Compañía

OktaVer más

addressDirecciónMadrid provincia
type forma de trabajoFull-Time
CategoríaTecnologías de la información

Descripción del trabajo

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth.
At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.
Join our team! We’re building a world where Identity belongs to you.

Senior Product Security Engineers are responsible for conducting security reviews on all of Okta’s products, providing security education to our engineers, and handling externally reported vulnerabilities. This ranges from code reviews, penetration tests, and architectural reviews on new features and existing code, in order to provide security education and guidance to the entire organization.

This position is not for someone who operates solely on scanner-based vulnerabilities. You will be required to demonstrate a strong technical understanding of web applications, backend services, penetration testing techniques and methodologies. You should have a clear understanding of Okta's authentication protocols, such as SAML and OAuth. Furthermore, you should have the desire to automate tasks by building tools to help discover vulnerabilities and be comfortable explaining and communicating vulnerabilities to developers, management and leadership by creating thorough documentation of findings.

The most important quality we are looking for is someone who has an “evil bit” - an innate ability to think and operate like an attacker while solving complex problems with expertise and creativity. At Okta we fully support externally publishing exciting new findings and will help you do it in the form of white papers, blog posts, and live presentations at conferences of your choice.

Job Duties and Responsibilities:

  • Work closely with Engineering teams on Design Reviews for new features or major changes
  • Audit code for security flaws and best practices
  • Perform Penetration Tests on new features and on the platform as a whole
  • Develop, implement, and communicate vulnerability mitigation strategies to development teams
  • Work solo and collaboratively to deliver projects on a deadline
  • Think like an attacker and solve complex problems with expertise and ingenuity
  • Give security presentations and represent Okta in private or public venues

Required Knowledge, Skills, and Abilities:

  • Ability to identify common (OWASP Top 10/CWE Top 25) web application vulnerabilities through secure code review (ex: Java, .Net, Go, C, C++, C#, Swift, Kotlin, Python)
  • Ability to conduct a manual Web Application Penetration Test using industry standard tools (ex: Burp Suite)
  • Knowledge of modern web application components, architecture, and design principles
  • Ability to explain vulnerability risks and remediation options to developers
  • Beginner level coding ability in at least one scripting language (ex: Python, Bash)

 Desired skills and Abilities:

  • Knowledge in current authentication and authorization protocols (OIDC, SAML)
  • Experience in mobile device (Android and/or iOS) application penetration testing
  • Experience with SAST, DAST, SCA, and fuzzing tools
  • Knowledge in current cryptographic algorithms and techniques
  • Experience in attacking network protocols and analyzing network traffic
  • Experience writing proof of concept scripts to demonstrate vulnerability exploitation

#LI-JP2 

#LI-Remote

What you can look forward to as an Okta employee!

  • Amazing Benefits
  • Making Social Impact
  • Fostering Diversity, Equity, Inclusion and Belonging at Okta

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live.

Refer code: 732583. Okta - El día anterior - 2024-03-01 04:49

Okta

Madrid provincia
Empleos populares de Security Engineer en las principales ciudades

Compartir trabajos con amigos

Trabajos relacionados

Senior Product Security Engineer

Information Security Engineer - (Appsec)

Revolut

Madrid provincia

2 Hace meses - visto

Vulnerability Management Product Security Engineer

Red Hat

Madrid, Madrid provincia

2 Hace meses - visto

MS Engineer - Security

Ntt

Madrid, Madrid provincia

2 Hace meses - visto

Informatiker/in, Wirtschaftsinformatiker/in, CyberSecurity Specialist, Cyber Security Engineer

Median Unternehmensgruppe

Madrid, Madrid provincia

2 Hace meses - visto

IT Security Engineer

Eurovision Labs

Madrid provincia

2 Hace meses - visto

Wirtschaftsinformatiker/in, Cyber Security Engineer,Informatiker/in, Cyber Security Specialist

Median Unternehmensgruppe

Madrid, Madrid provincia

2 Hace meses - visto

Cyber Security Engineer, Wirtschaftsinformatiker/in,Cyber Security Specialist, Informatiker/in

Median Unternehmensgruppe

Madrid, Madrid provincia

2 Hace meses - visto

Security Engineer (L3)

Ntt

Madrid, Madrid provincia

2 Hace meses - visto

Senior Security Engineer

Ntt

Madrid, Madrid provincia

2 Hace meses - visto

IT Cloud Security Engineer (hybrid setup)

Swiss Re

Madrid, Madrid provincia

2 Hace meses - visto

Senior Platform Security Engineer

Celonis

Madrid provincia

3 Hace meses - visto

Physical Security Engineer

Microsoft Corporation

Madrid, Madrid provincia

3 Hace meses - visto

Junior Security Engineer

Ntt

Madrid, Madrid provincia

3 Hace meses - visto

Physical Security Engineer

Microsoft

Madrid, Madrid provincia

3 Hace meses - visto

Security Engineer

Ebury

Madrid provincia

3 Hace meses - visto

Security Engineer

Ebury

Madrid, Madrid provincia

3 Hace meses - visto

Senior Microsoft Security Engineer

Ntt

Madrid, Madrid provincia

3 Hace meses - visto

Security Managed Services Engineer

Ntt

Madrid, Madrid provincia

3 Hace meses - visto