×
Register Here to Apply for Jobs or Post Jobs. X

Senior Forward Deployed Engineer - AI Agents

Job in Chicago, Cook County, Illinois, 60602, USA
Listing for: Okta
Full Time position
Listed on 2026-06-04
Job specializations:
  • IT/Tech
    Systems Engineer, Cybersecurity
Job Description & How to Apply Below
Position: Senior Forward Deployed Engineer - Okta for AI Agents
Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

About Okta for AI Agents

Okta secures access for 20,000 organizations and billions of users. Okta for AI Agents extends that work to the agentic shift. Deploying an AI agent is not like deploying traditional software. You are putting professional work output into production, and it needs deep integration, continuous tuning, and change management. Every agent needs an identity, a scope, an audit trail, and a way to be shut down when it goes wrong.

Most enterprises have not built this yet. We are.

We hire builders who see the cracks in enterprise agent identity that everyone else has learned to live with.

The Role

You embed inside four to five of Okta's most strategic enterprise customers as their dedicated technical partner for agent identity. You sit alongside their identity, platform, and security engineering teams, write production code in their environment, and own the technical outcome from prototype through production.

You are a builder-consultant. You go past architecture diagrams to code, debug, and ship bespoke agent identity solutions inside the customer's environment. You ship secure agents faster for the customer, and you feed real field insight back to Okta product engineering.

Responsibilities

* Become the customer's trusted technical voice on agent security. Sit in their standups, design reviews, and incident response. Earn a seat on their architecture review board and security council for agent risk decisions.

* Architect and deploy with the customer's team. Build Okta's agent security stack into their infrastructure:
Cross-App Access (XAA), Fine-Grained Authorization (FGA), MCP Gateway, and agent client registration. Own the identity, delegation, audit, and kill-switch architecture end to end, and coach their engineers on the patterns.

* Engage senior leadership. Brief the CISO, CIO, identity leaders, Chief AI Officer, and principal architects. Translate token-exchange flows into board-level agent risk, and AI governance mandates into architecture.

* Deliver white-glove deployment. Agents in production with full identity coverage, security review passed, governance requirements met, and posture visibility online. The customer points to you as the reason their agent program is real.

* Keep deployments defensible. Align architecture decisions to OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS, and to HIPAA, FedRAMP, or SOC 2 where the customer is regulated.

* Wire Okta into the customer's stack. Connect O4AA to their IdP for human-to-agent links, IGA for agent lifecycle, ISPM for posture, SIEM and EDR for behavior coverage, and policy engines for runtime decisions.

* Build evals and observability. Authorization decision latency, scope sprawl across agents, anomalous delegation chains, audit completeness, kill-switch verification, and rogue agent detection.

* Turn field patterns into product. Extract the recurring gaps from their architects and governance leads, and convert them into reusable modules and roadmap fixes that ship for every other customer.

* Be on site. Regular presence at customer locations. Trust and governance alignment happen in the room.

Requirements

* Engineering pedigree. 7+ years shipping production software, still hands-on in the IDE, with on-call experience and operational maturity in systems that authenticate and authorize at high throughput.

* Ability to travel, 35% (on occasion internationally)

* Identity protocols. OAuth 2.0, OIDC, SAML, SCIM, RFC 8693 token exchange, act claims, CIMD and DCR, DPoP.

* Agent security frameworks. Working knowledge of OWASP Top 10 for Agentic Applications, NIST AI RMF, and MITRE ATLAS. Familiarity with MCP,…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary