<?xml version="1.0" encoding="UTF-8"?>
<source>
  <jobs>
    <job>
      <externalid>b6611499-8b7</externalid>
      <Title>AI Identity Architect</Title>
      <Description><![CDATA[<p>Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI.\n\nOkta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era.\n\nThis work requires a relentless drive to solve complex challenges with real-world stakes.\n\nWe are looking for builders and owners who operate with speed and urgency and execute with excellence.\n\nThis is an opportunity to do career-defining work.\n\nWe&#39;re all in on this mission.\n\nIf you are too, let&#39;s talk.\n\nThe Identity Team\n\nThe Identity team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solution through identifying and resolving risks to the employees, product, and most importantly, our customers.\n\nWith the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business.\n\nThe AI Identity Architect Opportunity\n\nReporting to the VP of Identity &amp; Access Management, this role will be an AI Identity Pioneer, not just an IAM expert.\n\nYour &quot;been there, done that&quot; experience in securing autonomous agents at scale is your superpower.\n\nYou’ve seen how traditional OAuth flows break under agentic pressure, you’ve felt the pain of &quot;Secret Zero&quot; in a LangChain loop, and you know exactly where the industry’s current tools fall short.\n\nAt Okta, you won&#39;t just implement security; you will use your battle-tested experience to drive the product features needed to secure the next generation of identities.\n\nThe AI Identity Architect&#39;s mission is to own Okta’s enterprise identity strategy for autonomous AI agents.\n\nAs Customer Zero, you will implement Okta on Okta,validating identity patterns at production scale, feeding direct input into product roadmaps, and partnering with business units building internal agentic systems.\n\nWhat you’ll be doing\n\nProduct Vision &amp; Architecture (The &quot;Ratified R0&quot;)\n\nDrive the Roadmap: Act as a primary stakeholder for Okta’s product teams.\n\nTranslate your real-world experience securing agents into prioritized feature requests and product requirements.\n\nTarget State: Define a multi-year roadmap for Non-Human Identities (NHIs) and AI Agents aligned with Zero Trust (NIST 800-207) and Okta’s Secure Identity Commitment.\n\nPosture First: Use ISPM (Identity Security Posture Management) to discover unmanaged AI agents and eliminate &quot;Identity Debt&quot; across the enterprise.\n\nCross-App Access &amp; Brokered Delegation\n\nAgent-to-App Connectivity: Architect secure Cross-App Access patterns where agents act as intermediaries between enterprise systems.\n\nDelegated Authority: Refine how user identity is &quot;brokered&quot; to an agent (e.g. OAuth2 Token Exchange), ensuring the agent never has more power than the human user who triggered it.\n\nSession Scoping: Implement context-bound, short-lived tokens to prevent lateral movement by a compromised agent.\n\nOkta Customer Zero -- Validate and publish patterns using Okta primitives to secure the AI lifecycle for:\n\nOkta Identity Engine &amp; Auth0: Define how AI agents prove their identity within AuthN/AuthZ core concepts, implementing rigorous protocols for secure access delegation like OAuth2/OIDC, mTLS, and SPIFFE/SPIRE for workload attestation.\n\nOkta Privilege Access: Implement JIT/JEA access and ephemeral, vaulted secrets for agent tool-use.\n\nOkta Identity Governance &amp; Workflows: Automate the Joiner-Mover-Leaver (JML) lifecycle for agents, including automated certification and revocation.\n\nFine-Grained Authorization: Implement ReBAC for intent-bound decisions (e.g., &quot;Can this agent access the Finance API on behalf of the CFO?&quot;).\n\nServe as &quot;Customer Zero&quot; by architecting and stress-testing internal AI security frameworks, translating real-world deployment lessons into a continuous stream of public-facing white papers, blogs, and technical guides to steer industry best practices.\n\nAI Ecosystem &amp; Tech Stack Integration\n\nDefine how Okta identity is woven into modern AI orchestration layers:\n\nOrchestration: Secure identity patterns such as LangChain, LangGraph, AutoGPT, CrewAI, LlamaIndex, and Semantic Kernel.\n\nArchitect secure connectivity to AI model providers such as Azure OpenAI, AWS Bedrock, Google Vertex AI, OpenAI API, and Anthropic.\n\nWhat you’ll bring to the role\n\nThe &quot;Been There&quot; Factor: Proven track record of securing AI agents and non-human identities in a production environment.\n\nExperience: 7+ years in IAM/Security Architecture; proven strategy work across workforce, customer, and Non-Human Identities (NHIs).