×
Register Here to Apply for Jobs or Post Jobs. X

Application Security Engineer

Job in Seattle, King County, Washington, 98127, USA
Listing for: Opendoor
Full Time position
Listed on 2026-06-21
Job specializations:
  • IT/Tech
    Cybersecurity, AI Engineer (Applied/Software)
Salary/Wage Range or Industry Benchmark: 125000 - 150000 USD Yearly USD 125000.00 150000.00 YEAR
Job Description & How to Apply Below

About Opendoor

At Opendoor our mission is to tilt the world in favor of homeowners and those who aim to become one. Home ownership matters. It's how people build wealth, stability, and community. It's how families put down roots, how neighborhoods strengthen, how the future gets built. We're building the modern system of home ownership giving people the freedom to buy and sell on their own terms.

We’ve built an end-to-end online experience that has already helped thousands of people and we’re just getting started.

About

The Role

Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't.

As our Application Security Engineer, you'll own how we find, prioritize, and drive down application-layer risk across the consumer flows that put cash offers in homeowners’ hands, the GraphQL APIs that power our products, and the AI agents and vibe-coded tools our engineers ship every week. The job is to make it safe to build fast, not to slow things down.

What

You’ll Do
  • Define, build and operate Opendoor’s application vulnerability identification capability - the tooling, triage workflow and remediation techniques across our consumer products, internal admin tools and GraphQL API powering home acquisition, resale, mortgage, title and escrow.
  • Assess, rationalize and own our App Sec tooling stack - static and dynamic security testing, software supply chain risk detection and secrets scanning and integrate findings into developer workflows where engineers already live (Git Hub, Linear, Slack).
  • Own and mature our Hacker One program: tightening the triage workflow, improving signal to noise on incoming reports, strengthening researcher relationships and closing the loop with engineering teams so root causes get addressed quickly.
  • Lead threat modeling and security design reviews for new services, APIs, and mobile features. Turn the patterns you see into rules, lint checks, and CI guardrails so the next team doesn't make the same mistake.
  • Build AI agents and automated workflows that triage vulnerability reports, validate exploit reproductions, and draft remediation pull requests, replacing manual security review with high-signal automation.
  • Partner with engineering teams to harden authentication, authorization, and input validation across our codebase and production services, including the GraphQL gateway (Apollo) and our Kubernetes workloads - while driving a shift-left strategy that catches vulnerabilities before they ship.
  • Build Opendoor’s offensive security capability. Scope and run internal security testing, red team exercises and adversarial analysis of our highest-risk flows ensuring findings directly harden detection and response.
  • Set the bar for what "secure by default" looks like for AI-maximalist engineering, including vibe-coded apps, MCP servers, and agent-driven workflows that touch production data.
  • Build Opendoor’s security culture by establishing secure design standards, embedding into engineering team rituals and developing a strong security mindset - creating a foundation for engineers to think like attackers without slowing down.
Tech Stack
  • Languages:

    Go, Python, Type Script, Ruby, Terraform
  • Cloud: AWS, GCP, Azure, Kubernetes, Apollo GraphQL
  • App Sec Tooling:
    Git Hub Advanced Security (CodeQL, Dependabot, secret scanning), Semgrep, Hacker One, Burp Suite, Cloudflare WAF
  • AI Tooling:
    Claude, OpenAI, various agent frameworks, MCP — used heavily for vulnerability triage, exploit verification, and remediation drafting
What You’ll Need
  • Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You’ve built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
  • Comfort operating with high autonomy in ambiguous environments. You’ve defined what “good” looks like in a domain where no playbook existed, you’re energized by that, not unsettled by it.
  • Busin…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary