Staff Fullstack Engineer, SecureAI

Okta

Toronto (OH)

On-site

USD 112,000 - 154,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Equity
Annual bonus
Health, dental, vision insurance
RRSP match
Paid leave

Job summary

Okta is seeking a Staff Fullstack Engineer to shape the Identity Security Fabric and build secure, scalable AI-enabled identity infrastructure. You will own backend and frontend patterns, aligning with a North Star of getting AI and identity right in a unified control plane.

You will lead design, reviews, and delivery of AI-native workflows, while mentoring peers and driving CI/CD, observability, and reliability improvements across the team.

Qualifications

  • Bachelor's or Master's degree in Computer Science or related field.
  • At least 8 years of experience in full-stack software engineering.
  • Experience spanning backend and frontend development.

Responsibilities

  • Shape the technical strategy for the Identity Security Fabric with leadership.
  • Build the Runtime Policy Decision Point and authorization engines.
  • Design policy engine integration with Cedar and admin UI outputs.
  • Develop logic to map delegated agents to employees and forward identity.
  • Develop comprehensive audit logging for requests and decisions.
  • Advance AI-native development practices and CI/CD, observability, and tooling.
  • Prioritize tech debt and improve reliability and tooling.
  • Collaborate with Product and Design to meet customer outcomes.
  • Mentor engineers and raise team technical standards.

Skills

AI tooling
Backend architecture
API integration
Auth flows
Java backend
Frontend development
Team leadership
Security best practices

Education

Bachelor's or Master's in Computer Science

Tools

Cedar

Job description

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

About Okta Secures AI Team

The Okta for AI Agents Team is building the future of digital identity management. The way companies are using agents and allowing them access is undergoing a fundamental shift, enabling teams to move fast while staying secure.

Our North Star is clear: To get AI right, you have to get identity right. We are not just managing identities; we are building the industry's first Identity Security Fabric for the agentic era. As organizations rapidly deploy AI, these non-human entities are acting with access to critical tools, often bypassing traditional perimeters and creating a 'Shadow AI' crisis. Our mission is to move identity from a reactive gatekeeper to a unified control plane, transforming AI risk into business ROI.

We are tackling this by implementing a comprehensive four-pillar maturity model: Discover, Onboard, Protect, and Govern. We are driving innovation by defining the standards for Agentic Identity—including pioneer work with securing AI Agents and support for protocols like MCP. You will be helping us build the infrastructure that allows enterprises to scale AI safely, ensuring every access decision - whether made by a human or an automated agent is authenticated, authorized, and audited at scale.

We are a diverse team of engineers, product managers, and designers who are bringing Okta's expertise in identity to define the future of Agent Identity management, focusing on enablement while staying secure.

About the role

As a Staff Fullstack Engineer on the Okta Secures AI team, your mission is to build the industry's first Identity Security Fabric for the agentic era. You will be working on the designs and driving of our unified control plane features, ensuring that we operationalize our North Star: "To get AI right, you have to get identity right."

As a true full-stack role, you will actively design, build, and maintain both robust backend services and intuitive frontend interfaces. This role requires deep expertise in distributed systems and a commitment to AI-native engineering as our standard. You will rethink backend design, validation, and delivery through AI-augmented workflows, ensuring our platform provides secure, interoperable, and scalable access - enforcing the principle of least privilege for every agent action.

