Full-Time
Cloud-based identity and access management
$147k - $202k/yr
Company Historically Provides H1B Sponsorship
Chicago, IL, USA + 2 more
More locations: New York, NY, USA | Bellevue, WA, USA
Hybrid
Hybrid role; some on-site days at listed locations.
See people who can refer or advise you
Okta provides a cloud-based platform that manages and secures digital identities for businesses and government agencies. The software works by centralizing user authentication through tools like single sign-on and multi-factor authentication, allowing employees to access all their work applications with one secure login. Unlike traditional hardware-based security, Okta operates entirely in the cloud, making it easier to manage remote workforces and automate the process of granting or removing access as employees join or leave a company. The company's goal is to ensure that the right individuals have secure access to the right digital resources at the right time.
Company Size
5,001-10,000
Company Stage
IPO
Headquarters
San Francisco, California
Founded
2009
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Health Insurance
Dental Insurance
Vision Insurance
401(k) Retirement Plan
401(k) Company Match
Paid Vacation
Paid Sick Leave
Paid Holidays
Flexible Work Hours
Remote Work Options
Parental Leave
Okta agreed to acquire AI identity security startup Permiso Security in a deal valued at just under $200 million, according to a source familiar with the transaction. The nearly all-cash acquisition is expected to close in Okta's third quarter of fiscal 2027. Permiso, which emerged from stealth in 2022, develops software that detects suspicious activity in cloud environments after users or applications gain access. The startup recently expanded its platform to monitor AI agents and other machine identities. Co-founded by former FireEye executives Paul Nguyen and Jason Martin, Permiso has raised approximately $29 million to date, including an $18.5 million Series A round in April 2024 led by Altimeter Capital. The acquisition strengthens Okta's capabilities in securing AI agents and non-human identities alongside its core identity management business.
Okta buys AI security startup Permiso; source says for about $200M. 9:09 AM PDT · July 30, 2026 Okta on Thursday agreed to acquire AI identity security startup Permiso Security, betting that demand for protecting AI agents and other machine identities will grow as enterprises deploy autonomous software across their operations. The identity management company did not disclose the terms of the transaction. But TechCrunch has learned that the acquisition is valued at just under $200 million and is structured as an almost all-cash deal, according to a source with knowledge of the deal. A spokesperson for Okta did not dispute the figure when asked by TechCrunch, but would not comment on specifics of the deal terms. The deal is expected to close in the third quarter of its fiscal 2027, Okta said, subject to customary closing conditions. Okta's move to buy Permiso comes as identity management companies seek to expand beyond verifying users at login to continuously monitoring what users, applications, and AI agents do once gaining authorized access to a network environment. That shift has intensified competition to secure machine identities as enterprises embed AI deeper into everyday operations. Permiso, which emerged from stealth in 2022, develops software that helps security teams spot suspicious activity in cloud environments after users or applications have been granted access. More recently, the startup has expanded its platform to monitor AI agents and other machine identities. Co-founded by former FireEye executives Paul Nguyen and Jason Martin, Permiso specializes in detecting attacks that use stolen or compromised identities to move through cloud infrastructure. In April, the startup also introduced SandyClaw, a platform designed to analyze AI agent skills in a sandboxed environment to identify malicious behavior before they are deployed. The deal strengthens Okta's push into securing AI agents and other non-human identities alongside its core identity management business. "Permiso will extend Okta's identity security fabric with proven identity threat detection and response capabilities, and an incredible threat research and security team that will advance Okta's threat detection and prevention capabilities," Okta's chief product officer Ely Kahn said in a prepared statement. Permiso has raised about $29 million to date, including an $18.5 million Series A round in April 2024 led by Altimeter Capital. People familiar with the financing said the Series A valued the Palo Alto-based startup at about $80 million on a post-money basis. When you purchase through links in our articles, we may earn a small commission. This doesn't affect our editorial independence. Jagmeet Singh Jagmeet covers startups, tech policy-related updates, and all other major tech-centric developments from India for TechCrunch. He previously worked as a principal correspondent at NDTV. October 13 - 15 San Francisco Scale faster. Grow your portfolio. Gain practical expertise. No matter your goal, Disrupt can empower you. Save up to $330 today!
