- Company Name
- Okta
- Job Title
- Staff Security Engineer, TDI
- Job Description
-
**Job Title**
Staff Security Engineer, TDI
**Role Summary**
Provide tactical and strategic security engineering within Okta’s TDI environment. Lead vulnerability remediation, implement secure development practices, create secure baseline images, and build automation for continuous security improvement across AWS, endpoints, and SaaS applications.
**Expectations**
- 10+ years engineering experience in a SaaS or enterprise security context.
- Proven ability to lead remediation initiatives, mentor developers, and influence cross‑functional teams.
- Strong track record of integrating and operating vulnerability tools (Snyk, Semgrep, Qualys).
- Experience with AWS security, SRE principles, and securing cloud & SaaS stacks (Salesforce, ERP, Google Workspace, Slack, Zoom).
**Key Responsibilities**
- Drive end‑to‑end vulnerability and asset management for endpoints, cloud workloads, and on‑prem assets.
- Deploy, configure, and maintain Snyk, Semgrep, Qualys, and other scanning tools.
- Mentor developers and admins in remediation practices, enhancing speed and quality.
- Collaborate with GRC to update risk registers and support risk acceptance processes.
- Embed with product and engineering teams to advise on secure coding, pipeline security, and secure SDLC adoption.
- Automate secrets rotation, secrets management, and enforce best practices across systems.
- Build and maintain secure baseline container/VM images for AWS, coordinating update pipelines with SRE.
- Conduct lightweight security architecture reviews for lower environments.
- Develop automation for scanning, reporting, patch validation, and CI/CD pipeline security.
**Required Skills**
- Deep technical expertise in vulnerability scanning, patching, and remediation across cloud, endpoint, and SaaS environments.
- Hands‑on experience with Snyk, Semgrep, Qualys, CSPM, and CI/CD pipeline security tools.
- Proficiency in AWS security practices, SRE principles, and securing business technology stacks.
- Strong knowledge of secure SDLC/PDLC, supply‑chain security, and secrets management.
- Excellent troubleshooting, communication, and proactive problem‑solving abilities.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience).
- Preferred certifications: CISSP, CISM, OSCP, or similar security‑engineering credentials.
San francisco, United states
Hybrid
Senior
04-11-2025