Principal Forward Deployed Engineer

Reposted One Month Ago
Be an Early Applicant
Singapore, SGP
In-Office
Senior level
Cloud
The Role
Embed with enterprise customers to architect, build, and ship production agent identity and security solutions. Develop bespoke code, integrate Okta agent identity stack, coach customer engineers, ensure compliance, build observability, and convert field patterns into product improvements while engaging executive stakeholders and maintaining on-site presence.
Summary Generated by Built In

Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

Principal Forward Deployed Engineer, Okta for AI Agents

About Okta for AI Agents

Okta secures access for 20,000 organizations and billions of users. Okta for AI Agents extends that work to the agentic shift. Deploying an AI agent is not like deploying traditional software. You are putting professional work output into production, and it needs deep integration, continuous tuning, and change management. Every agent needs an identity, a scope, an audit trail, and a way to be shut down when it goes wrong. Most enterprises have not built this yet. We are.

We hire builders who see the cracks in enterprise agent identity that everyone else has learned to live with.

The Role

You embed inside four to five of Okta’s most strategic enterprise customers as their dedicated technical partner for agent identity. You sit alongside their identity, platform, and security engineering teams, develop sample and bespoke code, and own the technical outcome from prototype through production.

You are a builder-consultant. You go past architecture diagrams to code, debug, and ship bespoke agent identity solutions inside the customer’s environment. You ship secure agents faster for the customer, and you feed real field insight back to Okta product engineering.

Responsibilities
  • Become the customer’s trusted technical voice on agent security. Sit in their standups, design reviews, and incident reviews. Earn a seat on their architecture review board and security council for agent risk decisions.
  • Architect and deploy with the customer’s team. Build Okta’s agent security stack into their infrastructure: Cross-App Access (XAA), Fine-Grained Authorization (FGA), MCP Gateway, and agent client registration. Own the identity, delegation, audit, and kill-switch architecture end to end, and coach their engineers on the patterns.
  • Engage senior leadership. Brief the CISO, CIO, identity leaders, Chief AI Officer, and principal architects. Translate token-exchange flows into board-level agent risk, and AI governance mandates into architecture.
  • Deliver white-glove deployment. Agents in production with full identity coverage, security review passed, governance requirements met, and posture visibility online. The customer points to you as the reason their agent program is real.
  • Keep deployments defensible. Align architecture decisions to OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS, and to HIPAA, FedRAMP, or SOC 2 where the customer is regulated.
  • Wire Okta into the customer’s stack. Connect O4AA to their IdP for human-to-agent links, IGA for agent lifecycle, ISPM for posture, SIEM and EDR for behavior coverage, and policy engines for runtime decisions.
  • Build evals and observability. Authorization decision latency, scope sprawl across agents, anomalous delegation chains, audit completeness, kill-switch verification, and rogue agent detection.
  • Turn field patterns into product. Extract the recurring gaps from their architects and governance leads, and convert them into reusable modules and roadmap fixes that ship for every other customer.
  • Be on site. Regular presence at customer locations. Trust and governance alignment happen in the room.
Requirements
  • Engineering pedigree. 7+ years shipping production software, still hands-on in the IDE, with on-call experience and operational maturity in systems that authenticate and authorize at high throughput.
  • Identity protocols. OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD and DCR, DPoP.
  • Agent security frameworks and platforms. Working knowledge of OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS. Familiarity with Python, MCP, A2A, ISO/IEC 42001, and the EU AI Act. Comfortable mapping deployments to HIPAA, FedRAMP, and SOC 2.
  • Fine-grained authorization. ReBAC and ABAC with policy engines (OPA, Cedar, OpenFGA, or equivalent), and a working understanding of how agents acquire tokens, call APIs, and delegate.
  • AI hands-on. Build production integrations with Claude, ChatGPT, Microsoft Copilot, Agentforce, Bedrock, LangChain, CrewAI, the OpenAI Agents SDK, or MCP servers.
  • AI-native development. Daily use of Claude Code, Cursor, GitHub Copilot, or equivalent.
  • Customer-facing range. At home in a customer standup and a CISO briefing on the same day. You build trust with senior engineering leaders and you stay in the room when their internal politics get sharp.
  • High agency, founder’s mindset. A zero-to-one self-starter who owns outcomes end to end.
  • Ability to travel, on occasion internationally, up to 35%

