SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Okta is seeking a Technical Architect for its Threat Research organization to define and drive the technical vision for threat research efforts. This is a hands-on senior technical leadership role focused on understanding modern adversaries, developing new methodologies for discovering and analyzing attacker behavior, and translating research into actionable outcomes for customers and products.
The role emphasizes identity, cloud, SaaS, AI, and emerging technologies. The Architect will serve as a senior technical leader within the Threat Research organization, working closely with threat researchers, threat hunters, detection engineers, data scientists, product teams, and engineering teams across Okta.
Key responsibilities include: defining and driving technical direction for major threat research initiatives; identifying emerging attack surfaces and adversary behaviors; leading complex research efforts into novel adversary behaviors and attack techniques; developing research hypotheses and identifying necessary telemetry and artifacts; developing new research methodologies, analytical approaches, prototypes, and tooling; analyzing security telemetry and technical artifacts; translating threat research into actionable outcomes including detections, threat hunts, intelligence, product capabilities, and customer protections; establishing research methodologies and technical standards; partnering with threat hunting, detection engineering, data science, product management, and engineering teams; providing senior technical leadership during complex investigations and customer security events; participating in architecture and product design discussions; evaluating new technologies and analytical techniques; rapidly developing expertise in unfamiliar technologies; mentoring researchers and technical team members; representing Okta through technical research, publications, open-source projects, and conference presentations; building relationships with external researchers, customers, and security community members; and serving as a senior technical authority on threat research methodology and modern adversary behavior.
This is a hands-on role where the Architect is expected to personally perform research, analyze telemetry and artifacts, develop hypotheses, experiment with new approaches, and build tooling or prototypes when needed.
**Requirements:**
- 10+ years of progressively increasing technical responsibility in threat research, threat hunting, incident response, detection engineering, malware research, security research, or related disciplines
- Deep understanding of threat research methodologies including hypothesis development, telemetry and artifact analysis, threat hunting, adversary behavior analysis, validation of findings, and translation of research into actionable security outcomes
- Deep understanding of modern adversary tradecraft and techniques used to compromise and operate within enterprise environments
- Demonstrated history of conducting original research and identifying attacker behaviors, techniques, campaigns, or security risks not previously well understood
- Demonstrated ability to independently lead complex and ambiguous technical research efforts from hypothesis through analysis, validation, and actionable outcome
- Demonstrated ability to identify and evaluate data sources, telemetry, artifacts, and other inputs necessary to answer complex research questions
- Strong analytical skills and ability to draw meaningful conclusions from incomplete, noisy, or unfamiliar datasets
- Experience translating research findings into detections, threat hunts, intelligence, tooling, product capabilities, or customer protections
- Ability to rapidly develop technical expertise in unfamiliar technologies, platforms, datasets, and attack surfaces
- Experience analyzing security telemetry and identifying meaningful patterns within complex datasets
- Ability to personally perform hands-on technical research, experimentation, and prototyping
- Ability to develop research tooling or prototypes using Python, Go, JavaScript, or similar technologies
- Ability to establish technical direction and influence researchers and engineering teams without direct management authority
- Experience mentoring researchers or other senior technical professionals
- Demonstrated ability to communicate complex technical concepts clearly to researchers, engineers, customers, executives, and external audiences
- B.S. in Computer Science, Cybersecurity, Information Security, Computer Engineering, or related technical discipline, or equivalent practical experience
**Desirable qualifications:**
- Experience researching adversary activity across identity providers, cloud infrastructure, SaaS applications, enterprise authentication systems, endpoint environments, or other enterprise technologies
- Experience with identity technologies including Okta, Microsoft Entra ID, Active Directory, SAML, OAuth, OIDC, federation, authentication, authorization, sessions, and tokens
- Experience investigating adversary activity across AWS, Microsoft Azure, Google Cloud Platform, and major SaaS platforms
- Experience with large-scale security telemetry and query languages such as KQL, SQL, or similar
- Experience developing threat hunting or detection methodologies and working with detection engineering teams
- Experience developing or open-sourcing security research tools
- Demonstrated history of publishing original security research or presenting at recognized cybersecurity conferences
- Experience with malware analysis, reverse engineering, attacker infrastructure analysis, campaign tracking, attribution, or cyber threat intelligence methodologies
- Experience responding to or researching sophisticated targeted attacks, APT activity, ransomware operations, or advanced adversaries
- Experience working directly with customers during significant security incidents or complex investigations
- Experience contributing to patents, novel security techniques, or other intellectual property
- Experience applying machine learning, data science, or AI techniques to security research problems
- Understanding of emerging security risks involving AI agents, autonomous systems, machine identities, and workload identities
- Strong appreciation for experimentation and rapid prototyping as tools for answering research questions
- Advanced technical degree, industry certifications, or equivalent demonstrated research experience preferred