Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.
About Okta Secures AI Team
The Okta for AI Agents Team is building the future of digital identity management. The way companies are using agents and allowing them access is undergoing a fundamental shift, enabling teams to move fast while staying secure.
Our North Star is clear: To get AI right, you have to get identity right. We are not just managing identities; we are building the industry's first Identity Security Fabric for the agentic era. As organizations rapidly deploy AI, these non-human entities are acting with access to critical tools, often bypassing traditional perimeters and creating a 'Shadow AI' crisis. Our mission is to move identity from a reactive gatekeeper to a unified control plane, transforming AI risk into business ROI.
We are tackling this by implementing a comprehensive four-pillar maturity model: Discover, Onboard, Protect, and Govern. We are driving innovation by defining the standards for Agentic Identity - including pioneer work with securing AI Agents and support for protocols like MCP. You will be helping us build the infrastructure that allows enterprises to scale AI safely, ensuring every access decision - whether made by a human or an automated agent - is authenticated, authorized, and audited at scale.
We are a diverse team of engineers, product managers, and designers who are bringing Okta’s expertise in identity to define the future of Agent Identity management, focusing on enablement while staying secure.
About the role
As a Principal Software Engineer on the Agent Access Policies sub-team in the Okta Secures AI, you will serve as the technical leader and compass for the Okta Secures AI Team. You'll work across the breadth of the platform, tackling the highly complex, vaguely specified problems that span it and turning them into clear technical directions the team can execute against, without day-to-day oversight.
Above all, you'll own how the platform is architected to scale: the distributed systems behind it, the reliability and consistency guarantees developers depend on, and the coherence that keeps it easy to build on as usage grows. You'll champion the team's technical execution, raise the engineering bar, mentor the people around you, and partner with tech leads across teams to keep the wider platform aligned. You'll have real influence over how our platform holds up in a world where developers and agents are both first-class consumers.
What you’ll be doing
- Set the technical direction for the Agent Access Policies framework, and make the cross-cutting decisions that keep it coherent and easy to build on as it grows.
- Design the distributed systems behind the platform for throughput, reliability, and consistency, so the guarantees developers depend on hold up under real load.
- Take the hardest, most vaguely specified platform problems and turn them into clear, modular technical designs the team can execute against.
- Shape the platform so it holds up whether a person or an agent is calling it, and so both can build and automate their work against Okta for AI Agents.
- Set the standard for how the team designs, builds, and operates the platform, and lead deep, constructive reviews that grow the engineers around you.
- Operate peer-to-peer with tech leads in adjacent teams to review major architectural decisions and keep the wider platform aligned.
- Drive continual evolution in the adoption of AI-native development practices, helping the team rethink how we design, review, and ship software with AI as a core part of the workflow.
- Proactively identify and prioritize tech debt; drive improvements in areas beyond feature work - CI/CD, observability, documentation, reliability, and support processes.
- Partner with Product and Design to understand and own the desired customer outcome, not just the technical deliverable.
- Actively invest in the growth of peer engineers, taking responsibility for raising the technical bar of the team as a whole.
What you’ll bring to the role
- 10+ years of software engineering experience, with a proven track record as a Principal or Staff level individual contributor.
- Extensive experience designing and operating high-scale, reliable backend and event-driven systems, with a strong grasp of the tradeoffs in throughput, consistency, and failure handling.
- You can own vaguely specified problems and drive them to a clear technical direction without heavy top-down scoping.
- Experience working across engineering, product, and architecture in a fast-moving environment, and a habit of raising the bar for the people around you.
- Proven experience defining scalable backend architectures and integrating complex APIs with modern web technologies - including the ability to make and defend architectural decisions with lasting org-wide impact.
- Solid understanding of web authentication and authorization fundamentals - how auth flows work, and best practices for securing sensitive user data.
- Architectural expertise: Proven experience defining scalable backend architectures and integrating complex APIs with modern web technologies, including making decisions with lasting, org-wide impact.
- Backend proficiency: Deep expertise in building reliable, secure, enterprise-grade software in Java or another type-safe language.
- Prior experience leading a team of engineers through a meaningful shift in ways of working - whether around AI adoption, developer tooling, or engineering culture change is a strong plus.
- Bachelor’s or Master's degree in Computer Science or related field
Extra credit
- Experience with identity, authorization, or IAM protocols (e.g., OAuth, OIDC, SAML)
- Hands-on familiarity with agentic tooling, MCP, or LLM-facing design, and a sense for how agents consume a platform.
(P25830_3564651)
Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit: https://rewards.okta.com/can.
The annual base salary range for this position for candidates located in Canada is between:
$184,000 - $253,000 CAD
The Okta Experience
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.