Responsibilities
- Define, build, and operate application vulnerability identification, triage, and remediation capabilities across consumer products, internal tools, and GraphQL APIs.
- Assess and manage AppSec tooling for static and dynamic testing, software supply chain risk detection, and secrets scanning, integrating findings into GitHub, Linear, and Slack workflows.
- Own and mature the HackerOne bug bounty program and improve report triage, researcher relationships, and remediation follow-through.
- Lead threat modeling and security design reviews for services, APIs, and mobile features, and convert recurring patterns into rules, lint checks, and CI guardrails.
- Build AI agents and automated workflows for vulnerability triage, exploit validation, and remediation pull requests.
- Partner with engineering teams to improve authentication, authorization, input validation, GraphQL gateway security, and Kubernetes workload security.
- Build offensive security capabilities through internal security testing, red team exercises, and adversarial analysis.
- Establish secure-by-default standards for AI-enabled applications, MCP servers, and agent-driven workflows.
- Develop security design standards, participate in engineering rituals, and strengthen the organization’s security culture.
Requirements
- 5+ years of application security or software engineering experience with a security focus.
- Strong programming skills in at least one of Python, Go, TypeScript, or Ruby, with the ability to read and write the others.
- Track record of building agentic systems that replace reactive security work and manual processes.
- Hands-on deployment experience with GitHub Advanced Security, Semgrep, or equivalent security risk detection tools.
- Strong understanding of application and API vulnerability classes, including GraphQL, REST, and gRPC security issues.
- Practical threat modeling and security design review experience.
- Experience with AWS and Kubernetes cloud and container security, including identity and access management, secrets management, and CI/CD pipeline security.
- Experience with offensive security, penetration testing, API security, mobile security, red team operations, bug bounty programs, AI or machine learning pipeline security, agent frameworks, or MCP-style integrations is preferred.
- OSCP, OSWE, or similar offensive security certification is a bonus.
- Humility, curiosity, autonomy, and a business-enablement approach to security are expected.
Benefits
- Based in Opendoor’s downtown Toronto office.
- In-person work is required four days per week: Monday, Tuesday, Thursday, and Friday.
- Candidates must live within commuting distance of the Toronto office.
Tech Stack
Categories
About Opendoor
Founded in 2014, Opendoor’s mission is to power life’s progress one move at a time. The traditional real estate process is broken and our goal is simple: fix it. We are building a digital, end-to-end customer experience that makes buying and selling a home simple, certain, and fast. We have assembled a dedicated team with diverse backgrounds to support more than 250,000 customer transactions across 50 markets in the U.S. But the work is far from over. Transforming the real estate industry takes tenacity and dedication. It takes problem solvers and builders. It takes a tight-knit community of teammates doing the best work of their lives, pushing one another to transform a complicated process into a simple one. So where do you fit in? Whether you’re passionate about real estate, people, numbers, words, code, or strategy -- we have a place for you. For more information, please visit www.opendoor.com Keep up with latest Opendoor news and reports: https://linktr.ee/opendoorhq
