Infrastructure Security Engineer
Opendoor - Seattle, WA, US
Infrastructure Security Engineer
Our Security Engineering team builds intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity. We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't.
As our Infrastructure Security Engineer, you'll own the security of everything Opendoor runs on including multi-account AWS, Kubernetes clusters, the identity plane connecting every system, and the cloud workloads behind home acquisition, resale, mortgage, title, and escrow. There's meaningful work already in motion and real room to define where it goes next.
What You'll Do
Own the security architecture of our production cloud environment - AWS at the core, spanning multiple accounts, Kubernetes clusters, Terraform-managed infrastructure, and the identity plane that ties everything together.
Evaluate, build out and operate our cloud security visibility and protection platform ensuring it's deeply integrated into engineering workflows to drive the automated remediation of infrastructure risks.
Define and drive our zero trust access strategy, integrating device trust and identity-aware proxies to provide seamless, secure access to Opendoor infrastructure.
Harden our Kubernetes environment including RBAC, admission policies, workload identity, runtime protection, image signing, and base-image strategy on top of our Bottlerocket and Karpenter foundation.
Build new agentic detection and response workflows using AWS native primitives that close the loop from alert to investigation to remediation.
Drive a shift-left cloud security strategy within our pipelines using Terraform/Terrakube, GitHub Actions, Elastic Container Registry so that misconfigurations get caught at commit time.
Partner with the Infrastructure team on cloud-native security decisions: VPC architecture, ingress, secrets management (Vault), service identity, and how Okta extends into AWS, Azure, and GCP.
Run our cloud detection engineering: GuardDuty, Security Hub, CloudTrail, VPC flow logs — tuned for signal, integrated with Datadog and our incident response playbooks.
Set the bar for what "secure by default" looks like for AI-maximalist engineering — vibe-coded apps, MCP servers, and agent-driven workflows that touch production cloud infrastructure.
Mentor engineers across Opendoor on cloud security patterns, and turn the patterns you see into automated guardrails.
Tech Stack
Cloud Platforms: AWS (primary), Azure, GCP
Containers and Orchestration: EKS, Bottlerocket, Karpenter, Helm, Argo CD
Identity and Access: Okta, Duo, AWS Identity Center, Okta for Kubernetes, Platform SSO (macOS), HashiCorp Vault
Cloud Security Tooling: Lambda, GuardDuty, Security Hub, CloudTrail, Elastic Container Registry, VPC Flow Logs, Kinesis, GitHub Advanced Security, cloud security posture and workload protection platform
Detection and Observability: Datadog, Cribl, S3
Languages: Go, Python, TypeScript, Ruby, Terraform (HCL), Terrakube (self-hosted)
AI Tooling: Claude Code, Claude Cowork, OpenAI, Codex, Bedrock, Runlayer MCP, custom agent frameworks
What You'll Need
Deep conviction that AI and automation should eliminate manual work and increase the team's impact, and a track record to prove it. You've built agentic systems that replaced reactive security work, not just configured off-the-shelf tools.
Comfort operating with high autonomy in ambiguous environments. You've defined what "good" looks like in a domain where no playbook existed, you're energized by that, not unsettled by it.
Business enablement security mindset. You measure success by business impact and informed risk taking, not by tickets opened or compliance checklists completed.
5+ years of cloud or infrastructure security experience, with deep AWS expertise - you can read a CloudTrail event, write a service control policy, and explain why a particular identity trust policy is dangerous, all in the same conversation.
Strong skills in at least one of Go, Python, or TypeScript, with the ability to read and write Terraform and shell scripts. You are a builder.
Hands-on Kubernetes security experience — RBAC, network policies, admission control, workload identity, image and supply-chain security.
Experience deploying and operating cloud posture and workload protection tooling (Wiz, Prisma, Orca, Datadog, CrowdStrike Falcon Cloud, Lacework, or equivalent) with a strong opinion on what good looks like.
Identity first security mindset and demonstrated ability to build identity and access management solutions at scale.
Humility and genuine curiosity. You're as excited to learn from engineers across product and infrastructure and enable their work as you are to write detections or design guardrails.
Bonus Points
Experience designing or operating Zero Trust Network Access (Cloudflare Access, Tailscale, Twingate, Google BeyondCorp, etc.).
Detection engineering background with a threat modeling and adversarial mindset - writing detections that actually fire on real attacker behavior without burying the team in noise.
Experience securing AI and machine learning pipelines, agent frameworks, or MCP-style integrations that touch production data.
Familiarity with SOC 2, SOX, or other compliance frameworks in cloud environments and an instinct for when compliance work creates real security value.
Open source contributions to cloud security tooling (Cartography, Prowler, ScoutSuite, Falco, Kyverno, Open Policy Agent, Checkov, etc.).
Location
This role is based in our Seattle office, in-person four days per week (Monday, Tuesday, Thursday, Friday). Candidates must be based within commuting distance of the office.
About Opendoor
At Opendoor our mission is to tilt the world in favor of homeowners and those who aim to become one. Homeownership matters. It's how people build wealth, stability, and community. It's how families put down roots, how neighborhoods strengthen, how the future gets built. We're building the modern system of homeownership giving people the freedom to buy and sell on their own terms. We've built an end-to-end online experience that has already helped thousands of people and we're just getting started.
$159.3k - $202.4k
The AWS Cloud Security Response team operates on the ‘AWS’ side of the Shared Responsibility... ...security of AWS Cloud services. Our engineers independently investigate and resolve... ...service code, security data, and cloud infrastructure at massive scale. This role goes beyond...SuggestedInternshipFlexible hoursShift work- ...cybersecurity team where your expertise in cryptographic infrastructure and secure hardware directly protects the financial systems trusted by... ...millions of people around the globe.As a Sr Lead Security Engineer at JPMorganChase within the Cybersecurity & Technology Controls...Suggested
- We are seeking to expand our diverse team of Security Engineers dedicated to understanding and defending against contemporary cyber threats... ...execute various projects to improve the data protection infrastructure and boost efficiency and detection rates. Enjoy the freedom...SuggestedRemote work
$183k - $247.6k
...inventive research and development organization that designs and engineers high-profile consumer electronics. Starting with the best-... ...more. The RoleAre you interested in being part of a top-notch security team covering all Amazon devices? If you want to keep customers...SuggestedLocal areaFlexible hours$116.1k - $158.2k
...design, governance, and onboarding standardsEstablish engineering standards for identity, networking, monitoring, resiliency... ..., and operational supportPartner with architecture, infrastructure, networking, and security teams to deliver scalable cloud solutionsEnable and...SuggestedFull timeContract workLocal areaFlexible hours- ...we areAbout StripeStripe is a financial infrastructure platform for businesses. Millions of... ...sensitive financial or personal data—making security a top priority for Stripe.Stripe will... ...worthy of our users' trust. As an engineer on the Security team, you'll design and...
$165k - $242k
...Senior Security Engineer II, Cloud Security Livingston, NJ / New York, NY / Sunnyvale, CA / Bellevue, WA CoreWeave is The Essential... ...startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate...Permanent employmentFull timeTemporary workCasual workWork at officeFlexible hours$117.2k - $176.7k
...you are the future of Salesforce.The ExperienceSalesforce is seeking a Software Engineer (MTS) to design and build compliance automation on the Salesforce Platform within Product Security. This role is ideal for a Salesforce Platform Developer who wants to apply their...Full time- ...goals. Whoever deploys frontier compute infrastructure fastest will decide whether AI expands... ...to push the frontier forward. The Security Team Examples of key problems the team... ...make the secure path the fast path for engineers. Engineer detection and response...
$169.6k - $253k
...The Security Team of Scopely Explore (formerly known as Niantic) seeks a Cloud Security Engineer to improve the security stance of our infrastructure and production environments. Scopely Explore Engineering leads the development and operation of multiple successful mobile...Work at officeLocal areaImmediate startWorldwideFlexible hours$162k - $235k
...Senior Cloud Security Engineer Aurora's mission is to deliver the benefits of self-driving technology safely, quickly, and broadly.... ...security systems at scale. Cloud security collaborates with infrastructure and application teams closely. The areas we cover are...Work at officeLocal area3 days per week$117k - $156k
...com.Get to know the roleJob Title: Cloud Information Security EngineerJob Summary: Develops and executes security... ...applicable experience.Strong background in technical engineering and architecture, such as infrastructure/cloud engineering or software development.Proven...Temporary workRelocation package$137.7k - $186.3k
Mid-Level or Senior Product Security Engineer - Public Key Infrastructure (PKI) and Cloud ArchitectCompany:The Boeing CompanyBoeing Commercial Airplanes is seeking a Mid-Level (Level 3) or Senior(Level 4 or Level 5)Product Security Engineer - Public Key Infrastructure (...Permanent employmentFull timeWork experience placementCurrently hiringRelocationVisa sponsorshipWork visaFlexible hoursShift work- ...Job Description- IaC Security Scanning & Hardening: Integrate IaC security scanning tools (e.g., Checkov, TFSec, Snyk IaC, Terraform Validator) into CI/CD pipelines. Analyze and remediate findings from IaC scans (Terraform, CloudFormation, ARM templates). Develop...
- Brighton Jones is seeking a Sr. Systems Engineer to own and advance a scalable, secure hybrid infrastructure across on‑prem and cloud platforms including Azure, AWS, and M365. You will partner with Data & Analytics, Applications, Development, and Operations teams to deliver...
- A technology company in Seattle is seeking a proactive Cybersecurity Engineer to design and maintain technical security controls across their cloud infrastructure. The role involves ensuring compliance with SOC 2, HIPAA, and PCI DSS while supporting DevOps workflows. Strong...Remote job
$150k - $250k
What We Do At Goldman Sachs, our Engineers don’t just make things - we make things possible... ...and systems, architect low‑latency infrastructure solutions, proactively guard against cyber... ...services in public cloud safely and securely. We are at an early stage of modernizing...Full timeTemporary workPart timeWork experience placementShift work$127k - $249k
We are hiring an experienced Security Software Engineer (Staff or Senior) for our Infrastructure Security team to design and build scalable security controls and services within MongoDB Atlas multi-cloud infrastructure.The team sits within the Site Reliability Engineering...Work at officeLocal areaRemote workWorldwideFlexible hours- A leading data and AI infrastructure company in Bellevue, WA is seeking a senior leader to advance their data security initiatives. The role involves identifying key infrastructure... ...talent, and representing security engineering across the organization. Candidates should...
- Oracle Government Defense & Intelligence seeks a Principal Application Software Engineer to design, build, and operate secure cloud application services for sovereign environments. This senior contributor leads complex design, guides engineers, and resolves production issues...
$130k - $155k
...00.00/yr About Ascendion Ascendion is a full-service digital engineering solutions company. We make and manage software platforms and products... ...to be their best at Ascendion. About the Role Job Title: Security Engineer/ Azure Security Engineer At least 10 years combined...Full timeTemporary workWork experience placement- Oracle is seeking a Principal Software Development Engineer to lead the architecture and delivery of OCI’s... ...cryptographic components, HSM integration, and secure key lifecycle management across Oracle's cloud infrastructure and customers. You will drive end-to-end design,...
$60 - $63 per hour
A major retail company in Seattle is seeking an experienced Cyber Security Platform Engineer to bolster its enterprise security initiatives. The role requires expertise in cloud security, with an emphasis on implementing Zero Trust strategies and optimizing security platforms...Hourly payContract work- ...financial services firm in Seattle seeks a Senior Systems Engineer to develop and support a scalable infrastructure. This in-office role requires 8+ years of... ...maintaining hybrid IT infrastructure, implementing cloud security, and enhancing system performance. The firm offers...Work at office
$150k - $250k
The Goldman Sachs Group is seeking experienced engineers for a pivotal role in Seattle, focusing on cloud security architecture and the integration of AWS services. The ideal candidate will have over 6 years of experience in a dynamic DevOps environment, driving the development...$130k - $155k
A digital engineering solutions company is seeking a Security Engineer in Seattle, WA. This role requires extensive experience in IT and Cybersecurity, focusing on Azure technologies. Responsibilities include designing secure Azure environments and collaborating with DevOps...$142k - $220.5k
Job DescriptionNordstrom's Security Platform Engineering team is hiring a Sr. Technical Program Manager to serve as the operational backbone of... ...program management, preferably within a security, infrastructure, or platform engineering organization Demonstrated ability...Full timeFor contractors- Washington Department of Fish and Wildlife is seeking a Security Operations Engineer to design, implement, and monitor application security across on‑premises and cloud environments in a hybrid work model. The role collaborates with incident response, architecture, and...Remote work
- GEICO in Seattle seeks a Sr. Staff Engineer, Operations to lead platform security initiatives and build an operational excellence environment as we transition to an engineering-led security model. You will collaborate with CSIRT, GRC, and delivery teams to implement controls...
- Responsibilities Develops, implements, and sustains product security and resiliency throughout the requirements, design, build, test... ...innovative solutions. Requirements Bachelor of Science degree in Engineering, Engineering Technology (including Manufacturing Technology),...Work experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Infrastructure Security Engineer. Be the first to apply!
- infrastructure engineering manager Seattle, WA
- data infrastructure engineer Seattle, WA
- security infrastructure engineer Seattle, WA
- senior infrastructure engineer Seattle, WA
- remote infrastructure engineer Seattle, WA
- lead infrastructure engineer Seattle, WA
- entry level infrastructure engineer Seattle, WA
- infrastructure automation engineer Seattle, WA
- infrastructure engineer Seattle, WA
- principal infrastructure engineer Seattle, WA