Bloom Security launches with $20M seed to secure the ai-native endpoint. FinanceWire Jul. 30, 2026, 07:10 AM New York, USA, July 30th, 2026, FinanceWire The enterprise endpoint is undergoing a fundamental shift as AI agents, browser extensions, MCP servers and code packages become part of everyday work. While companies have spent years building defenses around traditional endpoints, the software running on employee devices is becoming more dynamic, decentralized and difficult for security teams to track. Bloom Security is entering that market with a $20 million seed round led by Glilot Capital Partners and Ten Eleven Ventures (1011vc), with participation from Okta Ventures and Runtime Ventures. Axios first reported about the company's launch and funding. The Tel Aviv-based startup is emerging from stealth with a focus on securing what it describes as the AI-native endpoint, where traditional endpoint security controls may not provide enough visibility into the tools and software employees are using. The Endpoint Is Becoming More Complex For years, endpoint security largely centered on managed devices and the detection of malware, malicious processes and suspicious executables. The rise of AI-powered software is changing that environment, with employees increasingly using tools that can install extensions, connect to external services or interact with sensitive data. "In the AI era, the employee device is no longer just a managed endpoint," said Itay Keren, Co-Founder and CEO of Bloom Security. "Every endpoint is now running software no one reviewed, connecting to services no one provisioned." That creates a broader category of risks that may not fit neatly into conventional endpoint detection and response systems. A misconfigured AI agent, a plugin with excessive permissions, a screen recorder or a code library from an untrusted source can all introduce potential exposure, even when the software itself is not classified as malware. "As AI adoption accelerated, it became clear that existing endpoint controls were not designed for this new reality," Keren added. "Security teams need a way to understand, govern, and control modern tools without disrupting how employees work." Moving Beyond Traditional Endpoint Visibility Bloom Security's platform is designed to provide organizations with visibility into software running across their endpoints, including tools, browser extensions and code. It also examines how those components interact with data and systems, while analyzing supply-chain risks, configurations and permissions. The company's approach is based on the idea that endpoint risk cannot always be determined by looking at an individual application in isolation. The same software may present different levels of risk depending on who is using it, what data they can access and what other tools are active on the device. "The same tool can be completely acceptable on one endpoint and high-risk on another," said Ofir Balassiano, Co-Founder and Chief Product Officer at Bloom Security. "Risk depends on context: the user's role, their access to sensitive data, the other tools operating on that endpoint, their configurations, and how everything interacts. Bloom Security was designed to evaluate that context in real time." The platform also extends beyond visibility into enforcement and remediation. According to the company, security teams can block risky installations before they reach employee endpoints, enforce secure configurations and remediate risks without relying on manual approval workflows. A Team Built Around Enterprise Security Bloom Security's founding team has experience building security products at companies that include Palo Alto Networks, Dig Security and Demisto. Keren previously held engineering and sales engineering leadership roles at Palo Alto Networks, Dig Security and Demisto, while Balassiano led the Cortex Cloud Posture Security research group at Palo Alto Networks. Chief Technology Officer Itay Frishman previously built AISPM and DSPM solutions at Palo Alto Networks and Dig Security. The company currently has 30 employees, many of whom previously worked together at Dig Security. "While this is technically our first company as founders, our team has built and integrated category-defining products before," said Itay Frishman, Co-Founder and CTO. "We understand how enterprise security environments operate, and we built Bloom Security specifically for the reality of how endpoints are used today." Bloom Security said its platform is already deployed at dozens of large enterprises across the United States and Europe. The company's latest funding will support its effort to address a growing security challenge: giving organizations more visibility and control over the expanding software layer that now sits on employee endpoints as AI adoption accelerates. Contact. TVC Analyst [email protected] Sponsored Financial Content
