Staff Site Reliability Engineer - Network Infrastructure
Okta
- Location
- Bengaluru, India
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 52 approvals (FY2023)
- Posted
- 2h ago
Skills
About this role
Secure Every Identity, from AI to Human
Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence.
This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk.
Workforce Identity Cloud
Okta Workforce Identity Cloud (WIC) provides easy, secure access for your workforce so you can focus on other strategic priorities, such as reducing costs and doing more for your customers.
If you like to be challenged and have a passion for solving large-scale automation, global traffic routing, and resilient cloud infrastructure problems, we would love to hear from you. The ideal candidate is someone who exemplifies the ethics of, “If you have to do something more than once, automate it” and who can rapidly self-educate on new network topologies, multi-cloud ecosystems, and agentic engineering models.
Position Overview
The Staff Software Engineer - Infrastructure will play a foundational role in architecting, evolving, and securing Okta's global core network fabric and multi-cloud platform layers. This position focuses on building highly resilient, edge management in AWS and GCP cloud, executing enterprise-wide cloud migrations (AWS to GCP), enforcing absolute Zero-Trust primitives (mTLS / TLS 1.3), and integrating cutting-edge AI automation layers (Agentic SRE) into our day-to-day operations.
As a Staff Engineer on this team, you will act as a key technical anchor in India, working closely with global counterparts to maintain Okta's high-availability SLAs while protecting the platform against active global DDoS attacks.
Key Responsibilities
• Global Ingress & Routerless Evolution (CFSaaS): Design and engineer Next-Gen traffic entryways utilizing Cloudflare for SaaS. Drive the migration toward modern, decentralized edge infrastructure—eliminating legacy hardware routing bottlenecks, shifting compute to Edge Workers, and lowering latency for millions of global requests.
• Multi-Cloud & Core Networking: Build, scale, and maintain Okta's multi-cloud backbone across AWS and GCP. Actively architect clean hub-and-spoke models utilizing AWS Transit Gateway (TGW), AWS Global Accelerator (AGA), and GCP Network Connectivity Center to unify converged enterprise product networks (Harmony).
• Zero-Trust Cryptographic Enforcement: Implement and manage strict cryptographic security controls at scale, driving the enforcement of TLS 1.3 externally and deep mTLS (Mutual TLS) mesh architectures internally across microservice proxies (Envoy/Nginx).
• Agentic SRE & AI Automation: Innovate on platform operations by designing deterministic playbooks and automated telemetry ingestion pipelines using AI models (LLMs/Agents). Move the team from reactive debugging to autonomous anomaly detection and self-healing systems.
• DDoS Firefight Ownership & Mitigation: Provide first-line technical triage during high-volume volumetric and application-layer (L7) DDoS attacks during India Data Center (IDC) hours. Analyze real-time proxy/VPC flow logs and implement rapid WAF mitigations to preserve cell isolation and tenant availability.
• Platform Automation (GitOps): Champion Infrastructure-as-Code (IaC) principles. Continuously identify and eliminate network configuration drifts across heterogeneous cloud landing zones by maintaining