Oak's $60M Seed Defines a Category. The Senior US Pool Is 14.
Oak raised $60M for AI-native identity on July 15, 2026. The senior US pool who has shipped agent-permission systems is 14. Here is where to find them.
If you are about to get a req that says "AI agent identity engineer, senior, 5+ years," you have a problem. The engineers who have actually shipped that thing you can count on two hands.
Oak came out of stealth on July 15, 2026 with a $60M seed round to build "AI-native identity management," a control plane that governs permissions for humans, machines, and AI agents alike. Accel, Greylock, and CRV co-led, with Hetz Ventures and AlphaDrive Ventures participating. The check is large. The category is real. The pool is not.
Why Oak's round makes this a sourcing crisis, not just a launch
Oak's $60M seed is one of the largest ever for an Israeli cyber firm, and it lands in a category where the total senior US practitioner pool is 14 people. That is the mechanical reason every competitor in agentic IAM is about to feel the squeeze.
Oak was founded by Shai Morag (CEO, who sold Ermetic to Tenable for $265M in 2023 and Secdo to Palo Alto Networks in 2018) and Tal Marom (CPO, ex-Tenable and Salesforce). The company already has roughly 50 staff, paying enterprise customers, and a product that is generally available. Accel gave Morag an informal standing offer to back whatever he built next, which tells you how much of this deal is founder access to an alumni graph rather than a cold market.
That alumni graph matters because the practitioner supply chain for AI agent identity is tiny and concentrated. Oak has said it will use the capital to expand its team across security and AI. So will Token Security. So will Oleria. So will the CyberArk unit inside Palo Alto Networks after that acquisition closes. They will all be hiring from the same 14 people.
What "AI-native identity" actually means, and who has built it
AI-native identity is an IAM control plane that treats AI agents as first-class principals, mapping each agent's tool calls to real-time, revocable permissions instead of static service-account credentials. Almost no one has shipped it in production.
The reason the pool is small is that the job requires two rare skill sets at once:
- Legacy IAM plumbing. SCIM, OAuth, SAML, OIDC, session brokering, JIT provisioning, policy engines.
- Agent scaffolding. Tool use, MCP servers, agent frameworks, prompt-injection defense, and how an autonomous loop actually chews through credentials.
Legacy IAM engineers understand the first bucket. LLM engineers understand the second. The intersection is where Oak, Token Security, and Oleria are fishing, and Accel's public thesis on the deal is that when it comes to identity management, experience still counts. It counts because there is no shortcut. Researchers have already tricked agents into leaking private code and even running a ransomware attack. You have either read those incident reports and thought "I could stop this," or you are guessing.
That is why Oak's differentiator, mapping access to actual app usage and revoking unnecessary permissions in real time, is not a product problem so much as a hiring problem. The engineers who can build that behavior are the same ones who have spent years watching outdated credentials and poor IAM turn into breaches.
The real numbers behind the category
Across Refolk's index, only 222 US professionals surface for the free-text signal "AI agent identity" in any function, and that number collapses to 14 at Senior, Manager, or Director level. In Israel, the same signal returns 8 people total, five of them in Tel Aviv.
Here is the full picture:
| Segment | Count | Note |
|---|---|---|
| US professionals matching "AI agent identity" (any function) | 222 | Refolk's index, free-text keyword |
| US, same signal, Senior / Manager / Director | 14 | 6.3% of the pool is senior-plus |
| US, "non-human identity" or "machine identity" headline signal | 5 | The "shipped-it" tip of the pyramid |
| Israel, "AI agent identity" (any function) | 8 | 5 in Tel Aviv |
| US-to-Israel ratio | 27.75x | Derived; Oak hires on both sides |
| Senior US practitioners per $M raised by Oak | 0.23 | Roughly $4.3M of seed capital per available senior US head |
A few things stand out. First, the 222 headline number is misleading because most of those profiles are sales engineers, solutions architects, and PMs who can talk about agent identity but have never shipped a policy engine. Second, the 5-person "shipped-it" slice includes one profile at Palo Alto Networks with the literal title "Machine Identity / AI Agent Security Specialist." That title barely exists as a formal role today. It will exist everywhere in 18 months.
Third, and most useful for anyone building a sourcing list right now, the US pool is concentrated in a handful of employers you can name and work top-down:
- SailPoint (2)
- Teleport (2)
- Beyond Identity
- CyberArk
- Duo Security
- Oleria Security
Combined with Ermetic, Tenable, and Palo Alto Networks alumni, that is essentially the whole graph. If you cannot get a warm intro into one of those companies, you are sourcing on hard mode.
Oak did not raise $60M because identity is hot. It raised $60M because the founders already know all 14 people you want.
DC beats SF for this niche, and here is why
Washington DC-Baltimore is the #1 US region in Refolk's index for the AI agent identity signal, ahead of any Bay Area metro. If you are sourcing this pool from a San Francisco desk you are working the wrong ZIP codes.
The mechanism is federal Zero Trust and ICAM (Identity, Credential, and Access Management). Federal programs have been forcing agencies to think about non-human identity, machine-to-machine authentication, and short-lived credentials for years, well before "AI agent" was a term of art. The engineers who came out of those programs are the only sizable cohort in the US who have argued about non-human identity at scale in production.
Geographic breakdown of the senior US signal, per Refolk's index:
- Washington DC-Baltimore: 3
- Houston: 2
- Denver: 2
- NYC: 1
That is the exact gap Refolk closes. You describe the person in plain English ("senior IAM engineer, DC metro, federal ICAM background, has shipped agent-permission logic") and get a ranked shortlist instead of a title-filter search that returns 60,000 "identity" hits with no signal.
The four-company alumni graph you should be mining
The practitioner graph for agentic IAM is a four-company graph: Ermetic, Tenable, CyberArk, and Palo Alto Networks. Add SailPoint, Okta/Auth0, Teleport, and Beyond Identity as the second ring, and you have covered almost everyone worth calling.
For sourcing AI security engineers in this niche, skip the generic "IAM engineer" search entirely. It returns thousands of profiles who have configured Okta but never thought about an agent making a tool call. Instead:
- Mine the Ermetic alumni list. Morag's previous exit produced a concentrated cohort of cloud-identity engineers who then dispersed to Tenable and startups. Many of the best hires Oak will make come from this list, and competitors need it too.
- Watch the PANW / CyberArk deal. Palo Alto Networks agreed to buy CyberArk. Acquisitions of this size dislodge senior engineers between announcement and close. That window is when the pool briefly becomes liquid.
- Track Token Security, Silverfort, Frontegg, and Oleria. These are the direct category-adjacent employers where the Israeli signal concentrates, and every departure from them is a signal.
- Read the Identity Underground. This practitioner community showed up repeatedly in the senior-level index cut. It is a real venue for reaching this pool outside LinkedIn.
- Work federal ICAM contractor rosters. The FedRAMP-adjacent shops have engineers who understand machine identity at a depth commercial teams often do not.
Agentic IAM hiring rewards the recruiter who works a named list of 40 people rather than a keyword search that returns 4,000. Refolk is built for exactly that motion: describe the shape of the person, including the alumni signal and the technical depth, and get the shortlist without wading through job-title noise.
What the "14" number means for competitors chasing Oak
If you are building against Oak in the AI agent identity space, your realistic senior US hiring pool is 14 people, minus whoever Oak has already signed, minus whoever is locked at Token Security or Oleria. That is single digits per major metro, and it is why founder-led sourcing beats posted roles for at least the next 12 months.
A few tactical implications:
- Do not post the role first. Post it after you have privately worked the alumni graph. A public JD in this category invites unqualified applicants and tips your competitors.
- Hire adjacent, train the LLM half. The scarcer skill is IAM depth. A senior IAM engineer from SailPoint or CyberArk can learn MCP and agent scaffolds in a quarter. An LLM engineer cannot learn SCIM edge cases in a quarter.
- Open a Tel Aviv node. Oak is hiring on both sides for a reason. Israel's 8-person signal is small in absolute terms but disproportionately senior, and the founder network there is dense.
- Budget for comp dislocation. With roughly $4.3M of Oak seed capital per available senior US head, comp for this niche is about to move. If your last offer to a staff IAM engineer was benchmarked to 2025 numbers, redo the math.
The reason Accel structured a standing offer to Morag before Oak even had a product is that they understood this dynamic. Product-first-mover advantage in a category with 14 practitioners is really hiring-first-mover advantage wearing a strategy deck. Oak got there first, and every competing round announcement from here to Q1 2027 will be racing against a shrinking pool.
FAQ
How large is the actual sourceable pool for AI agent identity engineers in the US?
Refolk's index returns 222 US professionals for the free-text signal "AI agent identity" across all functions, but the number collapses to 14 at Senior, Manager, or Director level, and only 5 profiles use "non-human identity" or "machine identity" as a headline concept. Most of the 222 are sales engineers or PMs. If you are hiring someone who has actually shipped an agent-permission system in production, plan for a pool in the low single digits per US metro.
Where should recruiters focus first for agentic IAM hiring?
Focus on a four-company alumni graph: Ermetic, Tenable, CyberArk, and Palo Alto Networks, plus SailPoint, Okta/Auth0, Teleport, Beyond Identity, and Oleria as the second ring. Geographically, prioritize the Washington DC-Baltimore corridor before the Bay Area, because federal Zero Trust and ICAM programs produced the largest cohort of engineers who have thought seriously about non-human identity. The Tel Aviv cluster of 8, concentrated at Token Security, Silverfort, Frontegg, Palo Alto Networks, and Oak itself, is small but disproportionately senior.
Why does Oak's $60M seed matter beyond Oak itself?
It defines a category, "AI-native identity" or agentic IAM, at a moment when the practitioner supply is a fraction of the demand the round will generate. Oak's product is already generally available with paying enterprise customers, which means competitors will hire against a supply base Oak has partially drained. With roughly $4.3M of seed capital per available senior US head, comp benchmarks for this niche are going to move fast.
What is the fastest way to build a shortlist for a role like this?
Skip generic keyword searches on LinkedIn, which will drown you in "identity" title matches with no real signal. Describe the person you want in plain English, including the alumni graph, the geographic bias toward DC, and the technical depth, and let a sourcing tool built for that motion return the shortlist. Refolk is designed for exactly this: ask for the person, get the ranked list across GitHub, LinkedIn, and the open web.