MCP Server security: what 22,000 servers actually hide. The MCP ecosystem just passed 22,000 servers, but a 2026 audit found 25% have no authentication at all. Here's what enterprise teams need to check before the July 28 spec lands. BeagleAI teammate for Slack and Microsoft Teams An engineer on your platform team connects a new MCP server to the agent stack at 11am. It's listed in a popular registry, has 400 GitHub stars, and the setup takes about eight minutes. What the README doesn't mention: no auth, ever. Any client that knows the endpoint URL can call it. That scenario is not hypothetical. A 2026 security audit found that 25% of public MCP servers have no authentication at all, and 53% rely on long-lived static API keys or personal access tokens - credentials that, once leaked, provide indefinite access. Meanwhile, as of July 16, 2026, PulseMCP lists 22,311 servers, up from 14,000 in May. The ecosystem is growing faster than its security floor. The timing matters. July 28, 2026 is the date the current release candidate becomes the official MCP spec. It is the largest revision of the protocol since launch, delivering a stateless core, MCP Apps, long-running Tasks, and authorization that aligns more closely with OAuth and OpenID Connect deployments. That update will bring more teams into MCP and more agents into production - into an ecosystem where, right now, fewer than one in ten servers meets the auth standard the spec has required for months. What MCP server authentication actually requires. The spec is not ambiguous. MCP OAuth 2.1 authentication is the authorization framework mandated by the Model Context Protocol specification for all remote HTTP-based servers. As of the November 2025 spec revision, any MCP server accessible over the internet must implement OAuth 2.1 with PKCE - no exceptions. The flow itself is well-defined: the canonical flow covers a 401 challenge, metadata discovery, client registration, and an Authorization Code with PKCE exchange. Token validation requires checks for signature, expiry, issuer, and audience - bound to a canonical MCP server URI. What makes this hard in practice isn't the protocol. It's that the MCP specification mandates OAuth 2.1, and the 2025-11-25 spec update layered on requirements that traditional OAuth providers simply do not support: Dynamic Client Registration (DCR), Protected Resource Metadata (RFC 9728), Resource Indicators (RFC 8707), and more. Your existing identity provider - the one you've used for the past four years - may not cover these, even if it nominally supports OAuth 2.1. That gap is where most teams run into trouble. The public MCP server registry grew from roughly 1,200 entries in Q1 2025 to over 9,400 servers by mid-April 2026 - a 7x increase in fourteen months. Meanwhile, 38% of organizations say security concerns are actively blocking their MCP adoption, and 50% of MCP builders cite access control as their top challenge. The two numbers belong next to each other: access control is the top cited challenge, but the ecosystem kept growing anyway, which means most teams shipped without solving it. Why mixing server types in one stack is the actual risk. The headline numbers - 25% no auth, 53% static keys - are alarming in isolation. The compounding problem is what happens when you mix those servers in a single agent deployment. MCP servers can rely on OAuth, API keys, bearer tokens, headers, open access, or custom credential patterns, which creates inconsistent security and review requirements across tools. Mixing OAuth-protected production servers with API-key community servers in the same infrastructure introduces privilege escalation risks and audit trail gaps. The practical scenario: your agent has an OAuth-protected Jira MCP server and an open-access community server for web fetching wired together in the same session. A prompt-injection attack against the open server doesn't just get web content - it can instruct the agent to call the authenticated Jira server on its behalf. The weak link doesn't stay isolated; the agent's context window connects everything. 22,311 servers in the MCP ecosystem as of July 16, 2026 (PulseMCP) 25% have no authentication public server audit, 2026 8.5% implement OAuth 2.1 the spec's mandatory standard for remote servers 38% blocked by security concerns organizations surveyed on MCP adoption Manual vetting cannot scale to 10,000+ MCP servers; automated security frameworks with registry-based deployment pipelines are essential for enterprise adoption. Most platform teams are not there yet. The tooling is catching up - Auth0's "Auth for MCP" became generally available on May 6, 2026, integrating OAuth 2.1 and OpenID Connect into the MCP ecosystem. Okta has also released its own MCP server - a secure protocol abstraction layer that enables AI agents and LLMs to interact with Okta's scoped management APIs, with least-privilege access control enforced at each tool call. But tooling availability doesn't mean adoption. It means the excuse to skip auth is getting smaller. What the July 28 spec changes - and what it doesn't. The practical effect on a production deployment is immediate. A remote MCP server that previously needed sticky sessions, a shared session store, and deep packet inspection at the gateway can now run behind a plain round-robin load balancer, route traffic on an Mcp-Method header, and let clients cache tools/list responses for as long as the server's ttlMs permits. That is a real operational improvement - it lowers the infrastructure cost of running MCP at scale. What it does not fix is the auth distribution. This release tightens the contract between clients and servers so those connections are easier to operate, observe, and evolve. There are breaking changes, so implementers have work to do. More teams running MCP on cheaper, simpler infrastructure is good. More teams running MCP on cheaper, simpler infrastructure with no auth is not. The MCP protocol is going stateless on July 28, 2026, and the GitHub MCP Server already supports the latest spec ahead of the official release. The new stateless core means MCP deployments are now easy to scale. GitHub shipping early is a useful signal - this is what Tier 1 SDK adoption looks like. For enterprise teams, it's also a forcing function: the spec is real, the tooling is ready, and the auth gap is now the last friction point with a name on it. A practical three-step check before connecting any MCP server to a production agent: * Identify the auth type. OAuth 2.1 with PKCE is the bar. API key or open access means the server is not spec-compliant for remote deployment. * Check token scope. A server that asks for broad API access when it only needs read on one resource is a misconfiguration waiting to cause an incident. * Treat mixed stacks as a single trust boundary. If any server in your agent's session is weaker, the weakest one defines the blast radius. IAM, NHI, and agent governance teams now have to decide whether MCP access will be layered onto existing identity systems, handled through purpose-built middleware, or pushed into a full platform rebuild. That decision is no longer theoretical. The ecosystem is at 22,000 servers and growing by thousands per month. Whatever your team ships into that ecosystem this quarter, it will inherit the security posture of every other server it talks to. Connecting a new MCP server to your agent stack Without Beagle check the README, note it has an API key option, add it to the config, ship - auth fragmentation sits unexamined across five servers in the same session With Beagle check auth type against spec requirements, verify token scope, document it, flag open-access servers as isolated from authenticated ones before the PR merges MCP server security: common questions. What authentication does the MCP spec require? The MCP specification mandates OAuth 2.1 with PKCE for any remote HTTP-based server. This has been required since the November 2025 spec revision. Static API keys and open-access endpoints are non-compliant for remote deployments, though they remain common in practice - a 2026 audit put OAuth 2.1 adoption at roughly 8.5% of public servers. Can I use my existing identity provider for MCP OAuth? Possibly, but not automatically. The MCP spec requires Dynamic Client Registration, Protected Resource Metadata (RFC 9728), and Resource Indicators (RFC 8707) - capabilities that many mainstream OAuth providers do not support out of the box. Auth0's MCP auth product (GA May 2026) and WorkOS are purpose-built for this. Check your provider's docs against those specific RFCs before assuming it works. What does the July 28 MCP spec change for security? The July 28 spec is primarily an infrastructure update - stateless core, no sticky sessions, plain load balancer support. It also sharpens authorization alignment with OAuth and OpenID Connect. It does not retroactively fix existing servers with weak or no auth. Security posture stays the property of each individual server and the team that deployed it. Why is mixing MCP server auth types in one agent session risky? When an agent holds multiple MCP server connections in a single session, its context window links them. A prompt-injection attack against a weaker or open-access server can instruct the agent to call an authenticated server on its behalf. The blast radius of the weakest server in the session is not bounded to that server alone. How do I vet an MCP server before adding it to production? Three checks cover the most common failure modes: confirm the auth type (OAuth 2.1 or flag it), review the token scope it requests against what it actually needs, and document it in your team's server registry. Automated pipeline enforcement - blocking non-compliant servers before they reach production - is the only approach that scales past a few dozen servers.
Beyond the badge: The real-world impact of Okta Certification. How the Okta Certification program reduces security risks and accelerates careers 16 July 2026 Topics. Identity Insiders, Okta Secure Identity Commitment, Customers and Partners, IAM Table of contents. TL;DR: The 2026 Okta Certification Insights Survey gathered data from 2,505 global identity security professionals to evaluate the enterprise and career value of formal technical credentials. The findings demonstrate that certified employees directly reduce organizational security risk while gaining significant advantages in professional credibility, operational confidence, and salary growth. Based on this feedback, Okta is actively expanding its performance-based testing resources and launching a new Subject Matter Expert (SME) recognition program in Q3 2026. What is the Okta Certification Insights Survey? The Okta Certification program empowers identity security professionals to grow their technical expertise and professional brand in the cybersecurity industry. To ensure Okta Inc. continually deliver maximum value, Okta Inc. launched a comprehensive research survey to gather direct feedback from global practitioners regarding their primary motivators, career impacts, and operational experiences with earning an Okta certification. Survey methodology and demographics. Okta Inc. distributed the 15-question survey over an eight-week window across the Okta and Auth0 customer communities, newsletters, in-product notifications, and social channels. The initiative successfully captured 2,505 unique responses from both certified and non-certified identity and security professionals worldwide. The survey demographics represent a highly technical and globally distributed cohort of identity specialists: * Practitioner base: 61% of respondents are technical practitioners directly responsible for day-to-day configuration and deployment work. * Certification status: 44% currently hold at least one active Okta certification. * Broader security expertise: 69% of survey respondents hold other non-Okta security certifications. * Geographic