jobsearch v0.0.1

← okta / Principal Product Manager, IAM Security & Agentic Identity

candidate_questions / art_p9kQw9wj8xg

role
okta / Principal Product Manager, IAM Security & Agentic Identity
model
anthropic/claude-sonnet-4.6
created
2026-07-20T18:10

Interviewer

Chris Norris is the Vice President of Identity & Access Management at Okta, where he leads the 'Okta on Okta' team — the exact organization this Principal PM role reports into. He joined Okta in August 2024, bringing roughly two years of tenure, after serving as VP of IAM at McKesson for two years where he led a major ITGC/SOX IAM transformation, deployed passwordless strategies, and built IDP resiliency architecture. His 25+ year career spans infrastructure, enterprise security, and IAM across Macy's, Coca-Cola, Crawford & Company, and Dell EMC. As the direct hiring manager, Chris will likely probe strategic judgment, ability to influence without authority, technical depth in IAM/session security, and the candidate's capacity to operate as Customer Zero. Shared context is limited but notable: Felix's Kaiser Permanente SOA PM work involved enterprise platform infrastructure and Splunk logging-as-a-service at scale, and his Intuit work on developer platforms and SDK infrastructure parallels Chris's emphasis on self-service, automation, and reducing engineer friction.

Questions to ask them (20)

