Back to jobs
Okta5K–10K employees

Principal Machine Learning Engineer, SecureAI

San Francisco, CA$238,000 – $326,000Posted 9 days ago

Immigration summary

Visa sponsorship

LikelyMedium confidence

This employer has recently sponsored work like this.

108 recent H-1B filings

View visa evidence

Green card sponsorship

Strong historyHigh confidence

This employer has recently sponsored green cards at scale.

60 recent certified PERM filings · 4 similar-role filings

View green card evidence

Job description

Secure Every Identity, from AI to Human

Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.

This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.

About Okta Secures AI Team

The Okta for AI Agents Team is building the future of digital identity management. The way companies are using agents and allowing them access is undergoing a fundamental shift, enabling teams to move fast while staying secure.

Our North Star is clear: To get AI right, you have to get identity right. We are not just managing identities; we are building the industry's first Identity Security Fabric for the agentic era. As organizations rapidly deploy AI, these non-human entities are acting with access to critical tools, often bypassing traditional perimeters and creating a 'Shadow AI' crisis. Our mission is to move identity from a reactive gatekeeper to a unified control plane, transforming AI risk into business ROI.

We are tackling this by implementing a comprehensive four-pillar maturity model: Discover, Onboard, Protect, and Govern. We are driving innovation by defining the standards for Agentic Identity—including pioneer work with securing AI Agents and support for protocols like MCP. You will be helping us build the infrastructure that allows enterprises to scale AI safely, ensuring every access decision—whether made by a human or an automated agent—is authenticated, authorized, and audited at scale.

We are a diverse team of engineers, product managers, and designers who are bringing Okta’s expertise in identity to define the future of Agent Identity management, focusing on enablement while staying secure.

About the role

In this role, you will join the Agent Access Policies sub-team under Okta Secures AI as a Principal Machine Learning (ML) Engineer to advance Okta's authorization capabilities. By replacing static, rule-based systems with dynamic AI security mechanisms, you will deliver real-time threat inspection, agent intent evaluation, and behavioral analysis—ensuring autonomous AI agents operate safely within specified bounds.

Your core mission will be architecting and driving features for our unified control plane to establish the premier Identity Security Fabric for the agentic era. In doing so, you will help execute our guiding principle: "To get AI right, you have to get identity right."

What you’ll be doing

  • Implement intent-based enforcement to verify agent runtime requests match their intended purpose, requiring key capabilities.
  • Apply LLM reasoning and prompt parsing to interpret prompts, tool payloads, and intent in real time.
  • Integrate low-latency inference or semantic evaluation engines directly into the API gateway request path.
  • Use embeddings, vector search, or zero-shot classification to score alignment between agent intent and executed actions.
  • Design confidence-scored decision engines that feed semantic verification results into policy frameworks (e.g., Cedar).
  • Establish evaluation benchmarks, prompt injection defenses, and guardrails to prevent bypasses or false positives.
  • Architect scalable ML and Generative AI systems integrating retrieval, inference, and evaluation pipelines.
  • Optimize prompting, context retrieval, and RAG workflows for accuracy, safety, and efficiency in Claude-based systems.
  • Build automated evaluation pipelines to measure model quality, correctness, groundedness, and safety in production.
  • Implement schema validation, structured output enforcement, and guardrails to ensure reliable, compliant AI outputs.
  • Mentor and coach engineers to support team and community growth.

What you’ll bring to the role

  • 10+ years of software development experience, with strong programming expertise in Python (and familiarity with Go or Typescript a plus).
  • Hands-on experience with applied machine learning, from feature engineering to training and fine-tuning models.
  • Hands-on experience with modern Generative AI platforms (AWS Bedrock, OpenAI, Anthropic, etc.).
  • Deep understanding of retrieval-augmented generation (RAG), embeddings, and knowledge-base workflows.
  • Hands-on experience with LiteLLM, LangGraph, LangChain, LlamaIndex, MCP, or other related AI agent frameworks.
  • Familiarity with ML frameworks (FastAPI, PyTorch, TensorFlow, Spark ML) and workflow orchestration tools (Airflow, etc.).
  • Experience defining evaluation metrics, pipelines, and feedback loops for ML/GenAI systems.
  • Proven ability to collaborate with product and engineering teams to drive greenfield initiatives forward, navigate unknowns, and iterate quickly and frequently.
  • Experience building tools or infrastructure for AI/ML applications, with a deep understanding of the developer lifecycle in an AI-native world.

Extra credit

  • Experience integrating AI-driven systems with identity, authentication, or security products.
  • Exposure to ethical AI, model risk, or compliance frameworks.
  • Familiarity with evaluation datasets, synthetic data generation, or LLM-as-a-judge methods.

Education:Bachelor’s or Master's degree in Computer Science or related field

(P25822_3552624)

#LI-Hybird

#LI-BB1

Below is the annual base salary range for candidates located in San Francisco Bay Area. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us.

The annual base salary range for this position for candidates located in the San Francisco Bay area is between: $238,000—$326,000 USD

The Okta Experience

We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one.

Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws.

If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation.

Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.

Sponsorship evidence

Why Openbound reached the conclusions above.

Visa sponsorship evidence

Current posting

Silent on sponsorship

Employer H-1B history

108
recent certified H-1B filings
32
new-hire petitions
0
filings for similar roles
92
so far in FY2026

Filed titles like this role: data engineer · manager data engineering · data scientist · data security engineer

More evidence details
  • 4 certified H-1B filings for closely related roles, though none for this exact title
  • 108 recent certified H-1B filings across the employer
  • Still filing this year — 92 filings in FY2026
  • 26 USCIS H-1B new-employment approvals, counted separately from LCA filings
  • Strong filing activity in CA
  • 340 further USCIS approvals for extensions or transfers
  • The supporting filings are for related work, not for this exact role
  • The posting says nothing about sponsorship either way

Strong filing activity in CA.

Green card sponsorship evidence

Employer PERM history

60
recent certified PERM filings
4
filings for similar roles
53
filings in this location
Certified PERM filings by fiscal year
202325
202449
202581
202624YTD

Filing history reflects past employer behavior; it isn't a promise for this opening.

All open roles at Okta
How Openbound evaluates sponsorship

Visa history uses official U.S. Department of Labor H-1B LCA disclosure data and USCIS H-1B petition history. Green card history uses DOL PERM disclosure data. Each is read for the employer as a whole, for roles like this one, and for this location, weighted toward the most recent fiscal years.

An employer is matched to its filing entities by verified legal name and reviewed aliases; a match is never made on a name resemblance alone. Where no verified entity can be matched, the page says so and draws no conclusion from the absence. 129 filing titles were examined for this employer.

What this posting states outranks history in both directions, and an employer's published policy outranks past filings. Filing history reflects past behavior; it is not a promise of sponsorship for this opening, and none of this is legal advice.