O

Okta

Cloud-based identity and access management

Engineering Manager - Okta Access Gateway

Full-TimeUpdated on 10/4/2026
CA$168k - CA$231k/yr+ Equity + Bonus + RRSP match
Senior, Expert
Toronto, ON, Canada
In Person

About the job

Requirements
  • At least 2 years of formal software engineering team management experience, or at least 4 years as a hands-on Lead or Staff Engineer leading complex, multi-engineer projects to delivery.
  • At least 8 years of total software engineering experience designing and operating enterprise-scale distributed systems or infrastructure products.
  • Strong background in server-side technologies such as Java with Spring Boot, Go, or C/C++, and distributed systems concepts including concurrency, caching, high throughput, and asynchronous processing.
  • Solid understanding of network architecture, TLS/SSL, reverse proxies and gateways, HTTP headers, DNS, and cloud environments such as AWS, Azure, or GCP.
  • A proven track record of managing agile delivery, CI/CD automation pipelines, and cross-functional dependencies across distributed teams.
  • Ability to articulate complex technical trade-offs to technical and executive stakeholders.
Responsibilities
  • Lead, mentor, and empower an engineering team while fostering an inclusive, high-performance, and psychologically safe engineering culture.
  • Drive engineers’ career progression through goal setting, regular one-on-ones, and continuous feedback.
  • Attract, interview, and hire engineering talent to grow Okta’s engineering presence in Toronto.
  • Own end-to-end execution and delivery of product roadmap initiatives, balancing feature velocity, technical debt, and software quality.
  • Establish predictable Scrum or Kanban delivery cadences, including scope estimation, milestone tracking, and stakeholder communication.
  • Promote operational rigor, security standards, high availability, and performance benchmarking for customer-deployed gateway appliances.
  • Partner with Product Management, Technical Architects, and UX designers to define technical roadmaps and product requirements.
  • Participate in architectural reviews, system design proposals, and threat modeling without micromanaging day-to-day code implementation.
  • Guide modernization of gateway capabilities, containerization, deployment automation, and integration with the Okta Identity Cloud.
Desired Qualifications
  • Knowledge of Identity and Access Management and authentication protocols, including SAML 2.0, OAuth 2.0/OIDC, Kerberos/IWA, header-based authentication, and FIDO2/WebAuthn.
  • Experience building or operating reverse proxies such as NGINX, Envoy, or HAProxy; API gateways; or Linux-based virtual appliances using OVA, AMI, VHD, or containers.
  • Experience with Zero Trust network access or enterprise hybrid integrations such as Oracle, SAP, IBM, or Microsoft.
  • Experience building or scaling engineering teams in a hybrid or distributed model.

About the company

Okta provides a cloud-based platform that manages and secures digital identities for businesses and government agencies. The software works by centralizing user authentication through tools like single sign-on and multi-factor authentication, allowing employees to access all their work applications with one secure login. Unlike traditional hardware-based security, Okta operates entirely in the cloud, making it easier to manage remote workforces and automate the process of granting or removing access as employees join or leave a company. The company's goal is to ensure that the right individuals have secure access to the right digital resources at the right time.

Company Size

5,001-10,000

Company Stage

IPO

Headquarters

San Francisco, California

Founded

2009

Get referred to Okta

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 fiscal 2027 revenue reached $805 million, up 11%, with cRPO up 14%.
  • Over 600 customers now spend above $1 million ACV, up more than 20%.
  • Okta for AI Agents became generally available, lifting deal values 50% to 60%.

What critics are saying

  • Microsoft Entra undercuts Okta in Microsoft-first enterprises, compressing pricing and renewal leverage.
  • SPIFFE-native rivals like Aembit and Teleport weaken Okta's agent-identity narrative by Q4 2026.
  • The 2023 support-breach history keeps buyers cautious; another identity incident would damage trust immediately.

What makes Okta unique

  • Okta controls workforce, customer, and agent identities across 5,000 integrations, uniquely broad.
  • Blueprint Alliance with AWS, CrowdStrike, Google Cloud, and Salesforce anchors its agent standard.
  • Agent SSO and Cross App Access turn short-lived tokens into default enterprise controls.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Retirement Plan

401(k) Company Match

Paid Vacation

Paid Sick Leave

Paid Holidays

Flexible Work Hours

Remote Work Options

Parental Leave

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↓ -10%

2 year growth

↑ 0%
Forkast
Oct 4th, 2026
Okta XAA ecosystem scales to 25+ partners as AI gateways become the identity enforcement layer.

