Staff Site Reliability Engineer, Security- GCP
Okta
Skill Required
Key highlights
- 8+ years of experience required
- BS in Computer Science or equivalent professional experience
- Immersive in-person onboarding experience
- Equal Opportunity Employer
Role overview
Secure Every Identity, from AI to Human. Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. Okta’s Workforce Identity Cloud Security Engineering group is looking for an experienced and passionate Staff Site Reliability Engineer to join a team focused on designing and developing Security solutions to harden our cloud infrastructure. This is a high-impact role in a security-centric, fast-paced organization poised for massive growth and success. You will act as a liaison between the Security org and the Engineering org to build technical leverage and influence the security roadmap, focusing on engineering security aspects of the systems used across our services.
Responsibilities
- Lead initiatives to strengthen our security posture for critical infrastructure and promote best practices across the engineering organization (Security Evangelism).
- Respond to production security incidents, perform root cause analysis, and build automated preventions to ensure high performance and reliability (Incident Response & Reliability).
- Identify manual security processes and automate them using custom tooling and CI/CD integrations (Automated Hardening).
- Develop technical documentation, runbooks, and procedures for a 24x7 online environment (Architecture & Documentation).
- Continuously evolve our monitoring platforms, moving from simple auditing to active, automated prevention (Platform Evolution).
- Design and maintain large-scale production IAM policies and secrets management workflows (IAM & Secrets Management).
- Implement and maintain Public Key Infrastructure (PKI) and ensure all GCE/GKE environments meet strict compliance standards (Infrastructure Hardening).
- Utilize industry-standard tools like OSQuery, Splunk, Chronicle, Nessus, or Qualys/CrowdStrike to monitor system health and security telemetry (Operational Excellence).
- Lead the phased transition of security policies from Audit/Detection mode to Blocking/Prevention mode, ensuring zero impact on production uptime (Strategic Rollouts).
- Identify gaps, propose innovative solutions, and contribute to roadmaps while driving alignment across multiple teams within the organization.
- Serve as a role model, providing technical mentorship to junior team members and fostering a culture of learning and growth.
Requirements
- 8+ years of experience architecting and running complex cloud networking and infrastructure, with at least 7+ years specialized in DevSecOps or Cloud Security.
- Minimum 3+ years of deep, hands-on experience securing GCP (GKE, GCE, Shared VPC etc).
- 10+ years of experience using Terraform and Chef to manage complex cloud resources and OS hardening.
- Expert-level proficiency in Go, Python, or Ruby for building custom security tooling and automated remediation.
- Proven track record of securing containerized workloads, including image scanning, K8s RBAC, and runtime security tools (e.g., CrowdStrike Falcon, Falco, or gVisor).
- A 'see a problem, fix the problem' mindset with the ability to debug complex networking, IAM, or performance issues under pressure.
- Strong grasp of Linux internals, OS hardening (CIS benchmarks), and IP protocols (TLS/SSL, DNSSEC, BGP).
- BS in Computer Science or equivalent professional experience.
Nice to have
- Experience designing a unified IAM framework across AWS and GCP, utilizing federated Identities such as Workload, Workforce Identity Federation with understanding of SAML & OIDC auth mechanism and automated 'Least Privilege' enforcement (Multi-Cloud IAM Governance).
- Deep understanding of multi-cloud reliability patterns, maintaining high availability (HA) during security patching or infrastructure-wide hardening (Cloud-Native Reliability Engineering).
- Advanced experience securing GKE, EKS, and kOps, specifically implementing Pod Security Standards, Network Policies, and Admission Controllers for a 'Zero-Trust' posture (Hardened Kubernetes Orchestration).
- Security Reviews & Threat Modeling at both Design & Implementation scope (Threat Modeling).
Benefits
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
- An immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Additional details
- We embrace innovation and pave the way to transform bright ideas into excellent security solutions that help run large-scale, critical infrastructure.
- We encourage you to prescribe defense-in-depth measures, industry security standards and enforce the principle of least privilege to help take our Security posture to the next level.
- Our Infrastructure Security team has a niche skill-set that balances Security domain expertise with the ability to design, implement, rollout infrastructure across multiple cloud environments without adding friction to product functionality or performance.
- We are responsible for the ever-growing need to improve our customer safety and privacy by providing security services that are coupled with the core Okta product.
- Join us and be part of a company that is about to change the cloud computing landscape forever.
- Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
- If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
- Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.
- Our global community, spanning over 20 offices worldwide, is united by a drive to innovate.