\n\nDeep knowledge of the core protocols OAuth2/OIDC (especially Token Exchange), SAML, mTLS, JWT, and Model Context Protocol (MCP).\n\nHands-on experience with Modern Identity framework SPIFFE/SPIRE.\n\nAbility to author Architecture Decision Records (ADR) and influence at the VP/CTO level, while simultaneously acting as a peer to Product Management.\n\nAnd extra credit if you have experience in any of the following!\n\nPrior work shaping identity strategy for autonomous/agent systems, multi-agent delegation, or brokered access patterns.\n\nExposure to policy-as-code (OPA/Cedar) and service-mesh identity.\n\nCertifications such as CISSP-ISSAP, CCSP, or TOGAF are welcome but not required or expected.\n\n#LI-SM1 #LI-Hybrid P21621_3398002</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>senior</Experiencelevel>
      <Workarrangement>hybrid</Workarrangement>
      <Salaryrange>$242,000-$332,000 USD</Salaryrange>
      <Skills>OAuth2/OIDC, SAML, mTLS, JWT, Model Context Protocol (MCP), SPIFFE/SPIRE, Architecture Decision Records (ADR), Policy-as-code (OPA/Cedar), Service-mesh identity, LangChain, LangGraph, AutoGPT, CrewAI, LlamaIndex, Semantic Kernel, Azure OpenAI, AWS Bedrock, Google Vertex AI, OpenAI API, Anthropic</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Okta</Employername>
      <Employerlogo>https://logos.yubhub.co/okta.com.png</Employerlogo>
      <Employerdescription>Okta provides identity management solutions for businesses.</Employerdescription>
      <Employerwebsite>https://www.okta.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/okta/jobs/7749222</Applyto>
      <Location>San Francisco, California</Location>
      <Country></Country>
      <Postedate>2026-04-18</Postedate>
    </job>
    <job>
      <externalid>e21cfc44-77a</externalid>
      <Title>Staff Distributed Systems Engineer - Collaboration</Title>
      <Description><![CDATA[<p>At Webflow, we&#39;re building the world&#39;s leading AI-native Digital Experience Platform, and we&#39;re doing it as a remote-first company built on trust, transparency, and a whole lot of creativity.</p>
<p>This work takes grit, because we move fast, without ever sacrificing craft or quality. Our mission is to bring development superpowers to everyone. From entrepreneurs launching their first idea to global enterprises scaling their digital presence, we empower teams to design, launch, and optimize for the web without barriers.</p>
<p>We&#39;re looking for a Staff Distributed Systems Engineer</p>
<p><strong>About the role:</strong></p>
<ul>
<li>Location: Remote-first (United States; BC &amp; ON, Canada)</li>
<li>Full-time</li>
<li>Permanent</li>
<li>Exempt</li>
<li>The cash compensation for this role is tailored to align with the cost of labor in different geographic markets. We&#39;ve structured the base pay ranges for this role into zones for our geographic markets, and the specific base pay within the range will be determined by the candidate’s geographic location, job-related experience, knowledge, qualifications, and skills.</li>
<li>United States (all figures cited below are in USD and pertain to workers in the United States)</li>
</ul>
<p>+ Zone A: $187,000 - $289,000 	+ Zone B: $175,000 - $271,000 	+ Zone C: $164,000 - $254,000</p>
<ul>
<li>Canada (figures cited below are in CAD and pertain to workers in ON &amp; BC, Canada)</li>
</ul>
<p>+ $212,000 - $328,000</p>
<ul>
<li>This role is also eligible to participate in Webflow&#39;s company-wide bonus program. Target amounts are a percentage of base salary and vary by career level. Payouts are based on company performance against established financial and operational goals.</li>
<li>Please visit our Careers page for more information on which locations are included in each of our geographic pay zones. However, please confirm the zone for your specific location with your recruiter.</li>
<li>Application Information:</li>
</ul>
<p>+ Application deadline: applications accepted on an ongoing basis until position is closed and filled 	+ This posting is for a new position 	+ Reporting to the Senior Manager, Engineering</p>
<ul>
<li>As a Staff Distributed Systems Engineer, you’ll:</li>
</ul>
