SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff DevSecOps Engineer (TS/SCI)

Okta - Washington, DC, United States - In-office - posted 2026-09-14

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 161,000 - 241,000 / annual

Okta is seeking a Staff DevSecOps Engineer to join the Security team's Vulnerability Management group in Washington, DC. This is a hands-on, strategic role focused on building centralized security posture analytics and reporting capabilities that aggregate findings, remediation status, and risk data across Okta's infrastructure, cloud, and business systems. You will work embedded within service environments alongside engineering and operations teams to strengthen Okta's security posture. Key responsibilities include: • Serve as a security subject matter expert for solution engineering and architecture reviews regarding vulnerability scanning and reporting automation • Develop agentic automation to scale security posture scanning, reporting, issue remediation, and patch validation • Lead technical efforts to evaluate, design, and implement new in-house developed security systems and feature enhancements • Build, maintain, and enhance custom automation and cloud infrastructure using Terraform to support team and AI workflows • Develop integrations with APIs, cloud platforms (AWS, GCP, Azure), and security infrastructure to improve vulnerability detection and remediation • Write and maintain scripts and automations, emphasizing Python-based solutions, to streamline security operations • Establish monitoring and alerting for security posture, misconfigurations, and threats across endpoints, SaaS, and cloud workloads • Collaborate with SRE to manage update pipelines and enforce compliance with baseline standards • Proactively identify and remediate security gaps; stay updated on emerging threats and solutions The role focuses on automating issue tracking and ownership assignment, identifying and routing unowned findings, partnering with remediation teams to accelerate closure, and developing remediation solutions. Longer-term, you will leverage AI to simplify security posture management, increase trust in data, automate analysis and prioritization, and provide actionable insights. REQUIREMENTS: • 10+ years of experience in Security Engineering, DevSecOps, Infrastructure Security, or SaaS applications within a large corporate environment • 10+ years of strong coding and scripting experience, with focus on building automation and custom tooling for security engineering teams • Experience developing and maintaining ETL/ELT pipelines for onboarding security data into data lakes • Ability to build and maintain scalable, fault-tolerant data pipelines to process vulnerability data • Proven track record of automating security controls and workflows using a cloud-first approach • Experience with Terraform and other infrastructure-as-code tools to orchestrate security infrastructure • Familiarity with CI/CD pipelines for security automation and drift management • Strong communication skills to collaborate with technical staff, support teams, executive leadership, and external vendors • Active U.S. TS/SCI security clearance with Full Scope Poly compliance required • U.S. person status (U.S. citizen, lawful permanent resident, protected individual, or U.S. national; visa holders do not qualify) • Must be on U.S. soil (50 states, District of Columbia, or outlying areas as defined in FAR 2.101) • Proven experience navigating Federal and DoD compliance frameworks, specifically FedRAMP and Impact Level 6 (IL6) PLUS (preferred): • 2+ years of experience building engineering solutions within highly regulated environments • Experience automating commercial or open-source vulnerability and misconfiguration scanners (Qualys, TenableSC, Prisma Cloud, Wiz, Orca, Lacework, Paramify, Atlassian Jira, ServiceNow, etc.) • Familiarity with industry standards and frameworks (CVE, CVSS, EPSS, OWASP, CISA KEV catalog)

Similar roles