Senior Product Security Engineer, Reviews

5 days ago


Dublin, Dublin City, Ireland Okta, Inc. Full time
Senior Product Security Engineer, Reviews

Ireland

Get to know Okta

Okta is The World's Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we're looking for lifelong learners and people who can make us better with their unique experiences. Join our team We're building a world where Identity belongs to you.

Application Security Engineers are responsible for conducting security reviews on all of Okta's products, providing security education to our engineers, and handling externally reported vulnerabilities. This ranges from code reviews, penetration tests, and architectural reviews on new features and existing code, in order to provide security education and guidance to the entire organization.

This position is not for someone who operates solely on scanner-based vulnerabilities. You will be required to demonstrate a strong technical understanding of web applications, backend services, penetration testing techniques and methodologies. You should have a clear understanding of Okta's authentication protocols, such as SAML and OAuth. Furthermore, you should have the desire to automate tasks by building tools to help discover vulnerabilities and be comfortable explaining and communicating vulnerabilities to developers, management and leadership by creating thorough documentation of findings.

The most important quality we are looking for is someone who has an "evil bit" - an innate ability to think and operate like an attacker while solving complex problems with expertise and creativity. At Okta we fully support externally publishing exciting new findings and will help you do it in the form of white papers, blog posts, and live presentations at conferences of your choice.

Job Duties and Responsibilities:

  • Work closely with Engineering teams on Design Reviews for new features or major changes
  • Audit code for security flaws and best practices
  • Perform Penetration Tests on new features and on the platform as a whole
  • Develop, implement, and communicate vulnerability mitigation strategies to development teams
  • Work solo and collaboratively to deliver projects on a deadline
  • Think like an attacker and solve complex problems with expertise and ingenuity
  • Give security presentations and represent Okta in private or public venues

Required Knowledge, Skills, and Abilities:

  • Ability to identify common (OWASP Top 10/CWE Top 25) web application vulnerabilities through secure code review (Java, .Net, Go, C, C++, C#, Swift, Kotlin, Python)
  • Ability to conduct a manual Web Application Penetration Test using industry standard tools (ex: Burp Suite)
  • Knowledge of modern web application components, architecture, and design principles
  • Ability to explain vulnerability risks and remediation options to developers
  • Beginner level coding ability in at least one scripting language (ex: Python, Bash)

Desired skills and Abilities:

  • Knowledge in current authentication and authorization protocols (OIDC, SAML)
  • Experience in mobile device (Android and/or iOS) application penetration testing
  • Experience with SAST, DAST, SCA, and fuzzing tools
  • Knowledge in current cryptographic algorithms and techniques
  • Experience in attacking network protocols and analyzing network traffic
  • Experience writing proof of concept scripts to demonstrate vulnerability exploitation

Security Reviews "Desired" Skills:

  • Knowledge in current authentication and authorization protocols (OIDC, SAML)
  • Knowledge in current cryptographic algorithms and techniques
  • Experience in research and presenting findings (internally or externally) in the security field
  • Experience reverse engineering Linux and/or Windows binaries
  • Experience in mobile device (Android and/or iOS) application penetration testing
  • Experience in attacking network protocols and analyzing network traffic
  • Experience writing proof of concept scripts to demonstrate vulnerability exploitation
  • Experience in professional software development
  • Knowledge of AWS and/or Google Cloud Compute from an attacker perspective
  • Experience with SAST, DAST, SCA, and fuzzing tools

What you can look forward to as an Full-Time Okta employee

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today .

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to participate in the job application or interview process, please use this Form to request an accommodation.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at .

U.S. Equal Opportunity Employment Information
Read more

Individuals seeking employment at this company are considered without regards to race, color, religion,national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, genderidentity, or sexual orientation. When submitting your application above, you are being given theopportunity to provide information about your race/ethnicity, gender, and veteran status. This informationhelps us support or diversity, inclusion, and belonging efforts, as well as maintain fair and equitablehiring practices.

Completion of the form is entirely voluntary . Whatever your decision, it will not beconsidered in the hiring process or thereafter. Any information that you do provide will be recorded andmaintained in a confidential file.

If you believe you belong to any of the categories of protected veterans listed below, please indicate bymaking the appropriate selection. As a government contractor subject to Vietnam Era Veterans ReadjustmentAssistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreachand positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air servicewho is entitled to compensation (or who but for the receipt of military retired pay would be entitled tocompensation) under laws administered by the Secretary of Veterans Affairs; or a person who was dischargedor released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date ofsuch veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S.military, ground, naval or air service during a war, or in a campaign or expedition for which a campaignbadge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S.military, ground, naval or air service, participated in a United States military operation for which anArmed Forces service medal was awarded pursuant to Executive Order

Individuals seeking employment at this company are considered without regards to race, color, religion,national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, genderidentity, or sexual orientation. When submitting your application above, you are being given theopportunity to provide information about your race/ethnicity, gender, and veteran status. This informationhelps us support or diversity, inclusion, and belonging efforts, as well as maintain fair and equitablehiring practices.

