hirly

Opal

Application Security Engineer

San Francisco

Apply through hirly

hirly scores this role against your resume, shows its reasoning, then writes a resume and cover letter for it and fills the application with you. Free to start — no card required.

hirly's read of this role

Role family
Engineering
Seniority
Mid level
Country
US
Work mode
Remote-friendly
First seen by hirly
1 Sept 2026

Derived automatically from the posting. Sign up to see how the role scores against your own resume.

the posting

About Opal Security:

At Opal, we’re building modern identity governance for the AI era—intelligent access management that empowers enterprises to move fast while staying secure. Our mission is to bring clarity, control, and confidence to complex enterprise environments, helping teams govern access without slowing down innovation.

The Role:

Most security engineers spend their careers bolting locks onto doors that were already built. This is not that job.

We're hiring an Application Security Engineer to own security across Opal's product and platform — and yes, own means what it sounds like. You'd be our dedicated security engineer, embedded directly with engineering, writing production code in Go and TypeScript, and building security into the product while it's still being designed. You’ll work closely with a team of engineers that genuinely care about getting this right, and a product that happens to be one of the most security-critical tools in enterprise software.

Oh, and one more thing: Opal is a security company. We sell access control to organizations that take security seriously. That means your work isn't a cost center — it's core to what we do.

This role lives on the Platform team and partners closely with Infrastructure Engineering on cloud security. It is explicitly scoped to application and product security — enterprise IT, compliance, and vendor risk management are handled separately.

What You’ll Do:

Secure Development Lifecycle -

Own the secure SDLC end-to-end: threat modeling, design reviews, code reviews — you set the bar

Run and coordinate app pentests (internal and external) and drive findings to closure

Build and own SAST/DAST/SCA tooling wired into CI/CD so security ships with the code

Triage and remediate vulnerabilities from every angle — bug bounty, internal scans, the works

Software Security Engineering -

Build and maintain the security-critical stuff: encryption services, authz enforcement, authn flows

Own the Auth0 ↔ Opal integration — tokens, sessions, MFA, SSO (SAML, OIDC, OAuth 2.0)

Ship production Go and TypeScript to harden APIs, enforce least-privilege, and close vuln classes for good

Create shared libraries that make the secure path the easy path for every product engineer

Incident Response & Cloud Security -

Be first on the scene for security incidents: investigate, contain, find the root cause, fix it

Partner with Infra on cloud hardening — AWS IAM, EKS, KMS, network segmentation

Level up detection and response by writing detection rules and improving logging and alerting

Security Culture -

Mentor engineers on secure coding, common vuln patterns, and security architecture — you make the org smarter

Help set the security roadmap by grounding it in real product risk

Be the security teammate engineers want to work with — a collaborator, not a bottleneck

You Might Be a Fit If You:

Have 4+ years in application security or software security engineering

Actually write production code — findings reports are the floor, not the ceiling

Know auth cold: OAuth 2.0, OIDC, SAML, session management, token lifecycle

Are comfortable in AWS and containerized environments (Kubernetes, Docker)

Bonus points for familiarity with our stack: Go, TypeScript, React, PostgreSQL, Redis, GraphQL

Have led complex, cross-functional security initiatives from kickoff to completion

Have run or participated in external pentests and seen findings through remediation

Thrive on ownership and ambiguity — you'd rather write the playbook than wait for one

Is this role actually a fit for you?

hirly answers with a score and its reasoning, then writes the resume and cover letter if you decide to go for it.

Score it against my resume
Application Security Engineer at Opal — hirly