About Okta

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transform how people move through the digital world, putting Identity at the heart of business security and growth. Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era.

Role Overview

The Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-service solutions provider by identifying and resolving risks to employees, products, and, most importantly, our customers. The Staff Product Security Engineer, PSIRT position is crucial in ensuring that Okta’s systems and services meet the highest security standards and align with our customers’ requirements. This position requires leadership, an innovative mindset, and expertise in security operations, responsible disclosure, vulnerability management, and program management.

Responsibilities

  • Responsible for defining, improving, formalizing, and implementing Okta’s Product Security Incident Response Program for all products and business units.
  • Responsible for the day-to-day operations of the bug bounty program, including researcher engagement, vulnerability triage and validation, severity assessment, remediation coordination, reward recommendations, and program process improvements.
  • Oversee the entire lifecycle from discovery to resolution, including triaging, impact assessment, coordination with engineering teams, and validating fixes while ensuring timely communication with internal and external stakeholders.
  • Lead the overall security disclosure program, from triaging to disclosure.
  • Report on the health of the program and the overall status of its activities.
  • Collaborate with internal teams to improve workflows, governance, and communication of vulnerabilities and risks.
  • Work closely with Engineering, IT, Product, Legal, and Security teams on cross-functional initiatives.
  • Mentor and provide guidance to junior engineers on incident response procedures, technical investigations, and vulnerability remediation.
  • Partner with leadership to drive proactive threat detection and vulnerability management.

The annual base salary range for this position for candidates located in Spain is between €74.000—€101.000 EUR. In addition, Okta offers equity (where applicable), bonus, and comprehensive healthcare coverage and financial benefits including paid time off and parental leave in accordance with our applicable plans and policies.

The Okta Experience

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

  • 6+ years of experience in Information Security with a focus on Product Security, Application Security, Vulnerability Management, and Security Operations.
  • Working experience in conducting comprehensive security code reviews to identify vulnerabilities and code flaws.
  • Working experience in Application Security vulnerabilities.
  • Working experience in Product Security concepts.
  • Working experience in risk management.
  • Working experience in handling incident response for product-related issues.
  • Knowledge of incident and log management tools.
  • Excellent communication and collaboration skills, particularly in technical writing, process documentation, and executive presentations.