Role description
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.
Company Description
Okta is the leading independent identity partner. We enable organizations to securely connect the right people and technologies, providing identity solutions that protect workforce and customer identities across a rapidly evolving technology landscape.
The P0 Threat Research organization operates at the intersection of adversary research, threat hunting, detection engineering, data science, and product innovation. Our mission is to understand modern adversaries better than anyone else and make that knowledge actionable for our customers and products.
Position Description
Architect, Threat Research will help define and drive the technical vision for Okta's threat research efforts. This role is focused on understanding how modern adversaries operate, developing new methodologies for discovering and analyzing attacker behavior, and translating that research into actionable outcomes for our customers and products.
Initial areas of emphasis include identity, cloud, SaaS, AI, and other emerging technologies, but success in this role is rooted in deep threat research expertise and the ability to rapidly develop expertise in new technologies and attack surfaces.
The Architect will serve as a senior technical leader within the Threat Research organization. This individual will work closely with threat researchers, threat hunters, detection engineers, data scientists, product teams, engineering teams, and other senior technical leaders across Okta.
This is a hands-on technical leadership role. The Architect is expected to establish research direction and methodology while continuing to personally perform research, analyze telemetry and artifacts, develop hypotheses, experiment with new approaches, and build tooling or prototypes when needed.
The ideal candidate is a researcher and technologist at heart who is comfortable operating in ambiguous problem spaces, following evidence wherever it leads, and turning incomplete or unfamiliar data into meaningful insights about adversary behavior.
Job Duties and Responsibilities
- Define and drive the technical direction for major threat research initiatives.
- Identify emerging attack surfaces, adversary behaviors, and areas where additional research can materially improve Okta's understanding of the threat landscape.
- Lead complex and open-ended research efforts into novel adversary behaviors, attack techniques, campaigns, and security risks.
- Develop research hypotheses and identify the telemetry, artifacts, intelligence, and other inputs necessary to investigate them.
- Develop new research methodologies, analytical approaches, prototypes, and tooling that improve the organization's ability to identify and understand threats.
- Analyze security telemetry and technical artifacts to identify attacker behaviors, infrastructure, techniques, trends, and previously unknown activity.
- Translate threat research into actionable outcomes, including detections, threat hunts, intelligence, product capabilities, tooling, research publications, and customer protections.
- Establish and improve research methodologies, technical standards, and processes that enable the Threat Research organization to operate effectively at scale.
- Partner closely with Threat Hunting, Detection Engineering, Data Science, Product Management, and Engineering to ensure research findings are incorporated into the broader Okta security ecosystem.
- Provide senior technical leadership during complex investigations and significant customer security events.
- Participate in architecture and product design discussions where understanding adversary behavior can improve product capabilities and security outcomes.
- Evaluate new technologies, datasets, telemetry sources, and analytical techniques that can expand Okta's research capabilities.
- Rapidly develop expertise in unfamiliar technologies and attack surfaces when required by emerging adversary activity.
- Mentor researchers and other technical team members, helping improve both individual capabilities and the overall research discipline.
- Represent Okta through high-quality technical research, publications, open-source projects, conference presentations, industry collaboration, and engagement with the broader security community.
- Build relationships with external researchers, customers, technology partners, and other members of the security community to improve visibility into emerging threats.
- Serve as a senior technical authority on threat research methodology and modern adversary behavior.
Required Knowledge, Skills, and Abilities
- 10 years or more of progressively increasing technical responsibility in threat research, threat hunting, incident response, detection engineering, malware research, security research, or related disciplines.
- Deep understanding of threat research methodologies, including hypothesis development, telemetry and artifact analysis, threat hunting, adversary behavior analysis, validation of findings, and translation of research into actionable security outcomes.
- Deep understanding of modern adversary tradecraft and the techniques used to compromise and operate within enterprise environments.
- Demonstrated history of conducting original research and identifying attacker behaviors, techniques, campaigns, or security risks that were not previously well understood.
- Demonstrated ability to independently lead complex and ambiguous technical research efforts from initial hypothesis through analysis, validation, and actionable outcome.
- Demonstrated ability to identify and evaluate the data sources, telemetry, artifacts, and other inputs necessary to answer complex research questions.
- Strong analytical skills and the ability to draw meaningful conclusions from incomplete, noisy, or unfamiliar datasets.
- Experience translating research findings into outcomes such as detections, threat hunts, intelligence, tooling, product capabilities, or customer protections.
- Ability to rapidly develop technical expertise in unfamiliar technologies, platforms, datasets, and attack surfaces.
- Experience analyzing security telemetry and identifying meaningful patterns within complex datasets.
- Ability to personally perform hands-on technical research, experimentation, and prototyping rather than operating solely in a leadership or advisory capacity.
- Ability to develop research tooling or prototypes using languages such as Python, Go, JavaScript, or similar technologies.
- Ability to establish technical direction and influence researchers and engineering teams without requiring direct management authority.
- Experience mentoring researchers or other senior technical professionals.
- Demonstrated ability to communicate complex technical concepts clearly to researchers, engineers, customers, executives, and external audiences.
Desirable Knowledge, Skills, and Abilities
- Experience researching adversary activity across identity providers, cloud infrastructure, SaaS applications, enterprise authentication systems, endpoint environments, or other enterprise technologies.
- Experience with identity technologies and concepts including Okta, Microsoft Entra ID, Active Directory, SAML, OAuth, OIDC, federation, authentication, authorization, sessions, and tokens.
- Experience investigating adversary activity across AWS, Microsoft Azure, Google Cloud Platform, and major SaaS platforms.
- Experience working with large-scale security telemetry and query languages such as KQL, SQL, or similar technologies.
- Experience developing threat hunting or detection methodologies and working with detection engineering teams to operationalize research.
- Experience developing or open-sourcing security research tools.
- Demonstrated history of publishing original security research or presenting at recognized cybersecurity conferences.
- Experience with malware analysis, reverse engineering, attacker infrastructure analysis, campaign tracking, attribution, or cyber threat intelligence methodologies.
- Experience responding to or researching sophisticated targeted attacks, APT activity, ransomware operations, or other advanced adversaries.
- Experience working directly with customers during significant security incidents or complex investigations.
- Experience contributing to patents, novel security techniques, or other forms of intellectual property.
- Experience applying machine learning, data science, or AI techniques to security research problems.
- Understanding of emerging security risks involving AI agents, autonomous systems, machine identities, and workload identities.
- Strong appreciation for experimentation and rapid prototyping as tools for answering research questions.
Education and Training
B.S. in Computer Science, Cybersecurity, Information Security, Computer Engineering, or a related technical discipline, or equivalent practical experience.
Advanced technical degree, industry certifications, or equivalent demonstrated research experience preferred.
The Okta Experience
- Supporting Your Well-Being
- Driving Social Impact
- Developing Talent and Fostering Connection + Community
We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.