Product Security Engineer: Threat Modeling & AI
Role details
Job location
Tech stack
Requirements
Okta is seeking a Staff Product Security Engineer in Barcelona to safeguard its products through comprehensive security reviews and guiding secure development practices. The ideal candidate will have expertise in penetration testing and a background in web application security.
You will also lead product security incidents, assess risks, and develop automation tools to enhance vulnerability detection. Strong communication skills are essential for this role, as you will engage with engineering teams and represent Okta externally through security research and publications.
Formación
- Deep technical understanding of web applications and backend services needed.
- Experience in manual code review for OWASP Top 10 / CWE Top 25 vulnerabilities.
- Ability to automate security testing using scripting (Python, Bash).
Responsabilidades
- Conduct comprehensive security reviews and guide engineering teams.
- Engage in code reviews, penetration testing, and architectural security assessments.
- Lead product security incidents and develop security tools for vulnerability detection.
Conocimientos
Web application security Penetration testing methodologies Authentication protocols (SAML, OAuth, OIDC) Automation of security processes Deep technical understanding of secure design principles Programming languages (Java, Go, Python, C/C++) Communication skills