
Posted 14 hours ago
Application Security Engineer
OpendoorApplication Security Engineer
Requirements
5+ years application security or software engineering experience, Proficiency in Python, Go, TypeScript, or Ruby, Expertise in GitHub Advanced Security or Semgrep, Experience with AWS and Kubernetes security, Strong grasp of GraphQL, REST, and gRPC security
Skills
PythonGoTypeScriptAWSKubernetesGraphQLSemgrep
About the role
Responsibilities
- Define, build, and operate application vulnerability identification capabilities, including tooling, triage workflows, and remediation techniques.
- Manage the AppSec tooling stack, integrating static and dynamic security testing into developer workflows like GitHub and Slack.
- Mature the HackerOne bug bounty program by improving signal-to-noise ratios and strengthening researcher relationships.
- Lead threat modeling and security design reviews for new services, APIs, and mobile features.
- Build AI agents and automated workflows to triage vulnerability reports and draft remediation pull requests.
- Partner with engineering teams to harden authentication, authorization, and input validation across GraphQL gateways and Kubernetes workloads.
- Develop offensive security capabilities, including internal security testing and red team exercises.
Requirements
- 5+ years of application security or software engineering experience with a strong security focus.
- Proficiency in at least one of the following languages: Python, Go, TypeScript, or Ruby.
- Hands-on expertise with security risk detection tools such as GitHub Advanced Security or Semgrep.
- Strong understanding of application and API security, including GraphQL, REST, and gRPC.
- Experience with cloud and container security, specifically within AWS and Kubernetes environments.
- Practical experience with threat modeling and architectural security reviews.
Preferred Qualifications
- Offensive security experience, including pentesting, API security, or red team operations.
- Experience running bug bounty or coordinated disclosure programs at scale.
- Mobile application security review experience (iOS and Android).
- Experience securing AI/ML pipelines, agent frameworks, or MCP-style integrations.
- Relevant offensive security certifications such as OSCP or OSWE.
About the Company
Opendoor is building the modern system of homeownership, providing an end-to-end online experience that gives people the freedom to buy and sell homes on their own terms. Our mission is to tilt the world in favor of homeowners and those who aim to become one.
ScoutJobs Agent
Get matches like this delivered daily
Sign up free — we'll pull jobs that fit your CV from across the web and rank them for you.
Get started — it's freeApplication Security Engineer
Opendoor · Toronto
