Application Security Engineer

Opal
San Francisco
Workplace: RemoteFull timeFunction: CybersecurityExperience: 4+ yearsSkills: ["Ownership","Collaboration","Problem-solving","Communication","Leadership"]

Own security across Opal's product and platform by embedding with engineering, writing production code in Go and TypeScript, and building security into the product from design to deployment. Lead secure SDLC, run internal and external pentests, and develop integrated security tooling. Drive encryption, authn/authz, and cloud security, while mentoring engineers on secure coding and security architecture.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Opal
Opal
3 months ago

Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 20 hours agoStatus: Live

Job Summary

Own security across Opal's product and platform by embedding with engineering, writing production code in Go and TypeScript, and building security into the product from design to deployment. Lead secure SDLC, run internal and external pentests, and develop integrated security tooling. Drive encryption, authn/authz, and cloud security, while mentoring engineers on secure coding and security architecture.
Location: San Francisco
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews.
  • •Run and coordinate app pentests (internal and external) and drive findings to closure.
  • •Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code.
  • •Triage and remediate vulnerabilities from every angle — bug bounty, internal scans, the works.
  • •Build and maintain security-critical components: encryption services, authz enforcement, authn flows; integrate Auth0 ↔ Opal; ship production Go and TypeScript; create shared libraries for secure paths.

Key Requirements

  • •4+ years in application security or software security engineering.
  • •Produce production code in Go and TypeScript and integrate security into the product development lifecycle.
  • •Strong knowledge of OAuth 2.0, OIDC, SAML, session management, and MFA/SSO.
  • •Experience in AWS and containerized environments (Kubernetes, Docker) and cloud security practices.
  • •Familiarity with stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL.
Experience:4+ years
Skills:OwnershipCollaborationProblem-solvingCommunicationLeadership
Tech Stack:GoTypeScriptReactPostgreSQLRedisGraphQLAWSKubernetesDockerOAuth 2.0OIDCSAML

Company Brief

Opal
Opal Security provides a data‑centric identity and access management platform that unifies visibility, intelligence, and workflows to enforce least‑privilege and remediate identity risk across human and machine identities for modern enterprises.
Industry: Cybersecurity
Company Size: Small (11 to 50 employees)
Growth: Growth Stage Startup
Funding: Series B
Headquarters: San Francisco, United States
Founded: 2020
Glassdoor
Glassdoor: 3.8
WebsiteLinkedInGlassdoor