
Application Security Engineer
Opal Security3 months ago
San Francisco, CA, USAMid Level
Responsibilities
- Own the secure software development lifecycle, including threat modeling, design reviews, and code reviews.
- Run and coordinate internal and external application penetration tests and drive findings to closure.
- Build and maintain SAST, DAST, and SCA tooling integrated into CI/CD.
- Triage and remediate vulnerabilities from bug bounty programs, internal scans, and other sources.
- Build and maintain encryption services, authorization enforcement, and authentication flows.
- Own the Auth0 and Opal integration, including tokens, sessions, MFA, SSO, SAML, OIDC, and OAuth 2.0.
- Write production Go and TypeScript to harden APIs, enforce least privilege, and address vulnerability classes.
- Create shared security libraries that enable secure implementation across product engineering.
- Investigate, contain, and remediate security incidents while identifying root causes.
- Partner with Infrastructure Engineering on AWS IAM, EKS, KMS, and network segmentation hardening.
- Write detection rules and improve logging and alerting for security detection and response.
- Mentor engineers on secure coding, vulnerability patterns, and security architecture.
- Help define the security roadmap based on product risk.
Requirements
- At least 4 years of application security or software security engineering experience.
- Ability to write production code and implement security solutions beyond producing findings reports.
- Strong knowledge of OAuth 2.0, OIDC, SAML, session management, and token lifecycles.
- Comfort working with AWS and containerized environments, including Kubernetes and Docker.
- Experience leading complex cross-functional security initiatives from kickoff through completion.
- Experience running or participating in external penetration tests and driving findings through remediation.
- Familiarity with Go, TypeScript, React, PostgreSQL, Redis, and GraphQL is preferred.
- Ability to work with ownership and ambiguity in a collaborative environment.
Tech Stack
Categories
About Opal Security
The best security and engineering teams use Opal, the AI-native access security platform, for real-time visibility, expressive policy-as-code, and direct control over every identity — from employees to service accounts to AI agents. Recognizing that access moves rapidly, touches everything, and changes constantly, our AI control plane is built for how identity works today and tomorrow. We are based in San Francisco, recently named to Notable Capital's Rising in Cyber 2026 list as selected by 150 leading CISOs, used by leading companies like Databricks, Notion, Cloudflare, Scale AI, CoreWeave, SpaceXAI, and Superhuman, and backed by Greylock, Battery Ventures, Silicon Valley CISO Investments (SVCI), and Cambium Capital.