Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Staff Vulnerability Management image - Rise Careers
Job details

Staff Vulnerability Management

Get to know Okta

Okta is The World’s Identity Company. We free everyone to safely use any technology—anywhere, on any device or app. Our Workforce and Customer Identity Clouds enable secure yet flexible access, authentication, and automation that transforms how people move through the digital world, putting Identity at the heart of business security and growth. 

At Okta, we celebrate a variety of perspectives and experiences. We are not looking for someone who checks every single box - we’re looking for lifelong learners and people who can make us better with their unique experiences. 

Join our team! We’re building a world where Identity belongs to you.

The Okta Security team’s mission is to strengthen Okta’s position as the leading Identity-as-a-Service solutions through identifying and resolving risks to the employees, product, and most importantly, our customers. With the ever-increasing pace of cloud application adoption, companies are struggling to find ways to accurately assess risk and act at the speed of their business. 

 

The Vulnerability Management Analyst is a key member of the Okta Security team and an essential collaborator with our broader Engineering organization. Reporting to the Director of  Vulnerability Management, the Vulnerability Management Analyst will play a key part in executing the Vulnerability Management Program’s strategy. The Vulnerability Management Program is a crucial pillar of the security organizations’ imperative to reduce the threats to Okta’s infrastructure and applications. You’ll be an integral part of building and sustaining strong and effective relationships across Okta with our Engineering, Product and Business Technology counterparts.

 

What You'll Do

 

  • Own the full lifecycle operations of Vulnerability Management AWS infrastructure, including designing new deployments as required
  • Develop and maintain automation solutions leveraging AWS services integrated with custom software serving the Vulnerability and Asset Management functions for Okta Security
  • Tend to the reliability needs of Okta Security’s Vulnerability Management infrastructure such as Infrastructure as code configurations, monitoring via AWS CloudWatch, and implementing alerting solutions leveraging a variety of AWS and web APIs
  • Keep up with newly published vulnerabilities/ CVEs and zero-days.
  • Support our partner teams with investigating vulnerability findings and remediation efforts, including software and operations engineers, IT staff and the broader Okta Security org.
  • Monitor and maintain awareness of critical vulnerabilities, driving patch management or mitigating processes to reduce impact.
  • Document, review and deliver requirements and recommendations related to vulnerability remediation which follow common industry standards and security frameworks.
  • Assist business stakeholders in assessing risk and prioritizing vulnerability remediation. Assist in providing risk context to vulnerability reports given the infrastructure purpose.
  • Understand the technical details of the published vulnerabilities as well as their real risk. Effectively communicate the perceived and real vulnerability impact.
  • Assist in analyzing data from internet scanning tools in order to validate its accuracy.
  • Validate vulnerability management changes for accuracy and completion to drive timely remediation of critical vulnerabilities.
  • Confirm remediation via automated and manual retesting.
  • Contribute to the definition of internal processes that allow for fast remediation of vulnerabilities to production systems.
  • Assess new and existing scan technologies to determine potential value and risk to the enterprise and ensure risk beyond defined thresholds is appropriately treated.
  • Monitor and respond to security inquiries, requests, and incidents as part of supporting the business through sound and timely cybersecurity response.
  • Support audit, governance, risk and compliance teams in scanning and reporting on various regulatory compliance and industry best practices including PCI, ISO 27001/27017/27018 , NIST SP 800-53, SOC 2 and FedRAMP.
  • Participate in other special projects or strategic initiatives at the direction of the Security team.

 

Your Background

 

  • 6+ years of multifaceted cyber security experience in a technology-centric company.
  • Experience in building and innovating a vulnerability management program.
  • Experience defining projects, including goals, resourcing, activities, targets, and milestones, and producing good effort estimations.
  • Experience in having had hands-on responsibility for analyzing common vulnerabilities.
  • Experience with commercial or open-source vulnerability scanners regarding at least one of these spaces: Infrastructure/ IP based Assets, Web Application, SAST, DAST, Containers.
  • Functional knowledge of vulnerabilities, exploitation and remediation. You should be able to explain vulnerabilities and exploits as well as propose remediations for the most common vulnerabilities.
  • Experience in building systems and solutions within a highly regulated environment.
  • Familiarity with industry standards and frameworks such as CVE, CVSS, and OWASP.
  • Solid understanding of security best practices in cloud environments.
  • Proficiency in scripting and automation with Python 
  • Familiarity with other scripting and automation tools is a plus.
  • Experience working with AWS Lambda or similar serverless computing environments for automating vulnerability management tasks
  • Proficiency in working with AWS services such as S3, DynamoDB, API Gateway, and others
  • Intermediate knowledge of TCP/IP.
  • Experience developing threat models.
  • Knowledge of at least one of AWS, GCP, Azure, etc.