Completion of the form is entirely voluntary . Whatever your decision, it will not beconsidered in the hiring process or thereafter. Any information that you do provide will be recorded andmaintained in a confidential file.

If you believe you belong to any of the categories of protected veterans listed below, please indicate bymaking the appropriate selection. As a government contractor subject to Vietnam Era Veterans ReadjustmentAssistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreachand positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air servicewho is entitled to compensation (or who but for the receipt of military retired pay would be entitled tocompensation) under laws administered by the Secretary of Veterans Affairs; or a person who was dischargedor released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date ofsuch veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S.military, ground, naval or air service during a war, or in a campaign or expedition for which a campaignbadge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S.military, ground, naval or air service, participated in a United States military operation for which anArmed Forces service medal was awarded pursuant to Executive Order

Pay Transparency

Okta complies with all applicable federal, state, and local pay transparency rules. For additionalinformation about the federal requirements, click here .

Voluntary Self-Identification of Disability
Form CC-305
Page 1 of 1
OMB Control Number
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years. Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor's Office of Federal Contract Compliance Programs (OFCCP) website at

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor's Office of Federal Contract Compliance Programs (OFCCP) website at .

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your "major life activities." If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson's disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

The foundation for secure connections between people and technology

Okta is the leading independent provider of identity for the enterprise. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With over 7,000 pre-built integrations to applications and infrastructure providers, Okta customers can easily and securely use the best technologies for their business. More than 18,800 organizations, including JetBlue, Nordstrom, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.

Follow Okta

First Name

Last Name

Email

Phone

Resume

Upload PDF

Paste

Resume/CV Upload Resume/CV (PDF must be less than 8 MB )

Resume/CV

Upload PDF

Paste

Upload Cover Letter (PDF must be less than 8 MB )

#J-18808-Ljbffr

  • Dublin, Dublin City, Ireland LZ Security & Service GmbH Full time

    eir evo talent are currently seeking applicants for a Senior Security Engineer/Analyst.This is a daily-rate contract position located with our client in Dublin. Hybrid options avaialble.Key Responsibilities:Assist in developing and implementing security policies, protocols, and procedures.Conduct security assessments through vulnerability testing and risk...


  • Dublin, Dublin City, Ireland Lastpass Full time

    LastPass is hiring a Senior Application Security Engineer (PHP):The LastPass Product Security team is looking for a Senior Application Security Engineer (PHP) to join their team and help ensure the security of their applications.If you enjoy tackling complex problems and are driven by scalability, then this role is perfect for you.Who will you collaborate...

  • Security Analyst

    2 weeks ago


    Dublin, Dublin City, Ireland Security Bank & Trust Co. Full time

    Senior Security Analyst Considering applicants in - Dublin, Leeds or London Style of work - Hybrid 2 days in office As our new Security Analyst you will drive Information Security and risk for global projects. You will be working to identify risks by analysing the latest threats to systems and providing security requirements for tech projects for...


  • Dublin, Dublin City, Ireland Zendesk, Inc. Full time

    Job DescriptionProduct Security at Zendesk is a globally distributed team of passionate, motivated and focused application security specialists. We know how to build applications securely and enjoy crafting creative approaches to scale security through automation, education or secure design. We develop processes and tools that allow us to make secure...


  • Dublin, Dublin City, Ireland Realtime Associates Limited Full time

    Realtime are looking for a highly skilled and experienced Senior Security Network Engineer to join our dynamic team. You will play a critical role in the design, implementation, and management of network security infrastructure. The ideal candidate will have extensive experience with Cisco Identity Services Engine (ISE) and hold certifications such as CCNA,...


  • Dublin, Dublin City, Ireland Playrix Full time

    Senior Security EngineerPlayrix is a major player in the mobile gaming industry, known for popular titles like Gardenscapes, Fishdom, and Township. We are currently seeking a Senior Security Engineer to join our Blue Team and play a key role in developing and implementing various InfoSec systems. Join us as we embark on new projects from scratch, offering...


  • Dublin, Dublin City, Ireland Zendesk International Ltd (Ireland) Full time

    Product Security Architect page is loaded Product Security Architect Apply locations Remote, Ireland time type Full time posted on Posted Today job requisition id R25916 Job Description Who we're looking for Product Security at Zendesk is a globally distributed team of passionate, motivated and focused application security specialists. We understand how...


  • Dublin, Dublin City, Ireland Rits Information Security Specialists Full time

    Rits Information Security is recruiting.Rits Information Security Specialists is looking for information security consultants in both junior and senior positions. These are permanent fulltime positions based in Citywest Business Campus, Dublin.The successful candidates will be responsible for delivering security related consulting services to our customers....


  • Dublin, Dublin City, Ireland MasterCard Full time

    Senior Product Manager - Technical (Systems & Business Analysis) page is loaded Senior Product Manager - Technical (Systems & Business Analysis) Apply locations Dublin, Ireland time type Full time posted on Posted 6 Days Ago job requisition id R Our Purpose We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by...


  • Dublin, Dublin City, Ireland ServiceNow Full time

    ServiceNow ServiceNow allows employees to work the way they want to, not how software dictates they have to. And customers can get what they need, when they need it. View company page At ServiceNow, our technology makes the world work for everyone, and our people make it possible. We move fast because the world can't wait, and we innovate in ways no one...


  • Dublin, Dublin City, Ireland Great-West Lifeco Full time

    Full Time 8 monthFixed Term ContractpositionHybrid role based in our City Centre officesWhat we offerWe have embraced a hybrid working model for most of our positions, which means that you can enjoy a balanced approach of working from home for part of the week and working from the office for the remainder of the week.We offer a comprehensive benefits package...


  • Dublin, Dublin City, Ireland Integral Ad Science, Inc. Full time

    We are looking for a Senior Application Security Engineer to join our team to help us build and secure the Integral Ad Science (IAS) infrastructure and security operations. As part of the Information Security team you will participate and collaborate with multiple Product and R&D teams to ensure that the IAS Platform and our architecture remains secure and...


  • Dublin, Dublin City, Ireland MasterCard Full time

    Senior Product Manager – Technical page is loaded Senior Product Manager – Technical Apply locations Dublin, Ireland time type Full time posted on Posted 2 Days Ago job requisition id R Our Purpose We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart and accessible....


  • Dublin, Dublin City, Ireland Squarespace Full time

    Squarespace is looking for a Senior Security Engineer to work alongside a dedicated team responsible for monitoring and responding to attacks across Squarespace and its subsidiaries. The ideal candidate will play a crucial role in enhancing our security posture by developing robust playbooks, crafting effective alerts, and actively participating in the...


  • Dublin, Dublin City, Ireland Microsoft Full time

    Overview Security represents the most critical priorities for our customers in a world awash in digital threats, regulatory scrutiny, and estate complexity. Microsoft Security aspires to make the world a safer place for all. We want to reshape security and empower every user, customer, and developer with a security cloud that protects them with end to...

  • Security Engineer

    2 weeks ago


    Dublin, Dublin City, Ireland Coinbase Full time

    At Coinbase, our mission is to increase economic freedom around the world , and we couldn't do this without hiring the best people. We're a group of hard-working overachievers who are deeply focused on building the future of finance and Web3 for our users across the globe, whether they're trading, storing, staking or using crypto. Know those people who...


  • Dublin, Dublin City, Ireland Okta, Inc. Full time

    Join Okta's Enterprise Security Team as a Senior Engineer At Okta, we are on a mission to empower everyone to use any technology, anywhere, on any device. Our focus on Workforce and Customer Identity Clouds allows for secure and flexible access, authentication, and automation, revolutionizing how individuals navigate the digital realm by placing Identity at...


  • Dublin, Dublin City, Ireland ServiceNow Full time

    Job OverviewWe are looking for an experienced AI Red Teamer to enhance our AI Red Teaming capability. In this key role, you will be leading the charge in testing and securing our AI systems, which include large language models, their infrastructure, and data. Your mission will be to spearhead our defensive strategies, develop comprehensive testing...


  • Dublin, Dublin City, Ireland MasterCard Full time

    Senior Software Engineer (Real Time Payments) page is loaded Senior Software Engineer (Real Time Payments) Apply locations Dublin, Ireland time type Full time posted on Posted Yesterday job requisition id R Our Purpose We work to connect and power an inclusive, digital economy that benefits everyone, everywhere by making transactions safe, simple, smart...


  • Dublin, Dublin City, Ireland Millennium Management Full time

    Application Security EngineerMillennium's Information Security Team is seeking an experienced Application Security Engineer to protect our applications from security threats. In this role, you will collaborate with software engineering teams to establish security controls, combining software engineering skills with knowledge of data and Information...