Back to jobs

Staff Software Engineer, Agent Gateway

San Francisco, California

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

The Agent Gateway Team

The Agent Gateway team owns the identity-aware infrastructure that connects enterprise AI agents to the tools, data, and services their organizations authorize. Every call from Claude, Agentforce,, Codex, and internal/homegrown agents to a resource flows through us. We enforce authorization, isolate credentials, mint the right token per target, and produce the audit trails that security teams rely on.

We are early in a rapidly evolving space. The standards (MCP, XAA, ID JAG, DCR for agents,CIMD) are being built under our feet. Our roadmap includes hardening the data plane for on-premises customer deployments, extending policy semantics beyond tool-level allowlists, adding native support for Agent-to-Agent brokered delegation,  XAA and scaling to tenants with thousands of virtual MCP servers.

The Staff Software Engineer Opportunity

Okta is looking for a Staff Software Engineer to serve as a technical anchor for the Agent Gateway team. You will own critical parts of the data and control planes and drive architectural design as the MCP and agent identity specs evolve.

In this role, you will work close to the metal on request routing, token exchange, credential resolution, and policy evaluation. You will work equally close to the identity control plane on config bundles, tenant fanout, and operational rollouts. You are expected to make sharp technology choices, prototype with agentic tooling, and turn rough product ideas into production-ready systems.

You will have the opportunity to build and scale services used by agentic traffic, ensuring workflows are reliable and performant at an unprecedented scale. This role sits at the critical intersection of product, security, and infrastructure.

What You’ll Be Doing

  • Architect and Lead: Own the end-to-end design and delivery of major gateway capabilities, from virtual MCP server aggregation to Agent-to-Agent brokered delegation, as well as on-premises deployment models.
  • Design for Security and Runtime: Set the standard for how the gateway handles credentials, tokens, tenant isolation, and audit logging. Every decision carries direct customer trust and compliance weight. The Gateway team sits in the path of agent runtime traffic, which is in the critical path for customers.
  • Move With the Protocols: Track and shape MCP, OAuth token exchange, and agent identity specifications. Feed lessons learned from production back into the specs and their reference implementations.
  • Ship With Agentic Tooling: Treat Claude, Claude Code, and MCP-connected agents as first-class parts of your engineering workflow. Set the pattern for how the team uses these tools across design, code generation, code review, and operations—including custom skills, subagents, and MCP servers that accelerate the entire team.
  • Raise the Bar: Drive code review, testing standards, incident retrospectives, and our design doc culture. Mentor engineers on the team and foster alignment across adjacent groups 

What You’ll Bring to the Role

  • Experience: 7+ years building distributed, highly available production backend systems.
  • Technical Depth: Hands-on experience shipping production services in Java and/or Go.
  • Domain Expertise: Strong grounding in OAuth 2.0, OIDC, and RFC 8693 token exchange. You should be highly comfortable reading, interpreting, and implementing spec-driven code.
  • Track Record: Proven success in shipping identity, authorization, or edge-of-network services at scale, including a deep understanding of the operational side (rollouts, feature flags, observability, incident response).
  • Agentic Fluency: Working fluency with agentic development tools (e.g., Claude Code, MCP servers, AI-assisted code review). You have concrete opinions on where they accelerate workflows and where they fall short.
  • Communication: A direct communication style, a talent for writing strong technical design docs, and the ability to operate seamlessly between a data plane service and a large identity control plane.

Extra Credit

  • Experience building or operating an MCP server, an agent framework, or an LLM-facing gateway in production.
  • Prior work on multi-tenant SaaS platforms at Okta or an equivalent enterprise identity provider.
  • Active contributions to standards work in the agent identity space (MCP, OAuth, GNAP, DCR).

 

(P9081_3512755)

#LI-Hybrid 

#LI-BB1 

 

Below is the annual base salary range for candidates located in San Francisco Bay Area. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.   

The annual base salary range for this position for candidates located in the San Francisco Bay area is between:

$194,000 - $267,000 USD

The Okta Experience

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
I acknowledge and agree to the processing of my personal data in accordance with Okta's privacy policy and personnel privacy policy (see below). *

Okta may use AI with this application. If you prefer to opt-out of ADMT/AEDT, please do not apply here; instead submit an ADMT/AEDT Opt Out form here.

Personnel Notice

(California residents, click here)

By checking this box, you consent to Okta using your data to evaluate your candidacy for this role and any other current or future roles that may be a fit for your profile. You may request the removal of your data at any time by contacting greenhouse@okta.com.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Okta’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...