Infrastructure Security Engineer
Opendoor
About Opendoor At Opendoor our mission is to tilt the world in favor of homeowners and those who aim to become one. Homeownership matters. It's how people build wealth, stability, and community. It's how families put down roots, how neighborhoods strengthen, how the future gets built. We're building the modern system of homeownership giving people the freedom to buy and sell on their own terms. We've built an end-to-end online experience that has already helped thousands of people and we're just getting started. About The Role Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't. As our Infrastructure Security Engineer, you'll own the security of everything Opendoor runs on including multi-account AWS, Kubernetes clusters, the identity plane connecting every system, and the cloud workloads behind home acquisition, resale, mortgage, title, and escrow. There's meaningful work already in motion and real room to define where it goes next.
What You'll Do
• Own the security architecture of our production cloud environment - AWS at the core, spanning multiple accounts, Kubernetes clusters, Terraform-managed infrastructure, and the identity plane that ties everything together.
• Evaluate, build out and operate our cloud security visibility and protection platform ensuring it's deeply integrated into engineering workflows to drive the automated remediation of infrastructure risks.
• Define and drive our zero trust access strategy, integrating device trust and identity-aware proxies to provide seamless, secure access to Opendoor infrastructure.
• Harden our Kubernetes environment including RBAC, admission policies, workload identity, runtime protection, image signing, and base-image strategy on top of our Bottlerocket and Karpenter foundation.
• Build new agentic detection and response workflows using AWS native primitives that close the loop from alert to investigation to remediation.
• Drive a shift-left cloud security strategy within our pipelines using Terraform/Terrakube, GitHub Actions, Elastic Container Registry so that misconfigurations get caught at commit time.
• Partner with the Infrastructure team on cloud-native security decisions: VPC architecture, ingress, secrets management (Vault), service identity, and how Okta extends into AWS, Azure, and GCP.
• Run our cloud detection engineering: GuardDuty, Security Hub, CloudTrail, VPC flow logs - tuned for signal, integrated with Datadog and our incident response playbooks.
• Set the bar for what "secure by default" looks like for AI-maximalist engineering - vibe-coded apps, MCP servers, and agent-driven workflows that touch production cloud infrastructure.
• Mentor engineers across Opendoor on cloud security patterns, and turn the patterns you see into automated guardrails. Tech Stack
• Cloud Platforms: AWS (primary), Azure, GCP
• Containers and Orchestration: EKS, Bottlerocket, Karpenter, Helm, Argo CD
• Identity and Access: Okta, Duo, AWS Identity Center, Okta for Kubernetes, Platform SSO (macOS), HashiCorp Vault
• Cloud Security Tooling: Lambda, GuardDuty, Security Hub, CloudTrail, Elastic Container Registry, VPC Flow Logs, Kinesis, GitHub Advanced Security, cloud security posture and workload protection platform
• Detection and Observability: Datadog, Cribl, S3
• Languages: Go, Python, TypeScript, Ruby, Terraform (HCL), Terrakube (self-hosted)
• AI Tooling: Claude Code, Claude Cowork, OpenAI, Codex, Bedrock, Runlayer MCP, custom agent frameworks What You'll Need
• Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
• Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
• Business enablement security mindset. You measure success by business impact and informed risk taking, not by tickets opened or compliance checklists completed.
• 5+ years of cloud or infrastructure security experience, with deep AWS expertise - you can read a CloudTrail event, write a service control policy, and explain why a particular identity trust policy is dangerous, all in the same conversation.
• Strong skills in at least one of Go, Python, or TypeScript, with the ability to read and write Terraform and shell scripts. You are a builder.
• Hands-on Kubernetes security experience - RBAC, network policies, admission control,workload identity, image and supply-chain security.
• Experience deploying and operating cloud posture and workload protection tooling (Wiz, Prisma, Orca, Datadog, CrowdStrike Falcon Cloud, Lacework, or equivalent) with a strong opinion on what good looks like.
• Identity first security mindset and demonstrated ability to build identity and access management solutions at scale.
• Humility and genuine curiosity. You're as excited to learn from engineers across product and infrastructure and enable their work as you are to write detections or design guardrails. Bonus Points
• Experience designing or operating Zero Trust Network Access (Cloudflare Access, Tailscale, Twingate, Google BeyondCorp, etc.).