The Okta Experience

  • Supporting Your Well-Being 
  • Driving Social Impact 
  • Developing Talent and Fostering Connection + Community

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.
Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.
If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.
Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Skills Required

  • 7+ years shipping production software; hands-on in IDE with on-call and operational experience
  • Expertise with identity protocols: OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, DPoP, act claims, CIMD, DCR
  • Working knowledge of agent security frameworks: OWASP Top 10 for Agentic Applications, NIST AI RMF, MITRE ATLAS; map deployments to HIPAA, FedRAMP, SOC 2
  • Familiarity with Python, MCP, A2A, MCP Gateway, ISO/IEC 42001, and the EU AI Act
  • Fine-grained authorization experience (ReBAC, ABAC) and with policy engines such as OPA, Cedar, or OpenFGA
  • Hands-on experience building production integrations with AI agents/platforms: Claude, ChatGPT, Microsoft Copilot, Agentforce, Bedrock, LangChain, CrewAI, OpenAI Agents SDK, or MCP servers
  • Daily use of AI-native developer tools (Claude Code, Cursor, GitHub Copilot, or equivalent)
  • Customer-facing skills: comfortable in engineer standups and executive briefings (CISO/CIO/Chief AI Officer)
  • High agency, zero-to-one self-starter mindset owning outcomes end-to-end
  • Regular on-site presence at customer locations and willingness to travel internationally up to 35%

Okta Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Okta and has not been reviewed or approved by Okta.

  • Healthcare Strength Health coverage spans medical, dental, vision, mental-health support, and income protection, complemented by preventive care options and wellness resources. These elements indicate robust coverage for both routine needs and more complex situations.
  • Parental & Family Support Policies include paid parental leave, adoption and surrogacy assistance, and fertility and family‑building benefits. Caregiving resources and flexible arrangements help employees navigate family responsibilities.
  • Leave & Time Off Breadth Flexible or unlimited PTO, separate sick time, paid holidays, and a company Wellbeing Week provide multiple avenues for time away. This breadth supports rest, recovery, and work‑life balance.

Okta Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
6,000 Employees
Year Founded: 2009

What We Do

Okta is the leading independent identity provider. The Okta Identity Cloud enables organizations to securely connect the right people to the right technologies at the right time. With more than 7,000 pre-built integrations to applications and infrastructure providers, Okta provides simple and secure access to people and organizations everywhere, giving them the confidence to reach their full potential. More than 10,000 organizations, including JetBlue, Nordstrom, Siemens, Slack, T-Mobile, Takeda, Teach for America, and Twilio, trust Okta to help protect the identities of their workforces and customers.

Similar Jobs

Cloudera Logo Cloudera

Artificial Intelligence Engineer

Artificial Intelligence • Cloud • Software • Big Data Analytics
In-Office
Singapore, SGP
3092 Employees

Red Hat Logo Red Hat

Principal Forward Deployed Engineer - AI PlatformPrincipal Forward Deployed Engineer - AI Platform/Kubernetes/Pytorch

Cloud • Information Technology • Internet of Things • Software • Consulting • Infrastructure as a Service (IaaS) • Automation
In-Office
Singapore, SGP
20000 Employees

Datadog Logo Datadog

Senior Partner Manager - Channels (Security)

Artificial Intelligence • Cloud • Security • Software • Cybersecurity
Easy Apply
Hybrid
Singapore, SGP
6500 Employees
Hybrid
Singapore, SGP
289097 Employees

Similar Companies Hiring

Rundoo Thumbnail
Cloud • Information Technology • Internet of Things • Software
Redwood City, California
70 Employees
NetBox Labs Thumbnail
Cloud • Software
US
125 Employees
Toro TMS Thumbnail
Cloud • Enterprise Web • Sales • Software • Transportation
Chicago, IL
80 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account