Infrastructure Security Engineer
$195.2k - $244kOpendoor
About Opendoor At Opendoor our mission is to tilt the world in favor of homeowners and those who aim to become one. Homeownership matters. It's how people build wealth, stability, and community. It's how families put down roots, how neighborhoods strengthen, how the future gets built. We're building the modern system of homeownership giving people the freedom to buy and sell on their own terms. We've built an end-to-end online experience that has already helped thousands of people and we're just getting started. About The Role Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't. As our Infrastructure Security Engineer, you'll own the security of everything Opendoor runs on including multi-account AWS, Kubernetes clusters, the identity plane connecting every system, and the cloud workloads behind home acquisition, resale, mortgage, title, and escrow. There's meaningful work already in motion and real room to define where it goes next.
What You'll Do
• Own the security architecture of our production cloud environment - AWS at the core, spanning multiple accounts, Kubernetes clusters, Terraform-managed infrastructure, and the identity plane that ties everything together.
• Evaluate, build out and operate our cloud security visibility and protection platform ensuring it's deeply integrated into engineering workflows to drive the automated remediation of infrastructure risks.
• Define and drive our zero trust access strategy, integrating device trust and identity-aware proxies to provide seamless, secure access to Opendoor infrastructure.
• Harden our Kubernetes environment including RBAC, admission policies, workload identity, runtime protection, image signing, and base-image strategy on top of our Bottlerocket and Karpenter foundation.
• Build new agentic detection and response workflows using AWS native primitives that close the loop from alert to investigation to remediation.
• Drive a shift-left cloud security strategy within our pipelines using Terraform/Terrakube, GitHub Actions, Elastic Container Registry so that misconfigurations get caught at commit time.
• Partner with the Infrastructure team on cloud-native security decisions: VPC architecture, ingress, secrets management (Vault), service identity, and how Okta extends into AWS, Azure, and GCP.
• Run our cloud detection engineering: GuardDuty, Security Hub, CloudTrail, VPC flow logs - tuned for signal, integrated with Datadog and our incident response playbooks.
• Set the bar for what "secure by default" looks like for AI-maximalist engineering - vibe-coded apps, MCP servers, and agent-driven workflows that touch production cloud infrastructure.
• Mentor engineers across Opendoor on cloud security patterns, and turn the patterns you see into automated guardrails. Tech Stack
• Cloud Platforms: AWS (primary), Azure, GCP
• Containers and Orchestration: EKS, Bottlerocket, Karpenter, Helm, Argo CD
• Identity and Access: Okta, Duo, AWS Identity Center, Okta for Kubernetes, Platform SSO (macOS), HashiCorp Vault
• Cloud Security Tooling: Lambda, GuardDuty, Security Hub, CloudTrail, Elastic Container Registry, VPC Flow Logs, Kinesis, GitHub Advanced Security, cloud security posture and workload protection platform
• Detection and Observability: Datadog, Cribl, S3
• Languages: Go, Python, TypeScript, Ruby, Terraform (HCL), Terrakube (self-hosted)
• AI Tooling: Claude Code, Claude Cowork, OpenAI, Codex, Bedrock, Runlayer MCP, custom agent frameworks What You'll Need
• Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
• Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
• Business enablement security mindset. You measure success by business impact and informed risk taking, not by tickets opened or compliance checklists completed.
• 5+ years of cloud or infrastructure security experience, with deep AWS expertise - you can read a CloudTrail event, write a service control policy, and explain why a particular identity trust policy is dangerous, all in the same conversation.
• Strong skills in at least one of Go, Python, or TypeScript, with the ability to read and write Terraform and shell scripts. You are a builder.
• Hands-on Kubernetes security experience - RBAC, network policies, admission control,workload identity, image and supply-chain security.
• Experience deploying and operating cloud posture and workload protection tooling (Wiz, Prisma, Orca, Datadog, CrowdStrike Falcon Cloud, Lacework, or equivalent) with a strong opinion on what good looks like.
• Identity first security mindset and demonstrated ability to build identity and access management solutions at scale.
• Humility and genuine curiosity. You're as excited to learn from engineers across product and infrastructure and enable their work as you are to write detections or design guardrails. Bonus Points
• Experience designing or operating Zero Trust Network Access (Cloudflare Access, Tailscale, Twingate, Google BeyondCorp, etc.).
