Principal Forward Deployed EngineerActive

The opportunity

You embed inside four to five of Okta’s most strategic enterprise customers as their dedicated technical partner for agent identity. You sit alongside their identity, platform, and security engineering teams, develop sample and bespoke code, and own the technical outcome from prototype through production.

What you'll do

  • Become the customer’s trusted technical voice on agent security. Sit in their: standups, design reviews, and incident reviews. Earn a seat on their architecture review board and security council for agent risk decisions.

  • Architect and deploy with the customer’s team. Build Okta’s agent security: stack into their infrastructure: Cross-App Access (XAA), Fine-Grained Authorization (FGA), MCP Gateway, and agent client registration. Own the identity, delegation, audit, and kill-switch architecture end to end, and coach their engineers on the patterns.

  • Engage senior leadership. Brief the CISO, CIO, identity leaders, Chief AI: Officer, and principal architects. Translate token-exchange flows into board-level agent risk, and AI governance mandates into architecture.

  • Deliver white-glove deployment. Agents in production with full identity: coverage, security review passed, governance requirements met, and posture visibility online. The customer points to you as the reason their agent program is real.

  • Keep deployments defensible. Align architecture decisions to OWASP Top 10 for: Agentic Applications, NIST AI RMF, and MITRE ATLAS, and to HIPAA, FedRAMP, or SOC 2 where the customer is regulated.

  • Wire Okta into the customer’s stack. Connect O4AA to their IdP for: human-to-agent links, IGA for agent lifecycle, ISPM for posture, SIEM and EDR for behavior coverage, and policy engines for runtime decisions.

What they're looking for

  • Engineering pedigree. 7+ years shipping production software, still hands-on: in the IDE, with on-call experience and operational maturity in systems that authenticate and authorize at high throughput.
  • Identity protocols. OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD and DCR, DPoP.
  • Agent security frameworks and platforms. Working knowledge of OWASP Top 10: for Agentic Applications, NIST AI RMF, and MITRE ATLAS. Familiarity with Python, MCP, A2A, ISO/IEC 42001, and the EU AI Act. Comfortable mapping deployments to HIPAA, FedRAMP, and SOC 2.
  • Fine-grained authorization. ReBAC and ABAC with policy engines (OPA, Cedar,: OpenFGA, or equivalent), and a working understanding of how agents acquire tokens, call APIs, and delegate.
  • AI hands-on. Build production integrations with Claude, ChatGPT, Microsoft: Copilot, Agentforce, Bedrock, LangChain, CrewAI, the OpenAI Agents SDK, or MCP servers.
  • AI-native development. Daily use of Claude Code, Cursor, GitHub Copilot, or equivalent.
  • Customer-facing range. At home in a customer standup and a CISO briefing on: the same day. You build trust with senior engineering leaders and you stay in the room when their internal politics get sharp.
  • High agency, founder’s mindset. A zero-to-one self-starter who owns outcomes end to end.