• Detection engineering background with a threat modeling and adversarial mindset - writing detections that actually fire on real attacker behavior without burying the team in noise.
• Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations that touch production data.
• Familiarity with SOC 2, SOX, or other compliance frameworks in cloud environments and an instinct for when compliance work creates real security value.
• Open source contributions to cloud security tooling (Cartography, Prowler, ScoutSuite, Falco, Kyverno, Open Policy Agent, Checkov, etc.). Location This role is based in our Miami office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office.
What You'll Do
• Own the security architecture of our production cloud environment - AWS at the core, spanning multiple accounts, Kubernetes clusters, Terraform-managed infrastructure, and the identity plane that ties everything together.
• Evaluate, build out and operate our cloud security visibility and protection platform ensuring it's deeply integrated into engineering workflows to drive the automated remediation of infrastructure risks.
• Define and drive our zero trust access strategy, integrating device trust and identity-aware proxies to provide seamless, secure access to Opendoor infrastructure.
• Harden our Kubernetes environment including RBAC, admission policies, workload identity, runtime protection, image signing, and base-image strategy on top of our Bottlerocket and Karpenter foundation.
• Build new agentic detection and response workflows using AWS native primitives that close the loop from alert to investigation to remediation.
• Drive a shift-left cloud security strategy within our pipelines using Terraform/Terrakube, GitHub Actions, Elastic Container Registry so that misconfigurations get caught at commit time.
• Partner with the Infrastructure team on cloud-native security decisions: VPC architecture, ingress, secrets management (Vault), service identity, and how Okta extends into AWS, Azure, and GCP.
• Run our cloud detection engineering: GuardDuty, Security Hub, CloudTrail, VPC flow logs - tuned for signal, integrated with Datadog and our incident response playbooks.
• Set the bar for what "secure by default" looks like for AI-maximalist engineering - vibe-coded apps, MCP servers, and agent-driven workflows that touch production cloud infrastructure.
• Mentor engineers across Opendoor on cloud security patterns, and turn the patterns you see into automated guardrails. Tech Stack
• Cloud Platforms: AWS (primary), Azure, GCP
• Containers and Orchestration: EKS, Bottlerocket, Karpenter, Helm, Argo CD
• Identity and Access: Okta, Duo, AWS Identity Center, Okta for Kubernetes, Platform SSO (macOS), HashiCorp Vault
• Cloud Security Tooling: Lambda, GuardDuty, Security Hub, CloudTrail, Elastic Container Registry, VPC Flow Logs, Kinesis, GitHub Advanced Security, cloud security posture and workload protection platform
• Detection and Observability: Datadog, Cribl, S3
• Languages: Go, Python, TypeScript, Ruby, Terraform (HCL), Terrakube (self-hosted)
• AI Tooling: Claude Code, Claude Cowork, OpenAI, Codex, Bedrock, Runlayer MCP, custom agent frameworks What You'll Need
• Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
• Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
• Business enablement security mindset. You measure success by business impact and informed risk taking, not by tickets opened or compliance checklists completed.
• 5+ years of cloud or infrastructure security experience, with deep AWS expertise - you can read a CloudTrail event, write a service control policy, and explain why a particular identity trust policy is dangerous, all in the same conversation.
• Strong skills in at least one of Go, Python, or TypeScript, with the ability to read and write Terraform and shell scripts. You are a builder.
• Hands-on Kubernetes security experience - RBAC, network policies, admission control,workload identity, image and supply-chain security.
• Experience deploying and operating cloud posture and workload protection tooling (Wiz, Prisma, Orca, Datadog, CrowdStrike Falcon Cloud, Lacework, or equivalent) with a strong opinion on what good looks like.
• Identity first security mindset and demonstrated ability to build identity and access management solutions at scale.
• Humility and genuine curiosity. You're as excited to learn from engineers across product and infrastructure and enable their work as you are to write detections or design guardrails. Bonus Points
• Experience designing or operating Zero Trust Network Access (Cloudflare Access, Tailscale, Twingate, Google BeyondCorp, etc.).
• Detection engineering background with a threat modeling and adversarial mindset - writing detections that actually fire on real attacker behavior without burying the team in noise.
• Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations that touch production data.
• Familiarity with SOC 2, SOX, or other compliance frameworks in cloud environments and an instinct for when compliance work creates real security value.
• Open source contributions to cloud security tooling (Cartography, Prowler, ScoutSuite, Falco, Kyverno, Open Policy Agent, Checkov, etc.). Location This role is based in our Miami office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office.
Vacancy posted 18 hours ago
Similar jobs that could be interesting for youBased on the Infrastructure Security Engineer in Miami, FL vacancy
- ...Job Title Cloud Security Engineer Location Doral, FL 33122 US (Primary) Category Intelligence Job Type Full-Time Career Level Staff Education Bachelor's Degree Travel Security Clearance Required Secret Job Description Prescient...SuggestedFull timeContract work
- ...mission-driven defensive cyber operations firm delivering security engineering, risk management, and compliance execution for federal and... ...Security Systems (ESS), LENEL platforms, and secure network infrastructure in a mission-critical DoW environment. These are full-...SuggestedFull timeWeekend work
$165k - $175k
...Overview The IT Security Team is looking for a seasoned professional to support a... ...Security Operations Center (SOC) Cloud Engineer is responsible for monitoring, detecting... ...such as Splunk SOAR. Work with infrastructure and DevOps teams to improve visibility...SuggestedHourly payWork experience placementLocal areaRemote workNight shift- ...Job Description Job Description Position: Cloud Security Engineer LCAT: Mid Location: SOUTHCOM HQ, Doral, FL / Off-site Office: U.S. SOUTHERN Command J2 Required clearance: Secret Required education: Bachelor's degree in Cybersecurity, Information...SuggestedTemporary workWork at officeFlexible hours
$115k - $135k
...company is looking for a Network Operations Technician in Miami, Florida. In this role, you will support and modernize networking infrastructure, ensuring 24/7 uptime while collaborating with global IT teams. Candidates should possess strong enterprise networking skills,...Suggested- CARNIVAL CRUISE LINES is hiring a Sr. Application Security Engineer to implement and maintain software security capabilities for their global... ...position will use your expertise in SAST, DAST, and cloud infrastructure to enhance security practices. The ideal candidate should...Remote work
$170.6k - $390k
...world to grow your career in information security! The opportunity The Senior... ...environments, and partnering closely with infrastructure, cloud, application, and security operations... ...as a Senior Manager in Cybersecurity Engineering, where you will play a pivotal role in...Summer holidayRemote workFlexible hours- ...Position: Cloud Security Engineer LCAT: Mid Location: SOUTHCOM HQ, Doral, FL / Off-site Office: U.S. SOUTHERN Command J2 Required clearance: Secret Required education: Bachelor's degree in Cybersecurity, Information Assurance, or a related field, or five...Full timeTemporary workWork at officeFlexible hours
- Kaseya Limited is seeking a Staff Network Engineer in Miami, Florida, responsible for designing, implementing, and maintaining complex network infrastructures across various environments. The role includes managing routers and switches, troubleshooting issues, and optimizing...
- ...government services provider in Miami is seeking an experienced Network Engineer to enhance and maintain a large-scale network infrastructure. Responsibilities include managing network systems, ensuring security, and providing documentation. Ideal candidates will possess a...
- ...Manufacturing Co is looking for an experienced Network Engineer in Miami, Florida. The ideal candidate will operate... ...scale network project, enhancing the reliability and security of wired and wireless infrastructures. The position requires a Bachelor’s degree in a related...
$80k
...Information Security Engineer Description SUKU is seeking an Information Security Engineer specializing in web application... ...security measures to protect our organization's infrastructure from evolving cyber threats. Responsibilities...Immediate startRemote workTrial periodFlexible hours- ...preparation of recurring cybersecurity scorecard data. - Monitor security tools and alerts, performing initial triage and escalating... ..., operating systems, databases, and network/security infrastructure. Job-Specific Minimum Requirements: - 1+ years of experience...Minimum wageContract workTemporary workWork experience placementRemote work
$85k - $105k
...We are seeking an experienced commercial Electronic Security Systems Field Engineer to join our federal team. This is a remote / virtual role with the ability to travel extensively to support project needs for various Department of Defense and other federal government...For subcontractorWork at officeLocal areaRemote workWorldwide- WinsAbove is seeking a Senior Solutions Engineer based in Miami or Austin. The ideal candidate has over 12 years of experience and is passionate about technology, capable of driving technical discussions, and helping customers realize the potential of Cloudflare’s products...
