Senior Forward Deployed Engineer

1 month, 2 weeks ago
Full-time
Senior
Software Development
Okta

Okta

Okta is a leading independent provider of identity solutions for enterprises, offering a comprehensive range of products and services to connect and protect employees, partners, and customers. With a focus on secure access, authentication, and automati...

Professional Services
5K-10K
Founded 2009

Description

  • Serve as the customer’s trusted technical partner on agent security by participating in standups, design reviews, incident response, and architecture governance forums.
  • Architect and deploy Okta’s agent security stack within customer infrastructure, including Cross-App Access (XAA), Fine-Grained Authorization (FGA), MCP Gateway, and agent client registration.
  • Own the end-to-end identity, delegation, audit, and kill-switch architecture for AI agents and coach customer engineers on implementation patterns.
  • Brief senior leaders such as CISOs, CIOs, identity leaders, Chief AI Officers, and principal architects on agent risk, token-exchange flows, and AI governance.
  • Deliver white-glove production deployments with full identity coverage, passed security review, met governance requirements, and visible security posture.
  • Align solutions to relevant security and compliance frameworks, including OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS, HIPAA, FedRAMP, and SOC 2.
  • Integrate Okta with the customer’s identity, governance, posture, security monitoring, and policy systems, including IdP, IGA, ISPM, SIEM, EDR, and policy engines.
  • Build evaluation and observability capabilities for authorization latency, scope sprawl, delegation anomalies, audit completeness, kill-switch verification, and rogue agent detection.
  • Capture recurring customer needs and translate them into reusable product modules and roadmap improvements for Okta.
  • Work regularly on site with customers to build trust and align on governance decisions.

Requirements

  • 7+ years of experience shipping production software, with hands-on development, on-call experience, and operational maturity in high-throughput authentication and authorization systems.
  • Strong knowledge of identity protocols including OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD, DCR, and DPoP.
  • Working knowledge of OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS, with familiarity with MCP, A2A, ISO/IEC 42001, and the EU AI Act.
  • Experience mapping deployments to regulated environments such as HIPAA, FedRAMP, and SOC 2.
  • Experience with fine-grained authorization using ReBAC and ABAC and policy engines such as OPA, Cedar, OpenFGA, or equivalent.
  • Hands-on experience building production integrations with tools or platforms such as Claude, ChatGPT, Microsoft Copilot, Agentforce, Bedrock, LangChain, CrewAI, the OpenAI Agents SDK, or MCP servers.
  • Daily use of AI-native development tools such as Claude Code, Cursor, GitHub Copilot, or equivalent.
  • Ability to operate comfortably with both technical teams and senior executives, including customer standups and CISO briefings.
  • High-agency, founder-style mindset with ownership of outcomes end to end.
  • On-site presence at customer locations as needed; this role is remote but requires regular travel or in-person customer engagement.

Benefits

  • Annual base salary range of $200,000 to $275,000 for candidates in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington.
  • Equity eligibility where applicable.
  • Bonus eligibility.
  • Health, dental, and vision insurance.
  • 401(k) plan.
  • Flexible spending account.
  • Paid leave, including PTO and parental leave.
  • Remote work with regular in-person customer presence and immersive in-person onboarding.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Identity Engineer

Hasbro 5K-10K Consumer Goods

Wizards of the Coast is hiring a Principal Identity Engineer to own the technical direction of its enterprise identity architecture, supporting Zero Trust, privileged access, and identity governance across cloud and on-premises environments.

Active Directory CI/CD Git OpenID Connect PowerShell Pulumi Python REST API SAML Terraform
15 hours, 37 minutes ago

Senior Device Engineer

Dragos 251-1K Professional Services

Dragos is hiring a Senior Device Engineer to build automation software that identifies, fingerprints, and interacts with network-connected devices across critical infrastructure environments.

Cybersecurity Docker Embedded Systems Go HTTP JavaScript Node.js TCP/IP TLS TypeScript
15 hours, 37 minutes ago

Elastic Engineer

Jolera 251-1K Internet Software & Services

Jolera is seeking an Elastic Engineer to design and operate scalable Elasticsearch-based environments for cybersecurity analytics, threat hunting, and detection workflows.

Cybersecurity Elasticsearch Encryption Java Kibana Linux Logstash Machine Learning Python Ruby
16 hours, 7 minutes ago

Staff Software Development Engineer - Windows Endpoint

BeyondTrust 1K-5K Professional Services

BeyondTrust is hiring a Staff Software Development Engineer to own Windows kernel-mode enforcement for its Identity Security Platform, building real-time security controls that decide whether actions on Windows endpoints are permitted or denied.

Agile C C++ Rust
16 hours, 7 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers