Oak's $60M Seed Is Chasing 210 IAM Engineers. Only 2 Are In The US.
Oak just raised $60M to build IAM for AI agents. The global pool of engineers who can actually ship it is 210, and only 2 sit in the US.
On July 15, 2026, Oak stepped out of stealth with $60M co-led by Accel, Greylock and CRV, one of the largest cyber seeds ever done in Israel. The pitch: an AI-native identity operating system that governs humans, machines, and agents from one control plane. The problem nobody in the press release wanted to say out loud: the engineers who can actually build that thing barely exist.
Why Oak's $60M seed is really a hiring problem
Oak has $60M and roughly 50 employees. The global talent pool it needs to grow into is measured in the low hundreds, and the US slice is measured on one hand. In Refolk's index of professional profiles, engineers who combine identity/access management keywords with senior or staff IC titles number just 210 worldwide. That is the entire realistic bench for a category that now includes Astrix Security, Aembit, Token Security, Andromeda Security, Cerbos, Arcade.dev, and every incumbent scrambling to bolt agent authorization onto legacy IAM.
Oak's structural advantage is founder Shai Morag, who has founded and sold three companies for a combined ~$500M (Integrity-Project to Mellanox in 2014, Secdo to Palo Alto Networks in 2018, and Ermetic to Tenable for $265M in 2023). Co-founder and CPO Tal Marom ran product at Tenable and Salesforce. That founding pair has a one-time alumni asset: the ex-Ermetic senior engineering diaspora, which public LinkedIn scans peg at roughly 50 people. Oak is already 50 people. Do the math. The founder network is already spent.
The intersection candidate does not exist yet
Anyone posting a job req that demands "3+ years shipping agent authorization" is gatekeeping against ghosts. The standards that define this work are six months old.
Consider the timeline:
- February 2026: NIST's NCCoE concept paper identifies agent authentication, zero-trust authorization, non-repudiation, prompt injection controls, and governance as the five focus areas for AI agent identity management.
- June 2025: The Model Context Protocol spec update integrated OAuth 2.1 and adopted RFC 9728 for protected resource metadata. This is the technical seam where IAM meets agents.
- 2026: IETF draft-klrc-aiagent-auth-00 lands, describing how AI agents should compose SPIFFE, WIMSE, OAuth and OpenID SSF.
There is no engineer alive with three years of production experience against these specs. The real target profile is not "IAM person who learned AI." It is a workload-identity engineer, specifically someone who has shipped SPIFFE or SPIRE in production, who now has enough MCP curiosity to reason about agent-scoped tokens. Block runs the full SPIFFE+WIMSE+OAuth stack in production. HashiCorp Vault 1.21 added native SPIFFE authentication that lets an agent holding an SVID exchange it for a Vault token. Those two orgs are the highest-yield sourcing targets on Earth for this profile, and every recruiter in the category knows it.
Hiring managers demanding three years of shipped agent-auth are gatekeeping against ghosts. The specs are six months old.
Title-based sourcing misses 97% of the pool
Filter by the literal title "IAM Engineer" and you get 6 people globally. Filter by IAM skills, keywords and senior/staff IC titles and you get 210. Sourcing this category by title erases ~97% of the addressable bench.
The reason is structural. The IAM engineering base skews to services shops and legacy identity vendors, not AI-native startups. Top employers in the cluster are Wipro, HCL, Deloitte, Oracle and Ping Identity. Those companies title people "Senior Software Engineer" or "Consultant," not "IAM Engineer." The signal is in the skill graph, the repo activity, and the project history, not the headline.
This is the exact gap Refolk closes. You describe the person in plain English ("senior engineers who have shipped SPIFFE in production and understand OAuth 2.1 token exchange") and get a ranked shortlist that pulls from GitHub commits, LinkedIn skill signals, and open-web mentions. Boolean strings on LinkedIn Recruiter cannot see repo commits to spiffe/spire or contributions to WIMSE drafts. That is where the real candidates live.
The five acronyms every sourcer needs to memorize
The IETF draft names them explicitly. If your keyword string does not include all five, you are sourcing the wrong category:
- SPIFFE (Secure Production Identity Framework For Everyone) is the workload identity standard that issues cryptographically verifiable identities (SVIDs) to services.
- SPIRE is the reference implementation of SPIFFE. Contributors here are the operational core of the pool.
- WIMSE (Workload Identity in Multi System Environments) is the IETF working group extending SPIFFE semantics across trust domains.
- OAuth 2.1 is the token-exchange substrate MCP adopted in June 2025.
- OpenID SSF (Shared Signals Framework) handles the continuous-access-evaluation piece.
Any candidate whose GitHub or writing touches three of these five is inside the top decile globally. That is the shortlist.
The Refolk index numbers
Here is what the index says about the addressable pool, laid out honestly.
| Segment | Count | Note |
|---|---|---|
| Global engineers with exact title "IAM Engineer" | 6 | Title-only sourcing collapses the pool |
| Global engineers, IAM keywords + senior/staff IC | 210 | The realistic worldwide bench |
| US-based subset (Seattle, Asheville visible) | ~2 | ~1% US density |
| India-based subset (BLR, HYD, MUM, NOI) | ~56% of top 25 | Services-shop concentration |
| Known ex-Ermetic engineers globally | ~50 | Oak's founder-network cluster |
| Oak's current headcount | ~50 | Founder cluster effectively fully absorbed |
Two US-based candidates. That is the number driving every seed round in the category. It is why Accel, Greylock and CRV wrote a $60M check for a 50-person company: the founder-alumni cluster is the only pre-built team of this shape in existence, and once it is spent, competitors are fishing in the same pond of ~two people per major US metro.