- ...About Iru Iru is the AI-powered security & IT platform used by the world’s fastest-growing companies to secure their users, apps... ...engagement and satisfaction. The Opportunity As a Staff Infrastructure Engineer at Iru, you will be instrumental in architecting and scaling...Full timeWork at office3 days per week
- ...Information System Security Engineer III (ISSE III) We are seeking an Information System Security Engineer III (ISSE III) to support a Navy cybersecurity program. The selected candidate will provide advanced cybersecurity engineering support, capture and refine security...Contract workTemporary workWork at office
- ...CGS is seeking an experienced Network Engineer to join a team focused on the evaluation... ...includes both wired and wireless network infrastructure and related hardware & software. The... ...infrastructure, implementation of network security patches and software/firmware updates,...Full timeLocal areaMonday to FridayFlexible hours
- ...Network Engineer Contract in Miami The Network Engineer is a hands‑on technical leader responsible for designing, securing, and maintaining the organization’s network infrastructure. This role oversees all aspects of network architecture, performance, and security while...Contract work
- (Hiring) Information Systems Security Engineer We are seeking an Information Systems Security Engineer to join our team! You will install and repair alarm wiring and equipment. Responsibilities: Install and program new alarm and security systems Troubleshoot...
- ...Senior Network Engineer Shape the future of defense with MANTECH! Join a team dedicated to safeguarding our nation through advanced... ...connectivity of enterprise network assets, ensuring compliance and secure operations on classified networks (SIPR, NIPR, JWICS)....Work at officeLocal areaNight shift
- ...NETWORK ENGINEER JOB DESCRIPTION JOB SUMMARY The Network Engineer is responsible... ...network systems that support ITS infrastructure-this includes traffic control systems,... ...ensures high availability, reliability, security, and performance of networked systems,...Temporary workWork at officeLocal areaRemote workNight shiftWeekend work
$77.5k - $176k
...Network Engineer The Opportunity: Maintain responsibility for completing site surveys and creating structured designs for the customer's network in support of voice, data, security, and audio and visual systems. Design technical documents such as engineered drawings...Full timeContract workPart timeFor subcontractorWork at officeLocal areaRemote work- ...Network Engineer We are seeking a Network Engineer to become an integral part of our team! You will be responsible for designing... ...other data networks Develop and execute test plans to check infrastructure and system performance Perform network modeling and...Local area
$130k - $180k
...proprietary trading firm, is seeking a Network Engineer to design, implement, and optimize its global network infrastructure. This role requires deep technical expertise... ...in trading environments. Manage security devices , including firewalls , and enforce...Remote workRelocation package- ...joined Zenity because the opportunity to define an entirely new security category was too compelling to pass up. Securing AI agents at... ...articulate Zenity’s value to both technical (security, engineering) and business stakeholders Contribute to deal strategy, including...
- ...Technology and Communications consulting, system engineering, integration, deployment and operation of... ...responsible for planning, designing, implementing, securing, and maintaining classified enterprise network infrastructure supporting mission-critical Department of...Full timeTemporary workPart timeWork at officeShift work
- ...Senior Network Engineer Miami, FL Imagine the ultimate destination for those who... ...cutting edge of technology, energy, and infrastructure. Hut 8 is on a mission to build and operate... ...networking, storage integration, and secure multi-tenant AI environments. The...Temporary workWork at office
- ...Network Engineer The Network Engineer is responsible for supporting the network infrastructure, administration of equipment, such as routers, switches and firewalls, and... ...images service packs, patches, hot fixes and security configurations), replacing failed...For contractorsLocal areaRemote workRelocationWeekend workAfternoon shift
$130k
...Job Description Senior Network Engineer Doral, Florida Employment Type:... ...Sensitive Compartmented Information (TS/SCI) security clearance Ability to work onsite in... ...managing classified network infrastructure with minimal supervision. The Senior...Full timeImmediate startNight shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Infrastructure Security Engineer. Be the first to apply!
Related searches
- security infrastructure engineer Miami, FL
- infrastructure engineer Miami, FL
- data infrastructure engineer Miami, FL
- infrastructure engineering manager Miami, FL
- senior infrastructure engineer Miami, FL
- remote infrastructure engineer Miami, FL
- infrastructure developer Miami, FL
- senior application security engineer Miami, FL
- IT security engineer Miami, FL
- network security engineer Miami, FL


