10 days ago
Responsibilities
- Lead initiatives that strengthen security posture and promote infrastructure security best practices across Engineering.
- Respond to production security incidents, perform root cause analysis, and build automated preventive controls.
- Automate manual security processes through custom tooling and CI/CD integrations.
- Develop technical documentation, runbooks, and operating procedures for a 24x7 environment.
- Evolve monitoring platforms from auditing and detection toward active automated prevention.
- Design and maintain large-scale IAM policies and secrets-management workflows.
- Implement and maintain PKI and enforce compliance standards across GCE and GKE environments.
- Use OSQuery, Splunk, Chronicle, Nessus, Qualys, and CrowdStrike to monitor system health and security telemetry.
- Lead phased transitions of security policies from audit or detection mode to blocking or prevention mode without affecting uptime.
- Drive technical alignment across teams, contribute to roadmaps, and mentor junior engineers.
Requirements
- 8+ years of experience architecting and operating complex cloud networking and infrastructure.
- At least 7+ years specializing in DevSecOps or Cloud Security.
- At least 3+ years of deep, hands-on experience securing GCP environments, including GKE, GCE, and Shared VPC.
- 10+ years of experience using Terraform and Chef to manage cloud resources and OS hardening.
- Expert proficiency in Go, Python, or Ruby for custom security tooling and automated remediation.
- Experience securing containerized workloads through image scanning, Kubernetes RBAC, and runtime security tools such as CrowdStrike Falcon, Falco, or gVisor.
- Strong ability to troubleshoot complex networking, IAM, and performance issues under pressure.
- Strong knowledge of Linux internals, OS hardening, CIS benchmarks, and IP protocols including TLS/SSL, DNSSEC, and BGP.
- Bachelor of Science in Computer Science or equivalent professional experience.
- Experience with unified IAM governance across AWS and GCP, federated identities, Workload and Workforce Identity Federation, SAML, OIDC, and least-privilege enforcement is preferred.
- Experience with multi-cloud reliability patterns and maintaining high availability during security patching or infrastructure hardening is preferred.
- Advanced experience securing GKE, EKS, and kOps using Pod Security Standards, Network Policies, and Admission Controllers is preferred.
- Experience with security reviews and threat modeling across design and implementation is preferred.
Benefits
- In-person onboarding is provided to accelerate impact and build team connections.
- The company supports employee well-being, social impact, talent development, and community connection.
- Okta has a global community spanning more than 20 offices worldwide.
Tech Stack
Categories
SecuritySite Reliability
About Okta
Okta secures AI. Okta is The World’s Identity Company. Freeing everyone to safely use any technology—anywhere, on any device or app.
