
Vision insurance
+4
Senior Software Engineer, AI Agentic Experience (Auth0)
Senior Software Engineer, AI Agentic Experience (Auth0)

Triwill Group • Chicago (IL), New York (NY), Bellevue (WA)

On-site
USD 147,000 - 202,000
Staff Software Engineer, AI-Core (Federal)
Staff Software Engineer, AI-Core (Federal)

Okta • San Francisco (CA)

On-site
USD 194,000 - 267,000
Equity
Bonus
Health Insurance
+4
Staff AI Security Engineer
Staff AI Security Engineer

Okta • Bellevue (WA)

Hybrid
USD 180,000 - 248,000
Equity
Bonus
Health insurance
+5
Senior Software Engineer, AI Agentic Experience (Auth0)
Senior Software Engineer, AI Agentic Experience (Auth0)

Okta • Chicago (IL)

On-site
USD 147,000 - 202,000
Equity
Annual bonus
Health insurance
+3
Software Engineer II, Frontend Agentic AI
Software Engineer II, Frontend Agentic AI

Okta • San Francisco (CA)

On-site
USD 140,000 - 192,000
Senior Software Engineer, AI Agentic Experience (Auth0)
Senior Software Engineer, AI Agentic Experience (Auth0)

Okta • Bellevue (WA)

On-site
USD 147,000 - 202,000