Opal Security

AI

ApplicationSecurityEngineer

San Francisco, California, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid candidates.

The Brief

“Application Security Engineer at Opal Security. Skills: Application Security, Software Security Engineering, Secure Development Lifecycle, Cloud Security, Incident Response. Own security across Opal's product and platform. Write production code in Go and TypeScript”

What You'll Achieve.

Bring clarity, control, and confidence to complex enterprise environments; Help teams govern access without slowing down innovation; Security ships with the code; Close vuln classes for good; Make the org smarter

Industry & Context.

AI
Problems you'll solve

Find the root cause, fix it

What They're Looking For.

Must Have

4+ years in application security or software security engineering, Actually write production code, Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle, Comfortable in AWS and containerized environments (Kubernetes, Docker)

Nice to Have

Familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL, Led complex, cross-functional security initiatives from kickoff to completion, Run or participated in external pentests and seen findings through remediation, Thrive on ownership and ambiguity

What You'll Do.

Own security across Opal's product and platform

Write production code in Go and TypeScript

Build security into the product

Own the secure SDLC end-to-end

Set the security bar for threat modeling

Run and coordinate app pentests

Drive findings to closure

Build and own SAST/DAST/SCA tooling wired into CI/CD

Triage and remediate vulnerabilities

Build and maintain security-critical services

Own the Auth0 ↔ Opal integration

Ship production Go and TypeScript to harden APIs

enforce least-privilege

and close vuln classes

Create shared libraries

Be first on the scene for security incidents

fix security incidents

Partner with Infra on cloud hardening

Level up detection and response

Write detection rules

Improve logging and alerting

Mentor engineers on secure coding

and security architecture

Help set the security roadmap

Be the security teammate engineers want to work with

How You'll Work.

Team & Collaboration

Embedded directly with engineering; Work closely with a team of engineers; Partners closely with Infrastructure Engineering; Collaborator, not a bottleneck; Led complex, cross-functional security initiatives

Process & Methodology

Led complex, cross-functional security initiatives from kickoff to completion

Full Job Description

About Opal Security: At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation. The Role: Most security engineers spend their careers bolting locks onto doors that were already built. This is not that job. We're hiring an Application Security Engineer to own security across Opal's product and platform — and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed. You’ll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software. Oh, and one more thing: Opal is a security company. We sell access control to organizations that take security seriously. That means your work isn't a cost center — it's core to what we do. This role lives on the Platform team and partners closely with Infrastructure Engineering on cloud security. It is explicitly scoped to application and product security — enterprise IT, compliance, and vendor risk management are handled separately. What You’ll Do: Secure Development Lifecycle - - Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews — you set the bar - Run and coordinate app pentests (internal and external) and drive findings to closure - Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code - Triage and remediate vulnerabilities from every angle — bug bounty, internal scans, the works Software Security Engineering - - Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows - Own the Auth0 ↔ Opal integra

Free ATS check

Applying for this Application Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about Opal Security?

Real rants from real employees. Read before you apply.

Read Company Rants →