Okta XAA ecosystem scales to 25+ partners as AI gateways become the identity enforcement layer. Okta's Cross App Access protocol is scaling through 25+ early adopters, and the AI gateway is becoming the identity checkpoint where agent connections get evaluated against enterprise policy before reaching any tool. Blair Hayes Forkast mind | 2026-10-03 10:26 PM PDT TrueFoundry, an AI gateway vendor, announced on October 1 that it had integrated Okta's Cross App Access (XAA) protocol into its gateway. That makes the gateway itself the identity checkpoint: the place where an agent presents credentials before any downstream tool or MCP server sees the request. It is the latest signal that XAA, Okta's open protocol for governing agent-to-app connections, is scaling not just through partner count but through the infrastructure layer where it actually matters. Okta's XAA ecosystem now includes over 25 early adopters, and the company's XAA developer playground opened this month. The identity gap XAA was built to close is straightforward. Most agents running in production authenticate with static API keys. Those keys do not expire, they are rarely scoped to a particular task, and they produce almost no audit trail. IT teams end up with limited visibility into what an agent actually accessed and when. Okta research cited by TrueFoundry puts numbers on the consequence: 88 percent of organizations report confirmed or suspected AI agent security incidents, and 92 percent of those that experienced an AI-related breach lacked adequate access controls. XAA replaces the static key with a short-lived token scoped to the specific task an agent is carrying out. The token is issued in real time against the user's active Okta identity, it can be revoked at any point, and it is logged so access remains auditable after the fact. Agent connections are evaluated against the organization's central identity policy in the same way a human user's access would be. Built on the ID-JAG standard (Identity Assertion Authorization Grant), XAA is an open OAuth extension that has been incorporated into MCP as its official authorization extension. It is vendor-neutral by design. Agent SSO, which launched in August 2026, brought XAA into Okta's workforce plans at no additional cost for over 20,000 customers, treating agents as first-class identities in the same directory as human users. XAA OIN Submission reached GA in the 2026.09.0 monthly release; the protocol itself is in Early Access with GA targeted for FY27.

Forrester
Oct 1st, 2026
Oktane 2026 recap: Okta announces A unified IAM control plane, with agent governance and identity details remaining unclear.

