368,291open jobs
9,430companies
50,343added this week
Browse all
Salary
$103k – $232k per year (Estimated)
Location
Remote/Hybrid (San Francisco, United States)
Seniority
Middle · 4+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Opal is a modern, data-centric identity security platform. Our platform offers a consolidated view and control of your whole ecosystem from on-prem to cloud and SaaS. Opal is backed by Greylock, Battery Ventures, and some of the top security exper...

About Opal Security:

At Opal, we’re building modern identity governance for the AI era-intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation.

The Role:

Most security engineers spend their careers bolting locks onto doors that were already built. This is not that job.

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed. You’ll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software.

Oh, and one more thing: Opal is a security company. We sell access control to organizations that take security seriously. That means your work isn't a cost center - it's core to what we do.

This role lives on the Platform team and partners closely with Infrastructure Engineering on cloud security. It is explicitly scoped to application and product security - enterprise IT, compliance, and vendor risk management are handled separately.

What You’ll Do:

Secure Development Lifecycle -

  • Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews - you set the bar

  • Run and coordinate app pentests (internal and external) and drive findings to closure

  • Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code

  • Triage and remediate vulnerabilities from every angle - bug bounty, internal scans, the works

Software Security Engineering -

  • Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows

  • Own the Auth0 ↔ Opal integration - tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)

  • Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good

  • Create shared libraries that make the secure path the easy path for every product engineer

Incident Response & Cloud Security -

  • Be first on the scene for security incidents: investigate, contain, find the root cause, fix it

  • Partner with Infra on cloud hardening - AWS IAM, EKS, KMS, network segmentation

  • Level up detection and response by writing detection rules and improving logging and alerting

Security Culture -

  • Mentor engineers on secure coding, common vuln patterns, and security architecture - you make the org smarter

  • Help set the security roadmap by grounding it in real product risk

  • Be the security teammate engineers want to work with - a collaborator, not a bottleneck

You Might Be a Fit If You:

  • Have 4+ years in application security or software security engineering

  • Actually write production code - findings reports are the floor, not the ceiling

  • Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle

  • Are comfortable in AWS and containerized environments (Kubernetes, Docker)

  • Bonus points for familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL

  • Have led complex, cross-functional security initiatives from kickoff to completion

  • Have run or participated in external pentests and seen findings through remediation

  • Thrive on ownership and ambiguity - you'd rather write the playbook than wait for one

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,291 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$110k – $131k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree
DevOps
AWS
Incident Management
VMWare
Apply
$118k – $142k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • El Segundo
C++
MATLAB
Python
SystemC
SystemVerilog
Verilog
VHDL
DevOps
CI/CD
QEMU
Chips/EDA
UVM
Apply
$129k – $232k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austin
C++
DevOps
CI/CD
Git
RTOS
Apply
$169k – $321k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Phoenix
AI/ML
AI Agents
Anomaly Detection
LLM Guardrails
DevOps
AWS
Kong
Amazon S3
API Gateway
Cybersecurity
Zero Trust
Apply
$140k – $215k per year • Remote/Hybrid • Full-Time • 4+ years exp • San Francisco
Go
TypeScript
Databases
Databricks
PostgreSQL
Redis
Frontend
GraphQL
DevOps
AWS
GCP
Kubernetes
Terraform
IAM
Design
Figma
Apply
Product Manager 6 months ago
$156k – $281k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • San Francisco
Databases
Databricks
AI/ML
AI Agents
DevOps
Cloudflare
IAM
Design
Figma
Apply
$140k – $250k per year • Remote/Hybrid • Full-Time • San Francisco
Databases
Databricks
DevOps
Terraform
IAM
Design
Figma
Management
Slack
Apply
$138k – $268k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • San Francisco
AI/ML
Perplexity
Runway
Edge AI
DevOps
Terraform
Apply
Software Engineer 2 years ago
$140k – $250k per year • In office • Full-Time • San Francisco
Databases
Databricks
DevOps
IAM
Design
Figma
Apply
$83k – $188k per year (Estimated) • In office • 2+ years exp • San Francisco
Python
AI/ML
AI Agents
LLM Guardrails
Model Context Protocol
DevOps
Terraform
Cybersecurity
Crowdstrike
GDPR
Least Privilege
Okta
SentinelOne
Management
Google Workspace
Slack
Apply
$171k – $273k per year • In office • Full-Time • 8+ years exp • PhD • San Francisco • Washington
AI/ML
A2A
Agentforce
AI Agents
Model Context Protocol
DevOps
AWS
GCP
Marketing
Salesforce
Apply
$173k – $260k per year • In office • Full-Time • PhD • San Francisco
JavaScript
Node JS
Python
Python
Celery
Django
Flask
Databases
RabbitMQ
Redis
AI/ML
Agentforce
AI Agents
DevOps
Akamai
AWS
CI/CD
Cloudflare
CloudFormation
Helm
Jenkins
Kubernetes
Spinnaker
Terraform
Marketing
Salesforce
Apply
$182k – $305k per year • Remote/Hybrid • Full-Time • 10+ years exp • PhD • San Francisco
AI/ML
Agentforce
AI Agents
Marketing
Salesforce
Apply
$173k – $260k per year • In office • Full-Time • 7+ years exp • PhD • New York • Indianapolis • San Francisco
AI/ML
AI Agents
Agentforce
Marketing
Salesforce
Apply
See all jobs
This is one of many
368,291 more open roles from verified company boards, updated every day.