Application Security Engineer

Opendoor

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Toronto, Canada
Posted
85 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $177k
$118k most similar roles pay here $226k

This listing doesn't post a salary. Most similar roles pay $145,525–$208,800.

Based on 240 similar postings.

Employer

About Opendoor

Opendoor is a digital real estate marketplace that buys and sells homes directly to consumers, simplifying the home selling and buying experience through instant offers and transparent pricing. Industry: Real Estate Technology & iBuying

Opendoor currently has 31 open roles on FindRole.

Listed pay typically runs $156,800–$335,000 across 6 roles with salary data.

Most-posted roles

View all roles at Opendoor

At a glance

TL;DR · Application Security Engineer

As an Application Security Engineer on the Security Engineering team, you will protect consumer flows, GraphQL APIs, and AI-driven tools by building automated guardrails to ensure engineering velocity remains high. You will define and operate vulnerability identification capabilities, manage the HackerOne bug bounty program, and perform threat modeling for new services and mobile features. Your daily work involves integrating security findings into developer workflows via GitHub, Linear, and Slack while building AI agents to automate triage and remediation. You will harden authentication and authorization across Kubernetes workloads and Apollo GraphQL gateways. The role requires proficiency in Go, Python, TypeScript, Ruby, and Terraform, alongside experience with AWS, GCP, Azure, Semgrep, and Burp Suite. You will secure the technical infrastructure of home acquisition, resale, mortgage, title, and escrow services while fostering a security-first culture for AI-driven development.

What you'll do

  • Build and operate vulnerability identification tools and triage workflows for consumer products and GraphQL APIs.
  • Manage the AppSec tooling stack including static/dynamic testing, supply chain risk detection, and secrets scanning.
  • Manage the HackerOne bug bounty program by improving triage workflows and strengthening researcher relationships.
  • Lead threat modeling and security design reviews to create automated guardrails and lint checks for new features.
  • Develop AI agents and automated workflows to triage vulnerabilities and draft remediation pull requests.
  • Partner with engineering teams to harden authentication, authorization, and input validation across Kubernetes workloads.
  • Execute offensive security testing and red team exercises to identify and mitigate risks in high-risk flows.
  • Establish "secure by default" standards for AI-driven engineering tools and agent-driven workflows.

What we're looking for

  • 5+ years of experience in application security or software engineering with a security focus.
  • Proficiency in at least one of Python, Go, TypeScript, or Ruby, with the ability to read and write code across others.
  • Hands-on expertise using GitHub Advanced Security, Semgrep, or equivalent tools for risk detection.
  • Strong knowledge of common application and API vulnerability classes including GraphQL, REST, and gRPC.
  • Practical threat modeling skills to identify critical risks in architecture diagrams and service designs.
  • Experience with cloud and container security on AWS and Kubernetes, including IAM and secrets management.
  • Ability to build AI agents and automated workflows for vulnerability triage and remediation.
  • Experience with offensive security, bug bounty programs, or mobile application security is preferred.

More like this

Similar roles

Application Security Engineer

Opendoor

Miami, FL 85 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid

Senior Application Security Engineer

Upstart

Remote (Canada) 7 days ago $166,900$230,900
Application Security Threat Modeling SAST DAST SCA CI/CD Python Java Go Ruby API Security Microservices GraphQL REST GenAI Secrets Management Cloud-Native AWS CISSP CSSLP CCSP
5+ yrs exp Remote

Staff Application Security Engineer

Brex

Remote 23 days ago $240,000$300,000
Application Security AI Security LLM Gateways AWS Kubernetes Python Go Kotlin gRPC GraphQL Microservices Threat Modeling Offensive Security Container Security
8+ yrs exp Remote

Staff Application Security Engineer

Datadog

101 days ago $244,000$305,000
Application Security Go Python Rust OWASP Top 10 SAST DAST API Security Threat Modeling Software Supply Chain Security Cryptography Infrastructure Security Observability
Hybrid

Infrastructure Security Engineer

Opendoor

Toronto, Ontario, Canada 86 days ago
AWS Kubernetes Terraform Go Python TypeScript Okta HashiCorp Vault Azure GCP EKS Helm Argo CD Datadog GitHub Actions Zero Trust S3 Lambda CloudTrail GuardDuty
5+ yrs exp

Infrastructure Security Engineer

Opendoor

Toronto, Ontario, Canada 86 days ago
AWS Kubernetes Terraform Go Python TypeScript Okta HashiCorp Vault Azure GCP EKS Helm Argo CD Datadog GitHub Actions Zero Trust S3 Lambda CloudTrail GuardDuty
5+ yrs exp