Opal Security
Application Security Engineer
San Francisco
Sponsorship not specifiedDetected 62 days ago
TypeScriptGoReactCode ReviewPostgreSQLRedisAWSDockerKubernetesCI/CDGraphQLOAuthCybersecurityIncident Response
About the role
- Most security engineers spend their careers bolting locks onto doors that were already built.
- You'll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software.
- Oh, and one more thing: Opal is a security company.
Responsibilities
- Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews - you set the bar
- Run and coordinate app pentests (internal and external) and drive findings to closure
- Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code
- Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows
- Own the Auth0 ↔ Opal integration - tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)
- Create shared libraries that make the secure path the easy path for every product engineer
- Partner with Infra on cloud hardening - AWS IAM, EKS, KMS, network segmentation
Nice to have
- Have led complex, cross-functional security initiatives from kickoff to completion
- Have run or participated in external pentests and seen findings through remediation
- Thrive on ownership and ambiguity - you'd rather write the playbook than wait for one
Skills
- Opal is a security company.
- It is explicitly scoped to application and product security - enterprise IT, compliance, and vendor risk management are handled separately.
- Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good
- Level up detection and response by writing detection rules and improving logging and alerting
- Mentor engineers on secure coding, common vuln patterns, and security architecture - you make the org smarter
- Help set the security roadmap by grounding it in real product risk
- Be the security teammate engineers want to work with - a collaborator, not a bottleneck
Company info
- At Opal, we're building modern identity governance for the AI era-intelligent access management that empowers enterprises to move fast while staying secure.
- Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation.
Apply directly at Opal Security →Create a free account for alerts like thisView Opal Security immigration profile
This listing is sourced directly from Opal Security's careers page and normalized into a canonical job model.