Application Security Engineer
Opendoor
About Opendoor At Opendoor our mission is to tilt the world in favor of homeowners and those who aim to become one. Homeownership matters. It's how people build wealth, stability, and community. It's how families put down roots, how neighborhoods strengthen, how the future gets built. We're building the modern system of homeownership giving people the freedom to buy and sell on their own terms. We've built an end-to-end online experience that has already helped thousands of people and we're just getting started. About The Role Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't. As our Application Security Engineer, you'll own how we find, prioritize, and drive down application-layer risk across the consumer flows that put cash offers in homeowners' hands, the GraphQL APIs that power our products, and the AI agents and vibe-coded tools our engineers ship every week. The job is to make it safe to build fast, not to slow things down.
What You'll Do
• Define, build and operate Opendoor's application vulnerability identification capability - the tooling, triage workflow and remediation techniques across our consumer products, internal admin tools and GraphQL API powering home acquisition, resale, mortgage, title and escrow.
• Assess, rationalize and own our AppSec tooling stack - static and dynamic security testing, software supply chain risk detection and secrets scanning and integrate findings into developer workflows where engineers already live (GitHub, Linear, Slack).
• Own and mature our HackerOne program: tightening the triage workflow, improving signal to noise on incoming reports, strengthening researcher relationships and closing the loop with engineering teams so root causes get addressed quickly.
• Lead threat modeling and security design reviews for new services, APIs, and mobile features. Turn the patterns you see into rules, lint checks, and CI guardrails so the next team doesn't make the same mistake.
• Build AI agents and automated workflows that triage vulnerability reports, validate exploit reproductions, and draft remediation pull requests, replacing manual security review with high-signal automation.
• Partner with engineering teams to harden authentication, authorization, and input validation across our codebase and production services, including the GraphQL gateway (Apollo) and our Kubernetes workloads - while driving a shift-left strategy that catches vulnerabilities before they ship.
• Build Opendoor's offensive security capability. Scope and run internal security testing, red team exercises and adversarial analysis of our highest-risk flows ensuring findings directly harden detection and response.
• Set the bar for what "secure by default" looks like for AI-maximalist engineering, including vibe-coded apps, MCP servers, and agent-driven workflows that touch production data.
• Build Opendoor's security culture by establishing secure design standards, embedding into engineering team rituals and developing a strong security mindset - creating a foundation for engineers to think like attackers without slowing down.
Tech Stack
• Languages: Go, Python, TypeScript, Ruby, Terraform
• Cloud: AWS, GCP, Azure, Kubernetes, Apollo GraphQL
• AppSec Tooling: GitHub Advanced Security (CodeQL, Dependabot, secret scanning), Semgrep, HackerOne, Burp Suite, Cloudflare WAF
• AI Tooling: Claude, OpenAI, various agent frameworks, MCP - used heavily for vulnerability triage, exploit verification, and remediation drafting What You'll Need
• Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
• Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
• Business enablement security mindset. You measure success by business impact and informed risk-taking, not by tickets opened or pen test reports filed.
• 5+ years of application security or software engineering experience with a security focus, with strong skills in at least one of Python, Go, TypeScript, or Ruby, and the ability to read and write code across the others.
• Hands-on expertise across the security risk detection toolchain with real deployment experience using GitHub Advanced Security, Semgrep, or equivalent.
• Strong grasp of common application and API vulnerability classes including GraphQL, REST, and gRPC security pitfalls - broken authorization, mass assignment, introspection exposure, insecure direct object references.
• Practical threat modeling skills. You can take an architecture diagram and a 30-minute conversation and walk out with the three things that actually matter.
• Experience with cloud and container security on AWS and Kubernetes, including identity and access management, secrets management, and continuous integration / continuous deployment pipeline security.
• Humility and genuine curiosity. You're as excited to learn from product engineers and enable their work as you are to break things. Bonus Points
• Offensive security experience including pentesting, API security, or mobile security, and/or red team operations.
• Experience running a bug bounty or coordinated disclosure program at scale.
• Mobile application security review experience (iOS and Android).
• Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations.
• OSCP, OSWE, or similar offensive certifications. Location This role is based in our downtown Miami office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office.
What You'll Do
• Define, build and operate Opendoor's application vulnerability identification capability - the tooling, triage workflow and remediation techniques across our consumer products, internal admin tools and GraphQL API powering home acquisition, resale, mortgage, title and escrow.
• Assess, rationalize and own our AppSec tooling stack - static and dynamic security testing, software supply chain risk detection and secrets scanning and integrate findings into developer workflows where engineers already live (GitHub, Linear, Slack).
• Own and mature our HackerOne program: tightening the triage workflow, improving signal to noise on incoming reports, strengthening researcher relationships and closing the loop with engineering teams so root causes get addressed quickly.
• Lead threat modeling and security design reviews for new services, APIs, and mobile features. Turn the patterns you see into rules, lint checks, and CI guardrails so the next team doesn't make the same mistake.
• Build AI agents and automated workflows that triage vulnerability reports, validate exploit reproductions, and draft remediation pull requests, replacing manual security review with high-signal automation.
• Partner with engineering teams to harden authentication, authorization, and input validation across our codebase and production services, including the GraphQL gateway (Apollo) and our Kubernetes workloads - while driving a shift-left strategy that catches vulnerabilities before they ship.
• Build Opendoor's offensive security capability. Scope and run internal security testing, red team exercises and adversarial analysis of our highest-risk flows ensuring findings directly harden detection and response.
• Set the bar for what "secure by default" looks like for AI-maximalist engineering, including vibe-coded apps, MCP servers, and agent-driven workflows that touch production data.
• Build Opendoor's security culture by establishing secure design standards, embedding into engineering team rituals and developing a strong security mindset - creating a foundation for engineers to think like attackers without slowing down.
Tech Stack
• Languages: Go, Python, TypeScript, Ruby, Terraform
• Cloud: AWS, GCP, Azure, Kubernetes, Apollo GraphQL
• AppSec Tooling: GitHub Advanced Security (CodeQL, Dependabot, secret scanning), Semgrep, HackerOne, Burp Suite, Cloudflare WAF
• AI Tooling: Claude, OpenAI, various agent frameworks, MCP - used heavily for vulnerability triage, exploit verification, and remediation drafting What You'll Need
• Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
• Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
• Business enablement security mindset. You measure success by business impact and informed risk-taking, not by tickets opened or pen test reports filed.
• 5+ years of application security or software engineering experience with a security focus, with strong skills in at least one of Python, Go, TypeScript, or Ruby, and the ability to read and write code across the others.
• Hands-on expertise across the security risk detection toolchain with real deployment experience using GitHub Advanced Security, Semgrep, or equivalent.
• Strong grasp of common application and API vulnerability classes including GraphQL, REST, and gRPC security pitfalls - broken authorization, mass assignment, introspection exposure, insecure direct object references.
• Practical threat modeling skills. You can take an architecture diagram and a 30-minute conversation and walk out with the three things that actually matter.
• Experience with cloud and container security on AWS and Kubernetes, including identity and access management, secrets management, and continuous integration / continuous deployment pipeline security.
• Humility and genuine curiosity. You're as excited to learn from product engineers and enable their work as you are to break things. Bonus Points
• Offensive security experience including pentesting, API security, or mobile security, and/or red team operations.
• Experience running a bug bounty or coordinated disclosure program at scale.
• Mobile application security review experience (iOS and Android).
• Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations.
