freehire launches on Product Hunt on 26 August.

Follow →

Staff Engineer, Identity & Access Management

Open 42d posting dated 3 hours ago

Summary

Designs, implements, and secures Okta’s own identity infrastructure while mentoring engineers and driving AI-enabled identity initiatives in a hybrid Sydney office.

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Identity Team

Okta's internal Identity team secures the foundational trust layer for our modern enterprise. As organizations adopt phishing-resistant MFA, attackers have shifted toward session hijacking and cookie theft. Furthermore, with the rise of autonomous AI workloads, we are extending our platform to protect and govern a growing sprawl of non-human, agentic workflows. Our mission is to ensure every person and machine can safely connect to the right technology at the right time.

About the Role

As a Staff Engineer at Okta, you will be a technical authority within our internal IAM team, driving the architecture and execution of our identity fabric. You will champion our "Customer Zero" philosophy, partnering with product engineering to deploy Okta's newest features internally before they reach global markets. This role requires a technical leader who acts with ownership and urgency, turning action into traction and ruthlessly simplifying complex problems. You will serve as a mentor, influence architectural decisions, and help determine the future of the platform. Must be a U.S. citizen and will be working within the U.S. boundary to meet requirements of the FedRAMP compliance for Level 2.

Here is the complete, consolidated job description tailored for the Staff Engineer level.

What You’ll Be Doing (Responsibilities)

  • Drive Customer Zero Execution: Act as a key technical bridge between internal stakeholders, the Okta on Okta team, and core Product teams. Lead the early adoption of cutting-edge internal capabilities, providing rigorous technical feedback to mature products before global release.
  • Architecture & Hands-On Implementation: Own the lifecycle, policy design, adaptive MFA, and federation (SAML, OIDC) for enterprise Okta tenants. Architect and enforce cloud IAM guardrails across AWS, GCP, and Azure, building API-based pipelines to automate complex workflows.
  • Technical Leadership & Mentorship: Serve as a core technical anchor for the engineering team. Mentor engineers, act as a primary review authority for IAM designs, and set technical standards across the organization.
  • Operational & Security Governance: Drive automation-first initiatives to eliminate systemic inefficiencies. Partner directly with Security, Audit, and Compliance teams to ensure identity controls natively meet audit requirements (SOC 2, ISO 27001, FedRAMP).
  • AI Security Integration: Drive the secure adoption of AI technologies by governing AI agents, machine identities, and service-to-service authentication within the enterprise identity layer.
  • Cross-Functional Partnering & Metrics: Collaborate with cross-functional partners to advance identity security, establish operational KPIs, and translate complex technical milestones into actionable leadership updates.

What You’ll Bring (Technical Requirements & Qualifications)

To be successful in this role, you should have deep, hands-on architectural experience across the modern identity and cloud infrastructure lifecycle. We are looking for a practitioner who understands both theory and real-world implementation.

  • Domain Experience: 3+ years of hands-on experience designing, implementing, and maintaining enterprise-scale IAM solutions.
  • Okta Platform Mastery: Deep expertise in managing complex enterprise Okta environments, including hands-on proficiency with Okta Identity Engine (OIE), Directory Integrations, Advanced Policies, Workflows, and Platform APIs.
  • Core Identity Protocols: Advanced expertise in modern authentication and authorization standards (OIDC, OAuth 2.0, SAML 2.0) and phishing-resistant MFA paradigms (FIDO2/WebAuthn, Passkeys).
  • Cloud & Infrastructure as Code: Proven experience defining identity controls as code using Terraform and Okta Workflows. Practical experience designing cloud IAM guardrails across multi-cloud environments (AWS, GCP, Azure) and M2M/service-to-service authentication.
  • Session & Zero Trust Security: Solid background in session lifecycle security, token management/revocation strategies, and continuous access evaluations (CAEP/eSSO) to mitigate session hijacking.
  • Technical Leadership & Mentorship: Demonstrated experience mentoring engineers, driving design reviews, and establishing engineering best practices across teams.
  • Compliance & Automation Mindset: Strong orientation toward automation-first design, with practical experience building identity controls that align with enterprise frameworks (SOC 2, ISO 27001, FedRAMP).
  • Travel: Occasional travel required as needed.

#LI - hybrid

#LI - remote

P5614_3488197

The Okta Experience

  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • Preferred First Name optional
  • LinkedIn Profile optional
  • Website optional
  • Are you legally authorized to work in the country you reside? choose one
  • Will you now or in the future require Visa Sponsorship? choose one
  • To the best of your knowledge, do you have any family members / relatives or personal relationships at Okta or at any suppliers, partners, or vendors that have a business relationship with Okta? (For purposes of this question, a “family member / relative or personal relationship” is defined as close personal friends (including sexual and/or romantic relationships), close relatives (spouse, partner, children, cousins, aunts, uncles, nieces, nephews, grandparents or grandchildren), someone who lives in your household, or anyone else with whom you have a close enough personal relationship or connection that it could improperly bias your conduct or decision making or be perceived to be capable of impacting your conduct or decision making. choose one
  • If yes, please identify name of person / vendor and describe relationship / association: optional
  • Do you have any outside business activity(ies) (advisory, consulting, or board roles, or side businesses) that you would continue engaging in or plan to engage in if you joined Okta in this role? choose one
  • If yes, please describe: optional
  • Have you been employed by Okta, Inc. or any of its subsidiaries in the past? choose one
  • I acknowledge and agree to the processing of my personal data in accordance with Okta's privacy policy and personnel privacy policy (see below). choose any
  • By checking this box, you consent to Okta using your data to evaluate your candidacy for this role and any other current or future roles that may be a fit for your profile. You may request the removal of your data at any time by contacting greenhouse@okta.com. choose any · optional

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available