Back to positions

Staff Security Engineer - Vulnerability Management US Public Sector

Remote role Full-time Open position

About the position The Okta Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solutions through identifying and resolving risks to the employees, product, and most importantly, our customers. With the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business. The Staff Security Engineer for Public Sector is a key member of the Okta Security team and an essential collaborator with our broader Engineering organization playing a key part in executing the Vulnerability Management Program’s strategy. The Vulnerability Management Program is a crucial pillar of the security organizations’ imperative to reduce the threats to Okta’s infrastructure and applications. You’ll be an integral part of building and sustaining strong and effective relationships across Okta with our Engineering, Product and Business Technology counterparts.

Responsibilities

  • Own the full lifecycle operations of Asset and Vulnerability Management scanning and reporting infrastructure, including designing new cloud based and on-prem deployments as required.
  • Assess new and existing scan technologies to determine potential business value.
  • Monitor and respond to security inquiries, requests, and incidents, understanding the technical details of the published vulnerabilities as well as their real risk. Effectively communicate the perceived and real vulnerability impact given the infrastructure context.
  • Contribute to the definition and execution of internal processes that allow for accelerated remediation of critical vulnerabilities and zero-days.
  • Support audit, governance, risk and compliance teams in scanning and reporting on various regulatory compliance and industry best practices including PCI, ISO 27001/27017/27018 , NIST SP 800-53 and SOC 2.
  • Assist Okta’s Public Sector compliance team in their preparation and maintenance of POAMs (Plan of Action & Milestones) and Continuous Monitoring (ConMon) processes.
  • Track and manage weaknesses or gaps in vulnerability related security controls, outlining tasks, required resources, milestones, and scheduled completion dates to achieve compliance with standards like NIST 800-171 and CMMC.
  • Participate in other special projects or strategic initiatives at the direction of the Security team.

Requirements

  • Must have ability to work independently on end to end delivery of infrastructure deployment and troubleshooting run time issues.
  • Proven experience in architecting, deploying, and operating self-hosted vulnerability management and cloud workload security solutions in AWS for regulated or restricted environments.
  • Must have proficiency in AWS core services such as host OS and container deployment, S3, DynamoDB, API Gateway, and others.
  • Experience working with AWS Lambda or similar serverless computing environments for automating vulnerability management scanning and reporting tasks.
  • Proficiency in Shell and python scripting and automation. Familiarity with other scripting and automation tools is a plus.
  • 5+ years of multifaceted cyber security experience in a technology-centric company.
  • 5+ years of experience in building vulnerability scanning solutions within a highly regulated environment such as FedRamp and various Impact Levels.
  • Functional knowledge of vulnerabilities, exploitation and remediation. You should be able to explain vulnerabilities and exploits as well as propose remediations for the most common vulnerabilities.
  • Familiarity with industry standards, frameworks and publications such as CVE, CVSS, EPSS, OWASP and CISA KEV catalog.
  • This position requires the ability to access federal environments and/or have access to protected federal data. As a condition of employment for this position, the successful candidate must be able to submit documentation establishing U.S. Person status (e.g. a U.S. Citizen, National, Lawful Permanent Resident, Refugee, or Asylee. 22 CFR 120.15) upon hire.
  • Bachelor's degree in Computer Science, Computer Engineering, or equivalent experience.

Nice-to-haves

  • Experience with commercial or open-source vulnerability and misconfiguration scanners and reporting tools regarding Infrastructure/ IP based Assets, Containers, CSPM and CNAPP. Examples: Qualys, TenableSC, Prisma Cloud, Wiz, Orca, Lacework, Paramify, Atlassian Jira, ServiceNow etc. are a plus.

Benefits

  • Amazing Benefits
  • Making Social Impact
  • Developing Talent and Fostering Connection + Community at Okta
  • health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave)

Apply tot his job Apply To this Job

Further positions

Senior Wealth Advisor & Practice Lead - Wealth Management / Personal Strategy - Boston region

Remote role Full-time

Sr. Staff Security Engineer – Vulnerability Management (HYBRID)

Remote role Full-time

Walmart Remote Client Support File Reviewer – Apply Instantly

Remote role Full-time

(USA) Manager, Digital Media - Paid Search

Remote role Full-time

Executive Assistant - Merchandising (Entertainment, Toys and Seasonal)

Remote role Full-time

[No Experience] Walgreens Data Entry Remote – Immediate Hiring

Remote role Full-time

Customer Support Representative Remote at Wayfair

Remote role Full-time

Wayfair Remote Positions WFH Jobs $/hour

Remote role Full-time

Walmart Careers Work From Home $25Hr Amazon Store

Remote role Full-time

Wayfair Content Moderator Jobs (Work From Home, Entry Level Vacancy Global

Remote role Full-time

Experienced Full Stack Data Entry Specialist – Web & Cloud Application Development

Remote role Full-time

Women’s Sports Sr Reporter

Remote role Full-time

Entry-Level Data Entry Clerk - Work from Home Opportunity at blithequark

Remote role Full-time

Experienced Digital Solutions Delivery Manager - Driving Omnichannel Excellence in B2B2C, D2C, and B2B Digital Experience Projects

Remote role Full-time

Experienced Provider Customer Service Call and Chat Representative – Remote Opportunity in Houston, TX for arenaflex

Remote role Full-time

Principal Consultant Cloud DFIR, Reactive Services (Unit 42)

Remote role Full-time

Experienced Customer Care Associate – Work from Home Opportunity at blithequark

Remote role Full-time

Experienced Data Entry Specialist – Flexible Work-from-Home Opportunity with arenaflex

Remote role Full-time

[Hiring] Curriculum Specialist - Pharmacy Technician Training @Colibrigroup

Remote role Full-time

Consultor Sênior de Vendas Técnicas

Remote role Full-time