• OSCP, OSWE, or similar offensive certifications. Location This role is based in our downtown Miami office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Application Security Engineer in Miami, FL vacancy
$140k - $200k
...Senior Application Security Engineer New York, New York; Miami, Florida; Remote (USA) Gemini is a global crypto and Web3 platform founded by Cameron and Tyler Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to...SuggestedWork at officeRemote workFlexible hours- ...Application Engineer/Customer Service Representative Ryan Herco Flow Solutions is the leading nation-wide distributor of fluid handling products providing ultrapure, corrosion-resistant fluid handling systems and expertise. We sell to a broad base of customers in industries...SuggestedHourly payFor contractorsWork experience placement
- ...Intune / Application Packaging Engineer Miami, FL (5 days onsite) Notes ~ They are seeking an experienced Intune / Application Packaging Engineer to support enterprise endpoint management and software deployment initiatives. ~ This role will be responsible...Suggested
- Kforce has a client that is seeking an Intune/Application Packaging Engineer Miami, FL. Summary: We are seeking an Intune/Application Packaging... ...technologies while partnering closely with infrastructure, security, and desktop engineering teams. Key Responsibilities: *...SuggestedTemporary work
- Applications Engineer Position OverviewWe are seeking an Applications Engineer to provide technical expertise and hands-on support for CNC systems and machining solutions. The role focuses on customer-facing engineering activities including CNC installation and commissioning...Suggested
- ...leading innovator in professional audio technology is seeking an Application Engineer to support the deployment, commissioning, optimization, and... ...arrangements, and a comprehensive benefits package designed to support wellbeing, financial security, and a productive work setupFlexible hours
- ...Title : Network Security Engineer Location : Miami, FL Hybrid Need local 12+ Months Contract Job Description - Specialization... ...with technical profiles such as Miguel Gallego, if applicable to the project # Added Value of the Profile...Contract workLocal areaRemote work
$4,500 - $5,800 per week
...Job Description At Citadel, Quantitative Research Engineers work closely with Quantitative Researchers to develop and implement automated... .... You will be able to indicate your timing preference in the application. Your Objectives Design, develop, test, and deploy...InternshipFlexible hours- ...Job Description Job Description In this role, you’ll partner closely with engineering, platform, and AI teams to design and enforce security controls for agentic AI–driven eCommerce experiences. Day to day, you’ll define runtime authorization and identity models for...
- ...years of experince on knowledge on Restful web services and Bootstrap/Angular • At least 4 years of experience in building web applications for mobile devices • At least 4 years of experience in developing applications based in Core Java, J2EE • At least 4 years...Permanent employmentFull timeH1b
- ...Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions... ..., consumable security services, and expert consultation to engineering teams for secure cloud and non-cloud infrastructure. The Role:...Full time
- ...Job Description Job Description AI Security Engineer Specialist North Point Technology is seeking an experienced AI Security Engineer Specialist to design, deploy, and optimize artificial intelligence solutions within cybersecurity operations. This role focuses...
- ...Become a Part of the Adventure! If you are a talented Software Engineer professional interested in working in the exciting field of... ...-engineer, and document source code of proprietary testbench applications. Organize, analyze, and interpret technical data and...For contractors
- (Hiring) Information Systems Security Engineer We are seeking an Information Systems Security Engineer to join our team! You will install and repair alarm wiring and equipment. Responsibilities: Install and program new alarm and security systems Troubleshoot...
- ...make an impact where it matters most. About the Role As a Design Engineer at Onebrief, you are the bridge between Product Design and... ...prototypes, and specs. Eligible for and able to obtain a U.S. security clearance (U.S. citizenship required). Bonus Background in mapping...Remote work
- ...fostering their growth and understanding of industry best practices and conduct Code reviews • Craft high-quality, scalable, and secure code. • Design and develop consumer-driven APIs that follow API-first design principles. • Would like experience with: 1)...Contract workRemote work
- ...Responsibilities Design and develop a highly-reliable Windows desktop application Architect voice communications platform for call... ...technologies Education: Bachelor's Degree in Computer Science or Electrical Engineering is required, Master's preferred....
