Opal Security

Opal Security

Application Security Engineer

San Francisco

Sponsorship not specifiedDetected 62 days ago
TypeScriptGoReactCode ReviewPostgreSQLRedisAWSDockerKubernetesCI/CDGraphQLOAuthCybersecurityIncident Response

About the role

  • Most security engineers spend their careers bolting locks onto doors that were already built.
  • You'll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software.
  • Oh, and one more thing: Opal is a security company.

Responsibilities

  • Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews - you set the bar
  • Run and coordinate app pentests (internal and external) and drive findings to closure
  • Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code
  • Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows
  • Own the Auth0 ↔ Opal integration - tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)
  • Create shared libraries that make the secure path the easy path for every product engineer
  • Partner with Infra on cloud hardening - AWS IAM, EKS, KMS, network segmentation

Nice to have

  • Have led complex, cross-functional security initiatives from kickoff to completion
  • Have run or participated in external pentests and seen findings through remediation
  • Thrive on ownership and ambiguity - you'd rather write the playbook than wait for one

Skills

  • Opal is a security company.
  • It is explicitly scoped to application and product security - enterprise IT, compliance, and vendor risk management are handled separately.
  • Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good
  • Level up detection and response by writing detection rules and improving logging and alerting
  • Mentor engineers on secure coding, common vuln patterns, and security architecture - you make the org smarter
  • Help set the security roadmap by grounding it in real product risk
  • Be the security teammate engineers want to work with - a collaborator, not a bottleneck

Company info

  • At Opal, we're building modern identity governance for the AI era-intelligent access management that empowers enterprises to move fast while staying secure.
  • Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation.

This listing is sourced directly from Opal Security's careers page and normalized into a canonical job model.