Application Security Engineer
Opal SecurityIdentity and company
San Francisco, United StatesSenior
Greylock Partners
Battery Ventures
Coatue
Box Group
SVCI
Cambium Capital
Software Engineering
About the role
TL;DR
Own security across Opal's product and platform, embedded with engineering.
- •We're hiring an Application Security Engineer to own security across Opal's product and platform.
- •You'll be embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed.
- •Key Responsibilities Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews Run and coordinate app pentests (internal and external) and drive findings to closure Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows Mentor engineers on secure coding, common vuln patterns, and security architecture Requirements Have 4+ years in application security or software security engineering Actually write production code
- •findings reports are the floor, not the ceiling Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle Are comfortable in AWS and containerized environments (Kubernetes, Docker) Thrive on ownership and ambiguity
- •you'd rather write the playbook than wait for one
Required skills
GoTypeScriptReactPostgreSQLRedisGraphQLAWSKubernetesCI/CDOAuthJWTSAMLIAMSSOMFA
Nice-to-have skills
SAML
Domain expertise
cybersecurity
Tech stack
GoTypeScriptReactPostgreSQLRedisGraphQLAWSKubernetesCI/CD