Opal

Application Security Engineer

Opal$120K — $160K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years in application security or software security engineering
  • Experience writing production code in Go and TypeScript
  • Strong knowledge of authentication protocols including OAuth 2.0, OIDC, and SAML
  • Comfortable with AWS and containerized environments like Kubernetes and Docker
  • Experience leading cross-functional security initiatives from start to finish
  • Participated in or managed external pentests and remediated findings
  • Ability to thrive in ownership and ambiguous situations

Responsibilities

  • Own the secure SDLC end-to-end, including threat modeling and design reviews
  • Coordinate application pentests and ensure findings are addressed
  • Integrate SAST/DAST/SCA tooling into CI/CD workflows
  • Triage and remediate vulnerabilities from various sources
  • Develop and maintain critical security features like encryption services and authentication processes
  • Improve API security and enforce least-privilege practices through production code
  • Investigate and manage security incidents and cloud security hardening

Benefits

  • Work at a core security company with a culture that values security
  • Collaboration with engineers who prioritize security from the design phase
  • Opportunity to mentor peers and elevate the company's security practices
  • Hands-on involvement in building critical security infrastructure
  • Direct influence over security strategies and roadmap
  • Gain experience with a range of security tools and technologies
  • Be part of a proactive security culture rather than a reactive one
Full Job Description
The Role:

Most security engineers spend their careers bolting locks onto doors that were already built. This is not that job.

We're hiring an Application Security Engineer to own security across Opal's product and platform - and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed. You'll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software.

Oh, and one more thing: Opal is a security company. We sell access control to organizations that take security seriously. That means your work isn't a cost center - it's core to what we do.

This role lives on the Platform team and partners closely with Infrastructure Engineering on cloud security. It is explicitly scoped to application and product security - enterprise IT, compliance, and vendor risk management are handled separately.

What You'll Do:

Secure Development Lifecycle -
  • Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews - you set the bar
  • Run and coordinate app pentests (internal and external) and drive findings to closure
  • Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code
  • Triage and remediate vulnerabilities from every angle - bug bounty, internal scans, the works

Software Security Engineering -
  • Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows
  • Own the Auth0 12 Opal integration - tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)
  • Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good
  • Create shared libraries that make the secure path the easy path for every product engineer

Incident Response & Cloud Security -
  • Be first on the scene for security incidents: investigate, contain, find the root cause, fix it
  • Partner with Infra on cloud hardening - AWS IAM, EKS, KMS, network segmentation
  • Level up detection and response by writing detection rules and improving logging and alerting

Security Culture -
  • Mentor engineers on secure coding, common vuln patterns, and security architecture - you make the org smarter
  • Help set the security roadmap by grounding it in real product risk
  • Be the security teammate engineers want to work with - a collaborator, not a bottleneck


You Might Be a Fit If You:
  • Have 4+ years in application security or software security engineering
  • Actually write production code - findings reports are the floor, not the ceiling
  • Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle
  • Are comfortable in AWS and containerized environments (Kubernetes, Docker)
  • Bonus points for familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL
  • Have led complex, cross-functional security initiatives from kickoff to completion
  • Have run or participated in external pentests and seen findings through remediation
  • Thrive on ownership and ambiguity - you'd rather write the playbook than wait for one

About Opal

Opal is a software company that provides a cloud-based collaboration platform for marketing teams. The platform allows teams to manage their marketing campaigns, content, and assets in one place, and provides tools for collaboration, workflow management, and analytics. Opal was founded in 2010 and is headquartered in Seattle, Washington. The company serves customers in a variety of industries, including healthcare, technology, and consumer goods.
Learn more about Opal
Size
200 employees
Industry
Founded
2011

Similar Jobs

More Jobs at Opal

More Information Technology Jobs

Find similar Application Security Engineer jobs: