About this role
Okta's product is identity, so security engineering there is not a supporting function bolted onto the side, it is the thing customers pay for. This role sits between the engineering and security organisations, developing requirements for the security roadmap and then building against them: researching, designing, implementing and owning security oriented frameworks and features intended to protect Okta's customers. A meaningful part of the job is influence rather than code, evangelising security practice across the engineering organisation and taking part in cross vertical code reviews with a security emphasis. The requirement list is Java heavy, asking for seven years of designing and implementing reliable, mission critical systems plus three years specifically designing security solutions for applications and distributed systems. Mentoring junior engineers is listed, but there are no reports, so this is a staff individual contributor seat.
Who this is for
Required
- 7+ years of development experience designing and implementing software systems in Java, building highly reliable and mission critical software.
- 3+ years of work experience designing and implementing security solutions for applications and distributed systems.
The day to day
- Acting as a liaison between the engineering and security organisations to develop requirements for the security roadmap.
- Evangelising security best practices across the engineering organisation.
- Researching, designing, implementing and owning security oriented frameworks and features with the goal of protecting Okta's customers.
- Routinely participating in cross vertical code reviews with an emphasis on security.
- Breaking down complex problems into sub tasks, prototyping rapidly and iteratively using agile practices.
- Coaching and mentoring junior engineers on the team.
Location and working style
Bengaluru, India, tagged hybrid. Okta describes an immersive in person onboarding experience at the start of employment, and recent Okta postings on this board have specified two days on site per week and travel to the Bengaluru office during the first week. Confirm both at the first screen.
Honest fit guidance
The split in the requirements is the thing to focus on. Seven years of Java is the base, and three years of applied security design is the differentiator. Application security engineers who have not done deep Java, and Java engineers who have never designed a security control, both sit slightly outside the stated bar. If you have both, there are not many roles that ask for exactly that combination.
The liaison and evangelism responsibilities mean a meaningful share of the job is persuading other engineers, writing things down and reviewing other people's code. Some engineers find that the most valuable work they do; others find it draining compared with building. Ask in the interview what the split looks like across a typical quarter.
Working on identity means the security work is genuinely consequential: the failure mode is somebody else's authentication. That raises both the interest and the pressure.
Okta has four roles in this edition, from a 3+ year AEM engineering role up to this one at 7+.
- 7+ years of development experience designing and implementing software systems in Java, building highly reliable and mission critical software.
- 3+ years of work experience designing and implementing security solutions for applications and distributed systems.
The day to day
- Acting as a liaison between the engineering and security organisations to develop requirements for the security roadmap.
- Evangelising security best practices across the engineering organisation.
- Researching, designing, implementing and owning security oriented frameworks and features with the goal of protecting Okta's customers.
- Routinely participating in cross vertical code reviews with an emphasis on security.
- Breaking down complex problems into sub tasks, prototyping rapidly and iteratively using agile practices.
- Coaching and mentoring junior engineers on the team.
Location and working style
Bengaluru, India, tagged hybrid. Okta describes an immersive in person onboarding experience at the start of employment, and recent Okta postings on this board have specified two days on site per week and travel to the Bengaluru office during the first week. Confirm both at the first screen.
Honest fit guidance
The split in the requirements is the thing to focus on. Seven years of Java is the base, and three years of applied security design is the differentiator. Application security engineers who have not done deep Java, and Java engineers who have never designed a security control, both sit slightly outside the stated bar. If you have both, there are not many roles that ask for exactly that combination.
The liaison and evangelism responsibilities mean a meaningful share of the job is persuading other engineers, writing things down and reviewing other people's code. Some engineers find that the most valuable work they do; others find it draining compared with building. Ask in the interview what the split looks like across a typical quarter.
Working on identity means the security work is genuinely consequential: the failure mode is somebody else's authentication. That raises both the interest and the pressure.
Okta has four roles in this edition, from a 3+ year AEM engineering role up to this one at 7+.
Apply on company site
Opens www.okta.com, the employer's own application page. Applying is always free.