Dimitri Boylan
Welcome to another episode of the Talent Transformation Podcast. Today, we have Tosh Onishi, the former head of talent acquisition at Okta. Tosh, thank you so much for joining us.
Tosh Onishi
Thank you for having me, it’s great to be here.
Dimitri Boylan
Yeah. It’s great to have you in. I thought maybe you could first start with a little bit about Okta and tell me about Visa, and how you moved from Visa and Okta to show you.
Tosh Onishi
So Okta are the market leader in identity security. So in cybersecurity, there’s a number of different verticals within security. So up there is the market leader and the number one player, in identity security. So think of it as when you log on to a corporate system and you login to your laptop at work, it helps to secure and verify who you are logging in.
But behind that, a big part of it is access management and governance around who gets access to what systems, what level of access you get. So, to put it in maybe a HR context, different people have different levels of access to an HCM system, for example. And some people can say sensitive information, whilst others can’t. So, Okta helps to manage all of that governance around access control.
That’s the big part of this business. A secondary part, which was through acquisition a number of years ago, is what’s known as customer identity. And so helping digital businesses and online businesses verify and secure the identity of customers logging to receive digital service. And that could be anything from banking, insurance, to streaming services. In fact, Netflix is probably one of his most famous clients in that space.
So that’s a little bit about the Okta business. I was there for just over a year, running talent acquisition in Asia-Pacific, and before that I was at Visa, the biggest payments network and payments company in the world. Again, in a TA capacity for about ten and a half years.
Dimitri Boylan
Okay. Well, that’s interesting.
And you know, the issue of identity has become rather prominent right now. And you know, the challenges that companies face in identity are not what they were a decade ago, right? How much did you get involved with understanding what’s going on with identity, what the challenges are there for your customers? And the challenges for you running TA and finding qualified people to be in the space?
Tosh Onishi
I think the biggest eye-opening experience I had was when Okta published a report back in May of 2025 about North Korean threat actors infiltrating U.S. companies through IT contracting jobs and using AI and deep learning to get hired by foreign companies, and use that as a way to steal data and run new-age security breaches.
Tosh Onishi
That was an incredibly valuable experience for me because whilst, and I was speaking about earlier in the panel discussion, candidate fraud and people not who they are or claiming to be other people and people interviewing for a job, and then a different person turns up on the first day. This stuff has existed for a while, but, I think now it’s become a lot more sophisticated with AI. I think it’s become a lot more prominent since Covid shifted the world to remote work.
There’s obviously a lot more remote hiring. We went away from in-person interviewing and in-person onboarding to 100% remote. That’s unfortunately opened the doors to a lot of threats that we’ve never experienced and threats that have only emerged in the last two or three years. Yeah. And so I think as an industry, we’re not fully prepared for how to combat these threats.
And one of the things that we did at Okta, and I saw the security team in Okta introducing, is actually going back to a very old school methods of onboarding people, interviewing people, verifying their identities, bringing back in-person connection before you actually onboard someone for their first day has become much more important now.
Dimitri Boylan
Yeah, it’s interesting because there’s been a lot of discussion around, you know what? I doesn’t want people to. Yeah. And, you know, clearly there’s a people component. There’s some things for people to do that are important. And one of them is recognizing who you are. Obviously AI can help with that. I mean, I think I had a similar kind of eye-opening moment when I was doing my roadshow, which was going around explaining to various customers what we thought was going to happen in AI and how that was going to affect HR.
And, you know, I got to a customer in the US, they said, well, what are you doing about state actors? Because we have a problem. And, you know, it made us go back and start thinking about, you know, AI in HR as a fraud detector because a lot of our customers are big banks, or they’re transportation networks, like the train network. The rail network, and, you know, postal services, our customers of ours around the world, too. So, you know, there’s a lot of, questions now about how does the AI get used by the nefarious actor to pick up their game? And how does AI get used by the HR department to counter that?
Dimitri Boylan
Yeah. So we had to kind of stop the tracks a little bit and go back and have some conversations and say, “Well, you know, it really wasn’t that wasn’t on our agenda.” We put it on, we said, “Okay, there are some interesting things you can do here.” But I was surprised at the issue coming so prominently in front of that.
Tosh Onishi
Yeah. And it’s, you know, as I said, it was a very surprising thing when it came up last year and it really forced us to rethink how do we verify that the people that were interviewing are genuinely who they say they are? And I think ultimately, by the time I left, there was I’d say a three-stage defense system.
Tosh Onishi
So there was a lot of work at the security team to train the recruiters and TA organization on what to look for and contact. If you suspect something. And then we took that into interview training with hiring managers. So that was one line of defense. A second line of defense was identity verification before you make an offer, and making sure that the person is who they say they are. And you could use very sophisticated AI tools that are available now that a lot of background and reference-checking companies are using to verify identity documents to the person taking a selfie, for example.
And then the last thing is insisting on in-person onboarding. So, making sure that you don’t onboard someone unless you’ve actually physically seen them in person. And yes, there’s an expense to that. But if you look at even some of the more prominent cyber security breaches that have been reported here in Australia, whether it’s Qantas, Optus, Medibank, some of the biggest companies in Australia, the most recognized names, with the Qantas breach, for example, last year was a simple case of identity theft and identity fraud.
And so making sure that your people are trained on that, making sure that you have the right processes and fail-safe steps in place to verify that the people you bring into your business and allowing into a confidential, highly protected environment with sensitive data, that’s becoming increasingly important. And spending $2000 or $3000 to fly someone in to do onboarding for a couple of days is nothing compared to the potential of a multimillion-dollar security breach.
Dimitri Boylan
And it’s a little easier onboarding because you know, you’re going to be employing the person. But it’s interesting because, you know, we talk about having very well-structured interview processes. You give out, or you can give out, a lot of company information during an interview process. You want these candidates to work for you. You want them to understand where they’re going to be. You want them to understand how things work. You have to ask a whole bunch of questions that are relevant to the way you operate. You have to tell them what kind of tools you use, because you ask them what kind of tools they use. You have to tell them what your infrastructure looks like if they’re an infrastructure person. They’re going to have a back-and-forth conversation with maybe ten different people in your organization over three months while they’re interviewing.
And even then, you know, you walk away from that process knowing a lot more about the company than you could find out from just, you know, getting on the internet.
Tosh Onishi
Absolutely.
Dimitri Boylan
So I think that when we talk about who is an applicant and is that applicant a double, triple dipper, for instance, mean, you know, if you have an applicant that is somehow really one person in many different facades that comes in and does 15 interviews with your company over a year, they could have a dossier that’s quite substantial to use. Which then, of course creates the opportunity, as you know, for the threat to mature.
Because threats often start with very simple things and tiny little bits of information that then make other people who have information think that that person already knows a bunch of information and somehow is entitled to it. And then they up the information and you go to somebody else with it. So, these threat profiles can get very sophisticated, the state actors of course being most sophisticated.
But you know, I think that, you know, for me at least, the banking industry and also the retail industry were most tuned into this type of thing. Retail, because, you know, they’re at the periphery of a lot of smaller crime, maybe not state actors, but energetic actors.
I always feel like in retail, there’s always somebody trying to get in the door. And so they were probably the earliest for us to really ask you where are you going with this? But I think a lot of it is, you know, knowing, having really good processes, first of all, just fundamentally being very well organized. But then, you know, starting very early on with is this really a proper applicant? Is this really the same person I’m interviewing that my colleague interviewed for this job? And, obviously, when you get to the offer level, the level you can even before that, I mean, our customers are now, of course, you know, having to bring people on site more just to do informational interviews because otherwise the person’s on ChatGPT and the answer is it’s a good answer to everything.
But we’re trying to develop sort of the tools in AI to make the processes more intelligent. How exposed did you get to that during your own deployment of your TA solutions inside Okta? Because Okta is advising. You know how it is when you’re TA somewhere in a company that does a lot of things, you don’t always do those yourself because sometimes you can’t, you don’t have the bandwidth or the resources or the budget. You know, were you very free to sort of take on these challenges inside Okta as well?
Tosh Onishi
Yeah, we were. I think the one thing that I really appreciated about Okta was a very strong culture of we are customer zero, so if we’re out there preaching things and tools and products and services that we’re trying to sell into the market, we need to use them and we need to be customer zero. So that was a really important point of this culture.
And I think the second thing that I realized in my time there is the future of TA and business partnership. One of the most important functions that TA needs to partner with in the future is security. And really understanding from the experts, what are the threats that they’re seeing? What can the security team do to educate people on the front lines of the hiring process?
How do we work together to bubble up issues or report a case if we’re suspicious? And then just constantly get that information because we’re involved in recruiting, our subject matter expertise is recruiting. Security teams are experts in security, whether it’s cyber security or physical security. And so I do think a critically important business partnership in the future will be between TA and security.
Dimitri Boylan
Well, that’s interesting because I don’t know if a lot of TA people would flag that as one of the most important things. You know, I mean, it may become that, but I don’t think, certainly a few years ago to was having a lot of conversations about that. I think that you’d be hard-pressed to find lots of discussion about that right now in the TA community.
Tosh Onishi
Yeah, I appreciate that. That’s a perspective that’s been formed by working for a security company. Well, sure, when you see the damage that can be done and how easily that damage can be done, it really opened my eyes to think, actually, yeah, this is really important.
Dimitri Boylan
Oh, I agree with you. I mean, the damages is astronomical. I mean, you forget a firewall, you’ve given somebody the password. You know, there in.
Tosh Onishi
And I think if you look at, you know, the severity of cybersecurity breaches that are getting reported in the media over the last few years, they’re becoming increasingly more severe. They have a much more detrimental impact. And you talk to anyone in the cybersecurity space, and they’re very much pushing to make sure that executive teams and boards understand the importance of security and the impact of breaches.
It’s not just, “Ah! Someone got in and stole some data.” It’s multi-million-dollar worth of fines, damages, let alone reputational damage, lost trust from customers. You know, coming back to Australia, there was a very prominent Australian business that got hacked. They’ve lost a lot of trust with the Australian public and they’re struggling as a result of that.
Dimitri Boylan
It can take years to recover from that.
Tosh Onishi
Yeah. Sometimes you don’t.
Dimitri Boylan
What do you think is, if you’re talking to somebody in TA that, you know, hasn’t really thought about this, that much. Where do they start thinking about it?
Tosh Onishi
So, I think they need to firstly understand what the potential threats are and how people are using these technologies to try and gain access where they should not do things that shouldn’t be doing. And as I said, I think the next thing they need to do is to be consulting with the security teams to say if we are concerned about some breaches or TA and hiring being a potential way in and an open door to a security breach, what can we be doing?
Dimitri Boylan
So let me be the devil’s advocate there. If the security guys say, “Yeah, just don’t give out any information. Don’t do anything. Lock the door. We love it. The door is locked.” TA can’t do that. Right. So, you know, it’s great to go to the security guys to learn what kind of threats there are because we need their help.
But, you know, if you get an answer that stops you from doing your job, you can’t act on that. So, what really does the TA organization start to think about after they’ve gotten briefed on all the different ways that you can have threats? I mean, let’s start with jobs.
Right? So, you know, you publish a lot of jobs. I always say in the software industry, I can tell a lot about how a company rolls based on their job descriptions, because I know who they’re hiring. And then I can tell the tools that they use if they’re hiring. But you have to advertise for those tools otherwise you won’t get somebody to know how to do it.
So I would say, you know, the first thing is what’s in your job descriptions, right? I mean, is there, you know, I mean, with my cyber guys and say, “Hey, here’s what’s in my job descriptions. By the way, your cyber job descriptions are really, really too specific.”
But, you know, certainly starting with what you’re publishing out to the world is a good place to start. But then, you know, as you start getting people in, I think the onus is on us, you know, on the TA side and the tech side to start figuring out is a resume the resume of a real candidate.
One of the things that was brought up to us was, lots of fake applicants that were really variations on a resume. So, you know, these people look very, very similar and similar. They turned out to be no particular person. They were a persona that somebody had designed to get into a software company where there’s a lot of financial subsystems.
You know, and so that one is, is something that you can kind of focus in on and say, “Okay, we can see how AI can help you with things like that.” I think for the TA community, the bottom line is AI is a pattern matcher, is great at looking at patterns, right.
Dimitri Boylan
And patterns that sometimes you don’t see because you got a lot of data, but you got a lot of jobs, you got a lot of applicants, a lot of people interviewing them. Maybe you have a 200 person recruiting department for your organization, and you know you’re not going to go in there and, and, and spot a pattern that’s right.
Dimitri Boylan
So I’d say AI, certainly at the very front door. You start looking at the input from the consumer and sort of questioning what is the quality of that content and what is the authenticity of that content, right.
Tosh Onishi
Well, there’s an age-old saying, right? If something seems too good to be true, it often is. And yeah, I think that’s where throughout my entire recruitment career, I have been told and trying to look beyond the résumé and to really get to know the candidate and what they can bring to an organization. And I’ll never forget something I was told in my very first recruitment job almost 20 years ago, something very profound my director said to me, he said, “Tosh, some of the best candidates that you will place in this job will have some of the worst resumes.” And he said, because they just don’t have practice looking for jobs. They’re so good at what they do, they get promoted, they get moved around the organization, they don’t have to go look for a job, so they don’t have a lot of practice.