• Detection engineering background with a threat modeling and adversarial mindset - writing detections that actually fire on real attacker behavior without burying the team in noise.
• Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations that touch production data.
• Familiarity with SOC 2, SOX, or other compliance frameworks in cloud environments and an instinct for when compliance work creates real security value.
• Open source contributions to cloud security tooling (Cartography, Prowler, ScoutSuite, Falco, Kyverno, Open Policy Agent, Checkov, etc.). Location This role is based in our Seattle office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office. The pay range for this role is: 195,200 - 244,000 USD per year (US Zone 2)
What You'll Do
• Own the security architecture of our production cloud environment - AWS at the core, spanning multiple accounts, Kubernetes clusters, Terraform-managed infrastructure, and the identity plane that ties everything together.
• Evaluate, build out and operate our cloud security visibility and protection platform ensuring it's deeply integrated into engineering workflows to drive the automated remediation of infrastructure risks.
• Define and drive our zero trust access strategy, integrating device trust and identity-aware proxies to provide seamless, secure access to Opendoor infrastructure.
• Harden our Kubernetes environment including RBAC, admission policies, workload identity, runtime protection, image signing, and base-image strategy on top of our Bottlerocket and Karpenter foundation.
• Build new agentic detection and response workflows using AWS native primitives that close the loop from alert to investigation to remediation.
• Drive a shift-left cloud security strategy within our pipelines using Terraform/Terrakube, GitHub Actions, Elastic Container Registry so that misconfigurations get caught at commit time.
• Partner with the Infrastructure team on cloud-native security decisions: VPC architecture, ingress, secrets management (Vault), service identity, and how Okta extends into AWS, Azure, and GCP.
• Run our cloud detection engineering: GuardDuty, Security Hub, CloudTrail, VPC flow logs - tuned for signal, integrated with Datadog and our incident response playbooks.
• Set the bar for what "secure by default" looks like for AI-maximalist engineering - vibe-coded apps, MCP servers, and agent-driven workflows that touch production cloud infrastructure.
• Mentor engineers across Opendoor on cloud security patterns, and turn the patterns you see into automated guardrails. Tech Stack
• Cloud Platforms: AWS (primary), Azure, GCP
• Containers and Orchestration: EKS, Bottlerocket, Karpenter, Helm, Argo CD
• Identity and Access: Okta, Duo, AWS Identity Center, Okta for Kubernetes, Platform SSO (macOS), HashiCorp Vault
• Cloud Security Tooling: Lambda, GuardDuty, Security Hub, CloudTrail, Elastic Container Registry, VPC Flow Logs, Kinesis, GitHub Advanced Security, cloud security posture and workload protection platform
• Detection and Observability: Datadog, Cribl, S3
• Languages: Go, Python, TypeScript, Ruby, Terraform (HCL), Terrakube (self-hosted)
• AI Tooling: Claude Code, Claude Cowork, OpenAI, Codex, Bedrock, Runlayer MCP, custom agent frameworks What You'll Need
• Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
• Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
• Business enablement security mindset. You measure success by business impact and informed risk taking, not by tickets opened or compliance checklists completed.
• 5+ years of cloud or infrastructure security experience, with deep AWS expertise - you can read a CloudTrail event, write a service control policy, and explain why a particular identity trust policy is dangerous, all in the same conversation.
• Strong skills in at least one of Go, Python, or TypeScript, with the ability to read and write Terraform and shell scripts. You are a builder.
• Hands-on Kubernetes security experience - RBAC, network policies, admission control,workload identity, image and supply-chain security.
• Experience deploying and operating cloud posture and workload protection tooling (Wiz, Prisma, Orca, Datadog, CrowdStrike Falcon Cloud, Lacework, or equivalent) with a strong opinion on what good looks like.
• Identity first security mindset and demonstrated ability to build identity and access management solutions at scale.
• Humility and genuine curiosity. You're as excited to learn from engineers across product and infrastructure and enable their work as you are to write detections or design guardrails. Bonus Points
• Experience designing or operating Zero Trust Network Access (Cloudflare Access, Tailscale, Twingate, Google BeyondCorp, etc.).
