Senior Product Security Engineer, Reviews

at  Okta

Dublin, County Dublin, Ireland -

Start DateExpiry DateSalaryPosted OnExperienceSkillsTelecommuteSponsor Visa
Immediate08 Nov, 2024Not Specified09 Aug, 2024N/ADesign Principles,C,Authentication,Swift,Kotlin,Developers,Sca,Python,Architecture,App,Fuzzing,Penetration Testing,Automation,C++,Windows,PerspectivesNoNo
Add to Wishlist Apply All Jobs
Required Visa Status:
CitizenGC
US CitizenStudent Visa
H1BCPT
OPTH4 Spouse of H1B
GC Green Card
Employment Type:
Full TimePart Time
PermanentIndependent - 1099
Contract – W2C2H Independent
C2H W2Contract – Corp 2 Corp
Contract to Hire – Corp 2 Corp

Description:

GET TO KNOW OKTA

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.
Join our team! We’re building a world where Identity belongs to you.

SENIOR PRODUCT SECURITY ENGINEER, REVIEWS

Product Security Engineers are responsible for conducting security reviews on all of Okta’s products, providing security education to our engineers, and handling externally reported vulnerabilities. This ranges from code reviews, penetration tests, and architectural reviews on new features and existing code, in order to provide security education and guidance to the entire organization.
This position is not for someone who operates solely on scanner-based vulnerabilities. You will be required to demonstrate a strong technical understanding of web applications, backend services, penetration testing techniques and methodologies. You should have a clear understanding of Okta’s authentication protocols, such as SAML and OAuth. Furthermore, you should have the desire to automate tasks by building tools to help discover vulnerabilities and be comfortable explaining and communicating vulnerabilities to developers, management and leadership by creating thorough documentation of findings.
The most important quality we are looking for is someone who has an “evil bit” - an innate ability to think and operate like an attacker while solving complex problems with expertise and creativity. At Okta we fully support externally publishing exciting new findings and will help you do it in the form of white papers, blog posts, and live presentations at conferences of your choice.

Job Duties and Responsibilities:

  • Work closely with Engineering teams on Design Reviews and Threat Models for new features or major changes
  • Audit code for security flaws and adherence to best practices
  • Perform penetration tests on new features and platforms as a whole
  • Develop, implement, and communicate vulnerability mitigation strategies to development teams
  • Work both solo and collaboratively to deliver projects on a deadline
  • Think like an attacker and solve complex problems with expertise and ingenuity
  • Give security presentations and represent Okta in private or public venues

Required Knowledge, Skills, and Abilities:

  • Expertise in identifying common (OWASP Top 10/CWE Top 25) web application vulnerabilities through secure code reviews (Java, .Net, Go, C, C++, C#, Swift, Kotlin, Python)
  • Proficient in conducting manual web application penetration tests using industry-standard tools
  • Extensive knowledge of modern web application components, architecture, and design principles
  • Ability to explain vulnerability risks, impact and remediation options to developers
  • Coding ability in at least one scripting language (ex: Python, Bash)
  • Capable of taking point on product security incidents and providing recommendations to the organization.
  • Be able to identify risks on large features or new products as well as being able to provide clear mitigations and follow up on remediation efforts
  • Ability to provide guidance and mentorship to junior engineers as well as non-security staff

    Desired Skills and Abilities:

  • Working knowledge of current authentication and authorization protocols (OIDC, SAML)

  • Experience in mobile device (Android and/or iOS) application penetration testing
  • Experience with testing Windows desktop applications
  • Experience with SAST, DAST, SCA, and fuzzing tools
  • Knowledge of current cryptographic algorithms and techniques
  • Experience in attacking network protocols and analyzing network traffic
  • Experience writing proof-of-concept scripts to demonstrate vulnerability exploitation

LI-JP2

LI-Remote

Responsibilities:

  • Work closely with Engineering teams on Design Reviews and Threat Models for new features or major changes
  • Audit code for security flaws and adherence to best practices
  • Perform penetration tests on new features and platforms as a whole
  • Develop, implement, and communicate vulnerability mitigation strategies to development teams
  • Work both solo and collaboratively to deliver projects on a deadline
  • Think like an attacker and solve complex problems with expertise and ingenuity
  • Give security presentations and represent Okta in private or public venue


REQUIREMENT SUMMARY

Min:N/AMax:5.0 year(s)

Information Technology/IT

IT Software - Network Administration / Security

Software Engineering

Graduate

Proficient

1

Dublin, County Dublin, Ireland