 

Who you are

 

  • You have a deep focus on execution, follow-through, accountability, and results.
  • You have a growth mindset; You thrive on challenge, you see learnings and opportunities, not failures.
  • You enjoy working with cross-functional teams and have exceptional stakeholder management skills.
  • You surround yourself with high energy, thriving teams to achieve quality outcomes.

 

Qualifications:

 

  • Bachelor's degree in Computer Science, Computer Engineering, or equivalent experience.

    #LI-Remote 

    #LI-LSS1

 

Below is the annual salary range for candidates located in Canada. Your actual salary will depend on factors such as your skills, qualifications, and experience. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental, and vision insurance, RRSP with a match, healthcare spending, telemedicine, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program, please visit: https://rewards.okta.com/can.

The annual base salary range for this position for candidates located in Canada is between:
$141,000$211,000 USD

What you can look forward to as a Full-Time Okta employee!

Okta cultivates a dynamic work environment, providing the best tools, technology and benefits to empower our employees to work productively in a setting that best and uniquely suits their needs. Each organization is unique in the degree of flexibility and mobility in which they work so that all employees are enabled to be their most creative and successful versions of themselves, regardless of where they live. Find your place at Okta today! https://www.okta.com/company/careers/.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to participate in the job application, interview process, or onboarding please use this Form to request an accommodation.

Okta is committed to complying with applicable data privacy and security laws and regulations. For more information, please see our Privacy Policy at https://www.okta.com/privacy-policy/

Okta Glassdoor Company Review
3.6 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Okta DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Okta
Okta CEO photo
Todd McKinnon
Approve of CEO

Average salary estimate

$176000 / YEARLY (est.)
min
max
$141000K
$211000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Staff Vulnerability Management, Okta

Join Okta as a Staff Vulnerability Management Analyst and be part of a transformative team that defines the future of secure identity management. Located in the vibrant city of Toronto, Canada, this role is perfect for individuals who thrive on tackling complex security challenges with innovative solutions. At Okta, we believe in the power of identity as the core of business security and growth, and we need someone like you to help strengthen our vulnerability management program! In this position, you'll collaborate closely with our Engineering and Product teams, ensuring that any potential risks are identified and addressed promptly. Your expertise will allow you to design and maintain automated solutions utilizing AWS services, ensuring that our Vulnerability Management infrastructure is resilient and efficient. Your role will involve monitoring vulnerabilities, documenting requirements, and assisting stakeholders in assessing risk. Are you ready to dive deep into the technology, analyze vulnerabilities, and communicate their impacts effectively? If you have a solid foundation in cyber security, enjoy working in cross-functional teams, and possess a growth mindset, Okta is eager to meet you. Embrace the challenge and help shape a world where identity belongs to everyone!

Frequently Asked Questions (FAQs) for Staff Vulnerability Management Role at Okta
What are the primary responsibilities of a Staff Vulnerability Management Analyst at Okta?

As a Staff Vulnerability Management Analyst at Okta, your primary responsibilities include overseeing the full lifecycle of vulnerability management for AWS infrastructure, developing automation solutions, monitoring cloud environments for vulnerabilities, and collaborating with various teams to ensure timely remediation of identified risks. You will be essential in maintaining a robust security posture through effective vulnerability assessments and patch management.

Join Rise to see the full answer
What qualifications do I need to become a Staff Vulnerability Management Analyst at Okta?

To qualify for the Staff Vulnerability Management Analyst position at Okta, candidates should have at least 6+ years of experience in cybersecurity within a technology-focused company, and a Bachelor’s degree in Computer Science or a related field. A solid understanding of vulnerability management principles, automation skills—particularly in Python—and familiarity with cloud environments like AWS are crucial for this role.

Join Rise to see the full answer
How does Okta support the career development of its Staff Vulnerability Management Analysts?

At Okta, we value continuous learning and career growth. As a Staff Vulnerability Management Analyst, you'll have access to various resources, mentorship opportunities, and a supportive environment that encourages skill enhancement. We foster a culture of collaboration and innovation, allowing you to work on challenging projects while expanding your expertise through hands-on experience and professional development initiatives.