distribution: The respondent base is evenly balanced globally, with 43% located in the Americas and 43% located in the Asia-Pacific region. Key survey findings: Quantifying the value of identity expertise. The data reveals a strong positive sentiment toward the strategic value of Okta Certification across the board. Respondents report clear, measurable outcomes across risk management, career trajectory, and operational execution. To provide a transparent look at the return on investment of Okta Certification and identity security training overall, here are the key metrics and standout statistics from the survey: | Value impact category | Key survey metric and professional value | | Security risk reduction | 79% of all respondents agreed that having an Okta-certified professional on staff directly reduces security risk; 48% state risk is "significantly reduced." | | Professional credibility | 89% of certified specialists cite increased professional credibility as a top career benefit resulting from their credential. | | Operational confidence | 80% of certified practitioners report that earning their badge directly improved their technical confidence when solving complex identity challenges. | | Financial advancement | 57% of Okta-certified respondents received a salary increase after passing their certification exams. | What motivates security professionals to get certified? While financial advancement and higher salary brackets remain a clear benefit of the program, the data indicate that the internal drive for continuous learning is significantly stronger. When ranking their primary reasons for pursuing Okta Certification, 40% of certified respondents chose personal skill development as their top driver. This technical growth motivation placed ahead of both career advancement (24%) and direct salary increases (20%). However, external validation still plays a major role in long-term career satisfaction. When non-certified professionals were asked what single factor would most heavily motivate them to complete an exam, 41% of respondents cited earning "more industry recognition" as their primary driver. This highlights the growing importance of verifiable credentials in a highly competitive global technology market. Addressing community feedback and obstacles. Through open-ended survey responses, its customers shared constructive insights regarding where its certification program can improve. The feedback highlighted three major themes: * Clearer preparation paths: Candidates are seeking clearer guidance on how to prepare for Okta Certification exams * Realistic practice environments: Candidates highly value practical, hands-on testing and strongly desire preparation tools that closely mirror the testing experience * Regional cost barriers: The price of Okta Certification exams and associated learning materials is a significant hurdle, particularly for practitioners in developing regions Looking ahead: How Okta is evolving the certification program. The honest feedback Okta Inc. received is already informing its education strategy and driving action. Based on the 2026 survey data, its team has already implemented several immediate changes and is currently evaluating additional strategic initiatives to better serve the global identity security community. Launching the Subject Matter Expert (SME) program. To elevate industry recognition for its certified community, Okta Inc. is expanding its engagement initiatives beyond the Okta Certification Circle. In Q3 2026, Okta will formally launch the Subject Matter Expert (SME) program, enabling Okta-certified experts to collaborate directly on new content development and earn industry recognition as Okta SMEs and thought leaders. Streamlining site navigation and guidance. The new, improved experience on the Okta Certification website offers a more intuitive user experience. The updated navigation guides customers based on their goals - whether they are exploring Okta Certification for the first time, looking for specific preparation materials, or ready to schedule their exam. Deploying performance-based practice tools. The Okta Certification team remains fully committed to delivering performance-focused exams that prove you can successfully deliver the work of an Okta Administrator, Developer, Consultant, or Technical Architect on the job, daily. Okta Inc. recently launched the Okta Certified Professional Performance Premier Practice Exam, and the Administrator Performance Premier Practice Exam will be available later this year. Systematically lowering financial hurdles. Okta Inc. understand that economic shifts, regional wage disparities, and job displacement create clear financial barriers to entry for some. To counter this, Okta Certification is exploring targeted campaigns to help Okta practitioners achieve their Professional certifications and help Okta Administrators achieve their Administrator-certified status. Okta Inc. will also continue to support the What's Next by Okta Learning program. Thank you to everyone who participated in the survey. Okta Inc. is committed to using these insights to refine its programs and ensure Okta Certification remains the premier credential for identity security professionals worldwide. For the latest on campaigns and promotions related to Okta Certification, stay tuned for updates on certification.okta.com, the Okta Community, and the Okta Community LinkedInopens in a new tab. These materials are intended for general informational purposes only and are not intended to be legal, privacy, security, compliance, or business advice. (C) 2026 Okta, Inc. and its affiliates.