Opendoor Logo

Opendoor

Application Security Engineer

Posted An Hour Ago
Be an Early Applicant
Hybrid
Seattle, WA, USA
195K-244K Annually
Senior level
Hybrid
Seattle, WA, USA
195K-244K Annually
Senior level
Own application-layer risk detection and remediation across consumer flows, GraphQL APIs, and internal tools. Build and operate AppSec tooling, manage HackerOne, run threat modeling and security design reviews, create CI guardrails, automate vulnerability triage with AI agents, and lead offensive testing and red team exercises to harden authentication, authorization, and cloud/container security.
The summary above was generated by AI

About Opendoor

At Opendoor our mission is to tilt the world in favor of homeowners and those who aim to become one. Homeownership matters. It's how people build wealth, stability, and community. It's how families put down roots, how neighborhoods strengthen, how the future gets built. We're building the modern system of homeownership giving people the freedom to buy and sell on their own terms. We’ve built an end-to-end online experience that has already helped thousands of people and we’re just getting started.

About The Role

Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't.

As our Application Security Engineer, you'll own how we find, prioritize, and drive down application-layer risk across the consumer flows that put cash offers in homeowners’ hands, the GraphQL APIs that power our products, and the AI agents and vibe-coded tools our engineers ship every week. The job is to make it safe to build fast, not to slow things down.


What You'll Do

● Define, build and operate Opendoor’s application vulnerability identification capability - the tooling, triage workflow and remediation techniques across our consumer products, internal admin tools and GraphQL API powering home acquisition, resale, mortgage, title and escrow. 

● Assess, rationalize and own our AppSec tooling stack - static and dynamic security testing, software supply chain risk detection and secrets scanning and integrate findings into developer workflows where engineers already live (GitHub, Linear, Slack).

● Own and mature our HackerOne program: tightening the triage workflow, improving signal to noise on incoming reports, strengthening researcher relationships and closing the loop with engineering teams so root causes get addressed quickly. 

● Lead threat modeling and security design reviews for new services, APIs, and mobile features. Turn the patterns you see into rules, lint checks, and CI guardrails so the next team doesn't make the same mistake.

● Build AI agents and automated workflows that triage vulnerability reports, validate exploit reproductions, and draft remediation pull requests, replacing manual security review with high-signal automation.

● Partner with engineering teams to harden authentication, authorization, and input validation across our codebase and production services, including the GraphQL gateway (Apollo) and our Kubernetes workloads - while driving a shift-left strategy that catches vulnerabilities before they ship.

● Build Opendoor’s offensive security capability. Scope and run internal security testing, red team exercises and adversarial analysis of our highest-risk flows ensuring findings directly harden detection and response.  

● Set the bar for what "secure by default" looks like for AI-maximalist engineering, including vibe-coded apps, MCP servers, and agent-driven workflows that touch production data.

● Build Opendoor’s security culture by establishing secure design standards, embedding into engineering team rituals and developing a strong security mindset - creating a foundation for engineers to think like attackers without slowing down. 


Tech Stack

● Languages: Go, Python, TypeScript, Ruby, Terraform

● Cloud: AWS, GCP, Azure, Kubernetes, Apollo GraphQL

● AppSec Tooling: GitHub Advanced Security (CodeQL, Dependabot, secret scanning),

  Semgrep, HackerOne, Burp Suite, Cloudflare WAF

● AI Tooling: Claude, OpenAI, various agent frameworks, MCP — used heavily for vulnerability triage, exploit verification, and remediation drafting


What You'll Need

● Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You’ve built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.

● Comfort operating with high autonomy in ambiguous environments. You’ve defined what “good” looks like in a domain where no playbook existed, you’re energized by that, not unsettled by it. 

● Business enablement security mindset. You measure success by business impact and informed risk-taking, not by tickets opened or pen test reports filed.

● 5+ years of application security or software engineering experience with a security focus, with strong skills in at least one of Python, Go, TypeScript, or Ruby, and the ability to read and write code across the others.

● Hands-on expertise across the security risk detection toolchain with real deployment experience using GitHub Advanced Security, Semgrep, or equivalent.

● Strong grasp of common application and API vulnerability classes including GraphQL, REST, and gRPC security pitfalls - broken authorization, mass assignment, introspection exposure, insecure direct object references.

● Practical threat modeling skills. You can take an architecture diagram and a 30-minute conversation and walk out with the three things that actually matter.

● Experience with cloud and container security on AWS and Kubernetes, including identity and access management, secrets management, and continuous integration / continuous deployment pipeline security.

● Humility and genuine curiosity. You're as excited to learn from product engineers and enable their work as you are to break things.


Bonus Points

● Offensive security experience including pentesting, API security, or mobile security, and/or red team operations.

● Experience running a bug bounty or coordinated disclosure program at scale.

● Mobile application security review experience (iOS and Android).

● Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations.

● OSCP, OSWE, or similar offensive certifications.


Location

This role is based in our downtown Miami office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office.

Opendoor Seattle, Washington, USA Office

2033 6th Ave, Seattle, WA, United States, 98121

Similar Jobs at Opendoor

3 Hours Ago
Hybrid
Seattle, WA, USA
195K-244K Annually
Senior level
195K-244K Annually
Senior level
eCommerce • Fintech • Real Estate • Software • PropTech
Design, implement, and operate cloud security architecture across multi-account AWS, Kubernetes, and Terraform-managed infrastructure. Build detection, protection, and automated remediation workflows; define zero-trust access and identity solutions; harden Kubernetes and cloud workloads; shift security left in CI/CD; partner with infrastructure teams and mentor engineers to embed security guardrails.
Top Skills: Argo CdAWSAws Identity CenterAzureBedrockBottlerocketCartographyCheckovClaudeCloudtrailCodexCriblCrowdstrike FalconDatadogDuoEksElastic Container Registry (Ecr)FalcoGCPGithub ActionsGithub Advanced SecurityGoGuarddutyHashicorp VaultHelmKarpenterKinesisKubernetesKyvernoLaceworkLambdaOktaOpen Policy AgentOpenaiOrcaPrisma CloudProwlerPythonRubyRunlayer McpS3ScoutsuiteSecurity HubTerraform (Hcl)TerrakubeTypescriptVpc Flow LogsWiz
4 Days Ago
Hybrid
Seattle, WA, USA
Mid level
Mid level
eCommerce • Fintech • Real Estate • Software • PropTech
As a Software Engineer at Opendoor, you'll build production systems, own features end-to-end, conduct technical design reviews, and integrate AI tools into workflows while mentoring teammates and enhancing product quality.
Top Skills: Ai ToolsDistributed SystemsRelational DatabasesSoftware Engineering
6 Days Ago
Hybrid
Seattle, WA, USA
157K-335K Annually
Mid level
157K-335K Annually
Mid level
eCommerce • Fintech • Real Estate • Software • PropTech
As an Applied Scientist, you will develop quantitative models for decision-making in pricing, resale strategy, and risk management, involving hands-on coding and collaboration with other teams.
Top Skills: PysparkPython

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account