- ...Role As a Software Engineer, Backend and Infrastructure, you will build the mission-critical backend powering our medical AI platform... ...reliability and data platforms with autonomy to shape performance, security, and infrastructure design for sensitive medical data. We...Full timeWorldwide
$18 - $50 per hour
...graduation and completion of the program Position Overview: As a Thermo-Mechanical Product Engineering Intern , you will support the development and application of Simcenter Simlab(Formerly known as Altair Simlab) by evaluating existing workflows and helping build...Remote jobHourly payFull timeInternshipWork at officeLocal area- ...of our largest clients in all of South Florida. This role is pivotal in transitioning functionality from our home grown billing application to Salesforce, ensuring seamless integration and maintaining current operations. The ideal candidate will possess strong.NET skills...Full timeContract work
- ...Claude Code, GitHub Copilot, Cursor, or similar) to accelerate application development, generate boilerplate, and scaffold features ~... ...tools ~ Experience reviewing and validating AI-generated code for correctness, security, and maintainability in production...Contract work
- ...Minimum 9 years of customization experience as a Lead Software Engineer - Salesforce. At least 3 years of prior experience in a... ...Minimum 3 years of experience in building LWC and lightning applications. In-depth technical expertise in Salesforce, including Sales...
- ANTI is the first functional beverage for hangovers. "Avoid a hangover for only $5?!" our consumers ask. Not only is ANTI the most convenient solution available (it's part of your drink!), but it's the only one that is actually an enjoyable part of the drinking experience...Full timePart timeInternshipRemote workFlexible hours
- ...About Iru Iru is the AI-powered security & IT platform used by the world’s fastest-... ...The Opportunity As a Senior Software Engineer (Full‑Stack, Front‑End Dominant) on Iru... ...experience building complex web applications with clear ownership of architecture decisions...Full timeWork at office3 days per week
- ...high reliability expectations, requires an engineer whose primary mandate is reliability,... ...disciplines. Work closely with product, platform, security, compliance, and other engineering teams... ...~ Relocation Assistance Package, if applicable. Work Model for this Role Hybrid...Full timeWork at officeWork from homeRelocation packageFlexible hours
- ...Title: DevOps Test Automation Engineer Location : Miami, FL (3 days onsite Monday, Tues, Wed) Type: 8+months Job discription ~ This is not a traditional QA role. It is an engineering role focused on DevOps, SRE, test automation, reliability, infrastructure...
$140k - $200k
...Winklevoss in 2014, offering a wide range of simple, reliable, and secure crypto products and services to individuals and institutions in... ...is unsafe, we fix it. The Role: Senior Software Engineer We're looking for a Senior Software Engineer to join a team...Full timeWork at officeRemote workFlexible hours- ...About Iru Iru is the AI-powered security & IT platform used by the world’s fastest-growing... ...The Opportunity As a Senior Software Engineer (Full-Stack) on Iru's Customer... ...and inclusion in the workplace. Qualified applicants will be considered for employment without...Full timeWork at office3 days per week
$140k - $200k
...offering a wide range of simple, reliable, and secure crypto products and services to... ...Predictions The Role: Senior Software Engineer (Mobile) As a Senior Mobile Engineer on... ...including 4+ years building production mobile applications with React Native. ~ Strong...Full timeContract workWork at officeRemote workFlexible hours- ...Description POSITION SUMMARY: The Image Processing Software Engineer is responsible for developing medical imaging software that... ...in Computer Science or a related field with an emphasis on application development ~3 or more years of software development experience...Local areaMonday to Friday
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer. Be the first to apply!
Related searches
- field applications engineer Miami, FL
- technical application engineer Miami, FL
- hydraulic application engineer Miami, FL
- application engineering manager Miami, FL
- junior application support engineer Miami, FL
- project application engineer Miami, FL
- senior application security engineer Miami, FL
- application security engineer Miami, FL
- application operations engineer Miami, FL
- senior application support engineer Miami, FL