<p>+ Collaborate with exceptional engineers on building systems and services for the world&#39;s largest companies. This platform powers millions of production websites and supports massive scale, including over 1% of global Internet traffic and more than 10 billion monthly visits. 	+ Lead architecture for distributed services at scale that synchronize shared state across clients, including clear correctness guarantees (eg: ordering, idempotency, convergence). These services require low latency and high availability, with SLO of 99.99% uptime. 	+ Define concurrency and conflict-resolution semantics for concurrent changes, including trade-offs and constraints. 	+ Design for failure: retries, partial outages, reconnection, and safe recovery paths, with explicit degradation behavior. 	+ Own operational excellence: define SLIs/SLOs, instrument tracing/metrics/logging, and drive reliability improvements through incident learning. 	+ Drive cross-team technical alignment via design docs and decision records; unblock execution across org boundaries. 	+ Raise the bar through design and code reviews, mentoring, and pragmatic standardization that increases leverage. 	+ Deliver maintainable, tested, performant systems and evolve them with a “crawl, walk, run” plan. 	+ Use modern tooling (including agentic coding, debugging and code review) to improve developer velocity and reduce time-to-diagnosis in production. 	+ Participate in engineering citizenship activities such as co-authoring engineering blogs, strengthening and improving our hiring processes, and leading internal hackathon teams. 	+ In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we&#39;ll help you incorporate them into your role.</p>
<ul>
<li><strong>About you:</strong></li>
<li>Requirements:</li>
</ul>
<p>+ BA/BS degree or equivalent experience 	+ You’ll thrive as a Staff Distributed Systems Engineer, if you have:</p>
<ul>
<li>At least 7, preferably 10+ years of building and operating large-scale production distributed systems where latency, correctness, and reliability (99.99% uptime) are non-negotiable.</li>
<li>Deep backend systems experience in one or more modern server environments (Java, Go, Rust, Python, Node.js, etc.), with the ability to ramp and adapt quickly in new stacks.</li>
<li>Expertise with distributed systems, concurrency, scaling, and debugging multi-layer systems.</li>
<li>Strong operational judgment: you define SLIs/SLOs, build observability, and improve systems via incidents and feedback loops, not heroics.</li>
<li>Staff behaviors: you lead multi-team initiatives, write appropriate design docs, influence architecture beyond your immediate team, and communicate across the organization.</li>
<li>Ability to make decisions with incomplete information, understand and communicate one-way vs. two-way doors, and move with urgency while keeping critical code operational.</li>
<li>Stay curious and open to growth , actively building fluency in emerging technologies like AI to unlock creativity, accelerate progress, and amplify impact.</li>
<li><strong>Our Core Behaviors:</strong></li>
</ul>
<p>+ Build lasting customer trust. 	+ Win together. 	+ Reinvent ourselves. 	+ Deliver with speed, quality, and craft.</p>
<ul>
<li><strong>Benefits:</strong></li>
</ul>
<p>+ Ownership in what you help build. 	+ Health coverage that actually covers you. 	+ Support for every stage of family life. 	+ Time off that’s actually off. 	+ Wellness for the whole you. 	+ Invest in your future. 	+ Monthly stipends that flex with your life. 	+ Bonus for building together.</p>
<ul>
<li><strong>Remote, together:</strong></li>
</ul>
<p>+ At Webflow, equality is a core tenet of our culture. We are an Equal Opportunity (EEO)/Veterans/Disability Employer.</p>
<p style="margin-top:24px;font-size:13px;color:#666;">XML job scraping automation by <a href="https://yubhub.co">YubHub</a></p>]]></Description>
      <Jobtype>full-time</Jobtype>
      <Experiencelevel>staff</Experiencelevel>
      <Workarrangement>remote</Workarrangement>
      <Salaryrange>$187,000 - $289,000 (USD)</Salaryrange>
      <Skills>distributed systems, backend systems, server environments, concurrency, scaling, debugging, operational judgment, SLIs/SLOs, observability, incident learning, design docs, decision records, code reviews, mentoring, pragmatic standardization, modern tooling, agentic coding, code review</Skills>
      <Category>Engineering</Category>
      <Industry>Technology</Industry>
      <Employername>Webflow</Employername>
      <Employerlogo>https://logos.yubhub.co/webflow.com.png</Employerlogo>
      <Employerdescription>Webflow is a digital experience platform that empowers teams to design, launch, and optimize websites without barriers.</Employerdescription>
      <Employerwebsite>https://webflow.com/</Employerwebsite>
      <Compensationcurrency></Compensationcurrency>
      <Compensationmin></Compensationmin>
      <Compensationmax></Compensationmax>
      <Applyto>https://job-boards.greenhouse.io/webflow/jobs/7630474</Applyto>
      <Location>U.S. Remote</Location>
      <Country></Country>
      <Postedate>2026-03-31</Postedate>
    </job>
  </jobs>
</source>