And he said, “Be wary of the people that have very, very good resumes and interview really, really well, there’s probably the reason why they’re so good at interviewing.” And it has rang true my entire career, and I’ve never forgotten that advice.
But, you know, you asked the question earlier about what can TA teams do when security teams try to shut the door? I think this is where a partnership mindset, but also a sense of accountability, is really important in TA. We need to take accountability for what we need to do, the information that needs to be disclosed in the interest of supporting the business and bringing in the very best talent, positioning ourselves as an employer of choice, and really getting that engagement with candidates that we really like.
And I think being able to have a very open conversation, you know, but it doesn’t just apply to security. I had many experiences with legal teams and privacy teams in a similar context, where you’re dealing with someone who has a very, very ultra risk-averse standpoint, who’s saying, “No, you can’t do this, no, you can’t do that, you can’t do that.”
But I think it’s about having an open conversation about what exactly are we trying to achieve in the business? How can we understand each other, and how can I, with a commercial objective, understand your risk management or security standpoint and how do we find a middle ground?
Another example, I met a commercial leader at Visa who had come from the risk management function. And he said to me, “Having spent time in Risk, I feel like I’m a better commercial leader, because I understand the importance of these people who exist to protect them. I understand why they do what they do. I understand why their work is important because I’ve been in their shoes. So, as a result, when I need something from them, I can position what I need a lot better. And I’m not an aggressive salesperson that will just go into a legal team’s office or risk office and say, ‘I don’t care what it takes, just do whatever I want because I‘m making money.’ I don’t take that approach; I don’t ram things down their throat. I’m much more consultative and I appreciate the need that they have to protect the company, and we always find the right middle ground. And as a result,” he said, “I’ve found that they are much more flexible and willing to work with me because they trust that I understand their point of view. They trust that I have listened to their advice. They trust it. Ultimately, it’s my decision, and I’m going to take accountability for whether it goes right or wrong.”
Dimitri Boylan
Yeah. It’s a new TA business relationship. You know, TA has it’s relationship with technology. Yes. It’s relationship with legal. You know, those have been developed over, you know, several years. This is a new one. Okay. I think it’s an interesting one for TA. There’s going to be a bit of a learning curve there. And it’s also not a… I think TA is used to this because, you know, it’s a situation where, you know, you may have all the right things you need one day, but the market shifts and then you don’t have what you need the next day. You never… It’s not something you win, just like recruiting is not something that you ever win. You know, you need somebody new again. You have to go back and do it again and there’s no one and done here. So I think it’s going to be an ongoing battle between the various actors and the threats that come in, and the ability to mitigate them.
I’m interested in going through those levels of defense, though, because, you know, we talk about the information we put out to attract candidates. You talk about responses that candidates give you with things like the resume. And, you know, the question of what the value of the resume is becoming, not just who has a good resume today, but now the resume is written by AI anyway, so, I don’t know if anybody wrote a resume any more. So, we don’t know what is the state of the resume going forward, right? It’s hard to say. Right?
Tosh Onishi
Yeah. It’s interesting. I think the resume has been becoming obsolete for a while. You just have to look at how many companies are offering the opportunity to apply for jobs with your LinkedIn profile. How many? I remember when I was recruited at Okta, I was approached by an executive recruiter at Okta in the US. I don’t think I sent my resume until I was about four interviews in. Because ultimately, and this is a piece of advice I used to give job seekers who asked me: A resume doesn’t get you a job, a resume just gets you an interview. So, I think people think that a resume is much more important than it actually is anyway. But if you’ve got enough information to get someone interested in talking to you about a job, your resume is irrelevant.
Dimitri Boylan
Well, then, I would say the third layer of defense is what happens when the interview process begins. Because the interview process, you’re going to have a person who was maybe in the organization. Well, of course, first of all, it’s expensive to interview people. You have to take line managers away from work and they have to interview people. And, you know, so the question is what is the methodology that the TA organization has to think about when they start to interview people. Not just recruiters interviewing people, but then hiring managers. And is it recruiters first and they think about whether or not this is authentic or not or whether they should be meeting them maybe face-to-face first before they send them on to hiring managers or not? Because, you know, if I don’t think we’re asking the hiring managers to play defense here.. You know, that would be another stretch, that’d be tough. I mean, certainly they want to be involved in it, right?
Dimitri Boylan
So there is some level of involvement that you need to. But it’s probably TA calling the shots there, right?
Tosh Onishi
Yes. And I think, one of the things that I have found recruiters don’t give themselves enough credit for is that at the end of the interview process, the recruiter knows the candidate better than anyone else.
Dimitri Boylan
Yeah.
