Open Positions at Opendoor | Join Our Team

Opendoor

Quick summary

Work type
On-site
Location
Seattle, WA
Posted
11 days ago

Market check

Salary context

How this pay compares to similar roles

Similar $180k
$120k most similar roles pay here $231k

This listing doesn't post a salary. Most similar roles pay $145,075–$214,850.

Based on 240 similar postings.

Employer

About Opendoor

Opendoor is a digital real estate marketplace that buys and sells homes directly to consumers, simplifying the home selling and buying experience through instant offers and transparent pricing. Industry: Real Estate Technology & iBuying

Opendoor currently has 50 open roles on FindRole.

Listed pay typically runs $156,800–$335,000 across 8 roles with salary data.

Most-posted roles

View all roles at Opendoor

At a glance

TL;DR · Open Positions at Opendoor | Join Our Team

As an Application Security Engineer at Opendoor in Seattle, you will be responsible for ensuring the security of all applications and services across consumer products, internal tools, and GraphQL APIs. You will own and evolve AppSec tooling, integrate findings into developer workflows, manage the HackerOne program, lead threat modeling, and build AI agents to automate vulnerability triage and remediation. Key technologies include Go, Python, TypeScript, Ruby, Terraform, AWS, GCP, Azure, Kubernetes/EKS, GitHub Advanced Security, Semgrep, Burp Suite, Cloudflare WAF, and various AI tools. You should have 5+ years of application security or software engineering experience with hands-on expertise in SAST/DAST/SCA tools, cloud and container security, and a strong understanding of common vulnerability classes. Bonus points for offensive security experience and running bug bounty programs.

What you'll do

  • Identify and resolve application vulnerabilities across consumer products, internal tools, and APIs.
  • Develop and maintain AppSec tooling stack including SAST/DAST, SCA, and secrets scanning.
  • Manage HackerOne program by triaging reports, validating exploits, and routing fixes to teams.
  • Conduct threat modeling and security design reviews for new services and APIs.
  • Build AI agents and automated workflows to triage vulnerability reports and draft remediation PRs.

What we're looking for

  • 5+ years of application security or software engineering experience with a focus on security.
  • Proficiency in at least one language from Python, Go, TypeScript, Ruby; ability to read/write code across multiple languages.
  • Hands-on expertise with SAST/DAST/SCA tools and real deployment experience using GitHub Advanced Security or equivalent.
  • Strong understanding of common application vulnerabilities including OWASP Top 10 and API security pitfalls.
  • Practical threat modeling skills to identify critical risks from architecture diagrams and discussions.
  • Experience in cloud and container security on AWS and Kubernetes, including IAM, secrets management, and CI/CD pipeline security.

More like this

Similar roles

Open Positions at Opendoor | Join Our Team

Opendoor

Tempe, AZ +1 11 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF GraphQL REST gRPC CI/CD IAM secrets management threat modeling OWASP Top 10 OWASP API Security Top 10

Open Positions at Opendoor | Join Our Team

Opendoor

Tempe, AZ +1 11 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF CI/CD GraphQL REST gRPC OAuth IAM Secrets Management Threat Modeling OWASP Top 10 OWASP API Security Top 10

Application Security Engineer

Opendoor

Miami, FL 3 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes Apollo GraphQL GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF CI/CD GraphQL REST gRPC OAuth JWT Docker Linux JSON Web Tokens OAuth2 OAuth 2.0
Hybrid

Application Security Engineer

Opendoor

Miami, FL 3 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes Apollo GraphQL GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF CI/CD GraphQL REST gRPC OAuth JWT Docker Linux SQL PostgreSQL Redis MongoDB JSON Web Tokens OAuth 2.0 OpenID Connect Kerberos SAML LDAP ZAP OWASP Top Ten Threat Modeling Cloud Security Secrets Management Mobile Application Security AI Security
Hybrid

Application Security Engineer

Opendoor

Toronto, Canada 3 days ago
Go Python TypeScript Ruby Terraform AWS Kubernetes Apollo GraphQL GitHub Advanced Security Semgrep HackerOne Burp Suite Cloudflare WAF Claude OpenAI MCP CI/CD GraphQL REST gRPC
Hybrid

Application Security Engineer

US Bank

Irving, TX +2 4 days ago $105,400$124,000
Jenkins SAST SCA DAST ServiceNow Java Docker CI/CD Linux Fortify Black_Duck FOSSA
Hybrid