> Markdown version of [/jobs/ext/2724540-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/2724540-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Product Security Engineer - **Company:** Ai. Okta - **Location:** Spain - **Salary:** €74,000.0 - €101,000.0 - **Contract:** Permanent contract - **Skills:** Code Review, Cyber Security, Software Vulnerability Management, Okta, Software Security - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/staff-product-security-engineer-psirt-okta-8814536 ## About the Role * 6+ years of experience in Information Security with a focus on Product Security, Application Security, Vulnerability Management, and Security Operations * Working experience in conducting comprehensive security code reviews to identify vulnerabilities and code flaws * Working experience in Application Security vulnerabilities * Working experience in Product Security concepts * Working experience in risk management * Working experience in handling incident response for product-related issues * Knowledge of incident and log management tools * Excellent communication and collaboration skills, particularly in technical writing, process documentation, and executive presentations #P25517_3504023 ## Description The Staff Product Security Engineer, PSIRT position is crucial in ensuring that Okta's systems and services meet the highest security standards and align with our customers' requirements. This position requires leadership, an innovative mindset, and expertise in security operations, responsible disclosure, vulnerability management, and program management. This position is available to candidates in Ireland and Spain. What You Will Do * Responsible for defining, improving, formalizing, and implementing Okta's Product Security Incident Response Program for all products and business units * Responsible for the day-to-day operations of the bug bounty program, including researcher engagement, vulnerability triage and validation, severity assessment, remediation coordination, reward recommendations, and program process improvements. * Oversee the entire lifecycle from discovery to resolution, including triaging, impact assessment, coordination with engineering teams, and validating fixes while ensuring timely communication with internal and external stakeholders * Lead the overall security disclosure program, from triaging to disclosure * Report on the health of the program and the overall status of its activities * Collaborate with internal teams to improve workflows, governance, and communication of vulnerabilities and risks * Work closely with Engineering, IT, Product, Legal, and Security teams on cross-functional initiatives * Mentor and provide guidance to junior engineers on incident response procedures, technical investigations, and vulnerability remediation * Partner with leadership to drive proactive threat detection and vulnerability management ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Get security done: streamlining application security with Aikido](https://www.wearedevelopers.com/videos/1638-get-security-done-streamlining-application-security-with-aikido) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 150 - The shift to AI generated code, fingerprinting and OKRs vs. doing your job](https://www.wearedevelopers.com/magazine/533-dev-digest-150-the-shift-to-ai-generated-code-fingerprinting-and-okrs-vs-doing-your-job) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)