Staff Software Engineer, Agent Gateway

Okta, Inc.
San Francisco, CA, United States
26 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$194,000.0 - $267,000.0
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Artificial Intelligence Audit Trail Software as a Service Code Generation Code Review Software Design Documents Programming Tools Network Service OAuth OpenID User-Centered Design
+3 more
Okta Large Language Models Backend

Job description

Okta is looking for a Staff Software Engineer to serve as a technical anchor for the Agent Gateway team. You will own critical parts of the data and control planes and drive architectural design as the MCP and agent identity specs evolve.

In this role, you will work close to the metal on request routing, token exchange, credential resolution, and policy evaluation. You will work equally close to the identity control plane on config bundles, tenant fanout, and operational rollouts. You are expected to make sharp technology choices, prototype with agentic tooling, and turn rough product ideas into production-ready systems.

You will have the opportunity to build and scale services used by agentic traffic, ensuring workflows are reliable and performant at an unprecedented scale. This role sits at the critical intersection of product, security, and infrastructure., * Architect and Lead: Own the end-to-end design and delivery of major gateway capabilities, from virtual MCP server aggregation to Agent-to-Agent brokered delegation, as well as on-premises deployment models.

  • Design for Security and Runtime: Set the standard for how the gateway handles credentials, tokens, tenant isolation, and audit logging. Every decision carries direct customer trust and compliance weight. The Gateway team sits in the path of agent runtime traffic, which is in the critical path for customers.
  • Move With the Protocols: Track and shape MCP, OAuth token exchange, and agent identity specifications. Feed lessons learned from production back into the specs and their reference implementations.
  • Ship With Agentic Tooling: Treat Claude, Claude Code, and MCP-connected agents as first-class parts of your engineering workflow. Set the pattern for how the team uses these tools across design, code generation, code review, and operations-including custom skills, subagents, and MCP servers that accelerate the entire team.
  • Raise the Bar: Drive code review, testing standards, incident retrospectives, and our design doc culture. Mentor engineers on the team and foster alignment across adjacent groups

Requirements

  • Experience: 7+ years building distributed, highly available production backend systems.
  • Technical Depth: Hands-on experience shipping production services in Java and/or Go.
  • Domain Expertise: Strong grounding in OAuth 2.0, OIDC, and RFC 8693 token exchange. You should be highly comfortable reading, interpreting, and implementing spec-driven code.
  • Track Record: Proven success in shipping identity, authorization, or edge-of-network services at scale, including a deep understanding of the operational side (rollouts, feature flags, observability, incident response).
  • Agentic Fluency: Working fluency with agentic development tools (e.g., Claude Code, MCP servers, AI-assisted code review). You have concrete opinions on where they accelerate workflows and where they fall short.
  • Communication: A direct communication style, a talent for writing strong technical design docs, and the ability to operate seamlessly between a data plane service and a large identity control plane.

Extra Credit

  • Experience building or operating an MCP server, an agent framework, or an LLM-facing gateway in production.
  • Prior work on multi-tenant SaaS platforms at Okta or an equivalent enterprise identity provider.
  • Active contributions to standards work in the agent identity space (MCP, OAuth, GNAP, DCR).

Benefits & conditions

3.93.9 out of 5 stars San Francisco, CA Hybrid work $194,000 - $267,000 a year, Pulled from the full job description

  • Parental leave
  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Flexible spending account, Below is the annual base salary range for candidates located in San Francisco Bay Area. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us. The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $194,000-$267,000 USD

The Okta Experience

  • Supporting Your Well-Being
  • Driving Social Impact
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please Okta The foundation for secure connections between people and technology

About the company

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence., Okta is the leading independent provider of identity for the enterprise. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With over 7,000 pre-built integrations to applications and infrastructure providers, Okta customers can easily and securely use the best technologies for their business. More than 19,300 organizations, including JetBlue, Nordstrom, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

1:48 min

The evolving role of software engineers alongside agents

David Soria Parra David Soria Parra +3 · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all