Oktane 2026 recap: Okta announces A unified IAM control plane, with agent governance and identity details remaining unclear. Oct 1 2026 At last week's Oktane conference in Las Vegas, Okta unveiled its ambitious vision for transforming the Okta platform into a control plane for AI agents and extending deeper into AI security. The strategy was reflected throughout the event's keynotes and product announcements, which focused heavily on agent identity, runtime authorization, agent-to-agent interactions, and ecosystem collaboration. In his opening keynote, Okta CEO Todd McKinnon emphasized that open standards and collaboration are necessary to scale AI, acknowledging that no single vendor can govern and secure the agent ecosystem alone. The announcement of the Blueprint Alliance, a coalition of vendors with expertise in a variety of areas, underscored this point. Blueprint Alliance is a multivendor, open identity and access management (IAM) for AI agents' architecture that has agent governance, identity management, authorization, and interoperability components. It intends to coordinate with other vendors on how to build interoperable identity infrastructures. There is also an opportunity for Okta/Auth0 to extend the Blueprint Alliance to customer IAM (CIAM), e-commerce, and loyalty programs in the future. It also highlights that the success of Okta's strategy ultimately depends on whether the security, and especially the IAM/identity security industry, converges around common standards for agent identity, trust propagation, authorization, and accountability. Okta is productizing its IAM-for-agent strategies and planning to unify all (human, nonhuman identity [NDI], and agentic) identity management into a single control plane. Okta sees agent authentication and session management being different from human authentication and session management. Dynamic AI agent authorization based on intent and context were center stage in announcements. Highlights: In collaboration with Anthropic and other vendors, Okta has been actively developing the Cross App Access extension and enterprise-managed access specifications, which are now part of the MCP authorization extensions (issued by Anthropic, based on OAuth 2.1 but not yet part of standards issued by a standards body). Keenly believing in open standards and protocols, Okta has been promoting industry collaboration and coopetition. At Oktane, Okta was also able to bring in panelists from reputable North American financial institutions to describe their IAM for AI agents journey. Challenges: SPIFFE has started to become the de facto standards for nonhuman identities. Okta still does not have a full SPIFFE agent identity implementation - such as Aembit or Teleport, for example - kand still have not disclosed any plans for any universal know-your-agent (KYA) standards or frameworks (Okta has support for SPIFFE-based authentication on the roadmap for Q4 2026). Given that the Auth0 (CIAM) and Okta (workforce IAM) stacks have different session management and AI agent management capabilities, not having a unified platform increases the vendor's product development costs. It also increases enterprises' costs of building a unified workforce and CIAM infrastructure with equal-strength and interoperable human and nonhuman identities. The vendor's strategy for using the existing fine-grained authorization solution for AI agents seems unclear. Lastly, Okta's pricing for IAM for AI agents is still unresolved; instead of monthly active user-based pricing (common with human IAM), it likely will be transaction-based. Opportunities: Okta may play an important role in developing foundations for intent discovery and authorization decision-making - areas where there are no mature standards today. Building vendor-agnostic reference architectures for human, nonhuman, and agentic AI identity management for clients is likely, and the Blueprint Alliance is a good first step in this direction. Okta is also venturing into the CIEM space with AWS admin identity analysis, complete with access request management. Verifying human-to-agent provider (using OAuth 2.0) and agent provider + agent-to-service provider trust will help overall agent adoption. Forrester clients interested in discussing IAM for AI agents: Please book an inquiry or guidance session with Forrester Research, Inc.. See andras cser at: Security & Risk Forum November 9-10, 2026, Washington DC Missed the journey mapping webinar? Watch the replay. A model does not have to be smarter than Forrester Research, Inc. to be a problem. It needs a goal that it is certain about, the resources to keep pursuing it, and no one watching. Two of those three exist already. Forrester Research, Inc. took one doom scenario apart to find out how worried enterprises should be. Don't let AI doomsday headlines dictate your strategy. Stay grounded in what's real, manage the risks you can control, and focus on the investments most likely to create new value.

Phemex
Oct 1st, 2026
Blue Horseshoe model highlights Amphenol and Okta following Score update.

Blue Horseshoe model highlights Amphenol and Okta following Score update. Phemex News 2026/10/01 04:38 The Blue Horseshoe model has identified Amphenol Corp ($APH) and Okta ($OKTA) as top picks based on 30-day institutional buying activity. Okta retains the number one position for the second consecutive week, while Amphenol has emerged as a new favorite under the updated scoring methodology. The BH Score was recently adjusted to prioritize the number of funds buying and the impact of purchases, aiming to surface emerging opportunities and rebounding stocks rather than mega-cap tech names or micro-caps. Users can now access these metrics, including 5-day and 1-day buying data, via the BI ETF platform. Disclaimer: The content provided on Phemex News is for informational purposes only. Phemex Limited do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. Phemex Limited strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.

Yahoo Finance
Sep 28th, 2026
Citizens lifts Okta target to $225, sees AI security role driving 'durable growth re-acceleration

Citizens has raised its price target for Okta to $225 from $180, maintaining an "Outperform" rating, citing the company's strategic position in AI identity security as a driver for durable growth re-acceleration. The new target implies about 15% upside from the stock's last close of $195.19. Okta's second-quarter revenue rose 11% year-over-year, whilst current remaining performance obligations increased 14%. The company raised its full-year revenue outlook to between $3.216 billion and $3.226 billion, representing 10% to 11% growth. Roth Capital noted that Okta for AI Agents is producing a 50%-60% uplift in deal values, though the opportunity remains early. The product helps businesses discover agents, control access, and monitor behaviour as AI agents increasingly require their own identities and controls. OKTA stock has rallied more than 133% this year.

Mind
Sep 28th, 2026
MIND Raises $30M to Advance AI-Powered Data Loss Prevention

MIND today announced $30M Series A funding led by Paladin Capital Group and Crosspoint Capital Partners with participation from Okta Ventures and YL Ventures.