What you'll be doing
  • Proactively shape the technical strategy of the Identity Security Fabric, partnering with leadership to prioritize the work streams for securing AI Agents.
  • Build the Runtime Policy Decision Point (PDP). Implement the request-time authorization engine at the Agent Gateway and at the agent to resource connection level to intercept and evaluate every agent request against per-agent, per-tool, and per-resource rules.
  • Design and support authoring from a policy engine like Cedar, schema validation, and evaluation - connecting the admin console's no-code UI builder output with direct API-published policies.
  • Develop the logic to validate which employees a delegated agent is permitted to represent and securely forward the acting user's identity to downstream resources.
  • Develop Comprehensive Audit Logging. Build secure logging mechanisms to record the outcome of every request (allow or deny) along with the specific rule or reason behind the decision.
  • Drive continual evolution in the adoption of AI-native development practices, helping the team rethink how we design, review, and ship software with AI as a core part of the workflow.
  • Proactively identify and prioritize tech debt; drive improvements in areas beyond feature work - CI/CD, observability, documentation, reliability, and support processes.
  • Partner with Product and Design to understand and own the desired customer outcome, not just the technical deliverable.
  • Actively invest in the growth of peer engineers, taking responsibility for raising the technical bar of the team as a whole.
What you'll bring to the role
  • Operates well beyond basic AI tool usage - understands how to apply AI meaningfully across the full software development lifecycle, can evaluate and adopt new AI tooling with good judgment, and is able to establish practices and bring a team along.
  • Proven experience defining scalable backend architectures and integrating complex APIs with modern web technologies - including the ability to make and defend architectural decisions with lasting org-wide impact.
  • Solid understanding of web authentication and authorization fundamentals - how auth flows work, and best practices for securing sensitive user data.
  • Architectural expertise: Proven experience defining scalable backend architectures and integrating complex APIs with modern web technologies, including making decisions with lasting, org-wide impact.
  • Backend proficiency: Deep expertise in building reliable, secure, enterprise-grade software in Java or another type-safe language.
  • Frontend flexibility: High proficiency in JavaScript/TypeScript with true fullstack range, including the ability to ship robust frontends.
  • Prior experience leading a team of engineers through a meaningful shift in ways of working - whether around AI adoption, developer tooling, or engineering culture change is a strong plus.
Extra credit
  • Experience with identity, authorization, or IAM protocols (e.g., OAuth, OIDC, SAML)
  • Work with agent frameworks, AI-facing APIs, or developer toolchains in the LLM space

Education and Experience: Bachelor's or Master's degree in Computer Science or related field At least 8 years of experience in full-stack software engineering, spanning both backend and frontend development.

(P25831_3552620)

Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit https://rewards.okta.com/can. The annual base salary range for this position for candidates located in Canada is between: $160,000 - $220,000 CAD.

The Okta Experience
  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Machine Learning Engineer, SecureAI
Staff Machine Learning Engineer, SecureAI

Okta • Toronto (OH)

Hybrid
USD 118,000 - 162,000
Staff Frontend Engineer, SecureAI
Staff Frontend Engineer, SecureAI

Okta • Toronto (OH)

On-site
USD 112,000 - 155,000
Equity
Bonus
Health insurance
+6
Principal Machine Learning Engineer, SecureAI
Principal Machine Learning Engineer, SecureAI

Okta • San Francisco (CA)

Hybrid
USD 238,000 - 326,000
Equity
Bonus
Health insurance
+5
Principal Machine Learning Engineer, SecureAI
Principal Machine Learning Engineer, SecureAI

Okta • San Jose (CA)

On-site
USD 238,000 - 326,000
Principal Machine Learning Engineer, SecureAI
Principal Machine Learning Engineer, SecureAI

Empleora • San Francisco (CA), Northern (KY)

Hybrid
USD 238,000 - 326,000
Equity
Bonus
Health insurance
+5
Senior Forward Deployed Engineer - Okta for AI Agents
Senior Forward Deployed Engineer - Okta for AI Agents

Okta • Dallas (TX)

On-site
USD 200,000 - 275,000
Health insurance
Dental insurance
Vision insurance
+4
Principal Forward Deployed Engineer, Okta for AI Agents
Principal Forward Deployed Engineer, Okta for AI Agents

Okta • Bellevue (WA)

On-site
USD 240,000 - 360,000
Health insurance
Flexible spending account
Paid leave including PTO and parental leave
Manager, Engineering, SecureAI
Manager, Engineering, SecureAI

Okta • Toronto (OH)

On-site
USD 118,000 - 162,000
FedRAMP High Template
FedRAMP High Template

Okta • San Francisco (CA)

Hybrid
USD 204,000 - 281,000
Equity
Bonus
Health insurance
+4
Staff Software Engineer, AI-Core (Federal)
Staff Software Engineer, AI-Core (Federal)

Okta • San Francisco (CA)

On-site
USD 194,000 - 267,000
Equity
Bonus
Health Insurance
+4