Join Rise to see the full answer
What technologies should I be familiar with as a Staff Vulnerability Management Analyst at Okta?

As a Staff Vulnerability Management Analyst at Okta, familiarity with AWS services such as Lambda, S3, and CloudWatch is essential. Additionally, experience with vulnerability scanners, knowledge of industry frameworks like CVE and OWASP, and proficiency in scripting and automation with Python will greatly enhance your effectiveness in this role.

Join Rise to see the full answer
What is the importance of automation in the Staff Vulnerability Management Analyst role at Okta?

Automation plays a vital role in the Staff Vulnerability Management Analyst position at Okta as it enables efficient and repeatable processes for identifying, assessing, and remediating vulnerabilities. By leveraging AWS services and custom software, you’ll be able to enhance the vulnerability management lifecycle, provide real-time monitoring, and ensure prompt responses to emerging threats, ultimately reducing the risk to Okta's infrastructure and applications.

Join Rise to see the full answer
Common Interview Questions for Staff Vulnerability Management
Can you describe your experience with vulnerability management programs?

When answering this question, highlight specific experiences you’ve had in creating or managing a vulnerability management program. Discuss your role, the tools you used, how you approached vulnerability assessments, and any successful remediation strategies you've implemented. Be concise yet detailed enough to showcase your understanding of best practices and frameworks in vulnerability management.

Join Rise to see the full answer
How do you prioritize vulnerabilities when presenting them to stakeholders?

Prioritizing vulnerabilities requires an understanding of both their technical details and potential impact on the business. In your response, talk about using frameworks like CVSS to evaluate severity, along with context about how specific vulnerabilities may affect business operations. Offer examples of how you’ve effectively communicated risks to non-technical stakeholders to drive timely action.

Join Rise to see the full answer
What AWS services have you used in previous roles for vulnerability management?

Discuss your experience with AWS services, especially those that pertain to vulnerability management such as AWS Lambda for automation, CloudWatch for monitoring, and others like DynamoDB. Share specific examples of how you utilized these services to improve security Postures, enhance detection capabilities, or streamline incident response.

Join Rise to see the full answer
How do you keep up to date with new vulnerabilities and security trends?

Express your proactive approach to staying informed about new vulnerabilities, such as subscribing to security alerts, following relevant cybersecurity blogs, participating in forums, or engaging with professional communities. Mention specific sources you rely on for timely information, including platforms like NIST, the CVE database, or security newsletters.

Join Rise to see the full answer
Explain a challenging vulnerability you encountered and how you addressed it.

Choose a relevant experience where you faced a significant vulnerability. Describe the initial discovery, the steps you took to analyze it, the remediation strategies you proposed, and the final outcome. Highlight your problem-solving skills and ability to work collaboratively with other teams during the resolution process.

Join Rise to see the full answer
What scripting or automation tools are you familiar with for vulnerability management?

Detail your experiences with scripting, especially in Python, as well as any other automation tools you've used. Discuss specific scripts you’ve written or processes you’ve developed to automate vulnerability scans, data collection, or patch management, noting how they have enhanced your team's efficiency and response times.

Join Rise to see the full answer
How do you assess the impact of a vulnerability on business operations?

In your answer, explain your process for evaluating a vulnerability's potential impact. Discuss using a combination of technical analysis, threat modeling, and collaborating with business stakeholders to quantify the risk and assess possible repercussions on business operations, thus enabling effective prioritization of remediation efforts.

Join Rise to see the full answer
Describe your experience collaborating with cross-functional teams.

Highlight specific instances where you worked closely with engineering, IT, or product teams. Emphasize your role in fostering communication, aligning objectives, and facilitating the timely remediation of security findings. Illustrating effective collaboration leads to a stronger emphasis on the importance of teamwork in vulnerability management.

Join Rise to see the full answer
What do you understand by the term 'risk context' in vulnerability management?

Explain that risk context refers to the understanding of a vulnerability concerning the specific environment and business operations. Discuss its importance in prioritizing remediation efforts and providing meaningful insights to stakeholders about how a vulnerability may affect their particular areas of responsibility.

Join Rise to see the full answer
How would you handle a situation where a critical vulnerability is found close to a product launch?

