Oh My JobFind Jobs
Company
  • About Us
  • Blog
  • Contact
Tools
  • Paycheck Calculator
Legal
  • Terms of Service
  • Privacy Policy
  • California Privacy Rights
For Employers
Post a Job

Application Security Engineer

Opal Security
Opal Security
San Francisco
May 20, 2026
Salary not listed
FullTime

Job Description

About the Role

Opal Security is building modern identity governance for the AI era. We're hiring an Application Security Engineer to own security across our product and platform—embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product from design through deployment. This is a hands-on role where security engineering is core to what we do, not a cost center.

Responsibilities

Secure Development Lifecycle

  • Own the secure SDLC end-to-end: threat modeling, design reviews, and code reviews
  • Run and coordinate application pentests (internal and external) and drive findings to closure
  • Build and own SAST, DAST, and SCA tooling integrated into CI/CD pipelines
  • Triage and remediate vulnerabilities from bug bounty programs, internal scans, and security assessments

Software Security Engineering

  • Build and maintain security-critical components: encryption services, authorization enforcement, and authentication flows
  • Own the Auth0 integration—managing tokens, sessions, MFA, and SSO protocols (SAML, OIDC, OAuth 2.0)
  • Ship production Go and TypeScript code to harden APIs, enforce least-privilege access, and eliminate vulnerability classes
  • Create shared libraries that make the secure path the default for all product engineers

Incident Response & Cloud Security

  • Lead security incident response: investigate, contain, identify root causes, and implement fixes
  • Partner with Infrastructure Engineering on AWS hardening—IAM, EKS, KMS, and network segmentation
  • Improve detection and response by writing detection rules and enhancing logging and alerting

Security Culture

  • Mentor engineers on secure coding practices, common vulnerability patterns, and security architecture
  • Contribute to the security roadmap by connecting it to real product risk
  • Work as a security collaborator with product teams, removing friction rather than adding it

Requirements

  • 4+ years in application security or software security engineering
  • Hands-on production code writing experience—beyond security findings reports
  • Deep knowledge of authentication protocols: OAuth 2.0, OIDC, SAML, session management, and token lifecycle
  • Comfortable working in AWS environments and containerized systems (Kubernetes, Docker)
  • Experience leading complex, cross-functional security initiatives from inception to completion
  • Demonstrated experience running or participating in external pentests and remediating findings
  • Comfort with ownership and ambiguity; preference for building solutions over following existing playbooks
  • Bonus: familiarity with Go, TypeScript, React, PostgreSQL, Redis, or GraphQL
Apply now
Share: