- Location
- San Francisco, California, USA
- Workplace
- Hybrid
- Employment
- Full time
- Level
- Mid level
- Posted
- 4 months ago
About this role
About Opal Security:
At Opal, we’re building modern identity governance for the AI era - intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation.
The Role:
Most security engineers spend their careers bolting locks onto doors that were already built. This is not that job.
We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed. You’ll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software.
Oh, and one more thing: Opal is a security company. We sell access control to organizations that take security seriously. That means your work isn't a cost center - it's core to what we do.
This role lives on the Platform team and partners closely with Infrastructure Engineering on cloud security. It is explicitly scoped to application and product security - enterprise IT, compliance, and vendor risk management are handled separately.
What You’ll Do:
Secure Development Lifecycle -
Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews - you set the bar
Run and coordinate app pentests (internal and external) and drive findings to closure
Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code
Triage and remediate vulnerabilities from every angle - bug bounty, internal scans, the works
Software Security Engineering -
Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows
Own the Auth0 ↔ Opal integration - tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)
Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good
Create shared libraries that make the secure path the easy path for every product engineer
Incident Response & Cloud Security -
Be first on the scene for security incidents: investigate, contain, find the root cause, fix it
Partner with Infra on cloud hardening - AWS IAM, EKS, KMS, network segmentation
Level up detection and response by writing detection rules and improving logging and alerting
Security Culture -
Mentor engineers on secure coding, common vuln patterns, and security architecture - you make the org smarter
Help set the security roadmap by grounding it in real product risk
Be the security teammate engineers want to work with - a collaborator, not a bottleneck
You Might Be a Fit If You:
Have 4+ years in application security or software security engineering
Actually write production code - findings reports are the floor, not the ceiling
Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle
Are comfortable in AWS and containerized environments (Kubernetes, Docker)
Bonus points for familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL
Have led complex, cross-functional security initiatives from kickoff to completion
Have run or participated in external pentests and seen findings through remediation
Thrive on ownership and ambiguity - you'd rather write the playbook than wait for one
As published by Opal. Applications are handled on their site.
Skills this posting mentions
About Opal
The best security and engineering teams use Opal to manage access for everyone and everything in the modern enterprise - from employees and contractors to service accounts and AI agents. Recognizing that access moves rapidly, touches everything, and changes constantly, our AI-proofed authorization control plane is built for how identity works (and what identity security needs) today and tomorrow: scale, speed, and intelligence. We are based in San Francisco, trusted by leading hypergrowth startups and the Fortune 500 alike, and backed by Greylock, Battery Ventures, Silicon Valley CISO Investments (SVCI), and other top experts from around the world. To learn more, visit www.opal.dev.
All 15 openings at OpalOne click, then it is written
Apply to Opal with a resume written for this role.
Queue Application Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Opal’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Opal
See all- 7 weeks ago
- 2 months ago
- 4 months ago
- 4 months ago
Enterprise Account Executive - East Coast
New York City, New YorkRemote
$260k - $300k/yrMid levelSales - 4 months ago
- 6 months ago
Similar roles elsewhere
See more- Today
Support Engineer, AI Infrastructure & Tooling
FigmaSan Francisco, CA • New York
$169k - $245k/yrMid levelEngineering
Put this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Opal publishes. Refolk is not the employer and does not handle their hiring. Applications go to Opal directly.