• Detection engineering background with a threat modeling and adversarial mindset - writing detections that actually fire on real attacker behavior without burying the team in noise.
• Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations that touch production data.
• Familiarity with SOC 2, SOX, or other compliance frameworks in cloud environments and an instinct for when compliance work creates real security value.
• Open source contributions to cloud security tooling (Cartography, Prowler, ScoutSuite, Falco, Kyverno, Open Policy Agent, Checkov, etc.). Location This role is based in our Seattle office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office. The pay range for this role is: 195,200 - 244,000 USD per year (US Zone 2)
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Infrastructure Security Engineer in Seattle, WA vacancy
- ...solutions, tested leadership, and trusted results to enable national security missions worldwide. Job Description This position is... ...upon award of contract SOSi is seeking a Cloud Security Engineer to support mission requirements for a structured approach to further...SuggestedFull timeContract workRemote workWorldwide
- ...Cloud Network Security Engineer Location: Bellevue, WA Key Responsibilities: IaC Security Scanning & Hardening: Integrate IaC security scanning tools (e.g., Checkov, TFSec, Snyk IaC, Terraform Validator) into CI/CD pipelines. Analyze and remediate findings from...Suggested
$175k - $308.5k
...Senior Cloud Security Engineer Apple Services Engineering (ASE), the team behind iCloud and Media services and the infrastructure that powers it, is looking for a Senior Security Engineer to partner with engineering teams working on new products and features. You will...SuggestedRelocation$162k - $235k
...looking for We're searching for a Senior Cloud Security EngineerYou will be part of the Cloud Security engineering team dedicated to building resilient,... ...scale. Cloud security collaborates with infrastructure and application teams closely. The areas we cover...SuggestedWork at officeLocal area3 days per week$187k - $220k
...Senior Cloud Security Engineer Bellevue, WA Join Us In Building The Future Of Finance Our mission is to democratize finance for... ...be part of a team which owns the security posture for cloud infrastructure on which all Robinhood products are built You will build...SuggestedWork at officeFlexible hoursShift work3 days per week$130k - $155k
...00.00/yr About Ascendion Ascendion is a full-service digital engineering solutions company. We make and manage software platforms and products... ...to be their best at Ascendion. About the Role Job Title: Security Engineer/ Azure Security Engineer At least 10 years combined...Full timeTemporary workWork experience placement$165k - $242k
...startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate... ...in March 2025. Learn more at What You'll Do As a Cloud Security Engineer at CoreWeave, you'll drive the security related efforts related...Permanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$234.4k - $385k
...About the Team Security is at the foundation of OpenAI's mission to ensure that artificial general intelligence benefits all of humanity... ...security culture. About the Role As a Security Engineer, Application Security you will be responsible for identifying and...Work at officeRemote workRelocation package$104k - $156k
Posting Type Remote/Hybrid Job Overview The Advanced Security Engineer is a technically deep, hands-on practitioner who forms the operational... ...development lifecycle, software engineering practices or infrastructure as code environments: contributing endpoint or network...Remote work$157k - $185k
...Security Engineer, Application Security Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth...Work at officeFlexible hoursShift work3 days per week- ...Principal Cloud Security Architect About the Role What if your deep knowledge of cloud security architecture could directly protect organizations from the risks they don't even know they have? We're looking for a Principal Cloud Security Architect to evaluate...Ongoing contractContract workFreelanceRemote workFlexible hours
- ...Security Engineer This is where security meets innovation at enterprise scale. As a security engineer, applications at WRITER, you'll... ...You'll work at the intersection of application security, AI infrastructure, and developer enablement—partnering with engineering teams...Full timeLocal areaFlexible hours
- ...cybersecurity team where your expertise in cryptographic infrastructure and secure hardware directly protects the financial systems trusted by... ...millions of people around the globe. As a Sr Lead Security Engineer at JPMorganChase within the Cybersecurity & Technology...