The geographic mismatch is the actual story
The IAM engineering base is India-heavy. The agent-auth standards work is US and EU centric. That mismatch is the hiring wall every AI-native security startup is about to slam into.
The Refolk index shows Bengaluru, Hyderabad, Mumbai and Noida dominating the top ten metros for IAM engineers. Seattle is the only US metro that cracks the list. That is not a talent problem you can offshore your way out of, because the standards, the working groups, and the customer conversations that shape those standards are all happening in San Francisco, Seattle, New York, London and Berlin.
Oak has already read the tea leaves. The company is roughly split between Israel and San Francisco, and a majority of Oak's staff will soon be based in the US. That is a deliberate bet against the geographic distribution of the existing IAM base. Every competitor will make the same bet, which means the two US-based senior IAM engineers in the index will get five inbound recruiters each by end of year.
Why India-based hiring is not the shortcut
The India-based pool is real, deep, and largely untapped by AI-native startups. But two friction points make it a slower play than the raw numbers suggest:
- Retraining cost. Most candidates in this cluster spent five to ten years inside SailPoint, ForgeRock, Okta, or Oracle IAM deployments. The agent-era primitives (workload identity, token exchange, MCP tool scoping) are net-new. Ramp time is real.
- Standards proximity. The people writing SPIFFE, WIMSE and OpenID AuthZEN specs are almost all in US and European time zones. Junior engineers in India can absorb the specs; senior engineers who help shape them are rarer, because the working groups meet at 8am Pacific.
Where the intersection candidates actually live
If you had to build a target list of 40 companies to source from tomorrow morning, it would look nothing like the "top IAM employers" list.
The high-yield hunt looks like this:
- Block. Production SPIFFE+WIMSE+OAuth stack. The biggest single reservoir of engineers who have shipped this end-to-end.
- HashiCorp. Vault 1.21 shipped native SPIFFE auth. Vault and Boundary teams are the second-biggest cluster.
- Tenable, post-Ermetic. Attrition from Tenable's post-acquisition period is a better hunt than Ermetic alumni, which Morag has locked. This is the non-obvious follow-on.
- Cerbos. Alex Olivier co-chairs the OpenID AuthZEN Working Group. His team is small but every hire is on-spec.
- Five9 and Bitwave. Jonathan Rosenberg and Patrick White authored the AAuth Agentic Authorization OAuth 2.1 Extension. Their reports and collaborators are the author-network of this field.
- MCP contributor graph on GitHub. There are over 13,000 MCP servers on GitHub deployed in 2025 alone. The maintainers of the top 200 by stars are a candidate list nobody is working systematically.
Building that list by hand from LinkedIn Recruiter takes weeks. Describing it to Refolk in one sentence ("engineers who maintain popular MCP servers on GitHub and have OAuth or workload identity in their work history") gets it back in minutes, which is roughly the difference between hiring in Q3 and hiring in Q1 next year.
What Gartner's 70% number does to the timeline
Gartner projects that by 2028, 70% of CISOs will adopt identity visibility and intelligence capabilities. Translate that into hiring pressure and you get the demand-side justification for the current seed-round arms race.
Every enterprise IAM buyer is about to demand agent governance in their next renewal cycle. Every incumbent (Okta, Ping, SailPoint, CyberArk, Microsoft Entra) will either build or acquire to fill it. Every startup in the category will be a target, and every startup will be forced to grow engineering fast enough to survive the acquisition due diligence. The 210-person global pool will not stretch to cover that demand. Salaries will compress up. Non-competes will get tighter. Founder-network hiring, which is how Oak got to 50 people in the first place, will stop working for anyone without a prior exit in the category.
That is the real reason Oak raised $60M at seed. Not because building the product costs $60M. Because hiring the people who can build it, in the US, against Astrix, Aembit, Token Security, Andromeda, Cerbos and Arcade.dev, absolutely does.
FAQ
How many engineers globally have actually shipped both IAM at scale and AI agent authorization?
Effectively zero with three or more years of production experience, because the relevant standards (MCP's OAuth 2.1 integration, IETF WIMSE, NIST NCCoE guidance) all landed between mid-2025 and early 2026. The realistic proxy is workload-identity engineers with SPIFFE or SPIRE production experience who have started building against MCP. Refolk's broader IAM-plus-senior-IC pool is 210 globally, and the intersection with agent-era work is a small fraction of that.
Who are the highest-yield companies to source IAM plus agent auth engineers from?
Block and HashiCorp are the two biggest known production users of the SPIFFE+WIMSE+OAuth stack and should be the top of any target list. After that: Cerbos (OpenID AuthZEN leadership), Tenable's post-Ermetic attrition cohort, and the maintainer graph of the 13,000+ MCP servers on GitHub. Legacy IAM vendors like Ping, SailPoint and Oracle have the volume but require significant retraining on agent-era primitives.
Why is title-based sourcing broken for this category?
Only 6 people globally hold the exact title "IAM Engineer" in the index, but 210 do the work under generic "Senior Software Engineer" labels at services shops and legacy vendors. Title-based Boolean strings on LinkedIn miss ~97% of the pool because the signal lives in skills, repo activity, and standards-body participation, not in the headline. Skill-graph and semantic search tools like Refolk surface the hidden 204 that title filters erase.
Is the Ermetic alumni pool really the story for Oak?
It is the founding story but not the growth story. The ex-Ermetic senior engineering cluster is roughly 50 people, which is roughly Oak's current headcount, meaning Morag's founder-network advantage is largely already spent. The next wave of Oak hires, and every competitor's hires, has to come from Block, HashiCorp, Tenable attrition, and the MCP maintainer graph. That is a much harder sourcing job and the reason $60M at seed makes sense.