Opendoor

Application Security Engineer

Opendoor
Apply
1 hour ago
Miami, FL, USASenior
H1B sponsor

Responsibilities

  • Define, build, and operate application vulnerability identification, triage, and remediation capabilities across consumer products, internal tools, and GraphQL APIs.
  • Assess and operate AppSec tooling for static and dynamic testing, software supply-chain risk detection, and secrets scanning, integrating findings into GitHub, Linear, and Slack workflows.
  • Own and mature the HackerOne bug bounty program, including report triage, researcher relationships, and remediation follow-through.
  • Lead threat modeling and security design reviews for services, APIs, and mobile features, converting findings into rules, lint checks, and CI guardrails.
  • Build AI agents and automated workflows for vulnerability triage, exploit validation, and remediation pull-request drafting.
  • Partner with engineering teams to harden authentication, authorization, input validation, GraphQL services, and Kubernetes workloads.
  • Build offensive security capabilities through internal testing, red-team exercises, and adversarial analysis.
  • Establish secure-by-default standards for AI-enabled applications, MCP servers, and agent-driven workflows.
  • Develop secure design standards, participate in engineering rituals, and strengthen the organization’s security culture.

Requirements

  • 5+ years of application security or software engineering experience with a security focus.
  • Strong programming skills in at least one of Python, Go, TypeScript, or Ruby, with the ability to read and write code across the others.
  • Hands-on deployment experience with GitHub Advanced Security, Semgrep, or equivalent security risk detection tooling.
  • Strong understanding of application and API vulnerability classes, including GraphQL, REST, and gRPC security issues.
  • Practical threat modeling and security design review experience.
  • Experience with cloud and container security on AWS and Kubernetes, including identity and access management, secrets management, and CI/CD pipeline security.
  • Demonstrated experience building agentic systems and automation that replace reactive security work.
  • Ability to operate autonomously in ambiguous environments and apply a business-enablement security mindset.
  • Preferred experience with penetration testing, API or mobile security, red-team operations, bug bounty or coordinated disclosure programs, mobile application security, AI/ML pipeline security, agent frameworks, or MCP integrations.
  • OSCP, OSWE, or similar offensive security certification is a bonus.

Benefits

  • The role is based in Opendoor’s downtown Miami office and requires in-person work four days per week: Monday, Tuesday, Thursday, and Friday.
  • Candidates must live within commuting distance of the Miami office.

Tech Stack

Categories

Opendoor

About Opendoor

1,001-5,000 employees

Founded in 2014, Opendoor’s mission is to power life’s progress one move at a time. The traditional real estate process is broken and our goal is simple: fix it. We are building a digital, end-to-end customer experience that makes buying and selling a home simple, certain, and fast. We have assembled a dedicated team with diverse backgrounds to support more than 250,000 customer transactions across 50 markets in the U.S. But the work is far from over. Transforming the real estate industry takes tenacity and dedication. It takes problem solvers and builders. It takes a tight-knit community of teammates doing the best work of their lives, pushing one another to transform a complicated process into a simple one. So where do you fit in? Whether you’re passionate about real estate, people, numbers, words, code, or strategy -- we have a place for you. For more information, please visit www.opendoor.com Keep up with latest Opendoor news and reports: https://linktr.ee/opendoorhq

Contact me