Tosh Onishi
The recruiter has spent the most amount of time with the candidate, and I would argue the recruiter has seen a more real version of that candidate and who they really are because, when people go for an interview, they’re on their best behaviour. But over the course of three or four interactions with the recruiter or even coordinator scheduling interviews, they become more relaxed, they start to drop the guard a little bit.
Recruiters and coordinators will see behavior in candidates that hiring managers never see. And TA teams, unfortunately, grossly underestimate the value of that insight and that perspective. And I have encouraged my teams at every opportunity to say if you suspect something, there’s something about this candidate that you don’t like or you think doesn’t fit the culture, or whatever else, no matter how much the hiring manager likes them, you need to speak up. Don’t stay silent. Because they underestimate how much hiring managers actually value that perspective.
And there were three distinct occasions in my recruiting career where I have had a candidate at the end of the process that everyone on the panel loved and was chomping at the bit to get an offer out and get them on board. And I stood up and I said, “No, we cannot hire this person. They are not aligned to our culture. They’re not in line with our values.” And I was just able to cite clear examples of how they had been disrespectful towards a coordinator in the tone of their emails or in other communications, or I pointed out that, “You think this person is amazing, but every time I’ve tried to contact them, it’s taken me three days and five phone calls to get them on the phone.”
Dimitri Boylan
And the hiring manager doesn’t see that because they just brought them in for an interview on Tuesday at two o’clock.
Tosh Onishi
All they see is someone turned up on time to an interview. Yeah. And I said, “I’m sorry, but you can’t hire this person.” And every time I’ve stuck my neck out, the hiring manager said, “Okay, that’s fine. We’re going to move on.” I just think recruiters have that level of insight that the business never has. And as a recruiting community, we need to stand up for that. We need to be confident in those insights that we have and not be afraid to stand up around when we think something’s not right.
I mean, for me, what I’ve noticed is it’s just building the confidence to have an opinion. And in the TA space, there’s been a lot of talk about how do you shift from being a recruiter to a talent advisor or a TA business partner? And at a very fundamental and simplistic level, it’s actually having an opinion and not being afraid to share it.
You know, a transactional recruiter is a yes person who does whatever the hiring manager wants, takes a brief and takes a shopping list of ten things and just gives the hiring manager whatever they want and whatever the hiring manager says is gospel. But as I was saying before, well actually no. The hiring manager has spent an hour with a person, you spent four hours with them, you have much more insight into who they are. You just need to have the confidence to share your opinion.
Now, your opinion may or may not sway the decision, and that’s okay. Ultimately, the hiring manager will take accountability for the decision that they make. But don’t let things pass without you sharing an opinion, particularly if you’ve noticed something that needs to be flagged or is a concern. So from my observation, the recruiters that I’ve worked with, at least, can pick up on these things, but they are very afraid to tell the hiring managers.
And part of it is, “It’s not my place.” And I’m like, “That actually is your place.” And part of it is, “But if we say no to this candidate, I’ve got no one else.” The cost of making a bad hire is far is much worse than having this job open for another two months. So, you just got to have the confidence to share your opinion, have a point of view.
Dimitri Boylan
What do you think is next in the identity management space? Where’s is that going right now from a technical perspective?
Tosh Onishi
Securing the identity of agents. So again, it was an AI study that Okta conducted last year, and 91% of companies said that they were already using AI agents in their daily workflows. Only 10% of them had some sort of a strategy to secure them. And if you look at everything that Okta is talking about right now about securing AI, it is about securing the identity of the agents.
So now you may know the identity of the thousand employees that you have, but if every thousand of those employees has ten agents working for them, do you know the identity of those agents, do you know what systems they should be accessing? The information they should be accessing at what level? In the identity space, that is the next huge challenge.
Dimitri Boylan
Yeah. There’s a lot of talk today about shadow AI, the AI that people are using, but it’s actually not part of the tech stack of the company at all. And, I think there’s a big challenge around that to.
Tosh Onishi
It even came up at Visa in the context of e-commerce. There are a lot of AI tools that can, for example, help people book a holiday. You can go in and say, “I want to go on holiday here. Here’s my budget, just to do it.” But the question is, is this agent actually authorized to charge $3,000 worth of airfares on your credit card? Do you know that that’s happening? So securing the identity of agents in many different contexts, and in a lot of contexts that many people underestimate, is incredibly important.
Dimitri Boylan
Well, I’d love to catch up with you again. Thank you so much for coming in. I’d like to hear what you’re doing when you get settled in your new gig.
Tosh Onishi
No, thank you. Thank you for having me, it’s been great.