$130.82k - $163.53k
...Armada is the hyperscaler for the edge, delivering modular AI infrastructure from first deployment to AI factory with speed, scale and... ...around the world. About the Role You will own security engineering across our Azure cloud, hybrid infrastructure, and edge computing...Full timeWork at officeFlexible hours$155k - $410k
...work to identify vulnerabilities, develop secure systems, and provide proactive... ...Preferred Fields of Study: Computer Engineering, Computer Applications, Computer Programming... ...secure-by-design cloud landing zones and Infrastructure-as-Code standards, enabling rapid, scalable...Temporary work$175k - $308.5k
...Senior Security Engineer Apple Services Engineering (ASE), the team behind iCloud services and the infrastructure that powers it, is looking for a Senior Security Engineer to partner with engineering teams working on new products and features. You will collaborate with...Relocation$237.6k - $297k
...We are seeking a Senior Security Engineer with a specialty in Detection and Incident Response to join our Security Engineering team. This role sits at the intersection of security operations and software engineering - you won't just investigate incidents, you'll build...Full time$168k - $210k
...on our promise to customers sending money globally, providing secure, simple, and reliable ways to manage their money, ensuring true... ...About the Role: We're searching for an early career Security Engineer to join Remitly's Threat Detection & Response Team. This role...Work at officeWorldwideFlexible hours3 days per week$158.8k - $238.2k
...Security Engineer Stripe is a financial infrastructure platform for businesses. Millions of companies - from the world's largest enterprises to the most ambitious startups - use Stripe to accept payments, grow their revenue, and accelerate new business opportunities...Work at officeLocal areaRemote work$127.35k
...availability, scalable, cloud-based systems with a strong focus on security. You will respond to and investigate escalated security... ...books and occasionally draft incident reports for leadership. Engineer solutions to address current security attack methods and detection...Work experience placementWork from home- ...journey to create a better future of work with AI. About the role Join WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's transforming how the world works. You'll build sophisticated detection systems...Full timeWork at officeLocal areaFlexible hours
- ...Tech Engineer We are an innovative performance apparel company for yoga, running, training, and other athletic pursuits. Setting the... ...required to provide on-call support when necessary. A strong focus on security is essential for success in this role, as you'll be involved in...
- ...Job Title: IAM Security Engineer Location: Seattle, WA 98101 (Onsite - 4 days/week) Duration: 03-month contract (with possible... ...human identities, such as service principals in Azure or Cloud Infrastructure platform (AWS, GCP, Oracle), ensuring they adhere to the...Contract workMonday to Friday
$139.5k - $258.1k
...Senior Security Engineer - Red Team We are the Apple Services Engineering (ASE) Security Red Team. We focus on deep technical security review work of critical ASE services and infrastructure. These security reviews will be scoped and focused on review depth and quality...RelocationShift work- ...goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands... ...to push the frontier forward. The Security Team Examples of key problems the team... .... You've partnered with network engineering without becoming the department of no....Live in
$160k - $210k
...Senior Security Engineer Seattle, Washington, United States Variant Bio is developing life-saving therapies by studying the genes... ...build and monitor the systems that safeguard our products and infrastructure, along with the privacy of the people who work with us....Flexible hours$300k - $405k
...Security Engineer, Detection & Response San Francisco, CA | New York City, NY | Seattle, WA; Washington, DC About Anthropic Anthropic... ...Experience with threat intelligence, malware analysis, infrastructure as code, detection engineering, or forensics Experience...Work at officeVisa sponsorshipFlexible hours$165k - $242k
...Offensive Security Engineer Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential Cloud for AI™. Built... ..., and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs...Permanent employmentTemporary workCasual workWork at officeFlexible hours- ...Security Engineer We are looking for a highly motivated individual with information security experience who is willing to collaborate with others to build the best in class security program. As a Security Engineer at Hive, you will work to protect sensitive company...Work experience placement
$174k - $239k
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential... ...AI by building the trusted, neutral infrastructure that enables organizations to safely embrace... ...We are looking for a Staff Software Engineer that will join the Auth0 Security...Permanent employmentLocal areaWorldwideFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Infrastructure Security Engineer. Be the first to apply!
Related searches
- senior infrastructure engineer Seattle, WA
- infrastructure engineer Seattle, WA
- infrastructure developer Seattle, WA
- principal infrastructure engineer Seattle, WA
- remote infrastructure engineer Seattle, WA
- infrastructure engineering manager Seattle, WA
- data infrastructure engineer Seattle, WA
- senior cloud security engineer Seattle, WA
- IT security engineer Seattle, WA
- sr information security engineer Seattle, WA

