[Remote] Senior Forward Deployed Engineer - Okta for AI Agents
Note: The job is a remote job and is open to candidates in USA. Okta is a company focused on securing identities for organizations and users. They are seeking a Senior Forward Deployed Engineer to act as a technical partner for enterprise customers, embedding within their teams to deliver bespoke agent identity solutions and ensure secure deployments.
Responsibilities
- Become the customer’s trusted technical voice on agent security. Sit in their standups, design reviews, and incident response. Earn a seat on their architecture review board and security council for agent risk decisions
- Architect and deploy with the customer’s team. Build Okta’s agent security stack into their infrastructure: Cross-App Access (XAA), Fine-Grained Authorization (FGA), MCP Gateway, and agent client registration. Own the identity, delegation, audit, and kill-switch architecture end to end, and coach their engineers on the patterns
- Engage senior leadership. Brief the CISO, CIO, identity leaders, Chief AI Officer, and principal architects. Translate token-exchange flows into board-level agent risk, and AI governance mandates into architecture
- Deliver white-glove deployment. Agents in production with full identity coverage, security review passed, governance requirements met, and posture visibility online. The customer points to you as the reason their agent program is real
- Keep deployments defensible. Align architecture decisions to OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS, and to HIPAA, FedRAMP, or SOC 2 where the customer is regulated
- Wire Okta into the customer’s stack. Connect O4AA to their IdP for human-to-agent links, IGA for agent lifecycle, ISPM for posture, SIEM and EDR for behavior coverage, and policy engines for runtime decisions
- Build evals and observability. Authorization decision latency, scope sprawl across agents, anomalous delegation chains, audit completeness, kill-switch verification, and rogue agent detection
- Turn field patterns into product. Extract the recurring gaps from their architects and governance leads, and convert them into reusable modules and roadmap fixes that ship for every other customer
- Be on site. Regular presence at customer locations. Trust and governance alignment happen in the room
Skills
- 7+ years shipping production software, still hands-on in the IDE, with on-call experience and operational maturity in systems that authenticate and authorize at high throughput
- Ability to travel, 35% (on occasion internationally)
- Identity protocols: OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD and DCR, DPoP
- Working knowledge of OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS. Familiarity with MCP, A2A, ISO/IEC 42001, and the EU AI Act. Comfortable mapping deployments to HIPAA, FedRAMP, and SOC 2
- Fine-grained authorization: ReBAC and ABAC with policy engines (OPA, Cedar, OpenFGA, or equivalent), and a working understanding of how agents acquire tokens, call APIs, and delegate
- Built production integrations with Claude, ChatGPT, Microsoft Copilot, Agentforce, Bedrock, LangChain, CrewAI, the OpenAI Agents SDK, or MCP servers
- Daily use of Claude Code, Cursor, GitHub Copilot, or equivalent
- At home in a customer standup and a CISO briefing on the same day. You build trust with senior engineering leaders and you stay in the room when their internal politics get sharp
- A zero-to-one self-starter who owns outcomes end to end
Benefits
- Okta offers equity (where applicable)
- Bonus
- Health, dental and vision insurance
- 401(k)
- Flexible spending account
- Paid leave (including PTO and parental leave) in accordance with our applicable plans and policies
- Immersive, in-person onboarding experience
Company Overview
Company H1B Sponsorship