Application Security Engineer

Opendoor

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Miami, FL
Posted
85 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

How this pay compares to similar roles

Similar $177k
$118k most similar roles pay here $226k

This listing doesn't post a salary. Most similar roles pay $145,525–$208,800.

Based on 240 similar postings.

Employer

About Opendoor

Opendoor is a digital real estate marketplace that buys and sells homes directly to consumers, simplifying the home selling and buying experience through instant offers and transparent pricing. Industry: Real Estate Technology & iBuying

Opendoor currently has 31 open roles on FindRole.

Listed pay typically runs $156,800–$335,000 across 6 roles with salary data.

Most-posted roles

View all roles at Opendoor

At a glance

TL;DR · Application Security Engineer

As an Application Security Engineer on the Security Engineering team, you will identify and mitigate application-layer risks across consumer flows, GraphQL APIs, and AI-driven tools. You will build and operate vulnerability identification capabilities, manage the HackerOne bug bounty program, and lead threat modeling for new services and mobile features. Your daily work involves integrating security findings into developer workflows via GitHub, Linear, and Slack while building automated AI agents to triage reports and draft remediation pull requests. You will harden authentication and authorization across Kubernetes workloads and Apollo GraphQL gateways. The role requires proficiency in Go, Python, TypeScript, Ruby, and Terraform, alongside experience with AWS, GCP, Azure, Semgrep, and Burp Suite. You will secure the product ecosystem by implementing shift-left strategies and establishing "secure by default" standards for AI-maximalist engineering and agent-driven workflows.

What you'll do

  • Build and operate vulnerability identification tools and triage workflows for consumer products and GraphQL APIs.
  • Manage the AppSec tooling stack including static/dynamic testing, supply chain risk detection, and secrets scanning.
  • Manage the HackerOne bug bounty program by improving triage workflows and strengthening researcher relationships.
  • Lead threat modeling and security design reviews to create automated guardrails and lint checks for new features.
  • Develop AI agents and automated workflows to triage vulnerabilities and draft remediation pull requests.
  • Harden authentication, authorization, and input validation across Kubernetes workloads and production services.
  • Execute offensive security testing, red team exercises, and adversarial analysis of high-risk flows.
  • Establish "secure by default" standards for AI-driven engineering tools and agent-driven workflows.

What we're looking for

  • 5+ years of experience in application security or software engineering with a security focus.
  • Proficiency in at least one of Python, Go, TypeScript, or Ruby, with the ability to read and write code across others.
  • Hands-on expertise using security detection tools such as GitHub Advanced Security, Semgrep, or equivalent.
  • Strong knowledge of application and API vulnerability classes including GraphQL, REST, and gRPC.
  • Practical threat modeling skills for architecture diagrams and service designs.
  • Experience with cloud and container security on AWS and Kubernetes, including IAM and secrets management.
  • Ability to build AI agents and automated workflows for vulnerability triage and remediation.
  • Experience in offensive security, bug bounty programs, or securing AI/ML pipelines is preferred.

More like this

Similar roles

Application Security Engineer

Opendoor

Toronto, Canada 85 days ago
Go Python TypeScript Ruby Terraform AWS GCP Azure Kubernetes GraphQL Apollo GitHub Advanced Security CodeQL Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI REST gRPC Threat Modeling
5+ yrs exp Hybrid

Senior Application Security Engineer

Upstart

Remote (Canada) 7 days ago $166,900$230,900
Application Security Threat Modeling SAST DAST SCA CI/CD Python Java Go Ruby API Security Microservices GraphQL REST GenAI Secrets Management Cloud-Native AWS CISSP CSSLP CCSP
5+ yrs exp Remote

Staff Application Security Engineer

Brex

Remote 23 days ago $240,000$300,000
Application Security AI Security LLM Gateways AWS Kubernetes Python Go Kotlin gRPC GraphQL Microservices Threat Modeling Offensive Security Container Security
8+ yrs exp Remote

Staff Application Security Engineer

Datadog

101 days ago $244,000$305,000
Application Security Go Python Rust OWASP Top 10 SAST DAST API Security Threat Modeling Software Supply Chain Security Cryptography Infrastructure Security Observability
Hybrid

Infrastructure Security Engineer

Opendoor

Miami, FL 86 days ago
AWS Kubernetes Terraform Go Python TypeScript Okta HashiCorp Vault Datadog GitHub Actions Zero Trust Azure GCP EKS Helm Argo CD S3 Kinesis CloudTrail GuardDuty Security Hub Elastic Container Registry
5+ yrs exp Hybrid

Infrastructure Security Engineer

Opendoor

Miami, FL 86 days ago
AWS Kubernetes Terraform Go Python TypeScript Okta HashiCorp Vault Datadog Azure GCP GitHub Actions Zero Trust S3 Kinesis Helm Argo CD CloudTrail
5+ yrs exp Hybrid