Describe your approach to assessing the severity of the vulnerability in relation to the product launch timeline. Talk about collaboration with engineering and business teams, immediate risk assessments, and communication strategies to provide actionable insights while working towards a rapid yet safe resolution to mitigate any risks associated with the launch.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Okta Remote Washington D.C.; Chicago, IL; Bellevue, WA; Denver, CO; Dallas, TX
Posted 9 days ago
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Maternity Leave
Paternity Leave
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off
Paid Volunteer Time
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Family Coverage (Insurance)
Medical Insurance
Mental Health Resources

Lead a dynamic team of Technical Account Managers in driving exceptional service for public sector clients at Okta.

Photo of the Rise User
Posted 10 days ago
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Maternity Leave
Paternity Leave
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off
Paid Volunteer Time
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Family Coverage (Insurance)
Medical Insurance
Mental Health Resources

Take on a pivotal role at Okta as a Staff Scrum Coach & Technical Program Manager, focusing on Scrum practices and multi-team technical program delivery.

Photo of the Rise User
Posted 5 hours ago

Join eHealth as a GRC Analyst to enhance their Information Security processes while working in a fully remote environment.

Photo of the Rise User
Posted 6 days ago

Join Synchrony as a VP, Staff Cryptography Engineer and lead the charge in safeguarding enterprise data through innovative cryptography solutions.

Join UChicago Medicine as an Inpatient Orders Analyst - Associate in a remote role and help advance healthcare through technology.

Photo of the Rise User
Posted 5 days ago

Join Visa's Cyber Security team as a Senior Cybersecurity Engineer focusing on IAM processes, leveraging AI for innovation and efficiency.

Photo of the Rise User
Posted 3 days ago

Join Visa's innovative Technology Organization as a Staff DevOps Engineer and help solve global-scale challenges in commerce technology.

Charles IT Hybrid No location specified
Posted 12 days ago

Join Charles IT as a Field System Administrator to provide essential technical support in a collaborative and inclusive environment.

Posted 21 hours ago

An exciting opportunity for an IT Application Owner at Deutsche Bank's Bucharest Technology Centre, focusing on technological improvements and compliance.

Photo of the Rise User
ManTech Hybrid US, Bexar County, TX; Texas, San Antonio, TX
Posted 21 hours ago

Join ManTech as a Systems Administrator 3 and play a key role in maintaining cloud infrastructure services for their clients.

Okta is a leading identity and access management company headquartered in San Francisco, California that is committed to allowing people to access applications on any device at any time, while still enforcing strong security policies.

562 jobs
MATCH
VIEW MATCH
BADGES
Badge ChangemakerBadge Future MakerBadge Global CitizenBadge Innovator
CULTURE VALUES
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
BENEFITS & PERKS
Maternity Leave
Paternity Leave
401K Matching
Paid Holidays
Paid Sick Days
Paid Time-Off
Paid Volunteer Time
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Family Coverage (Insurance)
Medical Insurance
Mental Health Resources
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
February 21, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
62 people applied to SOC Analyst I at Epsilon
S
14 people applied to SOC Intern at SHEIN
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Support Specialist (Temp) at Carnegie Learning
Photo of the Rise User
Someone from OH, Tiffin just viewed Game Operations Specialist at Genius Sports
u
Someone from OH, Loveland just viewed Customer Service Agent - Part Time at uhaul
Photo of the Rise User
Someone from OH, Cleveland just viewed HR Manager at Shearer's Foods
Photo of the Rise User
Someone from OH, Columbus just viewed Mid Level, System Administrator - (ETS) at Delivery Hero
Photo of the Rise User
Someone from OH, Mason just viewed Inside Sales Co-Op at VEGA Americas
Photo of the Rise User
44 people applied to IT Intern at USAA
Photo of the Rise User
Someone from OH, Sandusky just viewed Director of IT at Kyo
Photo of the Rise User
11 people applied to Cyber security analyst at Optimiza
T
9 people applied to Intern-Tech at TDS Telecom
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health
Photo of the Rise User
51 people applied to Cyber Crime Analyst at TEKsystems
Photo of the Rise User
8 people applied to Security Analyst at Maximus
Photo of the Rise User
Someone from OH, Avon Lake just viewed Advancement Specialist at Sierra Club
Photo of the Rise User
Someone from OH, Sidney just viewed Database Engineer Principal at Sagent
Photo of the Rise User
Someone from OH, North Canton just viewed Manager, Customer Success at impact.com
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Experience Representative at MYOB
Photo of the Rise User
Someone from OH, Lakewood just viewed Production Scheduling Supervisor at Shearer's Foods
Photo of the Rise User
Someone from OH, Hilliard just viewed General Manager at Super Soccer Stars