{"version":"0.1","company":{"name":"YubHub","url":"https://yubhub.co","jobsUrl":"https://yubhub.co/jobs/skill/security-control-gap-mitigation"},"x-facet":{"type":"skill","slug":"security-control-gap-mitigation","display":"Security Control Gap Mitigation","count":1},"x-feed-size-limit":100,"x-feed-sort":"enriched_at desc","x-feed-notice":"This feed contains at most 100 jobs (the most recently enriched). For the full corpus, use the paginated /stats/by-facet endpoint or /search.","x-generator":"yubhub-xml-generator","x-rights":"Free to redistribute with attribution: \"Data by YubHub (https://yubhub.co)\"","x-schema":"Each entry in `jobs` follows https://schema.org/JobPosting. YubHub-native raw fields carry `x-` prefix.","jobs":[{"@context":"https://schema.org","@type":"JobPosting","identifier":{"@type":"PropertyValue","name":"YubHub","value":"job_85f63ecb-5fc"},"title":"Staff Security Engineer","description":"<p>Secure Every Identity, from AI to Human</p>\n<p>Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organisations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.</p>\n<p>This is an opportunity to do career-defining work. We&#39;re all in on this mission. If you are too, let&#39;s talk.</p>\n<p><strong>Staff Security Engineer</strong></p>\n<p>Okta is The World’s Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.</p>\n<p>At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences.</p>\n<p>Join our team! We’re building a world where Identity belongs to you.</p>\n<p><strong>Responsibilities</strong></p>\n<p>The Staff Security Engineer is a key role for strengthening the organisation&#39;s security posture. You&#39;ll be responsible for performing security assessments of third-party integrations and connected apps, with a focus on mitigating API-related security risks. This position is vital for ensuring a &#39;secure-by-design&#39; approach for critical systems within the organisation.</p>\n<p><strong>What You Will Do</strong></p>\n<ul>\n<li>Lead Technical Security Reviews: Perform in-depth security reviews and threat modelling for complex enterprise applications and third-party integrations.</li>\n</ul>\n<ul>\n<li>Operationalize AI for Security: Take the lead in deploying and managing AI for Security use cases, such as integration security reviews, to automate and scale security operations.</li>\n</ul>\n<ul>\n<li>Risk Analysis &amp; Documentation: Analyse and document API permissions and risk levels for major integrations (e.g., Salesforce, Slack, Google) to ensure they meet internal standards.</li>\n</ul>\n<ul>\n<li>Develop Workflow Processes: Collaborate with stakeholders to design and implement repeatable security review workflows, such as the Salesforce API Integration Review.</li>\n</ul>\n<ul>\n<li>Vulnerability &amp; Control Gap Mitigation: Identify potential vulnerabilities and security control gaps in connected apps and recommend technical mitigation strategies to stakeholders.</li>\n</ul>\n<ul>\n<li>Report &amp; Visualize Posture: Contribute to and maintain metrics and dashboards that demonstrate the organisation&#39;s overall security posture for leadership.</li>\n</ul>\n<p><strong>What You Bring</strong></p>\n<ul>\n<li>Deep Technical Expertise: Proven experience in information security, specifically within application and enterprise security domains.</li>\n</ul>\n<ul>\n<li>API &amp; Integration Specialist: Strong background in assessing and mitigating risks associated with third-party APIs and connected application ecosystems.</li>\n</ul>\n<ul>\n<li>Advanced Security Principles: Understanding of &#39;secure-by-design&#39; principles and the &#39;least privilege&#39; model.</li>\n</ul>\n<ul>\n<li>Practical Threat Modelling: Hands-on experience identifying attack vectors and conducting risk assessments for complex systems.</li>\n</ul>\n<ul>\n<li>Tooling &amp; AI Proficiency: Experience working with security platforms for analysing application permissions and an interest or background in applying AI to streamline security tasks.</li>\n</ul>\n<ul>\n<li>Collaborative Influencer: Exceptional communication skills with a track record of aligning multiple teams toward shared security goals.</li>\n</ul>\n<ul>\n<li>Education: A Bachelor&#39;s degree in Computer Science, information security, or a related field.</li>\n</ul>\n<p><strong>Benefits</strong></p>\n<p>In addition to the annual base salary range for this position, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.</p>\n<p style=\"margin-top:24px;font-size:13px;color:#666;\">XML job scraping automation by <a href=\"https://yubhub.co\">YubHub</a></p>","url":"https://yubhub.co/jobs/job_85f63ecb-5fc","directApply":true,"hiringOrganization":{"@type":"Organization","name":"Okta","sameAs":"https://www.okta.com/","logo":"https://logos.yubhub.co/okta.com.png"},"x-apply-url":"https://job-boards.greenhouse.io/okta/jobs/7397934","x-work-arrangement":"hybrid","x-experience-level":"staff","x-job-type":"full-time","x-salary-range":"$141,000-$193,000 CAD","x-skills-required":["information security","application security","enterprise security","API security","integration security","threat modelling","risk analysis","security review workflows","vulnerability mitigation","security control gap mitigation","security posture visualization"],"x-skills-preferred":[],"datePosted":"2026-04-18T15:49:10.109Z","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Toronto, Ontario, Canada"}},"employmentType":"FULL_TIME","occupationalCategory":"Engineering","industry":"Technology","skills":"information security, application security, enterprise security, API security, integration security, threat modelling, risk analysis, security review workflows, vulnerability mitigation, security control gap mitigation, security posture visualization","baseSalary":{"@type":"MonetaryAmount","currency":"USD","value":{"@type":"QuantitativeValue","minValue":141000,"maxValue":193000,"unitText":"YEAR"}}}]}