Demo

Application Security Engineer

Opal Security
San Francisco, CA Full Time
POSTED ON 5/22/2026
AVAILABLE BEFORE 6/19/2026
About Opal Security

At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation.

The Role

Most security engineers spend their careers bolting locks onto doors that were already built. This is not that job.

We're hiring an Application Security Engineer to own security across Opal's product and platform — and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed. You’ll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software.

Oh, and one more thing: Opal is a security company. We sell access control to organizations that take security seriously. That means your work isn't a cost center — it's core to what we do.

This role lives on the Platform team and partners closely with Infrastructure Engineering on cloud security. It is explicitly scoped to application and product security — enterprise IT, compliance, and vendor risk management are handled separately.

What You’ll Do

Secure Development Lifecycle -

  • Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews — you set the bar
  • Run and coordinate app pentests (internal and external) and drive findings to closure
  • Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code
  • Triage and remediate vulnerabilities from every angle — bug bounty, internal scans, the works

Software Security Engineering -

  • Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows
  • Own the Auth0 ↔ Opal integration — tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)
  • Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good
  • Create shared libraries that make the secure path the easy path for every product engineer

Incident Response & Cloud Security -

  • Be first on the scene for security incidents: investigate, contain, find the root cause, fix it
  • Partner with Infra on cloud hardening — AWS IAM, EKS, KMS, network segmentation
  • Level up detection and response by writing detection rules and improving logging and alerting

Security Culture -

  • Mentor engineers on secure coding, common vuln patterns, and security architecture — you make the org smarter
  • Help set the security roadmap by grounding it in real product risk
  • Be the security teammate engineers want to work with — a collaborator, not a bottleneck

You Might Be a Fit If You

  • Have 4 years in application security or software security engineering
  • Actually write production code — findings reports are the floor, not the ceiling
  • Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle
  • Are comfortable in AWS and containerized environments (Kubernetes, Docker)
  • Bonus points for familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL
  • Have led complex, cross-functional security initiatives from kickoff to completion
  • Have run or participated in external pentests and seen findings through remediation
  • Thrive on ownership and ambiguity — you'd rather write the playbook than wait for one

Salary.com Estimation for Application Security Engineer in San Francisco, CA
$112,410 to $143,436
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Application Security Engineer?

Sign up to receive alerts about other jobs on the Application Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$88,984 - $115,784
Income Estimation: 
$111,369 - $141,168
Income Estimation: 
$117,871 - $153,580
Income Estimation: 
$109,939 - $144,341
Income Estimation: 
$114,500 - $144,633
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Opal Security

  • Opal Security San Francisco, CA
  • The Role Our BDRs are often the first voice prospects hear from Opal Security. Your job is to turn curiosity into real interest — helping potential custome... more
  • 2 Days Ago

  • Opal Security San Francisco, CA
  • About Opal Security At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast ... more
  • 3 Days Ago

  • Opal Security San Francisco, CA
  • About Opal Security At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast ... more
  • 4 Days Ago

  • Opal Security San Francisco, CA
  • About Opal Security At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast ... more
  • 10 Days Ago


Not the job you're looking for? Here are some other Application Security Engineer jobs in the San Francisco, CA area that may be a better fit.

  • Veeam Software San Francisco, CA
  • Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enab... more
  • 16 Days Ago

  • Benchling San Francisco, CA
  • Application Security Engineer Location San Francisco, CA Employment Type Full time Location Type Hybrid Department Engineering Compensation $147K – $200K •... more
  • 17 Days Ago

AI Assistant is available now!

Feel free to start your new journey!