categoryquestionwhy
interviewer_experience You joined Okta in August 2024 to lead the 'Okta on Okta' team — what was the state of that function when you arrived, and what's been the most surprising thing about being both the customer and the product organization simultaneously? Opens a genuine conversation about the team's maturity and Chris's own journey; surfaces real organizational context and potential friction points the candidate will inherit.
interviewer_experience At McKesson you built a fully self-service, automated rapid onboarding capability that removed the need for identity engineers in the loop — how much of that philosophy is shaping how you're structuring the Okta on Okta team's operating model today? Demonstrates deep profile research, connects his prior innovation directly to the current role's scope, and reveals how much autonomy and self-service thinking is baked into the team's DNA.
interviewer_experience You have a patent from your Dell EMC days on the CLARiiON Mirroview Persistent Fracture Log — that's a pretty rare thing for an infrastructure leader. How has that inventor mindset carried forward into how you think about building novel identity capabilities at Okta? Builds genuine rapport by acknowledging a distinctive career detail; reveals how Chris values technical depth and first-principles thinking, which matters for a Principal PM who will need to earn his trust.
role_team_dynamics For this Principal PM role, what does success look like at 30, 60, and 90 days — and is the expectation to first deeply understand the internal deployment landscape before influencing the external roadmap, or are those happening in parallel from day one? Critical for understanding the ramp expectations and whether the role is more 'learn then lead' or 'lead while learning,' which affects how the candidate should frame their onboarding approach.
role_team_dynamics The JD describes this role as a bridge between internal deployment findings and the core Okta and Auth0 product teams — how formalized is that feedback loop today, and where does the most friction tend to occur when internal insights need to change an external roadmap priority? Surfaces the real organizational dynamics and political landscape the candidate will navigate; shows strategic awareness of the influence-without-authority challenge.
role_team_dynamics How is the Okta on Okta IAM team structured today — are there dedicated engineers embedded with the PM, or is this more of a product strategy function that works through the core engineering org? Essential for understanding whether the candidate will have direct execution leverage or must operate purely through influence, which dramatically changes the day-to-day role.
role_team_dynamics The portfolio spans DBSSO, DBSC, ITP, ISPM, O4AA, and A4AA — that's a wide surface area for one Principal PM. Are these meant to be owned deeply in parallel, or is there a sequencing logic where some areas are more active right now than others? Reveals prioritization reality versus the aspirational JD scope; helps the candidate assess whether this is a focused role or a stretched one.
technical_environment On the agentic identity side — when you think about O4AA and A4AA, is the team currently working from a clean-slate architecture for agent authentication patterns, or are you adapting existing OAuth 2.0 and OIDC flows and finding the seams where they break for non-human workloads? Tests technical alignment and reveals how greenfield versus constrained the agentic identity work actually is; shows the candidate has real fluency in the protocol-level challenges.
technical_environment For Device Bound Session Credentials — Okta DBSSO relies on platform TPM/Secure Enclave binding while Chrome DBSC is a browser-layer credential; how mature is the internal deployment of each today, and are there endpoint management or MDM constraints inside Okta that are creating interesting edge cases? Demonstrates deep technical preparation on the specific portfolio area; surfaces real deployment complexity the candidate will own from day one.
technical_environment How does the team currently instrument and measure the security coverage gap — for example, tracking what percentage of sessions are hardware-bound versus still vulnerable to cookie exfiltration — and is that telemetry something this PM role would help define, or does it already exist? Connects to the KPI/metrics responsibility in the JD; reveals whether the measurement infrastructure is mature or needs to be built, which is a significant scope difference.
culture_working_style You've led large IAM organizations at McKesson and now at Okta — when a Principal PM on your team has a strong conviction that a feature isn't ready for EA but the external product team is pushing to ship, how do you expect that tension to be navigated? Reveals Chris's actual leadership style on conflict and how much air cover the candidate will have when playing the Customer Zero gatekeeper role; critical for understanding the political dynamics.
culture_working_style At McKesson you implemented 'Focus Fridays' to give your team dedicated time for learning — is there a similar philosophy on the Okta on Okta team around protecting time for deep technical exploration, given how fast the agentic identity space is moving? Shows the candidate did their homework on Chris's leadership values; surfaces whether the team culture supports the continuous learning this role demands.
culture_working_style How would you describe the working rhythm between this role and the VP level — are you looking for someone who brings you a weekly status update, or someone who operates largely autonomously and escalates only when they need a blocker cleared? Directly calibrates the autonomy expectation and Chris's management style, which is essential for a Principal-level candidate evaluating fit.
growth_development You've grown from Principal Storage Engineer to VP of IAM over 25 years — for someone coming in at the Principal PM level, what's the realistic growth trajectory on this team, and are there paths toward broader IAM strategy or product leadership over time? Shows long-term thinking and ambition without being presumptuous; leverages Chris's own career arc to make the question feel grounded and personal.
growth_development Given that agentic identity is genuinely nascent — there's no established playbook — how does the team approach building expertise in areas where even the vendor community is still figuring things out? Are there research partnerships, standards body engagements, or other mechanisms? Reveals the team's intellectual infrastructure for staying at the frontier; also signals the candidate's awareness that this role requires continuous self-education.
strategy_vision When you think about the 'Okta on Okta' function's north star — is the ultimate goal to make Okta the world's most credible reference customer for its own products, or is there a broader ambition to turn internal learnings into a published framework or methodology that the industry can adopt? Opens a strategic conversation about the team's external impact ambition; reveals whether Chris is thinking about this as an internal ops function or a thought leadership platform.
strategy_vision With AiTM attacks and session hijacking accelerating, and agentic workloads exploding simultaneously — how does the team prioritize between hardening existing human identity security versus building net-new infrastructure for non-human agents? Is there a framework, or is it driven by threat intelligence signals? Tests strategic judgment alignment; reveals whether the team has a principled prioritization model or is reactive to the loudest threat signal.
strategy_vision The Model Context Protocol is very early — it's not even a finalized standard yet. How is Okta thinking about making product bets on MCP for agent-to-data security when the underlying protocol could still shift significantly? Shows sophisticated awareness of the standards landscape; surfaces how the team manages technology risk when betting on emerging protocols, which is directly relevant to the candidate's execution responsibility.
shared_context At Kaiser Permanente I spent six years building SOA platform infrastructure and Splunk-based logging services for enterprise security teams — and one of the hardest parts was getting application teams to actually adopt centralized identity services rather than rolling their own. At McKesson you built a self-service onboarding capability specifically to solve that adoption problem. Is that same adoption friction something you're still seeing internally at Okta, and is part of this PM role about solving the internal change management challenge, not just the technical one? Builds genuine peer-level rapport by connecting the candidate's real experience to Chris's most cited McKesson achievement; reframes the candidate as someone who has lived the problem, not just read about it.
shared_context My work at Intuit involved scaling developer platform infrastructure to 675M engagements and building self-service tooling that reduced onboarding from weeks to minutes — which feels adjacent to what you described building at McKesson. In this role, is there an opportunity to apply that kind of developer experience thinking to how internal teams at Okta consume identity services, or is the scope more narrowly focused on security posture and threat response? Connects the candidate's strongest quantitative achievement to Chris's known priorities; tests whether the role has a developer experience dimension or is purely security-focused.

Conversation starters

⚠ Handle carefully